Privacy Policy
This policy explains how OST Automation ("we", "us", "our") collects, uses, and protects personal data in connection with Vitals, our clinic management platform.
Contents
- Controller and processor roles
- Our access to your clinic's data
- Information we collect
- How we use information
- Legal basis for processing
- Who we share data with
- Where data is stored
- Data retention
- Security & breach notification
- Your rights
- Special category (health) data
- Cookies
- Children's data
- Changes to this policy
- Contact us
1. Controller and processor roles
Vitals is used by clinics to manage their own patients' data. Two distinct roles apply, and it's important to understand which applies to which data:
- OST Automation as data controller — for account-level data about the clinic and its staff (names, emails, login credentials, billing information), we determine the purpose and means of processing, and act as the controller.
- The clinic as data controller, OST Automation as data processor — for patient data entered into Vitals by a clinic (records, appointments, payments, medical notes, lab orders, uploaded files), the clinic determines why and how that data is processed. We process it solely on the clinic's instructions, under a processing arrangement implicit in the clinic's use of the service. A written Data Processing Agreement is available on request.
2. Our access to your clinic's data
Vitals is architected so that one clinic can never see another clinic's data — enforced at the database level (Row Level Security), not just in the application interface. OST Automation may access clinic and patient data solely for legitimate operational purposes, such as providing technical support you've requested, investigating a security issue, or reviewing aggregate, non-identifying usage statistics to maintain the platform. We do not access patient data to read, use, or disclose it for any other purpose, and we never sell it.
3. Information we collect
From clinics and staff
- Name, email address, phone number, and role
- Login credentials (passwords are stored as irreversible cryptographic hashes — we never see or store a plain-text password)
- Billing and payment details, processed via our payment providers
Patient data entered by clinics
- Identifying details (name, contact information, date of birth, national ID where entered)
- Medical information (conditions, allergies, medications, medical history, clinical notes)
- Appointment, treatment, billing, and lab order records
- Photographs or documents uploaded to a patient's file
Usage data
- Login timestamps and general activity logs, used to maintain security and service reliability
4. How we use information
- To provide, operate, and maintain Vitals
- To authenticate users and secure clinic accounts
- To send service-related communications (e.g. billing notices, trial status)
- To send appointment reminders via WhatsApp, where a clinic has enabled that add-on
- To respond to support requests
- To improve the reliability and functionality of the platform
We do not use patient data for advertising, and we do not sell personal data of any kind, to anyone, under any circumstances.
5. Legal basis for processing
Where UK GDPR applies, we (or the relevant clinic, for patient data) rely on the following legal bases: performance of a contract (providing the service a clinic has signed up for), legitimate interests (maintaining and securing the platform), and consent (where a clinic has separately obtained a patient's consent for a specific purpose, such as WhatsApp reminders).
6. Who we share data with
We use a limited number of trusted subprocessors to operate Vitals:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and patient data |
| Twilio | WhatsApp appointment reminders (optional add-on) | Patient phone number, appointment details |
| Netlify | Website hosting | General site traffic |
| Stripe | Payment processing, where card payment is used | Clinic billing details |
We do not share data with any party for their own marketing purposes. We may disclose data where required by law, or to protect the rights, safety, or property of OST Automation, our customers, or others.
7. Where data is stored
Vitals' production database is hosted in West Europe (London, UK). Data is encrypted both in transit and at rest.
8. Data retention
We retain data for as long as a clinic's account remains active. If an account is closed, associated data is deleted within 30 days, unless the clinic requests an export beforehand (available at any time via the in-app Backup & Import tool) or longer retention is required by law. All processing takes place within the UK and European Economic Area — we do not transfer clinic or patient data outside the UK/EEA.
9. Security & breach notification
We apply industry-standard safeguards, including encryption in transit and at rest, hashed credential storage, and database-level access controls (Row Level Security) ensuring one clinic's data is never accessible to another. No system is perfectly secure. In the event of a personal data breach affecting a clinic's data, we will notify the affected clinic without undue delay, and, where required by law, support the clinic in notifying the relevant supervisory authority within 72 hours of becoming aware of the breach.
10. Your rights
If you are a clinic, you can access, export, or delete your data at any time from within Vitals, or by contacting us. If you are a patient and have a question about how your data is handled, please contact your clinic directly — they control your records, and we act only on their instructions. Where UK GDPR applies, individuals have rights including access, rectification, erasure, restriction, portability, and objection, subject to applicable exemptions.
11. Special category (health) data
Patient medical information constitutes "special category data" under UK GDPR, warranting a higher standard of protection. Clinics using Vitals to store such data act as the data controller and are responsible for ensuring they have an appropriate lawful basis (typically, provision of healthcare, or explicit patient consent) for processing it. We support this by applying strict technical access controls so that patient data is only ever accessible to the clinic that entered it.
12. Cookies
Our website and application use only essential cookies required for authentication and core functionality. We do not use third-party advertising or tracking cookies.
13. Children's data
Vitals may be used by clinics to store medical records belonging to minors, entered and controlled by the clinic as part of standard patient care, with the same protections applied as to any other patient record. Vitals itself is not directed at children as end users of the software.
14. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to clinic administrators. Continued use of Vitals after a change constitutes acceptance of the updated policy.
15. Contact us
Questions about this policy, or requests relating to your data, can be sent to contact@ostautomation.co.uk.