Privacy Notice
This notice explains what CareFlow collects, why it is used, who controls it and how to raise a privacy request.
Last updated 24 August 2026
Public-launch gate: this product-aligned draft must be reviewed and approved by qualified privacy, healthcare and commercial counsel for each supported jurisdiction before CareFlow accepts real healthcare data or payment under these terms. It is not presented as legal advice or a signed customer agreement.
Who this notice covers
CareFlow OS provides business software to healthcare organisations. The organisation operating a workspace normally decides why patient, staff and operational data is entered and acts as the data fiduciary/controller. CareFlow processes that workspace data to provide the service under the customer agreement.
CareFlow is responsible for account, billing, website-enquiry, security and service-administration data it collects for its own business purposes.
Data we handle
Account and identity data such as name, work email, role, organisation, verification status and password hash.
Workspace data entered by authorised customers, which may include patient, appointment, clinical workflow, laboratory, pharmacy, billing, staff and audit records.
Commercial and technical records such as plan, invoice, payment identifiers, support enquiries, IP-derived security signals, request path, response status and duration. CareFlow telemetry is designed not to store request bodies, passwords, tokens or medical records.
Why data is used
To create and secure accounts, provide tenant-scoped product functions, process payments, send transactional communications, answer support requests, prevent abuse, investigate incidents and satisfy documented legal or accounting duties.
CareFlow does not sell patient or workspace data and does not use clinical workspace data for advertising.
Sharing and subprocessors
Data is shared only with configured service providers needed for hosting, database, asset storage, payment, email or optional AI functions, and with authorities when legally required. The current conditional list is published on the Subprocessors page.
A customer should not enable an optional provider until its region, terms and data flow are acceptable for the intended data.
Security and retention
Implemented application controls are described in the Trust Centre. Deployment security, backups, device controls and customer access governance remain shared responsibilities.
Workspace deletion has a seven-day recovery period. Operational records are then erased; a redacted and pseudonymised security/financial audit minimum may be retained for up to 365 days. Other retention periods are listed in the Retention Schedule.
Your choices and requests
Workspace owners can request a structured export and schedule deletion after re-authentication. Individuals should first contact the healthcare organisation that collected their data; CareFlow will assist that organisation where required.
Privacy, security and grievance requests can be sent to hello@careflowosai.com. Include the organisation name and enough information to verify the request; never email clinical records or passwords.
Cookies and updates
CareFlow currently uses essential session and security storage needed to operate the service. A consent banner must be introduced before non-essential analytics, advertising or cross-site tracking is enabled.
Material changes will be dated and communicated through an appropriate product, email or contractual notice.
