Porelo

Privacy Policy

Last updated 7 August 2026

Porelo provides booking, client-record and payment software for aesthetic clinics ("the Service"), available at porelo.co.uk. This policy explains what personal data we handle, why, and the rights you have under UK data protection law, including the UK GDPR and the Data Protection Act 2018.

You can contact us about anything in this policy at hello@porelo.co.uk.

1. The two roles we play

Porelo handles personal data in two distinct capacities, and your rights work differently in each:

  • As a controller — for the data of clinic owners and staff who create Porelo accounts, for billing records, and for data about visitors to our own website. For this data, we decide how and why it is processed.
  • As a processor— for the client records that clinics keep inside Porelo (their clients' contact details, appointment history, notes, photos and consent forms). The clinic is the controller of that data; we process it only on the clinic's instructions. If you are a client of a clinic that uses Porelo, please direct privacy requests to the clinic first — we will assist them in responding.

2. Data we collect

  • Account data — your name, email address, clinic name and a securely hashed password when you create an account.
  • Clinic data — the details a clinic configures in Porelo: treatments, prices, schedules, practitioners, opening hours, contact details and public booking-hub content.
  • Client records entered by clinics— contact details, appointment history, notes, consent forms and related records. These may include health information, which is special category data; it is processed solely on the clinic's instructions to provide the Service.
  • Payment data — payments are processed by Stripe. We receive transaction records (amount, status, last card digits) but never store full card numbers.
  • Technical and security data — IP addresses, device and browser information, and security logs used to keep accounts safe and prevent abuse.

3. How and why we use data

  • To provide, operate and support the Service.
  • To send transactional messages: booking confirmations, reminders, verification emails and service notices.
  • To take payment for subscriptions and process deposits.
  • To secure the Service: detecting fraud, abuse and automated traffic, and investigating incidents.
  • To comply with legal obligations, such as tax record-keeping.

Our lawful bases are: performance of a contract (providing the Service you signed up for), legitimate interests (securing and improving the Service), legal obligation (accounting and tax records), and consent where the law requires it. Where we act as a processor, we rely on the clinic's instructions and the clinic's own lawful basis.

4. Sub-processors and service providers

We use a small number of providers to run the Service. Each is bound by contractual data protection terms:

  • Supabase — database, authentication and file storage.
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • Vercel — application hosting.
  • Cloudflare — bot protection (Turnstile) on sign-up and public forms.
  • Sentry — error monitoring, so we can find and fix faults.

We do not sell personal data, and we do not share it with third parties for their own advertising.

5. International transfers

Some of our providers may process data outside the UK. Where they do, transfers are protected by UK-approved safeguards, such as adequacy regulations or the UK Addendum to the EU Standard Contractual Clauses.

6. How long we keep data

  • Account data — kept while your account is open. After an account is closed we delete or anonymise it within 90 days, except records we must keep longer by law (for example, billing records for up to 6 years for tax purposes).
  • Clinic client records — kept for as long as the clinic instructs us to hold them. Clinics can delete records at any time, and closing a clinic account triggers deletion of its client data after a short export window.
  • Backups — deleted data leaves routine backups on a rolling schedule within a short period of deletion.
  • Security logs — kept only as long as needed to protect the Service.

7. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased in certain circumstances;
  • restrict or object to certain processing;
  • receive your data in a portable format; and
  • withdraw consent where processing is based on consent.

To exercise any of these rights, email hello@porelo.co.uk. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office (ico.org.uk). If your data is held in Porelo by a clinic, the clinic is the controller and your request should go to them first — we will support them in responding.

8. Cookies

Porelo itself uses essential cookies only: they keep you signed in and protect the Service against abuse. If a clinic has enabled ad measurement on its public booking pages, a Meta (Facebook) Pixel cookie may additionally be set on those pages — but only after you accept the consent notice shown there, and you can decline it. We set no other advertising or cross-site tracking cookies.

9. Children

The Service is a business tool and is not directed at children. Clinics are responsible for their own policies on treating and recording data about people under 18.

10. Changes to this policy

If we make material changes to this policy we will notify account holders by email or in the app before the changes take effect. The date at the top shows when it was last revised.