Version 1.0 · Effective date: 20 July 2026 Operator: The Private Clinic — العيادة الشخصية الطبية, a company registered in the Hashemite Kingdom of Jordan, Company No. 75818, National Establishment ID 200204705 (“Aura“, “we“, “us“). Contact / Privacy Officer: care@theprivateclinic.me
1 · Who this policy covers, and the three roles
Aura is a booking, practice-management and electronic-records platform operated on link.theprivateclinic.me and connected to care.theprivateclinic.me (together, the “Platform“). Three parties interact on it, and this policy is explicit about who is responsible for what — this allocation of roles is the foundation of the entire document:
- Providers — healthcare and wellness professionals who create an account, publish a public booking page, and manage clients. For their own account data, Aura is the data controller. For the client and patient records a Provider creates or collects through the Platform, the Provider is the data controller and Aura acts strictly as a data processor on the Provider’s documented instructions.
- Clients / patients — people who book sessions with a Provider. Their platform account data (login, bookings) is controlled by Aura; their health information (session notes, medications, chart entries) is controlled by the treating Provider.
- Visitors — anyone who views a public Provider page without booking.
By creating a Provider account or booking a session, you accept this policy. If you do not accept it, do not use the Platform.
2 · Data we collect
2.1 From Providers
- Identity & profile: name, email, phone, professional credentials, specialty, biography, profile photo, page handle, tagline, gallery media, and any content you choose to publish.
- Practice configuration: services, prices and currencies, working hours, special days, blocked times, timezone, language preference, page appearance settings.
- Business & billing: subscription plan, plan dates and trial status, Site 2 (WooCommerce) order history for plan purchases, commission percentage applicable to your plan, coupon configurations.
- Payout details: bank name, branch, beneficiary name, account number, IBAN, SWIFT, bank address and country — collected solely to execute payouts you request.
- Integration credentials: OAuth tokens for Google Calendar and Microsoft Calendar (we store tokens, never your passwords), your Zoom meeting link, webhook URLs you configure, and advertising pixel IDs you enter.
- Team data: roles and memberships (owner, provider, assistant) and invitation email addresses.
2.2 From Clients / patients
- Account data: name, email address and login credentials (passwords are hashed by WordPress; we never store them in readable form).
- Booking data: the service booked, date and time, timezone, booking status, payment amount and currency, package credits, and idempotency identifiers used to prevent duplicate bookings.
- Health records (special-category data): session notes, chart entries, medication records and any clinical information the treating Provider enters. These are entered by and belong to the Provider’s clinical relationship with the patient. They are never displayed to the client through the Platform, never used by Aura for any purpose other than storage and display to the authorized Provider, and never used for advertising, profiling or model training.
- Communications: booking-related emails we send on the Provider’s behalf, invitations and nudges the Provider triggers.
2.3 From Visitors and all users (technical data)
- Cookies we set:
aura_pref_lang,aura_lang_applied,aura_lang_auto(language preference),aura_client_tz(your timezone, so session times display correctly), and standard WordPress session cookies for logged-in users. - Local storage: interface state only — guided-tour progress, dismissed banners. No tracking identifiers.
- Usage analytics: page views and link clicks on public Provider pages, aggregated for the Provider’s own analytics dashboard. We do not build cross-site profiles.
- Logs: server logs and an internal diagnostic log (IP address, timestamps, request context) retained for security and troubleshooting.
We do not collect: government ID numbers, biometric data, or precise geolocation. Payment card numbers never touch Aura’s systems (§5).
3 · Why we process data, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Operating your account and the booking engine | Profile, practice, booking data | Performance of contract |
| Storing and displaying patient records to the authorized Provider | Health records | Processor acting on Provider’s instructions; the Provider must hold a lawful basis (typically the treatment relationship and applicable medical-records law) |
| Publishing the public page you configure | Data you choose to publish | Performance of contract; your explicit direction (§4) |
| Payouts and plan billing | Payout details, order history | Performance of contract; legal obligations (accounting) |
| Transactional email (confirmations, reminders, receipts, security notices) | Contact + booking data | Performance of contract / legitimate interest |
| Product announcements to Providers | Provider email | Legitimate interest, with opt-out (§9) |
| Security, fraud prevention, abuse response, account-lock protection | Technical data, logs | Legitimate interest / legal obligation |
| Legal compliance and defense of claims | Minimum necessary | Legal obligation / legitimate interest |
We do not sell personal data, rent it, or share it with data brokers — in any jurisdiction, under any revenue model.
4 · Public information — what you publish is public
When a Provider publishes a page at /@handle, everything on it — name, photo, credentials, bio, services, prices, availability, posts and links — is publicly accessible on the internet, indexable by search engines, and shareable by anyone. In addition:
- Link previews shared in messaging apps display a QR code image encoding your page address (generated by a third-party QR service that receives only the page URL — never client or health data).
- If you create a short link, the destination page URL is shared with the shortening service you selected through the Platform.
- Your page handle appears in URLs; choose it accordingly.
You control this exposure. Unpublishing content, deactivating a service, or deleting your account removes the material from the Platform, but Aura cannot recall copies already cached by search engines, messaging apps or third parties. Never place client or patient information on your public page. Doing so violates this policy and your professional obligations, and responsibility for such publication rests solely with you.
5 · Payments
Client payments and plan purchases are processed by the payment processors connected to care.theprivateclinic.me — HyperPay, PayTabs, Paymob and Zbooni. Card and wallet credentials are collected directly by those processors under their own privacy policies; Aura receives only the order outcome, amount, currency and status. Payout bank details are stored for the sole purpose of transferring your earnings and are visible only to you and authorized Aura payout administrators.
6 · Patient records: confidentiality architecture
This section governs the electronic records feature and is deliberately strict.
6.1 Ownership and control. The treating Provider is the controller of every chart entry, session note and medication record they create. Aura stores this data, displays it to the authorized Provider, and does nothing else with it.
6.2 Access control, as enforced in software.
- Clinical charts are visible only to the Provider who owns the client relationship (and, where a practice owner legitimately administers a team member’s practice, to that owner).
- Assistants (front desk) can never access clinical charts, notes, medications, revenue or content — this is enforced both in navigation and at the API permission layer.
- Clients cannot see Provider notes through any Platform interface.
6.3 No secondary use. Aura does not read, analyze, mine, sell, or train any system on patient records. Aggregated, non-identifying operational statistics (e.g., total bookings across the platform) never include clinical content.
6.4 Data Processing Addendum. Providers processing patient data through Aura are bound by the Data Processing Addendum published alongside this policy, which forms part of the Terms of Service and specifies processing instructions, sub-processors, security measures, breach assistance and deletion terms. If you do not accept the DPA, do not enter patient data into the Platform.
6.5 Provider warranties. By entering any client or patient data, the Provider warrants that they: (a) hold a lawful basis and, where required, valid consent for that processing; (b) comply with the medical-records, professional-secrecy and licensing laws of every jurisdiction in which they practice; (c) will provide their own patient-facing privacy notice where required by law; and (d) will not enter data of any person with whom they have no genuine professional relationship. The Provider indemnifies Aura against claims arising from the Provider’s breach of these warranties, per the Terms of Service.
7 · Integrations — data leaves the Platform only at your direction
Every integration below is off by default and activates only when a Provider connects or configures it. When you connect an integration, you instruct Aura to transmit the described data to that third party, whose own privacy policy then governs it:
| Integration | What is shared when YOU enable it |
|---|---|
| Google Calendar | Booking events (time, service name, and the client identifier you configure — either the client’s full name or an anonymous label) are written to your Google calendar; busy times may be read to block double-booking. Governed by Google’s policy; revocable in Settings → Integrations or your Google account. |
| Microsoft / Outlook Calendar | Same scope as Google, to your Microsoft account. |
| The Private Clinic listing sync | Your public profile and service data sync to your listing on care.theprivateclinic.me. No clinical data is ever synced. |
| Booking Webhook (Make.com, Zapier, n8n…) | Booking event payloads (client name, email, service, time, status) are sent to the URL you provide. You are the controller of this transfer: you must ensure the receiving system is secure and lawful. Aura is not responsible for data once delivered to your endpoint. |
| Zoom | Your meeting link is embedded in booking confirmations and Join buttons. Session content is governed by Zoom’s policy. |
| Marketing pixels (Google, Meta, TikTok…) | If you enter pixel IDs, those vendors’ scripts run on your public page only — never on the dashboard and never on any page containing clinical data — and collect visitor data under your responsibility as the party deploying them. You must ensure your use of pixels (including any consent banner obligations) is lawful in your market. |
| URL shortener / QR services | Receive only the public page URL. |
| Push notifications (mobile app) | A device token is stored to deliver booking notifications to your device. |
Sub-processors used by Aura itself (hosting, email delivery, infrastructure): Hostinger (hosting and email delivery). We will update this policy before adding any sub-processor that touches personal data.
8. AI Provider and AI-Assisted Features
Aura includes an optional Provider Copilot feature that assists providers with practice-management and clinical documentation tasks.
When a provider uses Aura AI, Aura may send the information necessary to answer that provider’s request to the AI service configured by Aura’s administrator. The current Aura AI implementation is designed to use OpenAI’s API as its external AI service.
Depending on the provider’s request, information sent to the AI service may include provider practice information, booking and scheduling information, and client information that the provider is authorized to access, including clinical documentation such as SOAP notes and assignments.
Aura AI is a provider-assistance feature. It does not independently diagnose, prescribe, make autonomous clinical decisions, or write information into a client’s clinical record without an authorized user action.
Aura does not use client clinical records obtained through Aura AI to advertise, sell to data brokers, or train generalized AI models. AI-generated responses are presented as drafts for provider review.
Google Calendar information is not used as input to Aura AI. Google Calendar event contents, calendar availability information, and other Google Calendar data obtained through the Google Calendar integration are handled separately for calendar synchronization and scheduling functionality and are not intentionally transmitted to Aura AI or the AI provider.
9. Google Calendar Data
When a provider connects Google Calendar, Aura requests access to the Google Calendar permission required for its calendar synchronization features.
Aura uses Google Calendar data only to provide the calendar functionality requested by the provider, including:
- creating booking events in the provider’s selected Google Calendar;
- updating existing Aura booking events when a booking is rescheduled or its relevant calendar information changes;
- removing Aura booking events when applicable;
- reading calendar events during the relevant scheduling period to identify busy times and help prevent double-booking.
Aura currently requests the Google Calendar scope:
https://www.googleapis.com/auth/calendar.events
Aura does not request Google Calendar permissions that are not required by these features.
Google Calendar event data is not used for advertising, sold to third parties, or used to create, train, or improve generalized artificial intelligence or machine-learning models.
Google Calendar data is not intentionally transferred to Aura’s AI provider for AI processing or model training.
The provider can disconnect Google Calendar from Aura at any time through Aura’s integration settings or through their Google Account permissions.
10. Google Limited Use Commitment
Aura’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Aura limits its use of Google Calendar data to providing the calendar synchronization and scheduling features described above. Google Calendar data is not used for advertising, sold to data brokers, or used to create, train, or improve generalized artificial intelligence or machine-learning models.
Access to Google Calendar data is limited to the purposes described in this Privacy Policy and to the operation, security, and support of the requested Aura calendar functionality.
11. AI Service Data Protection
Aura’s AI feature is separate from the Google Calendar integration. Google Calendar data is not intentionally supplied to the AI service.
Where client or clinical information is submitted to the configured AI service through Aura AI, that processing occurs only when an authorized provider uses the AI feature. The AI service and applicable account or service terms may govern processing of that information. Aura will maintain appropriate contractual, technical, and organizational safeguards for such processing.
The AI provider currently configured for Aura should be identified in the application’s current privacy disclosures and reviewed whenever the configured AI provider, endpoint, processing terms, or data-handling arrangements change.
12 · International transfers
The Platform is hosted with Hostinger. Providers and clients may access it from anywhere. Where personal data is transferred across borders — including to integration vendors you enable under §7 — we rely on contractual safeguards and the transfer provisions of Jordan’s Personal Data Protection Law No. 24 of 2023, and we respect the data-protection laws applicable where our users reside (including the Saudi PDPL and Egypt’s Law No. 151 of 2020 for users in those markets). Provider-directed transfers (webhooks, calendars, pixels) are made at the Provider’s instruction and responsibility.
13 · Marketing communications
- Transactional messages (booking confirmations, payment receipts, payout receipts, security alerts, plan and trial notices) are part of operating the service and cannot be opted out of while you hold an account, because the service cannot function safely without them.
- Non-essential announcements to Providers include an unsubscribe link; opting out is honored platform-wide via our suppression list.
- We never email a Provider’s clients for Aura’s own marketing. Client emails exist to serve the Provider–client relationship only.
- Booking-related emails sent “from” a Provider are sent on that Provider’s behalf as processor.
14 · Cookies and similar technologies
We use only the functional cookies and local-storage keys listed in §2.3. We set no advertising or cross-site tracking cookies of our own. Third-party cookies can appear in exactly two situations: (a) on a Provider’s public page where that Provider has deployed marketing pixels (§7 — the Provider’s responsibility, including any consent requirements), and (b) embedded content such as YouTube video covers a Provider adds to their page. Blocking cookies in your browser may break language preference and sign-in.
15 · Security
We apply layered safeguards: encrypted transport (HTTPS) across the Platform; hashed credentials; role-based access control enforced at the API layer (including the assistant restrictions in §6.2); brute-force lockout after repeated failed logins with administrator-controlled unlock; nonce-verified authenticated API requests; least-privilege administrative access; and diagnostic logging for incident investigation. No system is impenetrable; §13 describes our breach response.
16 · Retention and deletion
| Data | Retention |
|---|---|
| Provider account & practice data | Life of the account + 90 days, then deleted or anonymized |
| Patient records | Retained per the treating Provider’s instructions and the medical-records retention law of the Provider’s place of practice under their license — the Provider is responsible for knowing that obligation. Records are deleted or exported upon the Provider’s request, never automatically, so that no lawful retention duty is ever breached by an automated purge. |
| Bookings & financial records | 7 years, for accounting and tax law |
| Payout bank details | Until removed by the Provider or 90 days after the last payout |
| Server & diagnostic logs | 90 days |
| Email suppression list | Indefinitely (it exists to honor your opt-out) |
| Backups | Rolling 90-day cycle; deleted data ages out of backups within that cycle |
17 · Data breach response
If we become aware of a breach affecting personal data, we will: contain and investigate; notify the competent authority where required by applicable law and within its deadline; notify affected Providers so they can meet their own controller obligations toward patients; and document the incident. Providers must promptly notify us at care@theprivateclinic.me of any suspected compromise of their account or endpoints.
18 · Your rights
Subject to applicable law, Providers and clients may request: access to their data, correction, deletion, restriction, portability, and objection to processing based on legitimate interest, and may withdraw consent where consent is the basis (withdrawal does not undo prior lawful processing).
Routing rule that prevents disputes: requests concerning clinical records must be directed to the treating Provider, who controls them; Aura will assist the Provider as processor. Requests concerning platform account data go to care@theprivateclinic.me. We answer within 30 days, may verify identity first, and will explain any legal ground on which a request is declined (e.g., a medical-records retention law that overrides deletion). You may lodge a complaint with your supervisory authority.
19 · Children
The Platform is not directed at children. Account holders — Provider or client — must be 18 years of age or older. A Provider account holder must additionally be licensed or qualified to offer their services. Where a Provider treats minors, the Provider is responsible for obtaining guardian consent as required by law; booking accounts must be created by an adult guardian.
21 · What this policy does not cover
Third-party sites reached through links on Provider pages; the independent practices of integration vendors you enable; the content of communications between Provider and client outside the Platform; and care.theprivateclinic.me’s own storefront policies, which are published separately.
22 · Changes
We may amend this policy. Material changes will be announced to account holders (dashboard notice and/or email) at least 14 days before taking effect; the “Effective date” above always reflects the current version. Continued use after the effective date constitutes acceptance.
23 · Contact
Privacy questions, rights requests and complaints: care@theprivateclinic.me (The Private Clinic — العيادة الشخصية الطبية, Company No. 75818, Jordan).
