1. Overview
PhysioFlow is a practice management platform for physiotherapy clinics. We collect only the data needed to run the service, we never sell your data, we protect health information with the highest standards, and you can request deletion at any time.
This document covers: (a) how PhysioFlow (operated by Flowvance Ltd, "we", "us", "our") collects, uses, and protects personal data; and (b) the terms under which clinics and their patients use the PhysioFlow platform, including PhysioFlow Connect.
By using PhysioFlow — whether as a clinic owner, staff member, or patient — you agree to this policy. If you do not agree, please do not use the service.
2. Who We Are
Data Controller (for clinic accounts): Flowvance Ltd, registered in Nigeria. Email: privacy@flowvance.co
Data Processor role: For patient data entered by clinics, PhysioFlow acts as a data processor on behalf of the clinic (who is the data controller). This distinction is explained further in Section 13.
We are registered with the Nigeria Data Protection Commission (NDPC) and comply with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, as well as the EU General Data Protection Regulation (GDPR) for users in or serving patients in the European Economic Area.
3. Data We Collect
3.1 Clinic Account Data
| Category | Examples | Source |
|---|---|---|
| Identity | Clinic name, owner name, role | Registration |
| Contact | Email, phone, address | Registration / Settings |
| Financial | Bank account details (for invoicing), currency | Settings |
| Configuration | Webhook URLs, branding, preferences | Settings |
| Usage | Login times, feature usage, error logs | Automatically |
3.2 Patient Data (entered by clinics)
| Category | Examples | Classification |
|---|---|---|
| Identity | First name, last name, age, sex | Personal data |
| Contact | Phone number, email address | Personal data |
| Clinical — Special Category | Complaint, pain location, severity, diagnosis, SOAP notes, medications, red flag answers, outcome measures | Special category health data |
| Financial | Invoice amounts, payment status, consultation fees | Personal data |
| Appointments | Date, time, type, session notes | Personal data |
Health data is classified as special category data under GDPR Article 9 and NDPR. It receives the highest level of protection. We process it only on the explicit instruction of the clinic (data controller) for the purpose of providing healthcare services.
3.3 Patient Intake Data (PhysioFlow Connect)
When a patient submits a consultation request through a clinic's PhysioFlow Connect link, we collect the information they provide: name, phone, email, complaint, clinical symptoms, and answers to the safety screening questionnaire. This data is transmitted directly to the clinic and stored in our secure database on behalf of that clinic.
3.4 Technical Data
We automatically collect: IP address, browser type, device type, pages visited, time spent, and error reports. This is used solely for security, performance monitoring, and improving the service.
4. Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR) | NDPR Equivalent |
|---|---|---|
| Clinic account management | Article 6(1)(b) — Contract performance | Section 2.2 — Contractual necessity |
| Processing payments and invoices | Article 6(1)(b) — Contract performance | Section 2.2 — Contractual necessity |
| Patient health records (by clinic) | Article 9(2)(h) — Healthcare provision | Section 2.5 — Vital interests / healthcare |
| Patient intake via Connect | Article 6(1)(a) — Consent (explicit, via terms checkbox) | Section 2.1 — Consent |
| Service improvement and analytics | Article 6(1)(f) — Legitimate interests | Section 2.6 — Legitimate interest |
| Legal compliance | Article 6(1)(c) — Legal obligation | Section 2.4 — Legal obligation |
For patients submitting intake forms via PhysioFlow Connect, consent is collected explicitly via the checkbox declaration on the intake form at the time of submission. Consent can be withdrawn at any time by contacting the clinic or emailing us directly.
5. How We Use Your Data
We use personal data only for the purposes stated at collection. Specifically:
- To provide and maintain the PhysioFlow platform and all its features
- To enable clinics to manage appointments, patient records, invoices, and consultations
- To facilitate patient intake requests through PhysioFlow Connect
- To send transactional communications (invoices, appointment confirmations, booking links) on behalf of clinics to their patients
- To detect and prevent fraud, abuse, and security threats
- To comply with legal obligations including tax, financial regulations, and healthcare record-keeping requirements
- To improve, test, and maintain the security of our platform
We never sell personal data to third parties. We never use patient health data for advertising or profiling. We never share clinic or patient data with any third party except as described in Section 6 below.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Clinic account data | Duration of active subscription + 7 years after closure | Tax and legal compliance |
| Patient health records | Minimum 6 years from last contact (Nigeria: 5 years under MDA; UK: 8 years NHS standard) | Healthcare regulatory compliance |
| Patient intake requests | Duration of clinic account + 6 years | Healthcare records |
| Financial / invoice records | 7 years | FIRS and tax law requirements |
| Technical / access logs | 90 days | Security monitoring |
| Deleted clinic data | Purged within 30 days of verified deletion request | Right to erasure |
When a clinic account is closed, all patient data is exported to the clinic or deleted within 30 days, unless we are required by law to retain it.
8. Your Data Rights
Under GDPR and NDPR, you have the following rights regarding your personal data:
To exercise any right, email privacy@flowvance.co. We will respond within 30 days (GDPR: 1 month; NDPR: 30 days). We may ask you to verify your identity before processing a request.
For patient data held by a clinic, please contact the clinic directly in the first instance, as they are the data controller for that data. We will facilitate any requests as required.
9. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS 1.2+.
- Encryption at rest: Database contents are encrypted at rest by our hosting providers.
- Access control: Row-Level Security (RLS) enforced at the database layer — each clinic can only access its own data. Staff access is role-limited (Owner / Admin / Therapist / Receptionist).
- Authentication: Secure authentication via Supabase Auth with email verification and session tokens.
- Monitoring: Automated monitoring for unusual access patterns and security events.
- Edge Functions: Sensitive operations (clinic lookup, patient intake submission) run via server-side Edge Functions using a service role key — the anon key is never used for privileged operations.
- No direct anon database access: Patient-facing pages do not expose privileged database credentials.
In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
11. Children's Data
PhysioFlow is not directed at children under 13 for account registration. However, clinics may legitimately treat paediatric patients. In these cases:
- The clinic (as data controller) is responsible for obtaining appropriate parental or guardian consent before entering a minor's data into PhysioFlow.
- We process children's health data under the same strict health data standards as adult data.
- Parents or guardians may exercise data rights on behalf of a minor by contacting the clinic or us directly.
12. International Data Transfers
Our primary database is hosted in the European Economic Area (EEA) via Supabase's EU region. Some sub-processors may process data outside the EEA or Nigeria. Where this occurs, we ensure:
- Standard Contractual Clauses (SCCs) are in place for transfers outside the EEA.
- For Nigeria, we ensure equivalent transfer mechanisms as required by the NDPA 2023 and NDPR.
- We do not transfer health data to any country assessed as providing inadequate protection without additional safeguards.
13. Clinic Responsibility as Data Controller
When you use PhysioFlow to collect and manage patient data, you are the data controller and PhysioFlow is your data processor. This means you bear primary legal responsibility for ensuring patient data is collected lawfully, stored appropriately, and processed in accordance with GDPR, NDPR, and applicable health data laws.
By registering a clinic on PhysioFlow, you agree to:
- Obtain appropriate legal basis (typically explicit consent or healthcare provision) before collecting patient data.
- Provide patients with a fair processing notice (e.g. linking to this policy or your own privacy notice) before collecting their data.
- Ensure your staff handle patient data in accordance with applicable data protection law.
- Notify us immediately if you become aware of a data breach involving patient data processed through PhysioFlow.
- Respond to patient data rights requests in a timely manner, using PhysioFlow's export and deletion tools where available.
- Not use PhysioFlow to process data for any purpose incompatible with healthcare provision, administration, and practice management.
The Data Processing Agreement (DPA) governing our relationship as controller and processor is incorporated into these Terms of Service. A copy is available on request at privacy@flowvance.co.
14. Terms of Service
14.1 Eligibility and Account
PhysioFlow is available to registered healthcare professionals, clinic owners, and their authorised staff. By creating an account, you represent that you are authorised to operate a healthcare practice and that all information provided is accurate.
14.2 Acceptable Use
You agree to use PhysioFlow only for lawful purposes related to the administration and delivery of physiotherapy and allied health services. You must not:
- Use the platform to store or process data unrelated to your clinical practice.
- Attempt to access another clinic's data or circumvent any security controls.
- Upload malicious code, introduce security vulnerabilities, or attempt denial-of-service attacks.
- Resell, sublicense, or white-label the PhysioFlow service without written permission.
- Use patient data for any purpose not directly related to their care.
14.3 Subscription and Payment
PhysioFlow operates on a subscription basis. New accounts receive a 14-day free trial with full access to all features. After the trial, a paid subscription is required to continue using the service. Subscription fees are billed monthly or annually as stated at time of purchase. All fees are non-refundable except where required by applicable law.
14.4 Service Availability
We aim for 99.5% monthly uptime but do not guarantee uninterrupted service. Planned maintenance will be communicated in advance where possible. We are not liable for service interruptions beyond our reasonable control.
14.5 Limitation of Liability
To the maximum extent permitted by law, PhysioFlow (Flowvance Ltd) shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from use of the platform. Our total liability for any claim shall not exceed the subscription fees paid by you in the 3 months preceding the claim.
PhysioFlow is a practice management tool and does not provide clinical advice. Clinical decisions remain entirely the responsibility of the licensed healthcare professional.
14.6 Intellectual Property
All software, design, and content of the PhysioFlow platform is owned by Flowvance Ltd. You retain full ownership of all patient data and clinical records you enter. We claim no rights over your data.
14.7 Termination
You may close your account at any time. We will provide a data export within 14 days of your request. We may suspend or terminate accounts that violate these terms, with notice where reasonably practicable. Upon termination, patient data will be deleted within 30 days unless we are legally required to retain it.
14.8 Changes to Terms
We will notify registered clinic owners of material changes to these terms with at least 30 days' notice by email. Continued use after the effective date of changes constitutes acceptance.
14.9 Governing Law
These Terms are governed by the laws of the Federal Republic of Nigeria. Disputes shall be subject to the jurisdiction of the courts of Lagos State, Nigeria. For EU users, mandatory EU consumer protection and data protection laws apply in addition.
15. Contact & Complaints
Data Protection Officer / Privacy Enquiries:
Email: privacy@flowvance.co
Response time: Within 30 days
General Support:
Email: hello@flowvance.co
Supervisory Authorities
If you believe your data rights have been violated and we have not resolved your concern, you may lodge a complaint with:
- Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- European Union: Your national data protection authority — EDPB Member List