Privacy Policy

Privacy Policy

 

Dxy's Clinic

 

Last updated: 27 July 2026

Version: 1.0

 

1. Who we are

 

Dxy's Clinic ("we", "us", "our") is a medical aesthetics clinic operated by Dxy's Clinic

Limited.

 

- Registered office: 5th Floor, 167–169 Great Portland Street, London, W1W 5PF

- Clinic address (where treatments take place): Pampered Hands, Basement Floor,

Stoke Newington High Street, London, N16 7PA

- Email: Dxysclinic@outlook.com

- ICO registration number: ZB959706

 

We are the data controller for the personal data described in this policy.

 

We are not legally required to appoint a Data Protection Officer. Data protection enquiries are

handled by Dikxya Singh Thakuri and should be sent to the email address above.

 

2. What this policy covers

 

This policy explains how we handle personal data when you:

 

- send us a message, comment or enquiry through Instagram or other social media channels;

- contact us by email, phone or through our website;

- attend the clinic as a client.

 

It covers our use of Dxy AI OS, the internal system we use to receive, triage and respond to

messages. Where that system does something unusual — particularly its use of AI and its automated

clinical safety checks — this policy explains it plainly, because we think you are entitled to

know.

 

This policy does not cover Instagram or Facebook themselves. Meta Platforms operates those

services and is a data controller in its own right for what happens on them. Their handling of your

data is governed by [Meta's Privacy Policy](https://www.facebook.com/privacy/policy).

 

3. What personal data we collect

 

3.1 When you message us on social media

 

- Your social media handle and display name, and the platform's internal account identifier.

- The content of your message, including anything you choose to tell us about your health,

treatments, symptoms or concerns.

- Timestamps and the conversation thread the message belongs to.

 

We currently receive Instagram comments. If we add direct messages or other channels later, we

will update this policy first.

 

Where a message includes an image or video, we store the reference the platform gives us — we do

not download or keep a copy of the file itself.

 

We do not scrape your profile, collect your posts or followers, or build a picture of you from

sources other than the messages you send us. We hold only what is needed to reply to you and to keep

a proper record of that exchange.

 

3.2 When you become a client

 

Consultation records, treatment records, consent forms, medical history and aftercare records are

collected and stored separately from social media messages, and are governed by our clinical

record procedures.

 

4. Where your data is held

 

Your messages are stored in our own database, hosted in the United Kingdom (London region).

 

We deliberately hold client message content in a database we control rather than inside a

third-party social media inbox tool, so that we can guarantee how long it is kept, who can see it,

and when it is deleted.

 

5. Why we process your data, and our lawful bases

 

| What we do | Why | Lawful basis (UK GDPR Article 6) |

|---|---|---|

| Read and reply to your message | To answer your enquiry | Legitimate interests — replying to someone who has contacted us. Where the exchange concerns a booking or treatment, performance of a contract or steps taken at your request |

| Assess whether a message needs urgent clinical attention | Client safety | Legitimate interests (and vital interests where there is a risk to health) |

| Keep a record of the exchange and of any clinical escalation | Clinical governance, insurance, and our professional obligations | Legal obligation and legitimate interests |

| Anonymise or delete old messages | Data minimisation | Legal obligation (storage limitation) |

 

Where we rely on legitimate interests, we have considered whether our interest is overridden by your

rights, and we have limited what we collect and how long we keep it accordingly.

 

6. Health information (special-category data)

>

> Provisional lawful basis: Article 9(2)(a), subject to legal confirmation. Vital interests may

> apply only in a genuine emergency.

>

> The wording below is a DRAFT for a qualified adviser to check, not a settled position. In

> particular, the proposal that explicit consent is given *by the act of sending a message* has

> not been confirmed as meeting the UK GDPR standard for explicit consent, and must not be

> presented as settled until Dikxya's indemnity provider or a data-protection adviser confirms it.

> The rest of this policy is complete and accurate; this section alone is unresolved.

 

Messages you send us may contain health information — for example describing swelling, a lump,

pain, a reaction after treatment, or a medical condition relevant to a treatment you are asking

about. Under UK GDPR this is special-category data and receives additional protection.

 

We do not ask for health information through social media, and we would rather you did not send

it. Our booking and consultation process is where clinical information belongs, because that is

where we can take proper consent, keep it securely, and discuss it properly with you.

 

Where you do send it, we process it on the basis of your explicit consent (UK GDPR Article

9(2)(a)) — proposed as being given by choosing to send us that information in order to get a

response from us. *(DRAFT — this consent mechanism is subject to legal confirmation.)* We use

it only to understand what you are asking, to decide whether it needs clinical attention, and to

reply. We do not use it for anything else.

 

You can withdraw that consent at any time by asking us to delete the conversation. We will do so

unless we are required to keep a record that a safety concern was raised — and in that case we keep

only a record with no personal details in it (see §14 and §17).

 

If your message suggests a possible complication or an emergency, we may act on it to protect

your health even before we have discussed consent with you — for example by telling you to seek

urgent medical assessment. UK GDPR allows this where it is necessary to protect someone's vital

interests (Article 9(2)(c)).

 

For anything clinical, we will usually ask you to book a consultation rather than continue in

messages. That is not us avoiding your question — it is so that your information is handled

properly and you get a proper answer.

 

> Note for the reviewer — the specific question.

> The practitioner is not on a statutory professional register, so Article 9(2)(h) (health care

> provided by a health professional subject to professional secrecy) is not available, and this

> section relies on Article 9(2)(a) explicit consent, with 9(2)(c) vital interests for

> genuine emergencies.

>

> The known difficulty: explicit consent must precede processing, but an unsolicited Instagram

> message containing health information is already being processed when it arrives. The position

> taken above is that (a) health information is never solicited through social media, (b) what

> arrives is minimised and used only to triage and reply, (c) clinical discussion is moved to a

> consultation where consent is properly taken, and (d) emergencies rely on vital interests.

>

> Please confirm this is defensible, or tell us what to change. This is the one paragraph in

> the policy where being wrong actually matters.

 

7. Children and young people

 

Our treatments are for adults only. It is a criminal offence in England to administer botulinum

toxin or cosmetic fillers to anyone under 18, and we do not provide these treatments to under-18s

under any circumstances, with or without parental consent.

 

Our services are not directed at children, and we do not knowingly collect personal data from anyone

under 18. If we become aware that someone contacting us is under 18, we will not proceed with a

treatment enquiry, and we will delete their message unless we are required to retain it — for

example where it raises a safeguarding or clinical safety concern.

 

If you believe a child has sent us personal data, please contact us and we will remove it.

 

8. Photographs and images

 

Where we take photographs of your treatment area — for example before-and-after images — we do so

only with your specific, written consent, recorded separately from this policy.

 

- Clinical photographs form part of your treatment record.

- We will never use your image for marketing, social media or any promotional purpose without

your separate and explicit consent for that use.

- You may withdraw consent for marketing use at any time, and we will stop using the image and

remove it from material we control. Where an image has already been published on a third-party

platform, we will remove our copy and request removal, though we cannot always control copies

others have made.

- Withdrawing consent for marketing use does not affect the clinical record.

 

9. How we use AI — and where we do not

 

We use AI to help draft replies to routine questions. We want to be specific about its limits,

because these are enforced by our systems and not merely by policy:

 

A human always approves every message before it is sent. Nothing is ever sent to you

automatically. There is no configuration of our system in which an AI reply reaches you without a

person reading and approving it first.

 

AI is never used for clinical questions. Every incoming message is checked by a deterministic,

rule-based safety classifier — not an AI — which grades it. Where a message concerns treatment

suitability for you personally, a possible complication, or anything indicating a medical emergency,

the system refuses to let an AI draft a reply at all. Those messages go to the practitioner, who

writes any response personally.

 

When AI does draft, it is restricted to verified clinic information. Drafts are generated only

from a curated set of documents we maintain, and each draft records which sources were used and how

recently they were verified. Where the information is not available or confidence is low, the system

produces an explicit "insufficient verified knowledge" outcome rather than a plausible guess.

*AI-assisted drafting is still in development. No AI-drafted reply has been sent to any client.*

 

Your messages are not used to train AI models. We do not use client message content to train,

fine-tune or improve any AI model, ours or a third party's. We do not use it for analytics beyond

operating and auditing the inbox.

 

Our clinical safety rules are never learned from data. They are written and reviewed by a human,

version-controlled, and changed only deliberately. They are not adjusted by observing how the

practitioner edits replies.

 

10. Automated decision-making

 

We use an automated process to route messages — deciding whether a message can receive a drafted

reply or must go to the practitioner personally, and how urgently.

 

This is not a decision that produces legal effects or similarly significantly affects you. It

determines who handles your message and how quickly, and it is deliberately cautious: where the

system is unsure, it escalates to a human rather than proceeding. Every reply you receive is

written or approved by a person.

 

You can ask us to explain how a message of yours was handled. For every escalation the system

records which safety rule applied and the phrase that rule matched. Note that once a conversation has

been anonymised (see §14) we can still tell you which rule applied, but we will no longer hold the

message itself.

 

11. Urgent clinical concerns

 

If a message indicates a possible complication or an emergency, our system alerts the practitioner

immediately and reminds her repeatedly, for up to 24 hours, until she confirms she has seen it.

 

Alerts about clinical concerns are designed to carry no message content. They contain only a

severity level, a recommended action and an internal reference — never your name, your handle or

your words. This is enforced by the design of the system, not by convention.

 

A social media message is not an emergency service. If you believe you are experiencing a medical

emergency, contact 999, 111, or attend A&E. Do not wait for a reply from us.

 

12. Who we share your data with

 

We do not sell your data, and we do not share it for marketing purposes. We use the following

service providers ("processors"):

 

| Provider | What it does | Where | Receives message content? |

|---|---|---|---|

| Supabase | Database hosting — our system of record | United Kingdom (London) | Yes — this is where messages are stored |

| n8n Cloud | Workflow automation connecting our systems | EU (Frankfurt, Germany) | In transit, while passing a message into our database |

| Meta Platforms | Instagram — the source of the message | Global | Yes — it is their platform |

| Vercel | Hosting for the internal application the practitioner uses | United Kingdom (London) | In transit only, when the practitioner views or approves a reply |

| Telegram | Practitioner alerts | Global | No — alerts carry no message content and no identifying detail (see §11) |

| Anthropic (Claude) | AI assistance | United States | Currently used only to help produce our own marketing content. It will process client message content when AI-assisted drafting launches |

| OpenAI | Making our clinic's own reference documents searchable | United States | No — processes our own documents, not client messages |

 

We also use Blotato (social media publishing) and Google Drive (storage) for our own

marketing content. These do not receive client messages.

 

13. International transfers

 

Your message content is stored in the UK and processed in the UK and EU.

 

Where a provider is outside the UK — currently Anthropic and OpenAI, both in the United

States — transfers are made under the UK International Data Transfer Addendum to the EU Standard

Contractual Clauses, together with a transfer risk assessment.

 

14. How long we keep your data

 

Once a conversation is closed, it is automatically anonymised 90 days after the last message.

 

Anonymisation means the content is permanently removed — the message text, any media references,

your handle and display name, and the platform identifiers. What remains is a summary record with no

personal data in it: that a conversation happened, when, whether it was escalated clinically, at what

level, and whether that escalation was acknowledged.

 

We keep that summary because we have clinical-governance and insurance obligations to be able to show

that a concern was received and acted on. It cannot be used to identify you.

 

This runs automatically, every day. It does not depend on anyone remembering to do it.

 

We do not anonymise a conversation that is still open, that is inside the 90-day period, or that

contains a clinical concern nobody has yet acknowledged. A conversation stays open until it is

resolved and closed, so an unresolved conversation is retained until then. We review open

conversations and close them once they are resolved. You can ask us to delete your messages at any

time (see §17).

 

Clinical records created at the clinic (consultation notes, consent forms, treatment records) are

held separately and for longer, in line with professional retention requirements:

[TO BE CONFIRMED AFTER LEGAL/INDEMNITY ADVICE]

 

Backups

 

We take encrypted backups of our database once a day, and keep each one for up to 7 days. They

exist so that your data can be recovered if something goes wrong — a technical failure, or a mistake

on our side.

 

This means that when data is anonymised under this section, or deleted at your request under §17,

it may still exist in a backup for a short time afterwards. Backups are not edited — doing so

would defeat the point of having them — so a copy remains until that backup expires and is destroyed

automatically. In practice this is never more than 7 days, and backups are encrypted and readable

only by us. We do not use backups for any purpose other than recovery.

 

15. Security

 

- Access is deny-by-default. Our database refuses all access unless a specific rule permits it,

and only the practitioner's authenticated account can read client messages.

- The public key used by our application cannot read any client data. This is tested

automatically, and a change that broke it would fail those tests before reaching production.

- Every change to the system is reviewed and automatically tested before it goes live.

- Credentials for third-party services are held in an encrypted credential store, never in our

application or its source code.

- Records of what the system did are append-only — they cannot be altered or quietly deleted

after the fact. The single exception is that free-text practitioner notes are removed when a

conversation is anonymised under §14, which we do to protect your privacy.

 

16. Audit logging

 

We keep a permanent, tamper-resistant record of what our system did: when a message arrived, how it

was classified, whether it was escalated, when the practitioner acknowledged it, and when a reply was

approved and sent.

 

This event log deliberately contains no message content and no free text — only categories,

severity levels, timestamps and internal references. It exists so that we can demonstrate proper

clinical handling without retaining what you actually wrote.

 

17. Your rights

 

Under UK GDPR you have the right to:

 

- access the personal data we hold about you;

- rectify data that is inaccurate;

- erase your data ("right to be forgotten");

- restrict or object to our processing;

- data portability — receive your data in a usable format;

- withdraw consent, where we rely on consent.

 

To exercise any of these, contact Dxysclinic@outlook.com. We will respond within one month.

 

On erasure: we can remove your messages and contact details on request. Where we are required to

retain a clinical record — for example evidence that a safety concern was received and acted on — we

will tell you what has been retained and why. Anything retained is stripped of information that

identifies you.

 

Please note: once a conversation has been anonymised under §14, the content is gone and we can no

longer provide a copy of it, because we no longer hold it — other than briefly in a backup awaiting

expiry, as described under *Backups* in §14.

 

18. Complaints

 

If you are unhappy with how we have handled your data, please contact us first at

Dxysclinic@outlook.com so we can try to put it right.

 

You also have the right to complain to the Information Commissioner's Office:

 

- Website: [ico.org.uk/make-a-complaint](https://ico.org.uk/make-a-complaint/)

- Helpline: 0303 123 1113

 

19. Changes to this policy

 

We will update this policy when our processing changes. The version number and date at the top show

when it was last revised. Where a change materially affects how we handle your data, we will say so

prominently rather than quietly amending the text.

 

20. Contact

 

Dxy's Clinic Limited

Pampered Hands, Basement Floor, Stoke Newington High Street, London, N16 7PA

Dxysclinic@outlook.com

Fully insured · PolicyBee
4.9★ Google rating
Consultation included
Aftercare with every treatment

Stoke Newington · London

Ready when you are.

Begin with an honest consultation — no pressure, no obligation, just considered advice about what's right for you.

4.9★ on Google · Fully insured · Consultation included with same-day treatment