Calyx LogoCalyx
Free

Privacy Policy

Last updated: 31 July 2026

This policy explains how Calyx (operated by Calyx Clinical Systems Ltd, a company registered in England and Wales, company no. 17289410, and registered with the Information Commissioner's Office (ICO) under registration number ZC184788) handles personal data across our website (usecalyx.app), the clinic portal (portal.usecalyx.app), the patient portal (my.usecalyx.app) and our staff payments app, Calyx Tap & Pay. In this policy, "Calyx", "we" and "us" mean Calyx Clinical Systems Ltd.

Calyx is software for UK aesthetic clinics. Whether we are the "controller" or the "processor" of your data depends on who you are:

  • If you are a clinic, or a member of clinic staff, and for anyone we contact about buying Calyx, we are the controller of your account and marketing data.
  • If you are a patient of a clinic that uses Calyx, the clinic is the controller of your health and personal data, and Calyx acts as its processor – we handle that data only on the clinic's instructions and on its behalf. For questions about your patient records, contact your clinic directly. This policy tells you how we look after that data on the clinic's behalf.

1. Who to contact

  • General and privacy enquiries: data@usecalyx.app
  • Data protection contact: data@usecalyx.app
  • Data deletion requests: see our Data Deletion page, or email data@usecalyx.app (section 14, Deleting your data)

2. The data we process

Clinic and staff accounts (we are the controller): name, email, phone, role, clinic details, login and security data, billing/subscription data, and usage/audit logs.

Prospective customers (we are the controller): business name, contact name, email, and (for clinics we contact about listing on our directory) publicly available business details. See Marketing below.

Patient data (the clinic is the controller; we are the processor):

  • Identity and contact details (name, date of birth, address, email, phone).
  • Special-category health data: treatments, clinical notes, consent forms, before and after photographs, prescriptions.
  • Appointment, booking and payment records.
  • Messages between the patient and the clinic in the patient portal, and video-consultation connection data.

3. Special-category (health) data

Some patient data is "special-category" health data under UK GDPR and receives extra protection. The clinic (as controller) relies on Article 9(2)(h) (provision of health care) and/or the patient's explicit consent. Calyx processes it only to provide the software to the clinic, under a Data Processing Agreement, with access controls, encryption in transit and at rest, and strict data isolation between clinics.

We never send clinical or treatment detail to advertising networks. Clinical text is shared with our AI provider only when a clinic uses the optional AI note tools, and then only under a zero-data-retention agreement: it is not retained by the provider and is never used to train its models.

4. Why we process data and our lawful bases

PurposeLawful basis (controller data)
Providing and securing the Calyx serviceContract; legitimate interests
Billing and subscriptionsContract; legal obligation
Service and security communicationsLegitimate interests; legal obligation
Product marketing to businessesLegitimate interests / consent
Complying with law and resolving disputesLegal obligation; legitimate interests

For patient data, the clinic is the controller and sets the lawful basis (typically the provision of healthcare and/or consent); we act on its documented instructions.

5. Messaging: patient portal and WhatsApp

Clinics can message their patients securely through the in-app patient portal. Messages are stored within Calyx (under the clinic's control) and are visible to the clinic and the patient. This channel is for non-clinical communication such as appointment updates and general information.

Clinics can also message patients over WhatsApp, where the clinic has connected its own WhatsApp Business account. This is optional and used only by clinics that choose to enable it.

  • We send WhatsApp messages only to patients who have given explicit opt-in for this channel. A patient can opt out at any time by replying STOP, and we stop sending.
  • WhatsApp messages are delivered through Meta's WhatsApp Business Platform (the WhatsApp Cloud API). To deliver a message, Meta processes the patient's WhatsApp phone number and the content of the message. Content is limited to non-clinical information such as appointment reminders, confirmations and general updates; we never include clinical detail.
  • Meta is a service provider (sub-processor) for this channel, listed in Service providers below. As Meta operates outside the UK, the international-transfer safeguards in this policy apply.
  • WhatsApp encrypts messages in transit. Once received, messages are also stored within Calyx (under the clinic's control) alongside the patient's other conversations.

6. Video consultations

Clinics can hold live video consultations with patients inside Calyx. Video is provided by Daily.co (Daily).

  • Calls are live only and are not recorded by Calyx.
  • Video and audio are streamed between the participants through Daily's infrastructure, configured to the EU data region, under a Data Processing Agreement.
  • Your browser will ask permission to use your camera and microphone; you can decline or end the call at any time.

7. In-person card payments (Calyx Tap & Pay app)

Calyx Tap & Payis an optional mobile app for clinic staff that turns a compatible phone into a contactless card reader ("Tap to Pay"), so a clinic can take in-person card payments without separate hardware. It is used only by clinics that choose to enable it, and only by their staff. Staff sign in with their existing Calyx credentials. As elsewhere in this policy, the clinic is the controller of the payment and of any linked appointment or patient data, and Calyx acts as its processor; we are the controller of staff account data.

Card details are handled entirely by Stripe.Contactless card, Apple Pay and Google Pay details are captured and processed by Stripe's Tap to Pay technology and are never seen, stored, or transmitted by the app or by Calyx. Payments settle into the clinic's own connected Stripe account. Stripe's processing of card data is governed by Stripe's own privacy terms.

Location. To take a contactless payment, the app requires the device's location services to be switched on and location permission to be granted. This is because Stripe's Tap to Pay technology needs the device location to process a card-present payment and to help prevent fraud, as required by the card networks. The location is used only on the device, by the payment technology, for that purpose. Calyx does not read, store, transmit or track your location, and it is not used for any purpose other than enabling the payment.

Other device permissions. The app also uses NFC to read contactless cards, and requests certain permissions (Bluetooth, phone state and microphone) that the underlying Stripe payment software requires in order to run. The app does not record audio, place calls, or use these permissions for any purpose other than operating the card reader.

What the app processes.The app shows staff the pending charges pushed from the Calyx portal (the amount and the linked appointment) and updates their status. It sends only the payment reference and amount to Calyx; it does not send card details or location. Payment records are retained as set out in Data retention below; card data is retained by Stripe under Stripe's terms, not by Calyx. Stripe is listed in Service providers below.

8. Marketing communications

  • To patients: clinics may send marketing by email only to patients who have opted in. Every marketing message includes a one-click way to unsubscribe. We never include clinical detail.
  • To businesses and prospects: we may contact clinics about Calyx or our directory on the basis of legitimate interests or consent, in line with the Privacy and Electronic Communications Regulations (PECR). Every message includes an unsubscribe link, and we honour opt-outs.

9. Cookies, analytics and notifications

We use strictly necessary cookies to run the service (for example to keep you signed in). If you choose to enable browser or app notifications (web push), we store the technical subscription needed to deliver them; you can turn these off in your browser or device settings at any time. For a detailed list of cookies and options to manage them, see our Cookie Policy at usecalyx.app/cookies.

10. Service providers (sub-processors)

We use the carefully selected providers below to run Calyx. Each is bound by a data-processing agreement and processes data only to provide its service. The up-to-date list is always available at usecalyx.app/privacy.

ProviderWhat it doesLocationTransfer safeguard
SupabaseDatabase, authentication, file storageUK/EU (London region)Within UK/EU
VercelApplication hosting and content deliveryUS company; regional computeSCCs / UK IDTA
StripeCard payments (online and in-person Tap to Pay), payment terminals, and subscription billingUS / IrelandSCCs / UK IDTA
SquareCard payments (where a clinic uses Square)USSCCs / UK IDTA
ResendSending transactional and marketing emailUSSCCs / UK IDTA
XeroAccounting sync (where a clinic enables it)New ZealandUK/EU adequacy decision
Daily.coVideo consultationsEU data regionSCCs / UK IDTA
Meta Platforms Ireland Ltd (WhatsApp Business Platform)Delivering WhatsApp messages between a clinic and its consenting patientsIreland / USSCCs / UK IDTA
Anthropic (via Vercel AI Gateway)AI writing assistant and note-summary toolsUSSCCs / UK IDTA; no training on your data; zero data retention for clinical note summaries
GoogleBusiness-listing lookup and ratings (Places API); Google Analytics on public marketing and signup pagesUSSCCs / UK IDTA
PostHogProduct analytics and session replay on public marketing and signup pages (never the clinic dashboard or patient portal); form inputs are masked in recordingsEU cloud (Frankfurt)Within UK/EU

11. International transfers

Some of our providers are based outside the UK (primarily the United States). Where personal data is transferred internationally, we rely on the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, together with additional safeguards, so your data receives an equivalent level of protection.

12. Data retention

  • Patient data is retained for as long as the clinic (the controller) requires it, in line with its own retention obligations, and deleted or returned on its instruction or when its contract with Calyx ends.
  • Clinic and account data is retained for the life of the account and for a reasonable period afterwards to meet legal, accounting and dispute-resolution requirements.
  • Payment records are retained for 7 years in line with HMRC requirements.
  • Marketing data is retained until you opt out or it is no longer needed.
  • Deleted accounts: data is fully purged within 30 days of subscription termination.

13. Your rights

Under UK GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent.

  • Patients: because your clinic is the controller of your health data, please make requests to your clinic in the first instance; we will support the clinic in responding.
  • Clinic and account holders, and prospects: contact data@usecalyx.app.

We respond within one month. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to help first.

14. Deleting your data

You can ask us to delete the personal data we hold about you. How to do it depends on who you are, and there is a step-by-step guide on our Data Deletion page.

  • Patients: your clinic is the controller of your health and personal data, so please ask your clinic to delete it – the clinic can remove your records in Calyx, and we act on its instruction. You can also email data@usecalyx.app and we will pass the request to your clinic.
  • Clinics and account holders: email data@usecalyx.app from your account email address with the subject "Data deletion request", and tell us your clinic name and account email so we can verify it is you. If you would like a copy first, you can export your full database and records from your account before deletion.

Once we have verified the request, we delete or return the data and fully purge it within 30 days (we confirm within one month, in line with Your rights above). Some records are kept where the law requires – for example, payment records are retained for 7 years for HMRC (see Data retention). Deleting your Calyx account also ends access to the Calyx Tap & Payapp, which uses the same login; card data for past payments is held by Stripe under Stripe's terms, not by Calyx.

15. Security

We protect data with encryption in transit and at rest, strict per-clinic data isolation, role-based access controls, audit logging, and regular security review. Integration access tokens and other secrets are encrypted at rest. No system is perfectly secure, but we work hard to protect your information and to notify you and the regulator of any breach where the law requires.

16. Children

Calyx is intended for use by clinics and their adult patients. Where a clinic treats a minor, the clinic is responsible for the appropriate lawful basis and consent.

17. Changes to this policy

We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date, and clinic account holders notified by email at least 14 days in advance.

18. Contact

Calyx Clinical Systems Ltd – data@usecalyx.app. Data protection contact: data@usecalyx.app.