Privacy Policy

Last updated: 25 April 2026

Clinic Roll provides two free companion apps for Cliniko, built by a practicing osteopath in Brussels. This policy explains what data we handle when you use Clinic Roll (Notify and Leave) and how we protect it. We’re GDPR-native and EU-hosted by default — not as a bolt-on.

What we store

To run the service we store the minimum needed:

We do not store patient records, appointment content, or any clinical data. Patient-identifying data only passes through memory when sending a notification email — it is not written to any database we control.

Clinic Roll is free. We take no payments, so we hold no billing records and never see payment details.

Where your data lives

All persistent data storage is in EU regions: Cloudflare Workers KV (EU-hosted) and Supabase (eu-west-1, Dublin). Cloudflare Workers themselves run at the edge closest to the request.

Third parties

We rely on the following sub-processors:

Your rights under GDPR

You have the right to access, correct, export, or delete your data. Disconnecting from the Account page wipes all your stored configuration and operational logs. For formal GDPR requests, email hello@clinicroll.com and we’ll respond within 30 days.

Cookies

We use a single essential cookie (cr_session) to keep you signed in across both apps. Inside the apps (app.clinicroll.com, notify.clinicroll.com, leave.clinicroll.com) there is no tracking and no analytics.

On the public marketing site (clinicroll.com) we use Google Analytics 4 with IP anonymisation enabled to understand aggregate visitor traffic (page views, referrers, country-level location). No personally identifying information is sent to Google. We do not use ad cookies or cross-site tracking.

Contact

Questions about this policy? Email hello@clinicroll.com.