LeadFlow Healthcare CRM
Draft, pending legal review

Privacy Policy

Last updated: 26 September 2026

1. Who this policy is for

LeadFlow is software that hair transplant and aesthetic clinics use to manage enquiries, patients, follow-ups and messages. Two kinds of people have personal data in it: the clinic's staff who sign in, and the clinic's patients and enquirers.

For patient data, the clinic decides why and how it is used. Under the Digital Personal Data Protection Act, 2023 (DPDP Act) the clinic is the Data Fiduciary and LeadFlow processes the data on the clinic's behalf, as a Data Processor. If you are a patient, your first contact about your data is your clinic.

LeadFlow is operated by [legal entity name, to be supplied].

2. What we hold
  • Staff accounts: name, work email, phone if given, role, the clinics a person may access, and a hashed password. We never store a password in readable form.
  • Patients and enquirers, as entered by the clinic: name, phone, email if given, the treatment or concern, appointments, treatment cycles, notes, tasks, messages exchanged with the clinic, and the consent the patient has given or withdrawn.
  • Records of use: who changed or viewed a patient record and when, kept so the clinic can answer who saw what.
3. What it is used for

To run the clinic's follow-up work: reminding staff who to call, and, where the patient has consented, sending reminders about refills, sessions and appointments. We do not sell personal data, use it for advertising, or use patient data to train any model.

Consent comes first. LeadFlow does not send a patient an automated message unless the clinic has recorded that patient's consent for that kind of message. A patient can withdraw consent through the clinic at any time, and the withdrawal is recorded and respected from then on.

4. Where it is kept, and who else touches it

LeadFlow runs on these services, each of which processes data only to provide its part:

  • Convex, the database and backend.
  • Vercel, which serves the web application.
  • Resend, which delivers sign-in and account emails.
  • WhatsApp (Meta), only for clinics that connect a WhatsApp Business account, to deliver messages the patient has consented to.
  • Anthropic, only if a clinic switches on the reply-drafting assistant: the conversation being answered is sent to draft a reply, which staff read before anything is sent.

Some of these providers store data outside India. [Hosting regions to be confirmed before launch.]

5. How it is protected
  • Data is encrypted in transit (HTTPS) and at rest by our hosting providers.
  • Every record belongs to one clinic organisation, and each staff member sees only the clinics they have been given access to.
  • Changes to patient records and views of them are logged.

LeadFlow holds no security certification (such as ISO 27001 or SOC 2) and has not been audited against the DPDP Act. HIPAA is United States law and does not apply to clinics in India. If a personal data breach occurs we will tell the affected clinics without delay so that they can meet their duties under the DPDP Act.

6. How long it is kept

For as long as the clinic uses LeadFlow, and then for the period the clinic's agreement with us sets, after which it is deleted or returned to the clinic. Medical record retention periods are the clinic's to decide under the rules that apply to it.

7. Your rights

Under the DPDP Act you may ask for a summary of your personal data, ask for it to be corrected or erased, withdraw consent, and nominate someone to act for you. Patients should ask their clinic, which can act on it in LeadFlow; we will help the clinic do so.

If you are not satisfied with the answer, you may complain to the Data Protection Board of India.

8. Contact

Grievance contact: [name, email and address to be supplied]. For anything else, use our contact page.