Privacy Policy
Last updated: 26 September 2026
This Privacy Policy explains how Wellspring Scheduling Ltd (company number 15585434) (“Wellspring”, “we”, “us”) collects and uses personal data, and your rights under the UK GDPR, the EU GDPR and applicable data-protection law worldwide (see section 6 for country-specific detail if your practice is based outside the UK/EU). Our registered address is 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, and we are registered with the ICO under ZC209923. We have not appointed a formal Data Protection Officer; direct any privacy query to help@wellspringscheduling.com.
1. Two different roles
It matters in which capacity we handle data:
- As a controller — for personal data about our own website visitors, prospects and account holders (the practice owners and staff who sign up).
- As a processor — for the client/patient records, appointments, notes and payments that a practice enters into Wellspring. There, the practice is the controller and we process that data on their instructions. See our Data Processing Agreement.
This policy focuses on the data for which we are the controller. If you are a patient of a practice that uses Wellspring, please contact that practice about your data.
2. Data we collect
- Account data — name, business name, email, phone, password (hashed), and your role.
- Billing data — subscription plan and payment status. Card details are handled by our payment providers, not stored by us.
- Usage data — log data, device/browser information and how you use the app, to keep it secure and improve it.
- Support requests — when you use the in-app Help button, we store what you write, plus the page you were on, your role and your browser, so we can answer you. We ask you not to include client/patient details in a support request.
- Cookies & similar — see our Cookie Policy. Advertising/analytics cookies load only with your consent.
Practices may enter special category data (health information) about their own clients. We process that only as a processor, under the practice’s instructions and appropriate safeguards.
3. How we use data and our legal bases
- To provide the service and your account — performance of a contract.
- To take payment and manage subscriptions — performance of a contract.
- To secure, maintain and improve the service and prevent fraud — our legitimate interests.
- To send service messages (and, with consent or on a soft-opt-in basis, marketing about Wellspring itself) to you as the account holder — consent or legitimate interests. We do not use this data to market to your clients/patients; any marketing to your own clients is sent under your instruction and is covered by our Terms, not by us as a controller.
- To meet legal obligations such as tax and accounting — legal obligation.
4. Sharing & sub-processors
We do not sell personal data. We share it only with service providers that help us run Wellspring, under contract:
- Hostinger — Application & database hosting (production) — data held in the United Kingdom (Manchester data centre, confirmed 8 Sep 2026); Hostinger International Ltd is a Lithuanian (EEA) company.
- Backblaze — Encrypted off-site database backups — data held in the EU Central region (eu-central-003, EEA); Backblaze Inc. is a United States company.
- Airtable — Internal triage board for support tickets raised by clinic staff — Airtable Inc. is a United States company and the data is processed in the United States.
- Anthropic — AI-assisted drafting of replies to support tickets raised by clinic staff — Anthropic PBC is a United States company and the data is processed in the United States. NOT CURRENTLY ENABLED; we will give 30 days' notice before it is, and you may object.
- Stripe — Payments & subscriptions.
- PayPal / Square — Payment processing (if enabled).
- Meta Platforms — Advertising pixel (only with cookie consent).
- Resend (AWS, EU region) — Email delivery — confirmations, reminders, campaigns.
- Twilio — Text-message delivery — only if you connect your own Twilio account. You open the account with Twilio and pay Twilio directly; Wellspring sends your messages through it on your instruction and is not a party to your agreement with Twilio.
- Xero — Accounting sync (if you connect your own Xero account).
- Google Ireland Ltd / Microsoft Ireland Operations Ltd — Two-way calendar sync — per practitioner, only if they connect their own Google or Outlook account.
Some of the entries above (currently Xero, Twilio if you connect your own account to send text messages, and Google/Microsoft if you turn on two-way calendar sync) are integrations you choose to connect to your own account with that provider, rather than infrastructure we use to run Wellspring for everyone. We list them here for transparency, but it is your decision to connect them and your responsibility to have a lawful basis for sharing your clients’ data with them. If you generate a Wellspring API key to let a partner tool (e.g. an exercise-prescription platform) access your client list, that sharing happens under your control too — we simply provide the connection.
We may also disclose data where required by law, or to protect our rights, users or the public.
5. International transfers
Our production application and database run on a virtual private server provided by Hostinger, in Hostinger’sManchester, United Kingdom data centre. All live processing of your data takes place there, and we will notify you before we move the hosting of the service to another country.
Encrypted off-site copies of the database are held by Backblaze in its EU Central region, inside the EEA. The copies are encrypted before they leave our server and the keys are held only in the United Kingdom. No copy is kept longer than 90 days. See our Data Retention & Deletion Schedule, available on request.
Where data is transferred outside the UK/EEA — including to sub-processors listed in section 4 that are United States companies, or because your practice is based outside the UK/EEA — we rely on appropriate safeguards such as adequacy decisions or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
6. Regional specifics
Wellspring is used by practices in several countries. In addition to the UK GDPR and EU GDPR described above, the following applies depending on where your practice is based:
Australia
We handle your controller data in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 and, for an eligible data breach, the Notifiable Data Breaches (NDB) scheme. You may complain to us first, or to the Office of the Australian Information Commissioner (OAIC). As the controller of your own clients’ data, you are responsible for giving them any APP 5 collection notice required when you collect their information — ask us for a template if you’d like a starting point.
Canada
We handle your controller data in line with the federal Personal Information Protection and Electronic Documents Act (PIPEDA). You may complain to us first, or to the Office of the Privacy Commissioner of Canada (OPC). Depending on your province and the kind of practice you run, provincial health-privacy legislation (for example Ontario’s PHIPA) may also apply to you as controller of your clients’ health information — complying with that legislation is your responsibility, not ours.
United States
We handle your controller data in line with applicable state privacy laws. Wellspring does not currently support health-insurance billing for US practices, for HIPAA reasons — see section 5 of our Terms of Service. If that changes for your account under a signed Business Associate Agreement, this policy and our DPA will be updated to reflect HIPAA’s specific requirements for your data.
7. Retention
We keep account and billing data for as long as your account is active and then only as long as needed for legal, accounting or dispute-resolution purposes. Client data we hold as a processor is retained and deleted per the practice’s instructions and our DPA. Specific retention periods (account data, backups, audit logs) are set out in our internal Data Retention & Deletion Schedule, available on request.
8. Security
We use encryption in transit, access controls, isolated per-practice data, secure authentication and audit logging. No system is perfectly secure, but we take reasonable and appropriate measures to protect your data.
Authorised platform staff can, for support or troubleshooting purposes, temporarily access a practice’s account (including logging in as that practice’s admin). This access is restricted to staff who need it, and every instance is recorded in an audit log, including who accessed the account, when, and when access ended.
9. Your rights
Subject to law, you can request to:
- access a copy of your data;
- correct inaccurate data;
- erase data (“right to be forgotten”);
- restrict or object to processing;
- port your data to another provider; and
- withdraw consent at any time.
To exercise a right, email help@wellspringscheduling.com.
What erasure actually does, in a practice’s records. If you are a patient, ask your practice first — the practice decides what happens to its records and we act on its instruction. Where a patient record has no invoice, payment or clinical note against it, the practice can delete it outright and it is gone. For everyone else the practice can anonymise the record instead: the address, telephone number, email address, date of birth, emergency contact, uploaded files, online account and the content and recipient of every message we have sent are permanently removed, and the invoices, payments and the dates of appointments are kept, because the practice is required to keep those. Whether the wording of a clinical note is removed or kept is the practice’s decision, because its professional body may require it to keep them; we record which it chose.
Two things are kept on purpose, and we would rather say so than imply otherwise. First, your name stays on your invoices and payment records. It is removed from the patient record itself — which from then on reads “Deleted record” wherever your name used to appear — but a financial record has to say who it was for, and the practice is required to keep those for tax. Second, if you asked in writing, the practice can keep a copy of your own message asking to be erased, as its evidence that you asked for this; it is kept for as long as the rest of that record is kept, and only staff who could carry out the erasure themselves can read it. Apart from those two things, the erasure is not reversible and we keep no copy of what is removed.
Five places an erasure request cannot reach, stated plainly rather than implied away. The name of a gift-card recipient, which is not linked to any patient record. Free text a member of practice staff wrote about one patient inside another patient’s notes. Support requests the practice has raised with us, where staff sometimes name a patient — those are deleted on their own schedule rather than by an erasure request. Anything held by the practice’s own card-payment provider, which is the practice’s to clear with them. And our encrypted backups, from which a single record cannot be picked out; those copies expire, and none is kept longer than 90 days.
10. Complaints
If you have concerns we haven’t resolved, you may complain to the UK Information Commissioner's Office (ICO) or, depending on where your practice is based, the OAIC (Australia), the OPC (Canada), or your local data-protection authority.
11. Changes
We may update this policy; material changes will be notified in-app or by email. The date above shows the latest revision.
Questions about this page? Contact us at help@wellspringscheduling.com.
