Legal
Privacy policy
This policy explains how DiaryCare handles account, booking, communications, billing, and Google Calendar data.
Last updated: 4 August 2026
1. Who we are
DiaryCare is operated by George Elias, a sole trader, at 26 Strothers Avenue, Malvern, WR14 3RS, United Kingdom. Contact us at contact@diarycare.co.uk.
DiaryCare is the controller for clinic account, service administration, billing, security, and support data. A clinic normally acts as controller for its patients' booking and care-related data, while DiaryCare processes that data for the clinic. Patients should contact their clinic first about a booking record or privacy request; we will assist the clinic where required.
2. Information we handle
- Account information, including names, email addresses, authentication records, roles, invitations, and session information.
- Clinic information, including business details, locations, practitioners, services, availability, branding, booking rules, and notification settings.
- Patient and booking information supplied to a clinic, including name, contact details, appointment details, communication preferences, and answers to clinic-defined booking questions. Those answers may include health information where a clinic chooses to ask for it.
- Communications and delivery records for transactional email and SMS.
- Subscription, invoice, and metered-usage identifiers. Payment-card details are collected and handled by Stripe rather than stored by DiaryCare.
- Technical and security information, such as IP address, device and browser information, request logs, cookies, and diagnostic events.
- Support correspondence and information you provide when asking us for help.
3. How we use information
- Provide and secure clinic accounts, hosted booking pages, embedded booking, reminders, billing, reporting, and support.
- Create, confirm, reschedule, cancel, and administer appointments according to the clinic's instructions.
- Send transactional appointment and account communications by email or SMS.
- Prevent double-booking, diagnose failures, protect tenants from unauthorised access, and maintain service reliability.
- Meet legal, tax, accounting, fraud-prevention, and regulatory obligations.
Depending on the context, our lawful bases include performing a contract, taking steps requested before a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where it is specifically requested. Clinics are responsible for identifying their lawful basis and any condition required for patient health data.
4. Google Calendar data
Connecting Google Calendar is optional and begins only when an authorised practitioner selects Connect Google Calendar and grants Google's consent request. The default connection requests the narrow permissions needed to provide two visible features:
- Create and manage a dedicated DiaryCare calendar in the practitioner's Google account. Confirmed DiaryCare bookings are created there and are updated or removed when the booking changes.
- Read free/busy periods from the practitioner's primary calendar to hide unavailable times and show private, untitled busy blocks in DiaryCare.
Primary-calendar event content remains private by default. A connected practitioner may separately choose to share booking-relevant event context with clinic staff who already have access to their DiaryCare diary. Enabling that option starts a fresh Google consent flow for the read-only calendar.events.owned.readonly permission; another clinic role cannot silently grant it for the practitioner. Although the Google permission covers events on calendars owned by the account, DiaryCare restricts its use to the primary calendar.
After that explicit opt-in, the web diary may show the event title, description, location, organiser, attendees and their RSVP responses, meeting link, Google Calendar link, attachments, visibility and event-type labels, and whether the event is all-day or recurring. This can include content and attachments from events marked private or confidential in Google. The information is available to clinic staff permitted to view that practitioner's diary, so a practitioner should check that their primary-calendar content is appropriate to share with those staff before enabling the option. DiaryCare fetches these details when the web diary loads, does not persist them in its database, and cannot use the permission to edit or delete the external event. The details are not shown on public booking pages or sent to the DiaryCare mobile app, which continues to receive opaque busy intervals only.
Free/busy availability processing remains separate whether event-detail sharing is enabled or not. The free/busy response contains only start and end times and is processed transiently rather than retained as a copy of the practitioner's personal calendar. Booking events written to the dedicated DiaryCare calendar can include patient name and contact details, service, practitioner, clinic location, and the DiaryCare booking identifier so the practitioner can administer the appointment.
We store the dedicated calendar identifier, booking event identifiers, granted scopes, encrypted OAuth access and refresh tokens, connection health, and sync timestamps while the connection remains active. We also record which linked DiaryCare practitioner account completed event-detail consent so that unlinking or relinking that profile invalidates the consent. Stopping event-detail sharing stops DiaryCare fetching and displaying those details but does not remove the already granted permission from the Google account; sharing again requires a fresh Google consent flow. Disconnecting Google Calendar deletes the stored connection and encrypted tokens from DiaryCare; removing the grant from the Google account requires revoking DiaryCare in Google. The dedicated calendar and events already present in the Google account remain under the practitioner's control and can be deleted in Google Calendar. External primary-calendar event details are not stored for later deletion.
DiaryCare's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train general-purpose AI models. Human access is limited to a user-authorised support case, security investigation, legal requirement, or aggregated operational data that does not reveal an individual's calendar information.
5. Who receives information
Information is available to authorised staff of the clinic that controls the relevant booking. We also use service providers for hosting and databases, authentication infrastructure, email delivery (Resend), SMS delivery (Twilio), payments and billing (Stripe), and optional calendar integration (Google). Providers receive only the information needed to perform their service and are required to protect it. We may disclose information where law requires it, to protect rights or security, or as part of a business transfer subject to appropriate safeguards.
6. International transfers
Some providers may process information outside the United Kingdom. Where UK data protection law requires it, we rely on an adequacy regulation or approved contractual safeguards, together with proportionate technical and organisational measures.
7. Retention and deletion
We keep account, clinic, booking, communication, and billing records only for as long as needed to provide the service, follow the clinic's instructions, resolve disputes, maintain security, and meet legal or accounting obligations. Clinic account deletion removes tenant records from the active service, subject to legal holds and limited backup retention. OAuth tokens are deleted when the Google connection or clinic account is deleted. Security logs and backups expire on operational schedules appropriate to their purpose.
8. Security
We use access controls, tenant isolation, encryption in transit, encrypted Google tokens, restricted production secrets, logging, and backups to protect information. No internet service can guarantee absolute security. Please report a suspected security issue to contact@diarycare.co.uk.
9. Cookies
DiaryCare uses cookies and equivalent storage that are necessary for sign-in, session security, invitations, and core booking operation. We do not use Google Calendar data for advertising cookies or cross-site advertising profiles.
10. Your rights
Depending on the circumstances, UK data protection law may give you rights to access, correct, erase, restrict, object to processing, or receive a portable copy of personal data, and to withdraw consent where processing relies on it. These rights can be limited by law. Patients should contact their clinic about clinic-controlled booking information; account users can contact DiaryCare.
You may object at any time to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds or need the data for legal claims.
Contact contact@diarycare.co.uk to make a request. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
11. Changes
We may update this policy as DiaryCare changes. We will publish the revised date here and provide additional notice where a material change affects how we use personal data or Google user data.
