Legal

Privacy policy

What we hold, why we hold it, who can see it, and how to make us stop. Written to be read, not skimmed past.

Effective 28 July 2026 · Applies to wellnessa-i.com and the WA\ apps

Who this covers

WA\ is a clinical platform. Clinics use it to run their practice, clinicians use it to see patients and write up their work, and the people those clinics care for use it to hold their own record. This policy explains what happens to personal information across all of that: the website at wellnessa-i.com, the WA\ platform, and the three mobile apps — WA\ Profile for people receiving care, WA\ Clinicians for practitioners, and WA\ Admin for clinic staff.

It does not cover the clinics themselves. Each clinic on WA\ decides how it delivers care and publishes its own privacy notice for its patients. Where the two differ on matters of clinical care, your clinic’s notice governs the care and this one governs the platform underneath it.

Controller or processor

Data-protection law splits responsibility in two, and the split matters because it determines who you ask for what.

Clinical records

Your clinic is the controller. It decides what goes in your record and how long it stays. WA\ is the processor: we hold and move that data strictly on the clinic’s instructions, under a written data-processing agreement. Requests about your medical record go to your clinic; we will help them answer.

Everything else

For the public website, sales enquiries, clinician sign-ups, demo requests, referrals, support tickets and the running of the platform itself, WA\ is the controller and this policy is the whole answer.

What we hold

What we hold depends entirely on which of those you are.

If you visit the website

  • Anything you type into a form: name, email, phone, clinic, and what you asked us.
  • Basic technical information your browser sends — IP address, device and browser type, pages viewed — used to keep the site up and secure.

If you use WA\ Profile as a patient

  • Who you are: name, email, phone, date of birth, and the identifiers your clinic uses for you.
  • Your clinical record as your clinic maintains it: appointments, consultation notes, results, medications, allergies, conditions, letters and documents.
  • What you send: secure messages to your care team, questionnaire and intake answers, photographs you upload, and conversations with the in-app assistant.
  • Billing information: invoices, orders and payment status. Card details are handled by the payment provider and never stored by us.
  • Device tokens, if you turn on notifications, so a message can reach your phone.

If you are a clinician or clinic staff member

  • Your professional identity: name, work email, registration and role, and your signature if you sign documents through the platform.
  • Your work on the platform: notes, letters, prescriptions, approvals, messages, and the audit trail of what you did and when.
  • Recordings and transcripts of consultations, where the clinician has started a recording and consent for it is in place.

We do not collect precise location, we do not read your contacts or photo library beyond the files you choose to upload, and we run no advertising or tracking software anywhere on the platform or in the apps.

Why we use it

  • To provide the platform: showing you your record, delivering messages, booking appointments, producing letters and documents, taking payment.
  • To keep it safe: authentication, fraud and abuse prevention, audit logging, backups.
  • To support you: answering questions you send us, and diagnosing faults you report.
  • To improve the product: understanding which parts are used and where they fail. This work uses aggregated or de-identified information wherever it possibly can.
  • To meet legal and clinical-governance obligations, including record-keeping duties that apply to healthcare.

We do not sell personal data. We do not share it with data brokers. We do not use clinical data to advertise anything to anyone.

Our legal bases

Where WA\ is the controller, we rely on:

Contract

Running an account you or your clinic asked us to run.

Legitimate interests

Keeping the platform secure and working, and responding to enquiries you send us — balanced against your interests, and never used for clinical data.

Consent

Marketing email, and anything optional such as notifications. You can withdraw it at any time without affecting your care or your account.

Legal obligation

Tax, accounting, and responding to lawful requests.

Health data carries a higher bar. Where it is processed on a clinic’s instruction, the basis is the provision of healthcare by, or under the responsibility of, professionals bound by a duty of confidentiality — with the clinic accountable for it.

The mobile apps

The apps ask for a small number of device permissions, each tied to one feature. Every one can be refused, and refusing it disables only that feature.

Face ID / Touch ID

Locks the app on your device. The biometric check happens on the phone; we never receive your face or fingerprint data.

Camera and photos

Only the images you deliberately attach — a photograph for your clinician, a document upload. We do not browse your library.

Microphone

WA\ Clinicians only, and only during a consultation the clinician has explicitly started, with consent in place. There is no background listening in any of the apps.

Notifications

Optional. If enabled, the device token is stored so a new message or an upcoming appointment can reach you. Notification content is kept deliberately thin.

You can delete your WA\ Profile account from Settings inside the app. Deleting it closes your access immediately. Your clinical record itself belongs to your clinic and is kept for as long as healthcare record-retention rules require, then destroyed — see how long we keep it.

How AI is used

WA\ uses AI models to draft clinical notes and letters, summarise records, suggest replies and answer questions. Three commitments govern all of it:

  • A human signs. Nothing clinical — no note, letter, prescription or released result — leaves the platform without an authenticated clinician reviewing and signing it. The model proposes; a person decides.
  • Your data does not train anyone’s model. We use model providers under agreements that prohibit training on the content we send them, and we send only what the task needs.
  • It is recorded. Where AI contributed to a document, that is visible in the audit trail.

Who else sees it

We share personal data only with organisations that help us run the platform, each under a contract that binds them to our instructions and to confidentiality:

  • Cloud hosting and database providers, which store the platform’s data.
  • AI model providers, which process the specific text or audio needed to produce a draft or an answer.
  • Communication providers for email, secure messaging, video consultations and speech-to-text.
  • Payment providers, which handle card details directly so that we do not hold them.

Beyond that, we disclose data only where the law requires it, where it is necessary to protect someone from serious harm, or where you or your clinic instruct us to. If the business is ever reorganised or acquired, data may pass to the successor under the same commitments, and you will be told. A current list of the providers we use is available on request at hello@wellnessa-i.com.

Where it is stored

Clinical records are stored in the region their clinic operates in. Some of the providers above operate outside that region, so data may be transferred internationally. Where it is, we rely on approved safeguards — the UK International Data Transfer Agreement or the addendum to the EU Standard Contractual Clauses, together with technical protections such as encryption in transit and at rest.

How long we keep it

  • Clinical records are kept for the period the clinic’s regulatory retention schedule requires, then securely destroyed. The clinic sets this, not us.
  • Account and access data is kept while the account is active, and removed after closure other than what we must keep.
  • Audit logs are retained as long as clinical governance requires, because their purpose is to show who did what.
  • Enquiries and marketing contacts are kept for up to two years after our last contact, or until you unsubscribe.
  • Financial records are kept for the period tax law requires.

How it is protected

Encryption in transit and at rest, role-based least-privilege access, an immutable audit trail, passwordless sign-in with optional biometric locking on device, and engineering access to production data only through audited break-glass procedures. More detail is on the security page. No system is perfect; if a breach affects you, we will tell you and the regulator within the time the law allows.

Your rights

Depending on where you live, you can ask us to:

  • Give you a copy of the personal data we hold about you, in a portable form.
  • Correct anything inaccurate.
  • Delete it, where no legal or clinical duty requires us to keep it.
  • Restrict or object to a use of it, including profiling.
  • Withdraw a consent you gave, at any time.

Exercising any of these is free and we will answer within one month. If your request concerns your medical record, send it to your clinic — they are the controller, and we support them in answering. For everything else, write to hello@wellnessa-i.com.

Cookies

The website uses only what it needs to work: cookies and local storage that keep you signed in and keep the site secure. We run no advertising cookies and no cross-site tracking. The apps use secure on-device storage for your session rather than cookies.

Children

The apps are not intended for children to use on their own. Where a clinic provides care to someone under 16, access is arranged through a parent or guardian, and the clinic decides what is appropriate. If you believe a child has created an account without that arrangement, contact us and we will close it.

Changes to this policy

When this policy changes materially we will update the effective date above and, where the change affects you, tell you in the app or by email before it takes effect. Older versions are available on request.

Contact and complaints

Write to hello@wellnessa-i.com with anything about this policy, a request about your data, or a concern about how we have handled it. We would always rather hear it first.

If you are in the UK and we have not resolved it, you can complain to the Information Commissioner’s Office at ico.org.uk. If you are in the EEA, you can complain to your national supervisory authority.