Privacy policy

Last updated 20 July 2026

Privacy for connected email automation and campaigns.

This policy explains how MyHealthFollowup handles personal information for clinic account holders and for patients whose information is used by a connected clinic. The product stores the clinic setup and operational details needed for automations and campaigns. The connected booking platform remains the clinic's record for its own booking or patient information. Clinics should also maintain their own privacy notices for patient care and communication.

MyHealthFollowup is the registered Australian business name MYHEALTHFOLLOWUP, operated by William Douglas Lake, ABN 72 581 872 067.

Information We Handle

Appointment data can reveal health information. We treat patient identity, appointment context, templates, provider identifiers, and delivery data as sensitive unless it is clearly operational-only.

Clinic usersNames, email addresses, login identity, workspace roles, billing authority, support requests, and audit records for account activity.
Clinic setupClinic name, timezone, sender and reply-to details, phone, website, booking link, templates, merge fields, and automation rules.
Booking-calendar connectionCliniko API keys and Calendly OAuth credentials are handled as backend secrets. The database stores secret references, fingerprints, connection status, verification details, and the setup data needed for the connected workflow.
Patient and appointment dataFetched from the connected Cliniko or Calendly account when needed to match rules, schedule messages, render merge fields, or confirm send eligibility. This can include names, email addresses, provider IDs, booking time and type, practitioner or host, location, booking status, timezone, and any communication preferences the provider supplies.
Campaign audience and consentWhen a clinic uses Campaigns, we store the synced recipient name, email address, provider ID, audience status, consent source and evidence, and the available fields used for filtering. Cliniko marketing preferences can be synchronised. Calendly does not provide a marketing preference, so invitees remain ineligible until a clinic user records permission or confirms that selected Calendly event types already collect it.
Email delivery dataScheduled-message and campaign-recipient state, test-send details, provider message IDs, delivery outcomes, skip reasons, bounces, complaints, opens, clicks, unsubscribes, and redacted operational logs.
Billing dataStripe customer, subscription, checkout, portal, invoice, trial, and plan metadata. Payment card details are handled by Stripe, not stored by MyHealthFollowup.

How We Use It

The clinic controls which templates, automations, campaign audiences, and campaigns are created. MyHealthFollowup uses the information needed to run those workflows and support the clinic account.

Provide the dashboard, template import, preview, test-send, scheduling, delivery visibility, and billing features.
Verify booking-calendar connections, load account details, and apply clinic-defined automation rules.
Send clinic-authored appointment, follow-up, recall, and preparation emails selected by the clinic.
Prepare, schedule, and send clinic-authored campaigns to eligible patients selected by the clinic.
Record campaign consent changes and unsubscribes, and update the Cliniko marketing preference where the integration supports it.
Check current booking state and communication preferences before sending where those fields are available.
Troubleshoot support requests, investigate delivery problems, protect the service, and maintain audit history.
Manage trials, subscriptions, payment state, and account notices.

How We Collect It

MyHealthFollowup does not buy, rent, or scrape patient marketing lists. Patient, appointment, audience, and preference data comes from the clinic's connected booking account or from a clinic user recording permission in the dashboard.

From clinic users

When users create an account, connect a booking calendar, enter clinic details, import templates, configure automations, prepare campaigns, record consent, send tests, manage billing, or contact support.

From Cliniko

When a clinic connects its Cliniko account and authorises MyHealthFollowup to read the data needed for appointment-based email workflows and consent-aware patient campaigns.

From Calendly

When a clinic connects Calendly and authorises MyHealthFollowup to read the booking and invitee details needed for booking emails and campaign audience preparation. Calendly does not supply marketing consent. A clinic must record permission separately or confirm that the booking form for selected event types already collects it.

From service providers

From authentication, hosting, email delivery, billing, and infrastructure providers when they return the operational data needed to run the service.

Sharing And Processors

We use service providers to operate the product, and we do not sell patient data. These providers may include:
  • Cliniko, when reading connected clinic data under the clinic's API key.
  • Calendly, when reading connected booking data under the clinic's authorised OAuth connection.
  • AWS hosting, database, secrets, email delivery, backup, logging, and infrastructure services.
  • Clerk for production authentication and session management.
  • Stripe for checkout, subscription, invoice, billing portal, and payment handling.
  • Email providers and DNS/domain services needed to deliver and authenticate clinic emails.
  • Professional advisers, regulators, law enforcement, or courts where required or permitted by law.

Retention

Configuration, audit, billing, and delivery metadata are kept for product operation, troubleshooting, compliance, and account history. Rendered message content should not be retained as a long-term patient record. Where information is no longer needed, we aim to delete, de-identify, or minimise it where practical and lawful.

Security

We use backend secret handling, role checks, redacted operational views, audit logging, and late rendering to reduce unnecessary exposure. Production infrastructure is targeted to AWS in ap-southeast-2. Some providers may process or support data outside Australia as part of their normal operations.

Cookies And Local Storage

The product uses essential authentication, session, security, and dashboard state technologies. The public marketing site may use Google Ads measurement to understand campaign performance and improve sign-up flows. Booking-platform credentials are not stored in browser local storage.

Access And Correction

Clinic users can ask to access or correct personal information held in MyHealthFollowup by contacting support. If a patient asks about information in a connected booking system, we may direct the request to the clinic because the clinic controls that record and relationship.

Patient Preferences

The send path checks communication preferences supplied by the connected provider. Campaign unsubscribes stop future campaign sends in MyHealthFollowup and are sent back to Cliniko where supported. Calendly campaign permission is recorded and enforced in MyHealthFollowup because Calendly does not provide that preference. A clinic may apply permission automatically only to selected event types whose booking forms already ask for that permission. Clinics remain responsible for ensuring each email is appropriate and permitted.