Platform · Legal
GlowFlow Privacy Policy
Version of 5 August 2026
What changed: The operator is identified as a private company registered in South Africa, Dr Sophie Ramsaroop (Pty) Ltd trading as GlowFlow, with its registration number and registered office shown. VAT position corrected: GlowFlow is not registered for VAT and charges no VAT. The Information Regulator's contact particulars are now published. The Information Officer is identified here by role and role email address only, and is named in the PAIA manual. Retention periods remain outstanding rather than stated. Added the Lovable error-reporting and self-hosted-font disclosures.
This policy describes how GlowFlow, the platform operator, handles personal information. It is the platform-level document. If you are a patient or client of a clinic that uses GlowFlow, the clinic — not GlowFlow — decides why your information is collected, and its own privacy notice applies to you. You will find it in the footer of that clinic's website.
1. Our two roles
GlowFlow acts in two distinct capacities under the Protection of Personal Information Act, 4 of 2013 ("POPIA"):
- Operator (processor) — for all clinic client data: bookings, clinical records, consent forms, photographs and marketing lists. The clinic is the responsible party. GlowFlow processes that information only on the clinic's documented instructions, given through the software.
- Responsible party — for our own business relationships: clinic owner and staff accounts, subscription billing, support correspondence, and visitors to glowflow.online.
2. Who we are
- Trading name
- GlowFlow
- Legal entity
- Dr Sophie Ramsaroop (Pty) Ltd
- Legal form
- Private company registered in South Africa, trading as GlowFlow
- Registration number
- 2021/383189/07
- Registered address
- Unit 37, 12A Park Road, Malvern, Queensburgh, KwaZulu-Natal, 4093
- Contact
- admin@glowflow.online
3. Information Officer
GlowFlow has appointed an Information Officer in terms of POPIA and the Promotion of Access to Information Act, 2 of 2000 ("PAIA"). We do not publish that person's name or telephone number on this page; requests and enquiries reach the Information Officer at the role address below, and the officer is identified by name in our PAIA manual, as that Act requires.
- Role
- Information Officer
Each clinic appoints its own Information Officer for the client data it controls. That person is named on the clinic's own privacy notice and PAIA manual.
4. Where your information is processed — Ireland, European Union
The GlowFlow database, file storage and application servers are hosted in Ireland, in the European Union. Personal information collected through this platform is therefore transferred out of South Africa and processed in the EU.
Lawful basis for the transfer. Section 72 of POPIA permits a cross-border transfer where the recipient is subject to a law that provides an adequate level of protection. Ireland is subject to the EU General Data Protection Regulation (GDPR), which upholds principles substantially similar to POPIA and includes further-transfer restrictions comparable to section 72. Where a sub-processor operates outside the EU, we rely on a written data-processing agreement incorporating standard contractual clauses, so the recipient is bound by obligations that effectively uphold POPIA's principles, as required by section 72(1)(b).
The full list of sub-processors, what each receives and where it operates is on our sub-processor page.
5. What we process as responsible party
- Clinic owner and staff account details: name, email address, mobile number, role and password hash.
- Subscription and billing records: plan, invoice history and PayFast transaction references. We never see or store card numbers.
- Support correspondence you send us.
- Website server logs: IP address, user agent and requested page, kept for security and troubleshooting.
- Google Ads conversion data on glowflow.online — only if you accept optional cookies.
6. Special personal information
Clinics using GlowFlow store special personal information as defined in section 26 of POPIA, including:
- Health and medical history disclosed on intake and consent forms
- Medication, allergy and pregnancy status
- Clinical photographs taken before, during or after a procedure
- South African ID number, where the clinic requires it for medical record-keeping
GlowFlow processes this only as operator. It is held in an EU-hosted database with row-level access control, clinical photographs live in a private storage bucket reachable only through short-lived signed links, and location metadata is stripped from every image on upload. GlowFlow staff do not access clinical content except where a clinic asks us to in writing for a specific support issue.
7. How long information is kept
The categories of information we hold are set out below. The retention period for each, and the legal basis that fixes it, are currently being confirmed with the clinic's professional and tax advisers. Until that confirmation is in place we do not delete records in these categories, and we will publish the confirmed periods here as soon as they are settled. You can ask us at any time what we hold about you and ask for it to be deleted, and we will tell you whether a statutory minimum prevents deletion.
| Category | Retention period | Why |
|---|---|---|
| Clinical / treatment records and consent forms | To be confirmed: retention period | To be confirmed: legal basis |
| Clinical photographs | To be confirmed: retention period | To be confirmed: legal basis |
| Booking and appointment history | To be confirmed: retention period | To be confirmed: legal basis |
| Invoices, payments and PayFast transaction references | To be confirmed: retention period | To be confirmed: legal basis |
| Marketing contact details and consent records | To be confirmed: retention period | To be confirmed: legal basis |
| Email and SMS delivery logs | To be confirmed: retention period | To be confirmed: legal basis |
| Security, access and audit logs | To be confirmed: retention period | To be confirmed: legal basis |
| Closed clinic accounts | To be confirmed: retention period | To be confirmed: legal basis |
8. Security
- Encryption in transit (TLS) for every connection. Our database and file-storage provider, Supabase, states that data is encrypted at rest using AES-256; that statement is theirs, and we reproduce it rather than certify it ourselves.
- Row-level security in the database, so a clinic's staff can only reach that clinic's records.
- Role-based access: reception, therapist, admin and owner see different data.
- Clinical and consent files stored in private buckets, served only via short-lived signed URLs.
- Per-clinic payment credentials stored encrypted; platform and clinic money are kept separate.
- Audit logging of sensitive actions such as consent-form access and clinical record changes.
9. Security compromises (data breaches)
If GlowFlow becomes aware of a compromise affecting personal information, we notify the affected clinic as soon as reasonably possible after we become aware of it, and with reasonable regard for the needs of any law-enforcement investigation, with the detail known at that point and updates as the investigation continues.
Where the compromise affects clinic client data, the responsible party (the clinic) must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering the compromise, as required by section 22 of POPIA. GlowFlow supports the clinic with the technical detail it needs to do so.
Report a suspected security issue to admin@glowflow.online.
10. Your rights
Where GlowFlow is the responsible party, you may ask us to:
- Confirm what personal information we hold about you and give you a copy.
- Correct or delete information that is inaccurate, irrelevant, excessive or out of date.
- Stop processing where you object on reasonable grounds.
- Withdraw consent to marketing at any time.
Send requests to admin@glowflow.online. Where GlowFlow is only the operator — that is, for clinic client records — direct your request to the clinic. If you send it to us, we will forward it to the clinic and tell you we have done so; we may not release or delete a clinic's records on our own.
Formal access requests follow our PAIA manual.
11. Complaints
You have the right to lodge a complaint with the Information Regulator of South Africa about the way your personal information has been handled. That right exists under the Protection of Personal Information Act, 4 of 2013, and using it does not affect any other remedy available to you.
You are welcome to raise the matter with us first at admin@glowflow.online, but you do not have to. The Information Regulator (South Africa)'s contact particulars are:
- Regulator
- Information Regulator (South Africa)
- Physical address
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
- Telephone
- 010 023 5200
- Toll free
- 0800 017 160
- POPIA complaints
- POPIAComplaints@inforegulator.org.za
- General enquiries
- enquiries@inforegulator.org.za
- Website
- https://inforegulator.org.za
12. Changes to this policy
We update this policy when our processing changes. The version date appears at the top of this page, and material changes affecting clinics are communicated to the clinic owner by email before they take effect.