Privacy Policy
Last updated: March 2026
Who we are
ClinicRev is operated by Dr Matt George. Our website address is clinicrev.co.uk. We provide a revenue automation service for aesthetic clinics in the United Kingdom.
For any questions about this privacy policy or how we handle your data, contact us at hello@clinicrev.co.uk.
What data we collect
When you use our website or contact us, we may collect the following information:
- Your name and clinic name
- Email address
- Phone number (if provided)
- Any information you include in messages to us
We do not collect any data automatically through cookies or tracking scripts on this website beyond what is necessary for the site to function.
How we use your data
We use the information you provide to:
- Respond to your enquiry
- Arrange a demonstration of the ClinicRev system
- Send you information about our services that you have requested
- Set up and manage your account if you become a client
We will not send you unsolicited marketing communications. We will only contact you in relation to an enquiry you have made or a service you have subscribed to.
Lawful basis for processing
We process your personal data on the basis of legitimate interest (responding to your enquiry and providing a service you have requested) and, where applicable, on the basis of a contract between us.
Client clinic data
Where a clinic subscribes to ClinicRev, patient contact data may be processed by the system on behalf of the clinic. In this case, the clinic is the data controller and ClinicRev acts as data processor. A Data Processing Agreement is issued and signed before any patient data is transferred. This agreement sets out the data processed, the purpose, security measures, retention, and obligations on termination.
Patient data is:
- Used solely to operate the sequences configured for that clinic
- Never shared with any third party or any other clinic
- Never used for any purpose other than delivering the service to that specific clinic
- Returned or deleted in full on request or at the end of the agreement
Data sharing
We do not sell, rent, or share your personal data with any third parties for marketing purposes. Data may be processed by the following service providers who act as sub-processors:
- Our CRM, messaging, and automation infrastructure provider, used to operate the patient communication sequences
- Cloudflare, used for website hosting
These providers are contractually bound to process data only as instructed and to maintain appropriate security measures. The full list of named sub-processors, including the underlying CRM and infrastructure provider, is disclosed to clients in the Data Processing Agreement issued at onboarding.
Data retention
Enquiry data is retained for up to 12 months after your last contact with us, unless you ask us to delete it sooner. Client data is retained for the duration of the service agreement and deleted within 30 days of termination unless otherwise agreed.
Your rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict the processing of your data
- Request a copy of your data in a portable format
- Withdraw consent at any time where consent is the basis for processing
To exercise any of these rights, contact us at hello@clinicrev.co.uk. We will respond within 30 days.
Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated revision date.