Wellspring Scheduling Ltd —
Consolidated Legal Pack (Draft)
1. Privacy Policy
Effective Date: [Insert Date]
Last Updated: [Insert Date]
1.1 Introduction
Wellspring Scheduling Ltd (“we”, “our”, “us”) provides a scheduling and client management platform for healthcare and therapy professionals. Protecting the privacy and security of your personal and patient data is a priority.
This Privacy Policy explains:
- What information we collect
- How we use it
- Who we share it with
- Your rights under data protection laws
- We are the Data Controller for account and billing data and the Data Processor for patient data entered by our users.
1.2 Information We Collect
- Practitioner / Account Data:
- Name, email, phone
- Business name and address
- Professional registration numbers
- Notes/files uploaded for internal use
- Patient / Client Data (entered by users):
- Name, DOB, contact details
- Medical history and clinical notes
- Consent forms and uploaded documents/images
- Technical / Operational Data:
- AWS-hosted system usage data
- Cookies (essential only)
Note: We do not store credit card information; payments are handled by Stripe, Square, and PayPal.
1.3 Legal Basis for Processing
- Contractual necessity: Providing access and platform functionality
- Legal obligations: Compliance with UK GDPR and health record regulations
- Legitimate interests: Security, fraud prevention, and system improvement
- Explicit consent: Required for processing health data
1.4 Use of Data
- Platform functionality: Scheduling, client management, reporting, billing
- Email & calendar integration (Gmail, Outlook, etc.)
- Security and access control
- Optional features: Telehealth, messaging, AI-assisted tools, other api apps
1.5 Data Sharing / Third-Party Services
We may share or transmit data to:
- Core Platform Services
- AWS (hosting and storage)
- Stripe, Square, PayPal (payment processing)
- Email & Calendar Integrations
- Gmail, Outlook, and other calendar/email platforms
- Data shared only for providing two-way sync and email functionality
Important Notes
- You acknowledge and agree that all third-party providers’ terms and privacy policies apply
- We are not responsible for how third parties process or store data
- Users are responsible for maintaining patient confidentiality and obtaining consent
1.6 Data Storage & Transfers
- Hosted primarily in UK / EU regions
- Data is encrypted where technically feasible (at rest and in transit)
- Backups and redundancy implemented per AWS standard practices
- Transfers outside the UK/EU comply with GDPR standard contractual clauses
1.7 Patient Access
- Patients may log in to view or edit their data if enabled by the practitioner
- Users (practitioners) are responsible for obtaining consent to store and process patient data
- 1.8 Your Rights
- Access, correction, deletion of personal data
- Object to processing
- Data portability requests
- Lodge complaints with the ICO (ico.org.uk)
- Requests can be sent to: privacy@wellspring.bizrar.com
1.9 Data Retention
- Practitioner account data: retained until account closure
- Patient data: retained as required by users and applicable law
- Upon termination: data deleted after 14-day export window, unless retention is required by law
1.10 Security
- Access restricted to authorised personnel
- Industry-standard measures implemented
- Regular system reviews performed
Note: Security measures are described in good faith; audit details may be adjusted as infrastructure matures.
1.11 Cookies
- Only essential cookies used at launch
- Optional analytics/tracking may be added later with explicit consent
- Users can manage cookie preferences in browser settings
- 1.12 International Users
- Governed by England & Wales law
- GDPR and local data protection laws apply for EU users
Lawyer Review Note:
High-risk health professions and patient logins should be reviewed by a UK data protection lawyer to confirm compliance.
2. Terms & Conditions (T&C's)
Effective Date: [Insert Date]
Last Updated: [Insert Date]
2.1 Introduction
By using Wellspring Scheduling Ltd (“we”, “our”, “us”), you (“user”, “practitioner”, “clinic”) agree to these Terms.
This agreement governs:
- Platform access
- Account creation
- Billing and subscription
- Legal responsibilities
2.2 Eligibility
- Healthcare or therapy professional, clinic, or coaching service
- Users must comply with applicable professional standards
- Patients may log in only where enabled by practitioners
2.3 Account Responsibilities
- Keep login credentials secure
- Notify us immediately of unauthorized access
- Ensure data entered is accurate
- Obtain patient consent for data processing
2.4 Acceptable Use
You must not:
- Use the platform for unlawful activity
- Upload illegal, harmful, or non-consensual content
- Attempt to access other users’ accounts or data
- Use platform for life-critical emergency purposes
2.5 Subscription & Billing
- 30-day free trial applies unless otherwise stated
- Subscriptions auto-renew unless cancelled
- Payment processed via Stripe
- Refunds granted case-by-case at our discretion
2.6 Termination & Suspension
We may suspend or terminate accounts for:
- Non-payment
- Breach of terms
- Legal risk
Upon termination:
- 14-day data export window
- Retention for legal obligations
2.7 Liability Limitation
- Liability limited to the maximum extent permitted by law
Excludes:
- Loss of profits or revenue
- Indirect or consequential damages
- Clinical outcomes
- We do not provide medical advice or treatment
2.8 Intellectual Property
- Platform and materials are owned by Wellspring Scheduling Ltd
- Users retain ownership of data they input
- Users grant us a licence to process data per this agreement
2.9 Governing Law & Dispute Resolution
- England & Wales law applies
- Courts of England & Wales have exclusive jurisdiction
2.10 Third-Party Terms & Integrations
By using Wellspring Scheduling Ltd, you acknowledge that your use may involve:
- AWS hosting and storage
- Stripe, Square, or PayPal payment processing
- Gmail, Outlook, or other calendar/email services
- You agree to comply with all third-party terms and privacy policies and understand that Wellspring Scheduling Ltd is not liable for any third-party actions.
- Upon signing up, you agree you have read and agree to the Wellspring Scheduling Ltd Terms & Conditions and acknowledge that you are subject to the terms of any third-party services used, including AWS, Stripe, Square, PayPal, Gmail, and Outlook.
2.11 Future Features
- Telehealth, messaging, and other applications may be added over time
- All disclaimers, user responsibilities, and liability limitations apply to new features
3. Data Processing Agreement
3.1 Parties
- Customer / Practitioner / Clinic = Data Controller
- Wellspring Scheduling Ltd = Data Processor
3.2 Subject Matter & Duration
- Processing of patient data via the platform
- Duration: length of account + retention obligations
3.3 Nature & Purpose
- Scheduling, client management, reporting, billing
- Optional telehealth, messaging, AI, and email/calendar sync
3.4 Categories of Personal Data
Include, but not limited to:
- Patient names
- contact info
- DOB
- clinical notes
- consent forms
- uploaded documents
3.5 Data Controller Obligations
- Ensure lawful collection and processing of patient data
- Obtain necessary consent
- Comply with applicable professional standards
3.6 Processor Obligations
- Process data only per instructions from the Controller
- Implement appropriate technical and organisational measures
- Sub-processors:
- AWS
- Stripe, Square, PayPal
- Gmail, Outlook, calendar services
- Notify of data breaches without undue delay
- Delete or return data upon termination (after 14-day export period)
3.7 Security Measures
- Access limited to authorised personnel
- Encryption implemented where technically feasible
- Regular reviews conducted
- Note: Processor makes no warranties as to absolute security.
3.8 International Transfers
- Transfers outside UK/EU comply with GDPR contractual clauses
3.9 Liability & Indemnity
- Processor liability limited to maximum extent permitted by law
- Customer responsible for clinical outcomes, regulatory compliance, and patient consent
4. Cookie Policy
- Only essential cookies used at launch (login/session)
- Optional analytics/tracking may be added later
- Users can manage cookie preferences in browser settings
5. Medical & AI Disclaimer
The platform does not provide diagnosis, treatment, or medical advice
Users are responsible for:
- Clinical accuracy
- Patient consent
- Regulatory compliance
- AI features are assistive only and do not replace professional judgement
- Telehealth and messaging tools are provided to facilitate communication only
6. Refund & Billing Policy
- 30-day free trial
- Subscriptions auto-renew unless cancelled
- Refunds granted discretionary, case-by-case
- Subscription payments handled via Stripe
- We do not store card details
