Privacy Policy
How we collect, use, and protect your personal data
Last updated: 23 March 2026
Summary: MedFunnel is a B2B SaaS platform. We collect account and usage data from clinic users to operate the service. Patient data entered by clinics is processed on their behalf — the clinic remains the data controller for that data. We never sell personal data.
1. Who We Are
MedFunnel ("MedFunnel", "we", "us", or "our") operates the patient conversion and clinic workflow platform available at app.medfunnel.io and marketed at www.medfunnel.io.
For the purposes of data protection law, MedFunnel acts as:
- Data Controller in relation to the personal data of clinic users, administrators, and contacts who register for or interact with our platform.
- Data Processor in relation to patient and lead data entered into the platform by our clinic customers ("Clients"). In this capacity, we process data strictly on the instructions of each Client, who is the Data Controller for that data.
Contact us at: [email protected]
2. Data We Collect
2.1 Account and User Data
When a clinic registers for MedFunnel or when a clinic administrator creates user accounts, we collect:
- Full name and job title
- Business email address
- Encrypted password (hashed; we never store plaintext passwords)
- Clinic or organisation name
- Country and time zone
- Phone number (optional)
- Profile photo (optional)
- Role and permission level within the clinic workspace
2.2 Billing and Payment Data
We collect billing contact information (name, address, VAT number) for invoicing purposes. Payment card details are not stored by MedFunnel. All card processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. We receive only tokenised references and non-sensitive payment metadata from Stripe.
2.3 Patient and Lead Data (Processed on Behalf of Clients)
Clinic customers enter patient and lead data into the platform. This may include:
- Patient names, contact details, nationality, and date of birth
- Medical history, clinical notes, treatment plans, and doctor evaluations
- Photos and documents uploaded as part of patient intake
- WhatsApp and email communication history
- Offer details, deposit amounts, and payment records related to patient treatments
- Appointment and logistics information
Important: This data constitutes special category health data under GDPR Article 9. Clinics are responsible for ensuring they have a lawful basis to process this data and that patients are informed accordingly. MedFunnel processes this data solely on the clinic's instruction, subject to the Data Processing Agreement set out in our Terms of Service.
2.4 Communication Data
When you contact our support team, respond to surveys, or send us emails, we retain those communications to assist you and improve the service.
2.5 Technical and Usage Data
We automatically collect technical data when you use our platform, including:
- IP address and approximate location (country/city level)
- Browser type, version, and device type
- Operating system
- Pages visited, features used, and time spent on each section
- Clickstream data and interaction events
- Error logs and crash reports
- Session identifiers and authentication tokens
2.6 Marketing and Landing Page Data
When you visit our marketing website (www.medfunnel.io), we may collect:
- Contact information submitted via demo request forms
- Cookie and analytics data (see Section 6 and our Cookie Policy)
- UTM parameters and referral sources for marketing attribution
3. How We Use Your Data
We use the data we collect for the following purposes:
- Service delivery: Creating and managing accounts, processing subscriptions, enabling platform functionality.
- Billing: Processing payments, issuing invoices, managing subscription renewals.
- Support: Responding to enquiries, resolving technical issues, providing onboarding assistance.
- Security: Detecting and preventing fraud, unauthorised access, and abuse.
- Product improvement: Analysing usage patterns to improve features and fix issues.
- Communications: Sending transactional emails (receipts, notifications, password resets) and, where you have opted in, product updates and marketing messages.
- Legal compliance: Retaining records required by applicable law and responding to lawful requests.
4. Legal Bases for Processing (GDPR)
For users located in the European Economic Area (EEA), United Kingdom, or other jurisdictions where GDPR-equivalent law applies, we rely on the following legal bases:
- Contract (Article 6(1)(b)): Processing necessary to provide the services you have contracted for, including account management and billing.
- Legitimate Interests (Article 6(1)(f)): Security monitoring, fraud prevention, product analytics, and direct marketing to existing customers (where not overridden by your rights).
- Legal Obligation (Article 6(1)(c)): Retaining financial records as required by tax and accounting law.
- Consent (Article 6(1)(a)): Non-essential cookies and marketing emails to non-customers, where you have explicitly opted in.
- Special Category Data (Article 9(2)(h)): Patient health data entered by clinics is processed for medical or healthcare purposes on the instruction of the clinic as Data Controller.
5. Data Sharing and Third-Party Services
We do not sell, rent, or trade personal data. We share data only with the following categories of trusted sub-processors:
- Stripe, Inc. — Payment processing. Data transferred to the US under standard contractual clauses.
- Meta Platforms / WhatsApp Business API — Sending structured WhatsApp messages on behalf of clinics. Message content is subject to Meta's data policies.
- Resend (or equivalent email provider) — Transactional email delivery for platform notifications.
- Google LLC (Google Analytics 4) — Anonymised usage analytics on the marketing website. Governed by Google's data processing terms.
- Cloud infrastructure providers — Our platform is hosted on Google Cloud Platform in the EU (europe-west4 region). Data is not routinely transferred outside the EEA without appropriate safeguards.
- Support tooling — We may use helpdesk or CRM tools to manage support requests. We ensure these tools have appropriate data processing agreements in place.
All sub-processors are bound by contractual obligations that require them to protect personal data to at least the same standard as this policy.
6. Cookies and Tracking
We use cookies and similar tracking technologies on our marketing website and within the application. For full details, please see our Cookie Policy.
In summary, we use:
- Essential cookies: Required for authentication, sessions, and security. Cannot be disabled.
- Analytics cookies: Google Analytics 4, used to understand how the marketing website is used. Can be opted out.
- Functional cookies: Remembering your preferences and settings.
7. Data Retention
We retain data for as long as necessary to fulfil the purposes described in this policy, subject to the following guidelines:
- Active accounts: Data is retained for the duration of the subscription.
- Cancelled or terminated accounts: Account data is retained for 30 days after cancellation to allow for reactivation, then deleted or anonymised, except where retention is legally required.
- Patient data: Retained for the period configured by the clinic, or as required by applicable healthcare regulation in the clinic's jurisdiction. Clinics can export and delete patient data at any time.
- Payment and billing records: Retained for a minimum of 7 years in compliance with financial record-keeping obligations.
- Support communications: Retained for up to 3 years after your last interaction with us.
- Analytics data: Retained in aggregated, anonymised form; individual session data is deleted per Google Analytics' retention settings.
8. Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Right to restriction: Request that we restrict processing of your data in certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
- Right to lodge a complaint: Lodge a complaint with your national supervisory authority (for example, the ICO in the UK or the relevant EEA supervisory authority).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Note for patient data: If you are a patient whose data is held in MedFunnel by a clinic, please direct your data rights requests to the clinic directly, as they are the Data Controller for your information. We will cooperate with clinics to fulfil patient requests.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or alteration, including:
- Encryption of data in transit using TLS 1.2 or higher (256-bit SSL)
- Encryption of sensitive data at rest
- Row-level security and multi-tenant data isolation in our database
- Role-based access controls ensuring users only access data relevant to their role
- Regular security reviews and penetration testing
- Automated backups with point-in-time recovery
- Audit logging of all access to sensitive data
- Two-factor authentication availability for all accounts
No system is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant supervisory authorities in accordance with our legal obligations (within 72 hours where required under GDPR).
10. International Data Transfers
Our primary infrastructure is hosted within the European Union (Google Cloud, europe-west4). Where we transfer data to countries outside the EEA (for example, to US-based sub-processors such as Stripe or Google Analytics), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where relevant
11. Data Processing Agreement
For clinic customers processing patient data through MedFunnel, a Data Processing Agreement (DPA) governs our role as Data Processor. The DPA forms part of our Terms of Service. By accepting the Terms of Service, you enter into the DPA on behalf of your organisation. Clinics that require a separately executed DPA for compliance purposes may request one at [email protected].
12. Children's Data
MedFunnel's platform is intended for use by healthcare businesses and their staff. We do not knowingly collect personal data from individuals under the age of 16 in connection with our own marketing or account registration. Patient data involving minors may be entered by clinics in the course of legitimate healthcare services — the clinic bears responsibility for ensuring this is handled in accordance with applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify registered users of material changes by email or via an in-app notice at least 14 days before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related enquiries, data subject requests, or to report a security concern:
- Email: [email protected]
- General: [email protected]