Bedside

Privacy policy

What we hold, and why

Bedside carries messages between a clinic and its patients. This policy explains exactly what data that involves, who touches it, and how long it stays.

Last updated 9 August 2026

Two different roles

Which of us is responsible for a piece of data depends on whose data it is, and the distinction matters:

  • Patient data — names, contact details, appointment times, messages and shared files. The clinic decides what is collected and why; Bedsideonly processes it on the clinic's instructions. In data-protection terms the clinic is the controller and we are the processor.
  • Clinic staff accounts — the email address you sign in with, and how you use the product. Here Bedside decides the purpose, so we are the controller.

If you are a patient and want your data corrected or removed, contact the clinic that treats you. They control that record; we act on their instruction.

What we collect

  • From clinic staff: your email address, and your name if you sign in with Google. If you sign in with a password, our authentication provider stores only a salted hash of it — never the password itself.
  • Entered by the clinic about patients: name, phone number, email address, date of birth (used to unlock shared reports), appointment details, free-text notes the clinic chooses to add, and any file the clinic uploads to share.
  • Generated by using the product: the content and delivery status of messages sent and received, which reports were opened and when, and counts of messages sent for plan limits.

We do not run advertising trackers, we do not sell data to anyone, and we do not use patient data to train machine-learning models.

Why we hold it

  • To send the reminders, confirmations and messages a clinic asks us to send.
  • To let clinic staff see replies and manage appointments.
  • To deliver shared report files securely and show the clinic who opened them.
  • To keep accounts secure and to count usage against a plan's limits.

For clinic accounts, we rely on the contract between us and, where a feature is optional, on your consent. For patient data, the lawful basis is the clinic's to determine — we process it under their instructions.

Who else processes it

Bedside runs on a small set of infrastructure providers. Each receives only what it needs to do its job.

Supabase

Database, sign-in and file storage (EU-hosted)

Patient records, appointments, message history and shared report files.

Cloudflare

Hosting and delivery of the Bedside app

Traffic between your browser, your patients and Bedside.

Resend

Email sending

Patient name, email address and the content of each email.

Meta (WhatsApp Cloud API)

WhatsApp messaging

Patient phone number and the content of each WhatsApp message.

Google

Optional sign-in with a Google account

The staff member's name and email address, only if they choose Google sign-in.

Messaging providers necessarily receive the phone number and message content in order to deliver it — that is inherent to sending a text or a WhatsApp message, and their own terms apply to that delivery. We will update this list before adding a new provider.

How long we keep it

  • Shared report files are deleted automatically when the link expires, on a schedule the clinic sets. The record that a report existed remains as an audit trail, without the file.
  • Patients, appointments and message history stay for as long as the clinic keeps its account, because the clinic needs the history. Deleting a patient in the app deletes their record.
  • Access logs for shared reports record the outcome and the time only — no IP addresses, no browser details.
  • If a clinic closes its account, we delete its data on request.

Bedsideis deliberately not the master copy of anyone's records: the clinic's own practice system remains the retention copy. The less we keep, the less there is to lose.

Where it is held

The database, sign-in and file storage are hosted in the EU. Some providers listed above operate globally and may process data outside the EU or UK in order to deliver a message; where that happens it is governed by those providers' own transfer safeguards.

How it is protected

Every clinic's data is isolated at the database itself using row-level security, shared report links need both the link and the patient's date of birth, and integration keys are stored only as a fingerprint that cannot be read back. There is a fuller, plain-language explanation on our security page.

No system is perfect. If we discover a breach affecting personal data, we will notify affected clinics without undue delay so they can meet their own obligations to patients.

Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how it is used, or receive it in a portable format. You can also complain to your local data-protection authority.

Patients: contact the clinic that treats you — they hold your record. Clinic staff: contact us and we will help.

Messages patients receive

Clinics are responsible for having a proper basis to contact their patients. Any patient can stop messages at any time by replying STOP; Bedside honours that automatically on WhatsApp, and START resumes them.

Deleting your data

You can have your data removed at any time. How depends on who you are, because clinics — not Bedside— control their patients' records.

  • Patients: ask the clinic that treats you to delete your record. Deleting a patient in Bedside removes their details and message history. If you would rather just stop hearing from them, reply STOP to any message.
  • Clinic staff: delete individual patients, appointments and shared reports directly in the dashboard at any time.
  • Whole account: contact us through Hamza Builds and we will delete the clinic and everything in it. We will confirm once it is done.
  • Shared report files delete themselves when the link expires — no request needed.

Changes and contact

If this policy changes materially we will update the date at the top and tell clinics through the product. Questions, requests or concerns — including any of the rights above — email contact@hamzabuilds.com.

Bedside is operated by Hamza Builds, a proprietorship registered in Karnataka, India under UDYAM-KR-03-0729889.