Back to homepage
UK GDPR · PECR compliant

Privacy policy.

What we collect, what we do with it, and what we'll never do. Written in plain English — no legal sleight of hand.

Effective: 1 May 2026 Last updated: 13 May 2026 Version 1.0
The short version
  • We collect your name, email, and the numbers you enter into our calculator — nothing more.
  • We use that data to email you your report and occasionally send relevant clinic-growth content. You can unsubscribe in one click, anytime.
  • We never sell your data. Ever.
  • You have the right to see, correct, or delete everything we hold on you.
  • The full detail is below if you want it. Or email us with any question.

01 Who we are

ClinicGrow is a trading name operated by Malki Web Design, providing front-desk automation and CRM services to dental practices, aesthetics clinics, and medical professionals across the United Kingdom.

For the purposes of UK GDPR, ClinicGrow is the data controller for personal data collected through this website (clinicgrow.co.uk).

Get in touch about your data

For any data protection questions, requests, or concerns:

02 What we collect

We try to collect the absolute minimum needed to give you what you asked for. Here's the complete list:

When you use our ROI calculator

Data type
Examples
Source
Identity
Full name, email address
You enter it
Calculator inputs
Weekly appointments, no-show rate, treatment focus, average appointment value, marketing spend by channel
You enter it
Calculated outputs
Estimated monthly/annual loss, recovery projection, ROI calculations
Derived from your inputs
Consent record
Timestamp and IP address when you ticked the consent box
Automatically logged

When you book a demo

  • Identity: Name, email, phone number, clinic name
  • Booking metadata: Date/time of demo, timezone
  • Notes: Anything you write in the booking form's notes field

When you contact us by email, WhatsApp, or the contact form

  • The contact details you provide
  • The content of your message

When you visit the website

  • Standard server logs: IP address, browser type, pages visited, time spent — kept for 30 days for security and analytics
  • Cookies and similar technologies — see Section 8 below

We do NOT collect: patient health information, financial account details, payment card numbers (handled directly by Stripe), or any "special category" personal data under UK GDPR Article 9.

03 Why we collect it (and our legal basis)

Under UK GDPR, we need a lawful basis for every type of processing. Here's ours:

Purpose
What we do
Legal basis
Deliver your ROI report
Email your personalised report and breakdown after you submit the calculator
Consent (UK GDPR Art. 6(1)(a))
Marketing follow-up
Occasional emails with clinic-growth tips, case studies, and product updates
Consent (UK GDPR Art. 6(1)(a) + PECR Reg. 22)
Demo & sales process
Confirm bookings, prepare for the call, follow up afterwards
Legitimate interests (UK GDPR Art. 6(1)(f)) — providing a service you requested
Service delivery
Once you become a client, deliver and support the ClinicGrow platform
Contract (UK GDPR Art. 6(1)(b))
Legal compliance
Accounting records, tax returns, responding to legal requests
Legal obligation (UK GDPR Art. 6(1)(c))
Site security & analytics
Server logs, performance monitoring, anonymous traffic analysis
Legitimate interests (UK GDPR Art. 6(1)(f))

04 Who we share data with

We don't sell your data. We do share it with specific third-party services that help us run ClinicGrow. Each one is contractually bound to protect your data and use it only for the purposes we instruct. These are our sub-processors:

Pabbly Connect
India

Automation platform that receives calculator form submissions and triggers your report email.

Their privacy policy
GoHighLevel (GHL)
USA

CRM and email delivery platform — sends your report email and any follow-up communication.

Their privacy policy
Google (Workspace, Analytics)
EU / USA

Email infrastructure (hello@ inbox) and website analytics.

Their privacy policy
Meta (Facebook/Instagram)
EU / USA

Advertising platform — only if you arrived via a Meta ad and only with cookie consent.

Their privacy policy
Stripe
EU / USA

Payment processing for clients only. We never see your full card details.

Their privacy policy
Hosting & infrastructure
UK / EU

Website hosting and SSL certificates. Standard log retention (30 days).

Details on request

International transfers: Some sub-processors are based outside the UK or EEA. Where this happens, we rely on UK-approved transfer mechanisms (UK International Data Transfer Agreement, EU Standard Contractual Clauses with the UK Addendum, or Adequacy Decisions). You can request the specific safeguards used for any transfer.

05 How long we keep it

We don't keep data longer than necessary. Here's our retention schedule:

  • Calculator submissions & enquiries: 24 months from last interaction, then deleted unless you become a client
  • Marketing email list: Until you unsubscribe (one click in any email)
  • Demo bookings (no follow-up): 12 months
  • Client account data: For the duration of our contract plus 6 years (required by HMRC for accounting records)
  • Server logs: 30 days
  • Consent records: Kept as long as we hold any other data on you, so we can prove consent was given

06 Your rights

Under UK GDPR, you have eight statutory rights over your personal data. You can exercise any of these for free by emailing hello@clinicgrow.co.uk — we'll respond within one calendar month.

Right to be informed

This policy is part of that. Ask if anything's unclear.

Right of access

Request a copy of everything we hold on you.

Right to rectification

Tell us to correct any inaccurate data.

Right to erasure

"Right to be forgotten" — ask us to delete everything.

Right to restriction

Tell us to pause processing while a dispute is resolved.

Right to data portability

Get your data in a machine-readable format to take elsewhere.

Right to object

Object to processing based on legitimate interests, including marketing.

Rights re: automated decisions

We don't make solely automated decisions about you. The ROI calculator is illustrative, not a binding judgement.

Not satisfied with how we've handled your data?

You have the right to complain to the UK's data protection authority, the Information Commissioner's Office (ICO). Visit ico.org.uk or call 0303 123 1113. We'd appreciate the chance to put things right first — but it's your call.

07 How we keep it safe

We take reasonable, proportionate measures to protect your data:

  • Encryption in transit: All data sent to and from our website uses HTTPS/TLS
  • Encryption at rest: Stored data is encrypted at our sub-processors' infrastructure level
  • Access control: Only people who need access have access. Strong passwords and two-factor authentication are mandatory
  • Vendor due diligence: We only use sub-processors with credible security practices and Data Processing Agreements in place
  • Minimisation: We collect the least amount of data needed for each purpose

No system is completely secure, and if a personal data breach affects you, we'll notify you and the ICO within 72 hours where required by law.

08 Cookies & tracking

Cookies are small files stored on your device. We use a small number, grouped by category:

Category
Purpose
Requires consent?
Strictly necessary
Keeping the website running — session management, security, form submissions
No (essential)
Analytics
Anonymous traffic analysis (e.g. Google Analytics) so we can improve the site
Yes
Advertising
Meta Pixel, Google Ads conversion tracking — only set if you accept cookies
Yes

You can control cookies through your browser settings or, where available, our cookie banner. Blocking strictly necessary cookies may break parts of the site.

09 Children

This site and our services are not directed at children under 18. We don't knowingly collect data from anyone under 18. If you believe we have, please email us and we'll delete it.

10 Changes to this policy

We may update this policy from time to time — to reflect new features, legal changes, or improvements to how we explain things. The "Last updated" date at the top will always reflect the latest version. Material changes will be notified by email to active subscribers and clients.

11 Contact us

Any question about this policy, your data, or how to exercise your rights:

ClinicGrow — data protection contact

We aim to respond to all data protection enquiries within 5 working days, and to formal rights requests within one calendar month as required by UK GDPR.