What we hold, why we hold it, who can see it, and how to make us stop. Written to be read, not skimmed past.
WA\ is a clinical platform. Clinics use it to run their practice, clinicians use it to see patients and write up their work, and the people those clinics care for use it to hold their own record. This policy explains what happens to personal information across all of that: the website at wellnessa-i.com, the WA\ platform, and the three mobile apps — WA\ Profile for people receiving care, WA\ Clinicians for practitioners, and WA\ Admin for clinic staff.
It does not cover the clinics themselves. Each clinic on WA\ decides how it delivers care and publishes its own privacy notice for its patients. Where the two differ on matters of clinical care, your clinic’s notice governs the care and this one governs the platform underneath it.
Data-protection law splits responsibility in two, and the split matters because it determines who you ask for what.
Your clinic is the controller. It decides what goes in your record and how long it stays. WA\ is the processor: we hold and move that data strictly on the clinic’s instructions, under a written data-processing agreement. Requests about your medical record go to your clinic; we will help them answer.
For the public website, sales enquiries, clinician sign-ups, demo requests, referrals, support tickets and the running of the platform itself, WA\ is the controller and this policy is the whole answer.
What we hold depends entirely on which of those you are.
We do not collect precise location, we do not read your contacts or photo library beyond the files you choose to upload, and we run no advertising or tracking software anywhere on the platform or in the apps.
We do not sell personal data. We do not share it with data brokers. We do not use clinical data to advertise anything to anyone.
Where WA\ is the controller, we rely on:
Running an account you or your clinic asked us to run.
Keeping the platform secure and working, and responding to enquiries you send us — balanced against your interests, and never used for clinical data.
Marketing email, and anything optional such as notifications. You can withdraw it at any time without affecting your care or your account.
Tax, accounting, and responding to lawful requests.
Health data carries a higher bar. Where it is processed on a clinic’s instruction, the basis is the provision of healthcare by, or under the responsibility of, professionals bound by a duty of confidentiality — with the clinic accountable for it.
The apps ask for a small number of device permissions, each tied to one feature. Every one can be refused, and refusing it disables only that feature.
Locks the app on your device. The biometric check happens on the phone; we never receive your face or fingerprint data.
Only the images you deliberately attach — a photograph for your clinician, a document upload. We do not browse your library.
WA\ Clinicians only, and only during a consultation the clinician has explicitly started, with consent in place. There is no background listening in any of the apps.
Optional. If enabled, the device token is stored so a new message or an upcoming appointment can reach you. Notification content is kept deliberately thin.
You can delete your WA\ Profile account from Settings inside the app. Deleting it closes your access immediately. Your clinical record itself belongs to your clinic and is kept for as long as healthcare record-retention rules require, then destroyed — see how long we keep it.
WA\ uses AI models to draft clinical notes and letters, summarise records, suggest replies and answer questions. Three commitments govern all of it:
We share personal data only with organisations that help us run the platform, each under a contract that binds them to our instructions and to confidentiality:
Beyond that, we disclose data only where the law requires it, where it is necessary to protect someone from serious harm, or where you or your clinic instruct us to. If the business is ever reorganised or acquired, data may pass to the successor under the same commitments, and you will be told. A current list of the providers we use is available on request at hello@wellnessa-i.com.
Clinical records are stored in the region their clinic operates in. Some of the providers above operate outside that region, so data may be transferred internationally. Where it is, we rely on approved safeguards — the UK International Data Transfer Agreement or the addendum to the EU Standard Contractual Clauses, together with technical protections such as encryption in transit and at rest.
Encryption in transit and at rest, role-based least-privilege access, an immutable audit trail, passwordless sign-in with optional biometric locking on device, and engineering access to production data only through audited break-glass procedures. More detail is on the security page. No system is perfect; if a breach affects you, we will tell you and the regulator within the time the law allows.
Depending on where you live, you can ask us to:
Exercising any of these is free and we will answer within one month. If your request concerns your medical record, send it to your clinic — they are the controller, and we support them in answering. For everything else, write to hello@wellnessa-i.com.
The website uses only what it needs to work: cookies and local storage that keep you signed in and keep the site secure. We run no advertising cookies and no cross-site tracking. The apps use secure on-device storage for your session rather than cookies.
The apps are not intended for children to use on their own. Where a clinic provides care to someone under 16, access is arranged through a parent or guardian, and the clinic decides what is appropriate. If you believe a child has created an account without that arrangement, contact us and we will close it.
When this policy changes materially we will update the effective date above and, where the change affects you, tell you in the app or by email before it takes effect. Older versions are available on request.
Write to hello@wellnessa-i.com with anything about this policy, a request about your data, or a concern about how we have handled it. We would always rather hear it first.
If you are in the UK and we have not resolved it, you can complain to the Information Commissioner’s Office at ico.org.uk. If you are in the EEA, you can complain to your national supervisory authority.