Privacy Policy

Last Updated: April 21, 2026


1. Introduction

Cliara Technologies Ltd ("we," "our," or "Cliara") operates the Cliara platform at cliara.co.uk, a dental practice directory and booking service.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform.

Our Details:

We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


2. Information We Collect

2.1 Patient Information

When you book an appointment through Cliara, we collect:

We do NOT collect:

2.2 Practice Information

When a dental practice registers on Cliara, we collect:

2.3 Automatically Collected Information

We automatically collect:


3. How We Use Your Information

We process personal data only when we have a legal basis to do so under UK GDPR Article 6:

3.1 Contract Performance

We process data to fulfill our service to you:

PurposeData UsedLegal Basis
Processing appointment bookingsName, email, phone, appointment detailsContract
Sending booking confirmationsEmail, phone (via Resend and Twilio)Contract
Managing user accountsEmail, name, passwordContract
Providing customer supportAll account informationContract
Storing booking historyAppointment records, practice detailsContract + Legal Obligation (financial records)

3.2 Legitimate Interests

We process data for our business operations:

PurposeData UsedLegal Basis
Sending review requests post-appointmentEmail, phoneLegitimate Interest (quality feedback)
Displaying reviews publiclyReview text, rating, reviewer first nameLegitimate Interest (transparency)
Marketing to dental practices (B2B)Practice contact detailsLegitimate Interest (business development)
Analytics and platform improvementUsage data, anonymized metricsLegitimate Interest (service improvement)
Fraud prevention and securityIP address, device info, booking patternsLegitimate Interest (protecting users)

Your Rights: You can object to processing based on legitimate interests at any time by contacting us.

3.3 Consent

We process data with your consent for:

PurposeData UsedLegal Basis
Marketing emails to patientsEmail addressConsent (opt-in checkbox at registration)
Analytics cookiesBrowsing behaviorConsent (cookie banner)

Your Rights: You can withdraw consent at any time by unsubscribing from emails or changing cookie preferences.

3.4 Legal Obligations

We retain certain data to comply with UK law:


4. How We Share Your Information

4.1 Sharing with Dental Practices

When you book an appointment, we share your contact details with the practice:

4.2 Third-Party Service Providers

We use trusted service providers who process data on our behalf:

ProviderPurposeData SharedLocation
SupabaseDatabase hostingAll user dataEU (London, UK — eu-west-2 region)
StripePayment processing (practice subscriptions only)Practice billing informationEU/UK
ResendTransactional emailsEmail addresses, namesEU
TwilioSMS notificationsPhone numbersEU
Cloudflare R2Image storagePractice photos, logosEU
Google Maps APILocation servicesPractice addressesGoogle data centers (Standard Contractual Clauses in place)
Google Analytics 4Website analyticsAnonymized usage dataGoogle data centers (with consent only)
VercelWebsite hostingServer logs (IP addresses)EU/UK

All third-party providers are contractually required to protect your data and use it only for the specified purposes. We use Standard Contractual Clauses (SCCs) where data is transferred outside the UK/EU.

4.3 Legal Requirements

We may disclose your information if required by law:

We will never sell your personal data to third parties.


5. Data Retention

We retain personal data only as long as necessary:

Data TypeRetention PeriodReason
Active patient accountsUntil you delete your accountOngoing service provision
Inactive patient accounts2 years of inactivityAfter 2 years, we send a deletion warning. Account deleted 30 days later if no response.
Booking history7 years from booking dateLegal requirement (HMRC financial record-keeping)
ReviewsIndefinitely (or until you request deletion)Public content that other users rely on. If you delete your account, your name is anonymized to "Anonymous" but the review text remains.
Active practice accountsUntil subscription is cancelled + 30 daysOngoing service provision + grace period for reactivation
Cancelled practice accounts30 days after cancellationGrace period for reactivation, then deleted
Payment records7 yearsLegal requirement (HMRC)
Analytics data (Google Analytics 4)14 monthsGA4 default auto-deletion
Server logs (Vercel)30 daysVercel default retention

Note on Booking History: Even after account deletion, booking records are retained for 7 years (HMRC requirement for financial records). However, your personal contact details (name, email, phone) are redacted — replaced with "[REDACTED]" — so the booking history is no longer personally identifiable.


6. Your Data Protection Rights

Under UK GDPR, you have the following rights:

6.1 Right of Access

Request a copy of all personal data we hold about you.

How to exercise: Email hello@cliara.co.uk or use the "Download My Data" button in your account settings (provides instant JSON export).

6.2 Right to Rectification

Correct inaccurate or incomplete personal data.

How to exercise: Update your details in account settings, or email hello@cliara.co.uk.

6.3 Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data.

How to exercise: Use the "Delete My Account" button in account settings, or email hello@cliara.co.uk.

Important: Some data is retained for legal reasons (e.g., booking history for HMRC), but your contact details are redacted. Reviews are anonymized.

6.4 Right to Restrict Processing

Request that we temporarily stop processing your data (e.g., while disputing accuracy).

How to exercise: Email hello@cliara.co.uk.

6.5 Right to Data Portability

Receive your data in a machine-readable format (JSON) to transfer to another service.

How to exercise: Use the "Download My Data" button in account settings.

6.6 Right to Object

Object to processing based on legitimate interests or for direct marketing.

How to exercise:

6.7 Right to Withdraw Consent

Where processing is based on consent (e.g., marketing emails, analytics cookies), you can withdraw consent at any time.

How to exercise:

6.8 Right to Complain

If you believe we've mishandled your data, you can complain to the UK's data protection authority:

Information Commissioner's Office (ICO)


7. Data Security

We take security seriously and implement appropriate measures to protect your data:

Data Breach Notification: If we experience a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours, as required by law.


8. Age Restrictions

You must be at least 16 years old to use Cliara. If you are under 16, a parent or guardian must book appointments on your behalf using their own contact details.

If you are under 18, please ensure you have permission from a parent or guardian before booking an appointment.

We do not knowingly collect personal data from children under 16. If we discover we have inadvertently collected such data, we will delete it promptly.


9. Cookies and Tracking Technologies {#cookies}

We use cookies and similar technologies to improve your experience on our website.

9.1 What Are Cookies?

Cookies are small text files stored on your device by your web browser. They help us remember your preferences, keep you logged in, and analyze how you use our site.

9.2 Types of Cookies We Use

Essential Cookies (No Consent Required)

These cookies are necessary for the website to function:

Cookie NamePurposeDuration
sb-access-tokenKeeps you logged in (Supabase authentication)Session
sb-refresh-tokenRefreshes your login session30 days

Analytics Cookies (Consent Required)

These cookies help us understand how you use our site:

Cookie NamePurposeDurationProvider
_gaDistinguishes unique visitors2 yearsGoogle Analytics 4
_ga_*Maintains session state2 yearsGoogle Analytics 4

We only set analytics cookies if you click "Accept All" in our cookie banner. If you click "Reject All," analytics cookies are not set and Google Analytics does not track you.

9.3 Managing Cookies

Cookie Consent Banner: When you first visit Cliara, you'll see a banner asking for your cookie preferences. Your choice is stored for 1 year.

Change Your Mind: You can change your cookie preferences at any time by:

  1. Clearing cookies in your browser settings (this resets your choice and the banner will appear again)
  2. Emailing hello@cliara.co.uk to request we manually reset your consent

Browser Controls: You can also disable cookies entirely in your browser settings. However, this may affect website functionality (e.g., you won't stay logged in).

9.4 Do Not Track

Some browsers support a "Do Not Track" (DNT) signal. We respect DNT signals — if DNT is enabled, we do not load Google Analytics even if you previously accepted cookies.

9.5 Third-Party Cookies

We do not use third-party advertising cookies or tracking pixels (e.g., Facebook Pixel, Google Ads Remarketing).

The only third-party cookies on our site are:


10. International Data Transfers

Your data is primarily stored in the UK and EU:

Some service providers may process data outside the UK/EU:

Where data is transferred outside the UK/EU, we ensure adequate protection through:


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

How We Notify You:

Your Continued Use: By continuing to use Cliara after changes are posted, you accept the updated Privacy Policy.

We recommend reviewing this page periodically to stay informed.


12. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Email: hello@cliara.co.uk

Mail: Cliara Technologies Ltd
6 Pagett Close
Hucknall
NG15 7US
United Kingdom

Data Protection Contact: Nethmin Seneviratne (Director)

Response Time: We aim to respond to all data protection requests within 30 days (as required by UK GDPR).


13. Definitions


End of Privacy Policy

For Terms & Conditions, see: