← Back to Bia

Bia

Privacy Policy — UK edition

Version 2026-08-01

1. UK identity and scope

This UK edition is a separate privacy notice for people in the United Kingdom. It is not the EU GDPR text translated into English. The Brazilian legal entity or legal representative identified at the end of this document, referred to below as the Operator, offers the Bia product. This Policy explains how personal data from clinic representatives, team members, clients, patients, and visitors to public pages is processed under the UK GDPR and the Data Protection Act 2018. It is operational information and requires human legal review before UK sales.

2. Controller and processor roles under UK law

For registration, contracting, billing, security, support, and the Operator's relationship with a clinic, the Operator usually determines the purposes and acts as controller. For client and patient data entered or received by a clinic, the clinic usually determines the purpose and acts as controller, while the Operator processes the data to provide the service as processor. The role depends on the specific operation, contract, and instructions; the clinic must give its own notices where it is the controller.

3. Personal data and special category data

  • Account and team: name, clinic, email, provided phone number, role, permissions, hashed password, sessions, and access records.
  • Clinic operations: clients, conversations, calendar, services, professionals, preferences, notifications, and enabled integrations.
  • Clinical and special category data: form and anamnesis answers, aesthetic records, clinical photos, health information, terms, and notes supplied by the clinic or patient. Health information may be special category data under UK law.
  • Messages: text, audio, images, delivery metadata, and the history needed for WhatsApp support. A message may contain personal or health information supplied by a clinic or patient.
  • Billing: plan, cycle, currency, amounts, status, and provider identifiers. Full card details are collected in the Asaas or Stripe environment and are not stored by the system.
  • Security and audit: IP address, session identifiers, authentication events, administrative actions, and audit trails.
  • Visit and acquisition: random browser identifier, landing-page source, and UTM parameters. The anonymous flow does not receive a name, email, phone number, or patient content.

4. Purposes and lawful bases

Data is processed to create and protect accounts, perform the contract, operate the assistant and calendar, process payments, deliver transactional communications, provide support, prevent fraud, maintain audits, measure the commercial funnel, comply with legal obligations, and establish or exercise legal rights. Depending on the operation, the Article 6 UK GDPR basis may be contract, legal obligation, legitimate interests, consent, or another basis available in law. Where special category data is processed, a separate Article 9 condition and any required Data Protection Act 2018 Schedule 1 condition must also be identified.

The clinic must define and document the lawful basis and special category condition applicable to its care, give the required notices, and obtain any consent required by law. The Operator does not intend to make solely automated decisions producing legal or similarly significant effects; if that changes, the notice and safeguards will be updated before the change is used.

5. Artificial intelligence and clinical information

We use contracted and paid artificial-intelligence services. Clinical content recorded in the system — records, anamnesis forms, and questionnaires — is encrypted and is not sent to an external artificial-intelligence service. WhatsApp messages are processed by selected providers only to generate a reply, and each clinic's data is isolated: no clinic can access another clinic's data.

Recent message history may be used to generate replies, classify the conversation stage, and prepare continuity of care. Audio may be sent to Groq for transcription; images received in a conversation may be sent to OpenAI for interpretation; text is processed by DeepSeek in the technical version audited for this draft. These flows do not authorise sending stored records, anamnesis forms, or questionnaires to providers. AI output is not clinical advice and does not replace human judgement.

6. Providers and sharing

Sharing is limited to the recipient and function required for the service:

  • WhatsApp and Evolution API, to receive and send messages;
  • DeepSeek, for text processing; Groq, for audio transcription; OpenAI, for image interpretation;
  • Asaas, as a payment provider and subprocessor for Brazilian-real payments in the new flow; Stripe, as a payment provider and subprocessor for GBP, dollar, euro, and legacy-flow payments while that configuration remains active;
  • Resend, for transactional email;
  • Google Calendar, only when the clinic enables the integration;
  • hosting, database, queue, and monitoring infrastructure needed for operation;
  • authorities, professional advisers, or third parties when legally required or when exercising rights.

A provider may act as a processor, subprocessor, or independent controller depending on its service and contract. This Policy does not claim that providers stop using data for training; current provider contracts and terms must be verified and recorded before making that promise.

7. Transfers from the UK to Brazil

The Operator is established in Brazil. Sending UK personal data to the Operator or a provider in Brazil is a restricted international transfer where UK rules apply. No UK adequacy claim is made for Brazil in this notice. The declared basis for a restricted transfer is an appropriate safeguard under Article 46 of the UK GDPR, such as the UK International Data Transfer Agreement or the UK Addendum, together with a documented transfer risk assessment (called a data protection test in current UK legislation) and any supplementary measures identified. The Operator must verify and execute the actual safeguard for each provider before the relevant UK transfer; an Article 49 exception may be used only where its narrow legal conditions are met. People may request information about the safeguard through the privacy contact below.

8. Retention, deletion and minimisation

The current system does not apply one automatic deletion period to every persisted category. Data remains only while needed for the account and contracted operation and may be retained after closure for security, audits, legal obligations, fraud prevention, or exercising rights. Deletion requests are assessed according to the category, the controller or processor role, the lawful retention ground, and any applicable UK GDPR or Data Protection Act 2018 requirement. We aim to collect and retain only what the stated purpose requires.

9. Security and personal data breaches

Verified controls include password hashing, AES-256-GCM encryption of secrets and the clinical content identified in this Policy, tenant isolation with database policies, role-based permissions, audit trails, authentication, rate limits, and rechecks before sensitive actions. The Operator and each clinic must assess and manage incidents according to their controller or processor role and applicable law.

No control eliminates every risk. Suspected incidents or unauthorised access must be reported through the privacy contact listed at the end so the responsible controller can assess the event and take the required steps.

10. UK data protection rights and requests

Subject to the limits and conditions in the UK GDPR and the Data Protection Act 2018, a data subject may have the right to be informed, access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent where consent is the basis, and safeguards around solely automated decision-making. The right to object to direct marketing is absolute. Rights differ with the lawful basis and controller role; they are not all unconditional.

Requests should be sent to the privacy email listed below. The Operator may request information needed to confirm identity and locate the responsible controller. The usual response period is one calendar month, subject to lawful extensions. When the clinic is the controller, the Operator will provide the available technical assistance for its response. A person may complain to the UK Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/ without losing any other legal remedy.

11. Cookies and similar technologies

The pages use cookies or local storage needed for sessions, security, language, and attribution of a visit to registration. The anonymous acquisition identifier does not contain a name, email, phone number, or patient content. Optional advertising or analytics technologies require assessment and an appropriate consent mechanism before activation. Browser controls may also affect local storage.

12. Updates, contact and ICO complaints

This Policy may be updated to reflect legal, contractual, or service changes. The version appears at the top. Privacy requests, statutory notices, and breach reports should be sent to the Operator's privacy email shown below. A person in the UK may contact the ICO using the channel above. This document is operational information, not legal advice, and requires human legal review before the Operator sells to UK customers; mandatory law prevails where it applies.

UK Privacy Policy | Bia