Legal
Privacy Policy
Effective Date: April 18, 2026
1. Introduction
Welcome to ClinicFlow. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website clinicflow.lk and when you use the ClinicFlow clinic management system.
Please read this policy carefully. If you disagree with its terms, please discontinue use of our website and services.
2. Information We Collect
2.1 Website Visitors
When you visit our corporate website, we may collect:
- Contact form submissions including your name, clinic name, email address, and phone number.
- Basic usage data such as pages visited.
- Browser type and device information for security purposes.
2.2 ClinicFlow System Users
The ClinicFlow software is self-hosted on each clinic's own server. We, as the software developer, do NOT collect, store, or have access to:
- Patient personal information or medical records.
- Appointment data or consultation notes.
- Any data entered into a deployed ClinicFlow system.
All data within a deployed ClinicFlow instance is owned and controlled exclusively by the clinic operator.
3. How We Use Your Information
Information collected via our website contact form is used solely to:
- Respond to your demo request or inquiry.
- Provide you with information about ClinicFlow products and services.
- Complete your software purchase and deployment.
- Send important notices regarding your license or support.
We do not sell, trade, or rent your personal information to third parties.
4. Data Storage & Security
- Contact form submissions are transmitted via secure encrypted email.
- We do not maintain a database of website visitor information.
- All deployed ClinicFlow instances store data on the clinic's own server, not on our infrastructure.
- We implement reasonable technical measures to protect information transmitted through our website.
5. Third-Party Services
Our corporate website uses the following third-party services:
- Resend — for processing contact form email notifications.
- Vercel — for website hosting and delivery.
We are not responsible for the privacy practices of third-party services.
6. Cookies
Our website does not use tracking cookies or advertising cookies. Basic session cookies may be used for website functionality only.
7. Your Rights
You have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information from our records.
- Withdraw consent for communications at any time.
8. Clinic Operators' Responsibilities
If you are a clinic operator using ClinicFlow, you are the data controller for all patient information in your system. You are responsible for:
- Compliance with the Personal Data Protection Act of Sri Lanka and other applicable laws.
- Maintaining appropriate security measures for your server and data.
- Obtaining necessary patient consents for data collection and processing.
- Implementing your own privacy policy for your patients.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date at the top of this document. Your continued use of our website constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy, please contact us:
ClinicFlow
Email: hello@clinicflow.lk
Website: clinicflow.lk
madusanka.dev
ClinicFlow is a product of madusanka.dev
Sri Lanka