Privacy Policy

Last updated: 10 September 2026

Who is responsible for the data

Flow Clinic is built and operated by KENGTECH Co., Ltd. A clinic using the service is the controller of its customers' personal data, and we process that data on the clinic's instructions. The clinic is also the controller of the staff data it records, such as names, roles, and permissions. We act as controller for account credentials and security logs, billing, and our own business-contact data. This policy also covers people who contact us with enquiries or to book a demo.

Data we collect and its sources

  • Clinic owner and staff data, including name, email, phone, role, permissions, and usage history
  • Clinic customer data entered by staff or the customer, including contact and identity details, appointments, payments, photos, consent records, and clinical records that may contain health or other sensitive data
  • Google account data when a staff member chooses to sign in with Google: we receive the email address and the Google account identifier, and use them only to match a staff account the clinic already created. Signing in with Google never creates an account and gives us no access to anything else in the staff member's Google account, such as Gmail, files, or contacts
  • LINE, Facebook Messenger, and Instagram data, including platform user ID, profile name and photo, message content, message ID and time, read state, direction, staff tags or notes, and links to a clinic customer record; messages may themselves contain health data
  • Prospect data, including name, contact channel, clinic name, and messages sent to us by LINE, email, or a demo booking
  • Usage and security data, including IP address, device/browser type, access time, request metadata, activity logs, and limited website analytics collected by our providers

Data comes from system users, customers completing forms, connected messaging platforms, and systems or providers needed to operate Flow Clinic.

Purposes and lawful basis

We use data to manage appointments and care, deliver requested messages and documents, process payments, secure and support the service, and improve it using aggregated or de-identified data where practical. We do not sell personal data, use clinic customer data for our advertising, or use messages or clinical records to train advertising models.

The clinic determines the purposes and lawful basis for its customer data; we process it on the clinic's instructions. For data we control, we rely on contract, legal obligations, legitimate interests, or consent as appropriate. Sensitive data requires an applicable lawful basis and additional safeguards; it is not automatically processed on consent in every case.

We may contact clinic owners and prospects about Flow Clinic services, news, and offers. You can opt out at any time through the link in the message or by contacting us. We never send our own marketing to a clinic's customers. Some data is required to enter into a contract or provide the service; without it we may be unable to open an account or provide parts of the service.

Providers and international transfers

We disclose only the data each third-party provider needs for its role:

  • Messaging platforms such as LINE and Meta Platforms, when a clinic connects its account
  • Cloud hosting providers for the database and backend, located in Thailand
  • File storage providers for attachments and documents, which may be located outside Thailand
  • Online payment processors
  • Email delivery providers, and Google Calendar when a clinic enables appointment sync
  • Error monitoring and website performance providers, which may process data outside Thailand

Some providers may act as independent controllers for their own services. We use contractual and legal safeguards appropriate to international transfers, and do not intentionally expose customer data across unrelated clinics.

We may also disclose data to our professional advisers, such as lawyers or auditors, under confidentiality; to government authorities or courts where law or a lawful order requires it; and to a successor in a merger or transfer of the business, where the data remains subject to this policy.

Retention and deletion

Core data is retained while a clinic uses the service and afterward only as needed for data return, backups, disputes, or legal duties. The periods we actually apply are:

  • Clinic data after the agreement ends — 90 days for the clinic to request an export, after which we delete or de-identify it from primary systems and let backups expire on their normal rotation.
  • Read-access activity logs — 90 days, then deleted automatically. Logs of changes to data are kept as an audit record.
  • Ephemeral data such as sessions, OTP codes, and payment-link access codes — deleted once expired or used, on the daily clean-up cycle.
  • Our own financial and accounting records — for the period tax and accounting law requires, currently at least five years.

Retention of the clinic's medical and accounting records depends on the clinic's own legal duties, not ours. After a valid deletion request, data may first be removed from normal use and then deleted or de-identified from primary systems and backups on their lifecycle, unless law requires restricted retention. A Google account can be unlinked from the staff management screen, which removes the link data from primary systems. See /en/data-deletion.

Security and clinic boundaries

We use measures proportionate to risk, including encrypting connection tokens before storage, HTTPS/TLS over public networks, tenant-scoped access, and role-based permissions. No transmission or storage method is completely secure. Clinics remain responsible for administrator accounts, staff access, and connected platform accounts.

Your rights

Subject to PDPA conditions, you may have rights to access or copy, correct, port, delete, restrict, or object to processing, withdraw consent, and complain to Thailand's Personal Data Protection Committee. Clinic customers should contact the clinic first. For data we control, or if the clinic is unavailable, contact us below. We may request only what is needed to verify identity, and rights may be limited where law requires retention.

Facebook Messenger and Instagram

We use Meta data to show conversations only in the relevant clinic's inbox and allow authorized staff to reply. We do not share Meta-sourced data with any third party beyond the providers listed in this policy. Turning the channel off in Flow Clinic stops new message processing; it does not delete existing history or by itself confirm that Meta permissions have been revoked. See /en/data-deletion for deletion and authorization-removal instructions.

Cookies and website analytics

The Flow Clinic product that clinics use sets only strictly necessary cookies that keep you signed in, protect security, and remember your language choice, plus aggregate usage measurement through a third-party tool. It uses no advertising cookies and does not track you across other websites.

The flowclinic.tech website uses Vercel Web Analytics to measure visits, pages, referrers, approximate country, device and browser categories, and contact-channel clicks. It uses Vercel Speed Insights to measure page-load performance. These tools process aggregate measurements, do not use cookies to distinguish visitors, do not track visitors across websites, and receive no names, email addresses, phone numbers, messages, or images from us.

The website currently uses no marketing cookies or advertising trackers from Meta or Google. If we add them later, we will update this policy and obtain consent before enabling them where the law requires it.

We do not sell usage data to anyone. Disabling the necessary cookies will stop sign-in and parts of the product from working.

Minors and persons without legal capacity

Flow Clinic is a system for clinics and their staff and is not designed for minors to sign up on their own. We do not open user accounts for anyone under 20.

A clinic may record data about customers who are minors or lack legal capacity. In that case the clinic, as controller, is responsible for obtaining consent from the person exercising parental power or from the guardian, as the PDPA requires. If we learn that data about a minor is held without a valid lawful basis, we will work with the clinic to delete or de-identify it, unless law requires it to be kept.

Contact and policy changes

We may update this policy and will show the latest date above. If a change materially affects your rights, we will give reasonable advance notice. Contact KENGTECH Co., Ltd. at sawasdee@flowclinic.tech. The terms of service are at /en/terms, and for deletion requests see /en/data-deletion. Never email passwords, access tokens, OTPs, or unnecessary health records.