Wellspring Scheduling Ltd — 

Consolidated Legal Pack (Draft)

1. Privacy Policy

Effective Date: [Insert Date]
Last Updated: [Insert Date]

1.1 Introduction

Wellspring Scheduling Ltd (“we”, “our”, “us”) provides a scheduling and client management platform for healthcare and therapy professionals. Protecting the privacy and security of your personal and patient data is a priority.

This Privacy Policy explains:

  • What information we collect
  • How we use it
  • Who we share it with
  • Your rights under data protection laws
  • We are the Data Controller for account and billing data and the Data Processor for patient data entered by our users.

1.2 Information We Collect

  • Practitioner / Account Data:
  • Name, email, phone
  • Business name and address
  • Professional registration numbers
  • Notes/files uploaded for internal use
  • Patient / Client Data (entered by users):
  • Name, DOB, contact details
  • Medical history and clinical notes
  • Consent forms and uploaded documents/images
  • Technical / Operational Data:
  • AWS-hosted system usage data
  • Cookies (essential only)

Note: We do not store credit card information; payments are handled by Stripe, Square, and PayPal.

1.3 Legal Basis for Processing

  • Contractual necessity: Providing access and platform functionality
  • Legal obligations: Compliance with UK GDPR and health record regulations
  • Legitimate interests: Security, fraud prevention, and system improvement
  • Explicit consent: Required for processing health data

1.4 Use of Data

  • Platform functionality: Scheduling, client management, reporting, billing
  • Email & calendar integration (Gmail, Outlook, etc.)
  • Security and access control
  • Optional features: Telehealth, messaging, AI-assisted tools, other api apps

1.5 Data Sharing / Third-Party Services

We may share or transmit data to:

  • Core Platform Services
  • AWS (hosting and storage)
  • Stripe, Square, PayPal (payment processing)
  • Email & Calendar Integrations
  • Gmail, Outlook, and other calendar/email platforms
  • Data shared only for providing two-way sync and email functionality

Important Notes

  • You acknowledge and agree that all third-party providers’ terms and privacy policies apply
  • We are not responsible for how third parties process or store data
  • Users are responsible for maintaining patient confidentiality and obtaining consent

1.6 Data Storage & Transfers

  • Hosted primarily in UK / EU regions
  • Data is encrypted where technically feasible (at rest and in transit)
  • Backups and redundancy implemented per AWS standard practices
  • Transfers outside the UK/EU comply with GDPR standard contractual clauses

1.7 Patient Access

  • Patients may log in to view or edit their data if enabled by the practitioner
  • Users (practitioners) are responsible for obtaining consent to store and process patient data
  • 1.8 Your Rights
  • Access, correction, deletion of personal data
  • Object to processing
  • Data portability requests
  • Lodge complaints with the ICO (ico.org.uk)
  • Requests can be sent to: privacy@wellspring.bizrar.com

1.9 Data Retention

  • Practitioner account data: retained until account closure
  • Patient data: retained as required by users and applicable law
  • Upon termination: data deleted after 14-day export window, unless retention is required by law

1.10 Security

  • Access restricted to authorised personnel
  • Industry-standard measures implemented
  • Regular system reviews performed

Note: Security measures are described in good faith; audit details may be adjusted as infrastructure matures.

1.11 Cookies

  • Only essential cookies used at launch
  • Optional analytics/tracking may be added later with explicit consent
  • Users can manage cookie preferences in browser settings
  • 1.12 International Users
  • Governed by England & Wales law
  • GDPR and local data protection laws apply for EU users

Lawyer Review Note:
High-risk health professions and patient logins should be reviewed by a UK data protection lawyer to confirm compliance.

Effective Date: [Insert Date]
Last Updated: [Insert Date]

2.1 Introduction

By using Wellspring Scheduling Ltd (“we”, “our”, “us”), you (“user”, “practitioner”, “clinic”) agree to these Terms.

This agreement governs:

  • Platform access
  • Account creation
  • Billing and subscription
  • Legal responsibilities

2.2 Eligibility

  • Healthcare or therapy professional, clinic, or coaching service
  • Users must comply with applicable professional standards
  • Patients may log in only where enabled by practitioners

2.3 Account Responsibilities

  • Keep login credentials secure
  • Notify us immediately of unauthorized access
  • Ensure data entered is accurate
  • Obtain patient consent for data processing

2.4 Acceptable Use

You must not:

  • Use the platform for unlawful activity
  • Upload illegal, harmful, or non-consensual content
  • Attempt to access other users’ accounts or data
  • Use platform for life-critical emergency purposes

2.5 Subscription & Billing

  • 30-day free trial applies unless otherwise stated
  • Subscriptions auto-renew unless cancelled
  • Payment processed via Stripe
  • Refunds granted case-by-case at our discretion

2.6 Termination & Suspension

We may suspend or terminate accounts for:

  • Non-payment
  • Breach of terms
  • Legal risk

Upon termination:

  • 14-day data export window
  • Retention for legal obligations

2.7 Liability Limitation

  • Liability limited to the maximum extent permitted by law

Excludes:

  • Loss of profits or revenue
  • Indirect or consequential damages
  • Clinical outcomes
  • We do not provide medical advice or treatment

2.8 Intellectual Property

  • Platform and materials are owned by Wellspring Scheduling Ltd
  • Users retain ownership of data they input
  • Users grant us a licence to process data per this agreement

2.9 Governing Law & Dispute Resolution

  • England & Wales law applies
  • Courts of England & Wales have exclusive jurisdiction

2.10 Third-Party Terms & Integrations

By using Wellspring Scheduling Ltd, you acknowledge that your use may involve:

  • AWS hosting and storage
  • Stripe, Square, or PayPal payment processing
  • Gmail, Outlook, or other calendar/email services
  • You agree to comply with all third-party terms and privacy policies and understand that Wellspring Scheduling Ltd is not liable for any third-party actions.
  • Upon signing up, you agree you have read and agree to the Wellspring Scheduling Ltd Terms & Conditions and acknowledge that you are subject to the terms of any third-party services used, including AWS, Stripe, Square, PayPal, Gmail, and Outlook.

2.11 Future Features

  • Telehealth, messaging, and other applications may be added over time
  • All disclaimers, user responsibilities, and liability limitations apply to new features

3.1 Parties

  • Customer / Practitioner / Clinic = Data Controller
  • Wellspring Scheduling Ltd = Data Processor

3.2 Subject Matter & Duration

  • Processing of patient data via the platform
  • Duration: length of account + retention obligations

3.3 Nature & Purpose

  • Scheduling, client management, reporting, billing
  • Optional telehealth, messaging, AI, and email/calendar sync

3.4 Categories of Personal Data

Include, but not limited to:

  • Patient names
  • contact info
  • DOB
  • clinical notes
  • consent forms
  • uploaded documents

3.5 Data Controller Obligations

  • Ensure lawful collection and processing of patient data
  • Obtain necessary consent
  • Comply with applicable professional standards

3.6 Processor Obligations

  • Process data only per instructions from the Controller
  • Implement appropriate technical and organisational measures
  • Sub-processors:
  • AWS
  • Stripe, Square, PayPal
  • Gmail, Outlook, calendar services
  • Notify of data breaches without undue delay
  • Delete or return data upon termination (after 14-day export period)

3.7 Security Measures

  • Access limited to authorised personnel
  • Encryption implemented where technically feasible
  • Regular reviews conducted
  • Note: Processor makes no warranties as to absolute security.

3.8 International Transfers

  • Transfers outside UK/EU comply with GDPR contractual clauses

3.9 Liability & Indemnity

  • Processor liability limited to maximum extent permitted by law
  • Customer responsible for clinical outcomes, regulatory compliance, and patient consent
  • Only essential cookies used at launch (login/session)
  • Optional analytics/tracking may be added later 
  • Users can manage cookie preferences in browser settings

The platform does not provide diagnosis, treatment, or medical advice

Users are responsible for:

  • Clinical accuracy
  • Patient consent
  • Regulatory compliance
  • AI features are assistive only and do not replace professional judgement
  • Telehealth and messaging tools are provided to facilitate communication only
  • 30-day free trial
  • Subscriptions auto-renew unless cancelled
  • Refunds granted discretionary, case-by-case
  • Subscription payments handled via Stripe
  • We do not store card details