Privacy Policy

Effective date: 20 July 2026

This policy explains how Yamabushi Labs Ltd (“Yamabushi Labs”, “we”, “us”) processes personal information and the rights available to you under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where it applies, the EU General Data Protection Regulation (EU GDPR). It covers this public website and is intended to cover our separate application when it becomes operational.

Our role and the clinic’s role

We are a data controller when we decide why and how to process information about website visitors, business contacts, and our own customer-account administration.

For patient appointment and messaging information processed for a customer clinic, the clinic is expected to be the controller and Yamabushi Labs the processor. In that role, we process the information only on the clinic’s documented instructions and under a data-processing agreement. The clinic determines the purpose and lawful basis of that processing and provides its patients with the relevant privacy information. If the actual arrangement assigns the roles differently, we and the clinic will document that allocation and update the relevant information.

Who this policy covers

It applies to the personal information of:

  • visitors to this website;
  • prospective customers and business contacts who enquire with us;
  • users of our separate application once it becomes operational;
  • administrators and staff of customer organisations who use our services; and
  • individuals whose information a customer organisation asks us to process on its behalf.

Personal information we collect

Depending on how you interact with us, we may process the following categories of personal information:

  • Account and contact details — such as name, email address, business name, and role.
  • Patient and messaging details — once the application is operational, patient names, phone numbers, WhatsApp message content, and patient replies needed to provide clinic communications.
  • Appointment and clinic details — appointment dates and times and the relevant clinic or clinician details supplied by a customer clinic.
  • Technical and security records — logs, device and connection information, and records kept to keep our systems secure.

Appointment details and message content may reveal information about a person’s health. This is special-category personal data and requires additional protection. For clinic-controlled processing, the clinic is responsible for identifying both an applicable lawful basis and a condition for processing health data; Yamabushi Labs does not determine those grounds on the clinic’s behalf.

How and why we use personal information

We process personal information to:

  • respond to enquiries and provide information about Yamabushi Labs;
  • provide, operate, and support our services to customer organisations;
  • send appointment reminders and operational messages on behalf of customers;
  • keep our website and services secure and reliable; and
  • meet our legal, accounting, and regulatory obligations.

Lawful bases

When Yamabushi Labs acts as controller, we rely on the following lawful bases under UK GDPR or EU GDPR, as applicable:

  • Legitimate interests — to respond to business enquiries and to secure and improve our website and services.
  • Contract or steps before a contract — to respond to a request or administer services requested by a customer organisation.
  • Legal obligation — where the law requires us to retain or disclose information.
  • Consent — where we specifically ask for it; you may withdraw it at any time.

When we act as a processor, we do not choose the clinic’s lawful basis or special-category condition. Questions about the clinic’s reasons for processing patient data should normally be directed to that clinic, although we will assist it with data-protection requests as required by our agreement.

Service providers and subprocessors

We use service providers to operate the website, business communications, and the application once it becomes operational. Our confirmed current or planned providers are:

  • Railway — website and application hosting;
  • Neon — application database hosting and database backups;
  • Namecheap and Google/Gmail — domain email forwarding and mailbox handling; and
  • Meta/WhatsApp — messaging-platform connectivity once that service is operational.

A provider may act as our processor, subprocessor, or a separate controller depending on the service and processing involved. Where a provider processes clinic-controlled information on our behalf, we will appoint it as a subprocessor where required and maintain the necessary contractual safeguards. We will update this section when the provider map changes. No separate AI provider is used for the first release.

Automated processing

The first release does not use AI to classify cancellation or rescheduling intent. If we introduce that functionality later, we will assess its data-protection impact, update the relevant notices and agreements before use, and explain any meaningful consequences for individuals. We do not currently use solely automated processing to make decisions that produce legal or similarly significant effects about individuals.

International transfers

Some providers may process information outside the UK or European Economic Area. Where data-protection law requires a transfer safeguard, we use an applicable adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, and any additional safeguards required for the transfer. The applicable mechanism depends on the provider, locations, and our role in the processing, and will be confirmed before application launch.

Security

We use appropriate technical and organisational measures to protect personal information, including access controls, encryption in transit, and keeping systems patched and monitored. No system can be guaranteed completely secure, and we keep our measures under review.

Retention

We keep personal information only for as long as necessary for the purposes described above, to provide our services, and to meet legal, accounting, and regulatory obligations, after which it is deleted or anonymised. Data-deletion requests are handled as described on our data deletion page.

Your rights

Subject to the conditions and exemptions in applicable law, you have the right to:

  • be informed about how we use your information;
  • access a copy of your personal information;
  • have inaccurate information corrected;
  • have information erased in certain circumstances;
  • restrict or object to certain processing;
  • data portability; and
  • withdraw consent where processing relies on it.

To exercise any of these rights, contact us using the details below.

Complaints

If you have a concern about how we handle your personal information, please contact us first so we can try to resolve it. You may also complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk. If EU GDPR applies, you may complain to the supervisory authority in the EU country where you live, work, or believe an infringement took place. In Italy, this is the Garante per la protezione dei dati personali .

Contact us

Privacy enquiries: support@yamabushilabs.com

Yamabushi Labs Ltd is a company registered in England and Wales (company number 17341529).

Registered office: Flat F, 128 Reaston Street, London, England, SE14 5FW

Changes to this policy

We may update this policy from time to time. When we do, we will revise the effective date at the top of this page and, where changes are significant, take reasonable steps to bring them to your attention.