Draft — pending legal review
This page is a working draft prepared to describe how Doxia currently operates. It has not yet been reviewed by a qualified solicitor and should not be relied on as legal advice or a final, binding statement of Doxia's terms. Contents may change once formal legal review is complete.
1. Who we are
Doxia ("Doxia", "we", "us") provides an AI-assisted enquiry capture and qualification tool for UK aesthetics and med-spa clinics. This policy explains what personal data we collect through our website, dashboard, and enquiry widget, why we collect it, and the choices and rights you have over it. You can contact us at smartbiz1607@gmail.com.
2. Two kinds of data, two roles
Doxia handles two distinct categories of personal data, and we play a different legal role for each:
- Clinic account data (your clinic's name, email, phone number, and login credentials) — here, Doxia is the data controller. We decide why and how this data is processed, as described in this policy.
- Patient enquiry data (the name, email, phone, and message a patient submits through your embedded widget) — here, your clinic is the data controller, and Doxia acts only as a data processor, handling that data on your instructions and for the sole purpose of running the enquiry-management service you've signed up for. If you are a patient of a clinic that uses Doxia, your clinic — not Doxia — is responsible for how your enquiry is used and is the right party to contact about your data rights in the first instance.
3. What we collect
- Account information: clinic name, contact email, phone number, and a hashed password (via Supabase Auth — we never see or store your password in plain text).
- Patient enquiry data: name, email, phone number, treatment interest, and free-text message, submitted through your website's embedded widget.
- Billing data: your subscription tier and status. Card and payment details are collected and processed directly by Stripe — Doxia never sees or stores full card numbers.
- Technical data: a single session cookie that keeps you signed in to the dashboard, and a local, on-device preference for light/dark mode. See Section 8 for the full detail — we don't use any analytics or advertising cookies.
4. How we use it
- To provide the dashboard, widget, and enquiry-management service you've signed up for.
- To automatically read, score, and flag incoming patient enquiries for follow-up priority and safety review (see Section 5 — this involves sending enquiry text to Anthropic's Claude AI model).
- To send transactional emails — e.g. notifying a clinic when a new enquiry arrives.
- To manage your subscription and billing via Stripe.
- To respond to support or contact form enquiries.
5. Who we share data with
We use a small number of specialist providers to run Doxia, each acting as a data processor under contract with us. We don't sell personal data, and we don't share it for advertising purposes.
- Supabase hosts our database and handles account authentication, storing both clinic account data and patient enquiry data.
- We use Resend to send transactional emails, such as new-enquiry notifications and contact form submissions.
- Subscription payments are processed by Stripe, which receives billing contact details and payment information directly. Doxia never stores your card numbers.
- Anthropic's Claude API receives the treatment interest and message text of a patient enquiry, using it to automatically assess how ready-to-book the enquiry is and flag anything needing careful human review. This is only a suggestion: a human at your clinic always makes the final call, and a status changes only once your team accepts or overrides it.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, property, or safety of Doxia, our customers, or others.
6. Legal basis for processing (UK GDPR)
- Contract — processing your clinic's account data and, as a processor, patient enquiry data, is necessary to provide the service you've subscribed to.
- Legitimate interests — for security, fraud prevention, and improving the reliability of the service.
- Legal obligation — where we're required to retain or disclose data by law (e.g. tax/accounting records for billing).
7. Data retention
We keep account and enquiry data for as long as your clinic's account remains active, so the service continues to work as expected. If you delete your account (Settings → Manage subscription/Danger zone), your clinic record, every lead and enquiry tied to it, and your login are permanently and immediately deleted from our systems — see Section 9. Billing records that Stripe retains for tax/accounting purposes are governed by Stripe's own retention practices.
8. Cookies and similar technologies
Doxia does not use analytics, advertising, or tracking cookies of any kind — on this website, the dashboard, or the enquiry widget embedded on clinic websites. We've audited every cookie and local storage entry the platform sets, and there are exactly two, both strictly necessary for the service to function:
- A session cookie on the dashboard (app.doxia.uk) that keeps you signed in for up to 8 hours. Without it, you'd be asked to log in on every page.
- A local, on-device preference storing whether you've chosen light or dark mode for the dashboard. This never leaves your browser.
Because both are strictly necessary for a service you've actively requested (signing in; remembering a display preference you set), UK PECR rules mean we don't need your consent to use them, and this website does not show a cookie consent banner. This site's widget, when embedded on a clinic's own website, sets no cookies or local storage at all.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Have your data erased. You can do this yourself at any time from Settings in the dashboard: doing so permanently deletes your clinic record, every lead and enquiry tied to it, and your login, automatically cancelling any active Stripe subscription first.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), if you believe your data has been mishandled.
If you're a patient rather than a clinic user, please contact the clinic you enquired with first, since they control how your enquiry data is used. Doxia will assist them in fulfilling your request.
10. International transfers
Some of our processors (Section 5) may process or store data outside the UK. Where this happens, we rely on the safeguards those providers make available (such as Standard Contractual Clauses or equivalent adequacy protections) to ensure your data continues to receive an appropriate level of protection.
11. Children's data
Doxia is intended for use by aesthetics and med-spa businesses and their adult patients. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy as the service evolves or once formal legal review is complete. Material changes will be reflected by updating the "Last updated" date above.