Privacy Policy & Terms of Service
✓ GDPR Compliant ✓ NDPR Compliant ✓ Health Data Standards
📅 Effective: 1 July 2025 🔄 Last updated: June 2026 🌍 Jurisdiction: Nigeria & Global

1. Overview

Plain English Summary

PhysioFlow is a practice management platform for physiotherapy clinics. We collect only the data needed to run the service, we never sell your data, we protect health information with the highest standards, and you can request deletion at any time.

This document covers: (a) how PhysioFlow (operated by Flowvance Ltd, "we", "us", "our") collects, uses, and protects personal data; and (b) the terms under which clinics and their patients use the PhysioFlow platform, including PhysioFlow Connect.

By using PhysioFlow — whether as a clinic owner, staff member, or patient — you agree to this policy. If you do not agree, please do not use the service.

2. Who We Are

Data Controller (for clinic accounts): Flowvance Ltd, registered in Nigeria. Email: privacy@flowvance.co

Data Processor role: For patient data entered by clinics, PhysioFlow acts as a data processor on behalf of the clinic (who is the data controller). This distinction is explained further in Section 13.

We are registered with the Nigeria Data Protection Commission (NDPC) and comply with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, as well as the EU General Data Protection Regulation (GDPR) for users in or serving patients in the European Economic Area.

3. Data We Collect

3.1 Clinic Account Data

CategoryExamplesSource
IdentityClinic name, owner name, roleRegistration
ContactEmail, phone, addressRegistration / Settings
FinancialBank account details (for invoicing), currencySettings
ConfigurationWebhook URLs, branding, preferencesSettings
UsageLogin times, feature usage, error logsAutomatically

3.2 Patient Data (entered by clinics)

CategoryExamplesClassification
IdentityFirst name, last name, age, sexPersonal data
ContactPhone number, email addressPersonal data
Clinical — Special CategoryComplaint, pain location, severity, diagnosis, SOAP notes, medications, red flag answers, outcome measuresSpecial category health data
FinancialInvoice amounts, payment status, consultation feesPersonal data
AppointmentsDate, time, type, session notesPersonal data
Special Category Data

Health data is classified as special category data under GDPR Article 9 and NDPR. It receives the highest level of protection. We process it only on the explicit instruction of the clinic (data controller) for the purpose of providing healthcare services.

3.3 Patient Intake Data (PhysioFlow Connect)

When a patient submits a consultation request through a clinic's PhysioFlow Connect link, we collect the information they provide: name, phone, email, complaint, clinical symptoms, and answers to the safety screening questionnaire. This data is transmitted directly to the clinic and stored in our secure database on behalf of that clinic.

3.4 Technical Data

We automatically collect: IP address, browser type, device type, pages visited, time spent, and error reports. This is used solely for security, performance monitoring, and improving the service.

5. How We Use Your Data

We use personal data only for the purposes stated at collection. Specifically:

  • To provide and maintain the PhysioFlow platform and all its features
  • To enable clinics to manage appointments, patient records, invoices, and consultations
  • To facilitate patient intake requests through PhysioFlow Connect
  • To send transactional communications (invoices, appointment confirmations, booking links) on behalf of clinics to their patients
  • To detect and prevent fraud, abuse, and security threats
  • To comply with legal obligations including tax, financial regulations, and healthcare record-keeping requirements
  • To improve, test, and maintain the security of our platform
What We Never Do

We never sell personal data to third parties. We never use patient health data for advertising or profiling. We never share clinic or patient data with any third party except as described in Section 6 below.

6. Data Sharing & Third Parties

We share personal data with the following categories of third parties, under strict data processing agreements:

Third PartyPurposeLocationSafeguard
Supabase Inc.Database hosting and authenticationUSA (EU servers available)DPA in place; SOC 2 Type II certified
Resend Inc.Transactional email deliveryUSADPA in place; Standard Contractual Clauses
n8n GmbHWorkflow automation (webhook delivery)Germany (EU)EU-based; GDPR compliant
Hetzner / DigitalOceanServer infrastructureEU / USAISO 27001; DPAs in place
Clinics using PhysioFlowAs instructed by clinic — patient data is visible to the clinic that collected itVaries by clinicClinic is data controller; bound by these terms

We do not transfer data to countries without adequate protection without first implementing appropriate safeguards (Standard Contractual Clauses or equivalent NDPR mechanisms).

7. Data Retention

Data TypeRetention PeriodReason
Clinic account dataDuration of active subscription + 7 years after closureTax and legal compliance
Patient health recordsMinimum 6 years from last contact (Nigeria: 5 years under MDA; UK: 8 years NHS standard)Healthcare regulatory compliance
Patient intake requestsDuration of clinic account + 6 yearsHealthcare records
Financial / invoice records7 yearsFIRS and tax law requirements
Technical / access logs90 daysSecurity monitoring
Deleted clinic dataPurged within 30 days of verified deletion requestRight to erasure

When a clinic account is closed, all patient data is exported to the clinic or deleted within 30 days, unless we are required by law to retain it.

8. Your Data Rights

Under GDPR and NDPR, you have the following rights regarding your personal data:

📋
Right to Access
Request a copy of all personal data we hold about you.
✏️
Right to Rectification
Request correction of inaccurate or incomplete data.
🗑️
Right to Erasure
Request deletion of your data where there is no legal basis to retain it.
⏸️
Right to Restriction
Request that we limit processing of your data in certain circumstances.
📦
Right to Portability
Receive your data in a machine-readable format to transfer elsewhere.
🚫
Right to Object
Object to processing based on legitimate interests or for direct marketing.
↩️
Withdraw Consent
Where processing is based on consent, withdraw it at any time without penalty.
⚖️
Right to Complain
Lodge a complaint with the NDPC (Nigeria) or your national data protection authority.

To exercise any right, email privacy@flowvance.co. We will respond within 30 days (GDPR: 1 month; NDPR: 30 days). We may ask you to verify your identity before processing a request.

For patient data held by a clinic, please contact the clinic directly in the first instance, as they are the data controller for that data. We will facilitate any requests as required.

9. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS 1.2+.
  • Encryption at rest: Database contents are encrypted at rest by our hosting providers.
  • Access control: Row-Level Security (RLS) enforced at the database layer — each clinic can only access its own data. Staff access is role-limited (Owner / Admin / Therapist / Receptionist).
  • Authentication: Secure authentication via Supabase Auth with email verification and session tokens.
  • Monitoring: Automated monitoring for unusual access patterns and security events.
  • Edge Functions: Sensitive operations (clinic lookup, patient intake submission) run via server-side Edge Functions using a service role key — the anon key is never used for privileged operations.
  • No direct anon database access: Patient-facing pages do not expose privileged database credentials.

In the event of a personal data breach that is likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

10. Cookies & Tracking

PhysioFlow uses minimal, strictly necessary cookies and browser storage:

Cookie / StoragePurposeDurationType
Supabase session tokenKeeps you logged in to the dashboardSession / 7 daysStrictly necessary
localStorage (clinic preferences)Remembers your UI settings (sidebar state, last page)Until clearedFunctional

We do not use advertising cookies, tracking pixels, or third-party analytics tools that collect personal data. Patient-facing pages (intake, invoice, booking, programme) set no cookies and use no local storage beyond what is strictly required for the form to function.

11. Children's Data

PhysioFlow is not directed at children under 13 for account registration. However, clinics may legitimately treat paediatric patients. In these cases:

  • The clinic (as data controller) is responsible for obtaining appropriate parental or guardian consent before entering a minor's data into PhysioFlow.
  • We process children's health data under the same strict health data standards as adult data.
  • Parents or guardians may exercise data rights on behalf of a minor by contacting the clinic or us directly.

12. International Data Transfers

Our primary database is hosted in the European Economic Area (EEA) via Supabase's EU region. Some sub-processors may process data outside the EEA or Nigeria. Where this occurs, we ensure:

  • Standard Contractual Clauses (SCCs) are in place for transfers outside the EEA.
  • For Nigeria, we ensure equivalent transfer mechanisms as required by the NDPA 2023 and NDPR.
  • We do not transfer health data to any country assessed as providing inadequate protection without additional safeguards.

13. Clinic Responsibility as Data Controller

Important for Clinics

When you use PhysioFlow to collect and manage patient data, you are the data controller and PhysioFlow is your data processor. This means you bear primary legal responsibility for ensuring patient data is collected lawfully, stored appropriately, and processed in accordance with GDPR, NDPR, and applicable health data laws.

By registering a clinic on PhysioFlow, you agree to:

  • Obtain appropriate legal basis (typically explicit consent or healthcare provision) before collecting patient data.
  • Provide patients with a fair processing notice (e.g. linking to this policy or your own privacy notice) before collecting their data.
  • Ensure your staff handle patient data in accordance with applicable data protection law.
  • Notify us immediately if you become aware of a data breach involving patient data processed through PhysioFlow.
  • Respond to patient data rights requests in a timely manner, using PhysioFlow's export and deletion tools where available.
  • Not use PhysioFlow to process data for any purpose incompatible with healthcare provision, administration, and practice management.

The Data Processing Agreement (DPA) governing our relationship as controller and processor is incorporated into these Terms of Service. A copy is available on request at privacy@flowvance.co.

14. Terms of Service

14.1 Eligibility and Account

PhysioFlow is available to registered healthcare professionals, clinic owners, and their authorised staff. By creating an account, you represent that you are authorised to operate a healthcare practice and that all information provided is accurate.

14.2 Acceptable Use

You agree to use PhysioFlow only for lawful purposes related to the administration and delivery of physiotherapy and allied health services. You must not:

  • Use the platform to store or process data unrelated to your clinical practice.
  • Attempt to access another clinic's data or circumvent any security controls.
  • Upload malicious code, introduce security vulnerabilities, or attempt denial-of-service attacks.
  • Resell, sublicense, or white-label the PhysioFlow service without written permission.
  • Use patient data for any purpose not directly related to their care.

14.3 Subscription and Payment

PhysioFlow operates on a subscription basis. New accounts receive a 14-day free trial with full access to all features. After the trial, a paid subscription is required to continue using the service. Subscription fees are billed monthly or annually as stated at time of purchase. All fees are non-refundable except where required by applicable law.

14.4 Service Availability

We aim for 99.5% monthly uptime but do not guarantee uninterrupted service. Planned maintenance will be communicated in advance where possible. We are not liable for service interruptions beyond our reasonable control.

14.5 Limitation of Liability

To the maximum extent permitted by law, PhysioFlow (Flowvance Ltd) shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from use of the platform. Our total liability for any claim shall not exceed the subscription fees paid by you in the 3 months preceding the claim.

PhysioFlow is a practice management tool and does not provide clinical advice. Clinical decisions remain entirely the responsibility of the licensed healthcare professional.

14.6 Intellectual Property

All software, design, and content of the PhysioFlow platform is owned by Flowvance Ltd. You retain full ownership of all patient data and clinical records you enter. We claim no rights over your data.

14.7 Termination

You may close your account at any time. We will provide a data export within 14 days of your request. We may suspend or terminate accounts that violate these terms, with notice where reasonably practicable. Upon termination, patient data will be deleted within 30 days unless we are legally required to retain it.

14.8 Changes to Terms

We will notify registered clinic owners of material changes to these terms with at least 30 days' notice by email. Continued use after the effective date of changes constitutes acceptance.

14.9 Governing Law

These Terms are governed by the laws of the Federal Republic of Nigeria. Disputes shall be subject to the jurisdiction of the courts of Lagos State, Nigeria. For EU users, mandatory EU consumer protection and data protection laws apply in addition.

15. Contact & Complaints

Data Protection Officer / Privacy Enquiries:
Email: privacy@flowvance.co
Response time: Within 30 days

General Support:
Email: hello@flowvance.co

Supervisory Authorities

If you believe your data rights have been violated and we have not resolved your concern, you may lodge a complaint with:

  • Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • European Union: Your national data protection authority — EDPB Member List