Legal

Privacy Policy

Effective 18 September 2026 · Version 2026-09-18

Quick reference. For Google integrations, we specifically describe the Google account data we access, the purposes for which it is used, how it is stored and shared, how long it is retained, and how you can revoke access or request deletion. This Privacy Policy describes: (1) the types of personal and sensitive data 360Frontdesk collects, (2) how and why that data is collected, (3) how data is used and processed, (4) how data is shared with third parties including Google, (5) how data is secured and retained, and (6) how you can access, correct, delete, or export your data. A summary table of data types and purposes appears in Section 6, and data deletion instructions appear in Section 11.

1. Introduction

This Privacy Policy explains how 360Frontdesk ("we", "our", "us") collects, uses, stores, processes, and protects personal data when you use our platform and related services (the "Service").

360Frontdesk is operated by:

360FrontDesk FZE

Trade License No. 262274277888

Dubai, United Arab Emirates

Email: hello@360frontdesk.com

By using the Service, you acknowledge and agree to the practices described in this Privacy Policy.

2. Scope of this Policy

This Privacy Policy applies to:

  • clinic users and staff using the platform;
  • website visitors;
  • patient communication data processed through the Service;
  • integrations connected to the Service.

This Policy does not apply to:

  • third-party websites or services;
  • external platforms integrated by customers;
  • Meta, WhatsApp, Google, HubSpot, OpenAI, or other third-party providers governed by their own privacy policies.

3. Role of the Parties

In most cases:

  • the clinic or healthcare provider is the data controller responsible for patient data;
  • 360Frontdesk acts as a data processor/service provider on behalf of the clinic.

For certain operational data relating to our own business operations, we may act as an independent data controller.

4. Information We Collect

We may collect and process the following categories of information:

A. Clinic Account Information

Collected when you register, sign up, or update your account.

  • clinic or business name, trade license number, and industry;
  • authorized contact name, email address, and phone number;
  • authorized staff user accounts (name, email, role);
  • billing contact details and billing email;
  • subscription and plan details;
  • branch names, addresses, working hours, and WhatsApp numbers;
  • payment method metadata (processed via Stripe; we do not store full card numbers).

B. Patient / End-User Communication Data

Collected when patients or end-users interact with your Frontdesk via WhatsApp, web, or integrated channels.

  • patient or contact name;
  • phone number (WhatsApp number);
  • email address, where provided;
  • WhatsApp and chat message content;
  • appointment requests, bookings, and status;
  • conversation history and transcripts;
  • language preferences;
  • uploaded files, images, documents, or voice notes;
  • voice note transcriptions (when transcription is enabled);
  • lead and enquiry details captured by the AI assistant.

C. Technical and Usage Information

Collected automatically when you access the Service.

  • IP address;
  • browser type and version;
  • device information and identifiers;
  • operating system;
  • login activity and authentication events;
  • pages and features accessed within the platform;
  • analytics and usage metrics;
  • crash and error reports.

D. AI Interaction Data

Collected when the AI assistant processes messages and generates responses.

  • prompts and message context sent to AI models;
  • generated AI responses;
  • workflow and automation interactions;
  • AI quality, safety, and abuse-monitoring information;
  • feedback on AI responses (e.g. corrections or escalations).

E. Sensitive and Health-Related Information

Collected only when a patient or clinic voluntarily shares it through the communication channels.

  • health symptoms, conditions, or medical details shared in messages;
  • appointment reasons that may reveal health information;
  • any other sensitive information patients choose to share.

We do not knowingly request sensitive data beyond what is necessary to operate the Service. Clinics are responsible for ensuring that the collection and processing of any health or sensitive data complies with applicable healthcare and data protection laws.Google User DataWhen you choose to connect a Google account or Google service to 360Frontdesk, we may access certain information from your Google account through Google APIs. The specific information accessed depends on the Google service and permissions you authorize.Depending on the integration, this may include:your Google account name, email address, and profile information used for authentication;Google Calendar information necessary to provide appointment scheduling and calendar synchronization, including calendar event titles, dates, times, descriptions, attendees, and related scheduling information;OAuth authentication credentials or access tokens necessary to maintain the authorized connection.360Frontdesk requests only the Google permissions necessary to provide the Google-enabled features you have chosen to use. We do not access Google account information that is not required for those features.

5. How We Collect Information

We collect information through the following methods:

  • Information you provide directly — when you create an account, complete the signup wizard, configure settings, upload documents, or contact support.
  • Information from patient interactions — when patients message your Frontdesk via WhatsApp or other connected channels, the content of those interactions is processed to deliver the Service.
  • Automatic collection — log data, cookies, device identifiers, and usage analytics are collected automatically when you use the platform.
  • Third-party sources — limited information may be received from integrated services (e.g. Google Calendar, Meta/WhatsApp, HubSpot) when you connect those integrations, governed by those providers' own privacy policies.

Where consent is required for collection, clinics are responsible for obtaining that consent from their patients under applicable law.

6. How We Use Information

We use personal data to:

  • create and manage clinic and staff accounts;
  • provide, operate, and maintain the Service;
  • manage appointments, bookings, and reminders;
  • process, route, and store WhatsApp and chat messages;
  • generate AI-assisted responses and automate workflows;
  • transcribe voice notes and process uploaded files;
  • provide customer and technical support;
  • process payments and manage subscriptions (via Stripe);
  • send account, billing, and service-related notifications;
  • improve platform functionality, reliability, and AI quality;
  • maintain platform security and prevent unauthorized access;
  • monitor and detect abuse, fraud, or misuse;
  • generate analytics, reporting, and operational insights for clinics;
  • comply with legal, regulatory, and contractual obligations.

We do not sell personal data to third parties.

We do not use personal data for targeted advertising.

Summary of Data Types and Purposes

Data TypePurposeLegal Basis
Account & billing informationAccount creation, subscription management, paymentsContract performance
Patient contact details & messagesDelivering WhatsApp communication and appointment servicesContract performance & consent
Appointment & booking dataScheduling, reminders, and calendar synchronizationContract performance
AI interaction dataGenerating responses, improving AI quality, safety monitoringLegitimate interest
Technical & usage dataSecurity, analytics, platform improvement, fraud preventionLegitimate interest
Google account dataCalendar sync and sign-in, only when you connect GoogleConsent
Health-related informationProcessing patient messages as instructed by the clinicConsent & contract performance

7. AI and Automated Processing

The Service uses artificial intelligence and automated systems to assist clinics with patient communication and workflow automation.

This may include:

  • automated replies;
  • FAQ handling;
  • appointment scheduling;
  • lead qualification;
  • language processing;
  • voice transcription.

AI-generated responses may not always be accurate, complete, or appropriate for every situation.

Clinics remain responsible for medical decisions, patient communications, regulatory compliance, and human oversight.

8. Legal Basis for Processing

We process information based on one or more of the following:

  • performance of contractual obligations;
  • legitimate business interests;
  • consent obtained by the clinic where required;
  • compliance with legal obligations;
  • protection of legitimate operational and security interests.

Clinics are responsible for obtaining any patient consents required under applicable UAE healthcare or data protection laws.

9. Sharing of Information

We may share information with trusted service providers and subprocessors solely as necessary to provide the Service. Each subprocessor is bound by contractual obligations to protect data and process it only as instructed.

These may include:

  • Meta / WhatsApp — for sending and receiving WhatsApp Business messages;
  • 360dialog — WhatsApp Business API provider;
  • OpenAI — for AI text generation and language processing;
  • Supabase — database and authentication infrastructure;
  • Google — for Google Calendar integration, Google sign-in, and Google Cloud services;
  • HubSpot — for CRM integration where connected;
  • Stripe — for payment processing and subscription billing;
  • hosting and infrastructure providers;
  • analytics and monitoring providers.

Data Shared with Google

When you connect Google integrations (such as Google Calendar or Google Sign-In), limited Google account data is accessed and used solely to provide the requested integration features. This may include:

  • basic profile information (name, email, profile picture) for sign-in;
  • calendar event details (titles, times, descriptions) for appointment synchronization;
  • authentication tokens to maintain the connection.

Google account data is used only to deliver the integration you have authorized and is not used for any other purpose. Specifically:

  • Google Calendar data (event titles, times, descriptions, and attendees) is used solely to synchronize appointments between 360Frontdesk and your calendar;
  • Google sign-in profile data (name, email, profile picture) is used only to authenticate your login;
  • authentication tokens are stored securely and used to maintain your authorized connection;
  • we do not transfer Google data to any other service for unrelated purposes;
  • we do not use Google data to train AI models;
  • we do not share Google data with advertising platforms.

You may disconnect Google integrations at any time from your account settings, after which we cease accessing the associated Google data and delete the stored authentication tokens within 30 days.

We require subprocessors to implement reasonable security and confidentiality protections.

We may also disclose information where required by law, pursuant to regulatory requests, to protect rights or safety, or in connection with a merger, acquisition, or restructuring.Google API Services – Limited Use360Frontdesk's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.Google user data is used only to provide or improve the user-facing features of 360Frontdesk that you have requested or authorized.We do not use Google user data for:targeted advertising or personalized advertising;selling or transferring Google user data to data brokers or information resellers;determining creditworthiness, lending, or similar financial eligibility;advertising or retargeting purposes;creating advertising profiles about users;training generalized or non-personalized artificial intelligence or machine-learning models;any purpose unrelated to providing or improving the Google-enabled functionality requested by the user.We do not sell Google user data.We do not transfer Google user data to third parties except where necessary to provide the Google-enabled functionality, comply with applicable law, or as otherwise permitted by the Google API Services User Data Policy. Any such processing is limited to the purpose for which the data was provided.We do not use Google Calendar data or Google account data to determine eligibility for services, make decisions about individuals, or create profiles unrelated to the functionality of 360Frontdesk.Google user data is not combined with data obtained from other sources for advertising purposes.Storage and Transfer of Google User DataGoogle user data that is stored by 360Frontdesk is retained only for as long as necessary to provide the Google-enabled functionality or to meet applicable legal, security, or contractual requirements.Where Google user data is stored on our infrastructure or processed by a service provider acting on our behalf, we apply appropriate contractual, technical, and organizational safeguards designed to protect that information.Google user data may be processed or stored in countries outside the country in which you reside, including through infrastructure or service providers used to operate 360Frontdesk. Such processing is subject to applicable data protection requirements and the safeguards described in this Privacy Policy.Access to Google user data within 360Frontdesk is limited to authorized personnel and service providers who require access to operate, maintain, secure, or provide the relevant functionality.Storage and Transfer of Google User DataGoogle user data that is stored by 360Frontdesk is retained only for as long as necessary to provide the Google-enabled functionality or to meet applicable legal, security, or contractual requirements.Where Google user data is stored on our infrastructure or processed by a service provider acting on our behalf, we apply appropriate contractual, technical, and organizational safeguards designed to protect that information.Google user data may be processed or stored in countries outside the country in which you reside, including through infrastructure or service providers used to operate 360Frontdesk. Such processing is subject to applicable data protection requirements and the safeguards described in this Privacy Policy.Access to Google user data within 360Frontdesk is limited to authorized personnel and service providers who require access to operate, maintain, secure, or provide the relevant functionality.

10. International Data Transfers

Your data may be processed or stored outside the United Arab Emirates depending on the infrastructure and third-party providers used.

By using the Service, you acknowledge and consent to such transfers where legally permissible.

We take commercially reasonable measures to ensure appropriate safeguards are implemented.

11. Data Retention

We retain data only for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security and operational integrity.

General retention guidelines:

  • Account data — retained for the duration of your subscription and deleted within 30 days after account termination, unless legal obligations require longer retention.
  • Conversation and message data — retained for the duration of your subscription to enable conversation history and continuity; deleted within 30 days of account termination.
  • AI interaction data — retained as needed to provide the Service and improve AI quality, then deleted or anonymized.
  • Usage and log data — retained for up to 12 months for security and analytics purposes.
  • Billing records — retained as required by applicable tax and financial regulations.

Retention periods may vary depending on clinic configuration, legal requirements, operational needs, and regulatory obligations.

We may delete or anonymize data after termination or inactivity periods. Clinics may also request deletion of their data, subject to legal and contractual obligations.

Data Deletion and Account Closure

You may request deletion of your data at any time. To do so:

  • email us at hello@360frontdesk.com with the subject "Data Deletion Request";
  • include your account email and clinic name so we can verify your identity;
  • upon verification, we will delete your account data, conversation history, and associated records within 30 days;
  • you may also disconnect specific integrations (e.g. Google, WhatsApp) individually from your settings without deleting your entire account;
  • some records may be retained beyond 30 days where required by law, tax regulations, or legitimate security obligations.

When an account is terminated, all associated patient communication data, AI interaction logs, and configuration settings are permanently deleted, except where retention is legally required. Google User Data Retention. Google user data is retained only for the period necessary to provide the Google integration or for legitimate security, legal, contractual, and operational purposes. When a user disconnects a Google integration, 360Frontdesk stops accessing Google data through the revoked authorization. Stored authentication tokens associated with the integration are deleted within 30 days, subject to applicable legal or security retention requirements.Users may request deletion of Google-related data held by 360Frontdesk by contacting us at hello@360frontdesk.com with the subject line "Google Data Deletion Request."We will process verified deletion requests in accordance with this Privacy Policy and applicable law.

12. Security Measures

We implement commercially reasonable technical and organizational safeguards designed to protect information against unauthorized access, misuse, accidental loss, disclosure, or destruction.

Security measures may include:

  • encryption of data in transit using TLS/HTTPS;
  • encryption of sensitive data at rest where supported by our infrastructure;
  • role-based access controls limiting data access to authorized personnel only;
  • multi-factor authentication for administrative access;
  • secure authentication systems for user accounts;
  • secure, audited infrastructure providers (e.g. Supabase, Stripe);
  • continuous monitoring and security logging;
  • regular security reviews and vulnerability assessments;
  • incident response and breach notification procedures.

Access to personal data is restricted to authorized employees and contractors who need it to operate the Service, and all such personnel are bound by confidentiality obligations.

However, no platform or internet transmission can be guaranteed fully secure. In the event of a personal data breach, we will notify affected users and relevant authorities as required by applicable law.

13. Patient and User Responsibilities

Clinics are responsible for:

  • obtaining required patient notices and consents;
  • ensuring lawful use of the Service;
  • maintaining internal access controls;
  • reviewing AI-generated communications where appropriate;
  • ensuring compliance with healthcare and privacy regulations.

Users should avoid sharing unnecessary sensitive medical information through unsecured channels where possible.

14. Cookies and Analytics

We may use cookies and similar technologies to maintain sessions, improve usability, analyze traffic and performance, remember preferences, and enhance security.

Types of cookies and technologies we may use:

  • Essential cookies — required for authentication and core platform functionality;
  • Preference cookies — remember settings such as language and theme;
  • Analytics cookies — help us understand how the platform is used so we can improve it;
  • Security cookies — support fraud prevention and account protection.

We do not use cookies for targeted advertising.

You may control or disable certain browser cookie settings directly through your browser preferences. Disabling some cookies may affect platform functionality.

15. Your Rights

Subject to applicable law, users may have rights to:

  • request access to and a copy of personal data we hold about them;
  • request correction of inaccurate or incomplete information;
  • request deletion of personal data where legally permissible;
  • request restriction of or object to certain processing activities;
  • request data portability of information they provided;
  • withdraw consent where processing is based on consent;
  • request disconnection of third-party integrations (e.g. Google, WhatsApp, HubSpot).You may disconnect Google integrations at any time from your account settings. When you disconnect a Google integration, 360Frontdesk will stop accessing Google data through that authorization.Following disconnection, we will delete stored OAuth authentication tokens associated with that connection within 30 days, unless retention is required by applicable law or reasonably necessary for security or fraud-prevention purposes.Where Google user data has been stored by 360Frontdesk solely to provide the disconnected integration, we will delete or anonymize that data within the applicable retention period described in Section 11, subject to legal, contractual, security, or dispute-related retention requirements.Disconnecting Google does not necessarily delete your 360Frontdesk account. You may separately request deletion of your 360Frontdesk account and associated personal data using the process described in Section 11.Google Account Data RightsWhere 360Frontdesk has accessed Google user data through an authorization granted by you, you may revoke that authorization by disconnecting the relevant Google integration from your 360Frontdesk account or by withdrawing the application's access through your Google Account settings.You may also contact us to request access to, correction of, or deletion of Google user data held by 360Frontdesk, subject to applicable legal and contractual requirements.Revoking Google access prevents future access through that authorization but does not automatically delete your 360Frontdesk account. Account deletion and deletion of associated data may be requested separately as described in Section 11.

To exercise these rights, or to ask a question about how your data is collected or used, contact us at: hello@360frontdesk.com

We may require identity verification before processing requests and will respond within a reasonable timeframe, generally within 30 days.

16. Third-Party Services

The Service may contain integrations or links to third-party services not controlled by us.

We are not responsible for third-party privacy practices, external platform security, or third-party content or policies.

Users should review the applicable privacy policies of integrated providers.

17. Children's Privacy

The Service is not directed toward children under the age of 18.

Clinics remain responsible for obtaining any legally required parental or guardian consents relating to minors.

18. Changes to this Privacy Policy

We may update this Privacy Policy periodically.

Material updates may be communicated through email notifications, dashboard notices, or website updates.

Continued use of the Service after updates become effective constitutes acceptance of the revised Privacy Policy.

19. Governing Law

This Privacy Policy shall be governed by the laws of the United Arab Emirates and the applicable laws of the Emirate of Dubai.

Any disputes relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Dubai, United Arab Emirates.

20. Contact Us

360FrontDesk FZE

Trade License No. 262274277888

Dubai, United Arab Emirates

Email: hello@360frontdesk.com

For privacy-related questions or requests, please contact us at the email above.