AesthPA

Legal

Privacy notice

How AesthPA handles personal data — what we collect, why, and what you can ask us to do with it.

Last updated 6 August 2026


Who we are

AesthPA is a brand of WE ARE AI WORKS LAB LIMITED, a company registered in England and Wales (number 16598066), with its registered office at 34 Mason’s Yard, High Street Wimbledon, London, England, SW19 5BY.

We are the data controller for the personal data described in section 3. For the clinic data described in section 4, we act as a processor.

The two roles we play

This is the most important thing to understand about how we handle data, because it determines who you should contact about it.

Controller
For our website visitors, enquiries and demo requests, and the people who hold accounts with us. We decide why and how that data is processed, so ask us about it.
Processor
For the client and patient data a clinic puts into AesthPA. The clinic decides why and how that data is processed. We act on the clinic’s instructions, so ask the clinic about it.

If you are a client or patient of a clinic that uses AesthPA and you want to see, correct or delete your information, please contact that clinic directly. They are the controller of your record, and we will support them in responding to you.

Data we hold as controller

Where we decide how data is used, we process:

  • Enquiry and demo request data — your name, work email, phone number, clinic or company name, and anything else you choose to tell us, so that we can respond and arrange a walkthrough.
  • Account data — the name, email and role of people at a subscribing clinic, used to give access, provide support and administer the subscription.
  • Billing data — the details needed to invoice and take payment. Card details are handled by our payment provider and are not stored by us.
  • Support and correspondence — messages you send us and our replies, so we have a record of what was asked and what we did.
  • Website analytics — aggregate, cookieless usage measurement, described in section 9.

Clinic and patient data we hold as processor

When a clinic uses AesthPA, personal data about its clients passes through the service — for example contact details, appointments, consent records, forms, call and message records, and payment status. Depending on how a clinic uses the product, this can include health information, which is special category data under the UK GDPR.

We process that data only on the clinic’s documented instructions and for the purpose of providing the service. We do not sell it, and we do not use it to advertise to their clients.

The clinic is responsible for establishing its own lawful basis and, for health data, its condition for processing special category data, and for giving its clients a privacy notice of its own.

Why we process it, and our lawful basis

Contract
Providing the service to a subscribing clinic, administering accounts, and taking payment.
Legitimate interests
Responding to enquiries, providing support, keeping the service secure, preventing fraud and misuse, and understanding in aggregate how the website is used. We balance these against your interests and rights.
Consent
Sending marketing about our product where consent is required. You can withdraw it at any time without affecting anything we did beforehand.
Legal obligation
Keeping accounting and tax records, and responding to lawful requests.

Where we act as processor (section 4), the clinic — not us — determines the lawful basis for processing its clients’ data.

Who we share it with

We do not sell personal data. We share it only with service providers who help us run AesthPA, and only as far as they need it. These fall into the following categories:

  • Hosting and infrastructure providers, who store and serve the application and its data.
  • Telephony and messaging providers, who carry calls, SMS and messaging on a clinic’s behalf.
  • Email delivery providers, for transactional and notification email.
  • Payment providers, who process card payments and hold the card details we never see.
  • AI processing providers, used to transcribe and summarise communications and to draft suggested actions for a human to review.
  • Professional advisers, such as accountants and lawyers, where they need it to advise us.

Each is bound by contract to process data only on our instructions and to keep it secure. We can provide the current list of named sub-processors on request, and clinics are told about material changes to it.

We may also disclose data where the law requires it.

Where data is held

We aim to keep personal data in the UK or the European Economic Area. Some of our providers process data outside that area.

Where that happens, we rely on an approved safeguard — such as UK adequacy regulations, or the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — so the data keeps an equivalent level of protection.

How long we keep it

  • Enquiries that do not become customers: up to 24 months from your last contact with us.
  • Account and service data: for the life of the subscription, then a limited window during which a clinic can export it, after which it is deleted.
  • Billing and accounting records: six years, as UK tax law requires.
  • Support correspondence: up to 24 months after the matter is closed.

Where we hold data as processor, retention follows the clinic’s instructions and our agreement with them.

Cookies and analytics

This website does not set cookies and does not load third-party tracking scripts.

We use privacy-friendly analytics to understand how the site is used in aggregate. It records things like the page visited, the referring site, approximate country, and device and browser type. It does not use cookies, does not build a profile of you, and does not track you across other websites.

Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls that limit who can reach what, separation of each clinic’s data from every other clinic’s, and logging of administrative access.

No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify the people and regulators the law requires us to.

Your rights

Under the UK GDPR you have the right to:

  • Ask what personal data we hold about you and get a copy of it.
  • Have inaccurate data corrected.
  • Ask us to delete data, where there is no overriding reason for us to keep it.
  • Ask us to restrict how we use it, or object to our use of it where we rely on legitimate interests.
  • Receive data you gave us in a portable, machine-readable form.
  • Withdraw consent at any time, where we rely on it.

To exercise any of these, write to us at the address in section 13. We will respond within one month. If your data sits with a clinic that uses AesthPA, we will pass your request to them, as they are the controller.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first so we can try to put it right.

You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk.

Contact us

For anything in this notice, including requests about your data, write to:

WE ARE AI WORKS LAB LIMITED34 Mason’s YardHigh Street WimbledonLondonEnglandSW19 5BY

Changes to this notice

We may update this notice as the service develops or the law changes. The date at the top shows when it last changed, and we will tell subscribing clinics about material changes.