Skip to content
Wakten
How it works Features See it live Who it's for
🇬🇧EN
🇬🇧 English 🇮🇹 Italiano 🇫🇷 Français
Request a demo
Overview Terms of Service Privacy Policy Data Processing Agreement Sub-processors Cookie Policy

Legal

Privacy Policy

Last updated: 8 October 2026

1. About this policy

Wakten is an online booking and patient-management platform for clinics, doctors, dentists, wellness centres and other health and care professionals. This Privacy Policy explains how WAKTEN LTD ("Wakten", "we", "us", "our") collects and uses personal data when you:

  • visit our website, wakten.com;

  • use the Wakten app as a clinic owner, administrator or member of staff;

  • book an appointment through a clinic's Wakten booking page;

  • receive our marketing; or

  • contact us by email or otherwise.

We process personal data in line with the UK General Data Protection Regulation ("UK GDPR"), the UK Data Protection Act 2018 and, where it applies to us, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR"). In this policy, "GDPR" means whichever of the two applies to you.

2. Who we are and how to contact us

Company WAKTEN LTD
Registered in England and Wales, company number 17501914
Registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
ICO registration number ZC268879 (UK data protection register)
Privacy contact contact@wakten.com

We are not required to appoint a Data Protection Officer. Please send any question about this policy or about how we use your personal data to contact@wakten.com.

3. Our representative in the European Union

Wakten is established in the United Kingdom. Because we offer our services to people in the European Union, we have appointed a representative in the EU under Article 27 of the EU GDPR. If you are in the EU, you, or an EU data protection authority, may contact our representative instead of, or as well as, contacting us directly:

EU representative Fatine Benhammou
Address Via Marzabotto 40, 20099 Sesto San Giovanni (MI), Italy
Email eu-rep@wakten.com

4. Our two roles: controller and processor

Wakten handles personal data in two different capacities, and your rights are exercised differently in each.

4.1 Where Wakten is the controller

We decide how and why personal data is used, and we are responsible for it, for:

  • our customers (clinics and other businesses) and the people who run them;

  • the staff accounts created for our customers' employees and practitioners;

  • visitors to our website; and

  • anyone who contacts us, including prospective customers.

Sections 5 to 15 of this policy describe this processing.

4.2 Where Wakten is a processor for a clinic

When a clinic uses Wakten to manage its patients and appointments, the clinic is the controller of its patients' personal data and Wakten acts as its processor. We process that data only on the clinic's documented instructions, under a data processing agreement that meets Article 28 of the GDPR. We do not use patient data for our own purposes.

If you are a patient, the clinic's own privacy notice explains how it uses your data, and the clinic is the right place to send requests about your data (for example, to see or correct it). If you contact us, we will pass your request to the clinic and help it respond. Section 6 summarises the patient data we process on clinics' behalf.

5. Personal data we collect as controller

Category What it includes Where it comes from
Account data First and last name, email address, password (we only store a secure hash, never the password itself), preferred language, role and permissions, the clinic location(s) you work at You, or the administrator of your clinic who invited you
Google sign-in data If you choose to sign in with Google: your Google account identifier, name and email address Google
Practitioner data For doctors and other practitioners: working hours, days off, the services you offer and on which days You or your clinic
Activity and audit data Records of actions taken in the app, such as appointments created or changed, changes to roles and permissions, access to clinical notes, failed sign-in attempts and account lockouts Generated by the app when you use it
Business and billing data Business name, address and phone number, contact person, billing details and invoices You
Communications Emails, messages and support requests you send us and our replies You
Marketing data Name, job title, business name and contact details of clinics and professionals, and your marketing preferences You, events, public professional sources and social networks
Technical data IP address, browser type, device information and server log data Collected automatically when you use the app or website

We do not ask our customers or their staff for special category data (such as health information) about themselves.

6. Patient data we process for clinics

As a processor (see section 4.2), we store and process the following on behalf of the clinics that use Wakten:

  • Identity and contact details: first and last name, date of birth, phone number, email address, postal address and preferred language;

  • Appointment details: date and time, practitioner, service, price, status (for example booked, cancelled, attended or missed) and the channel the booking came from;

  • Notes: notes added by clinic staff and, where the clinic uses the feature, clinical notes written by practitioners.

Because appointments with health professionals and clinical notes can reveal information about a person's health, some of this data may be special category data under Article 9 of the GDPR. The clinic is responsible for having a lawful basis for it. We protect it with additional safeguards: clinical notes are visible only to the practitioner who wrote them, and every access to them is logged.

When a patient books through a booking page, we send emails on the clinic's behalf to confirm, update or cancel the appointment.

We never use patient data for our own marketing or advertising.

7. Why we use your data and our legal basis

We only use personal data where the GDPR gives us a lawful basis to do so.

Purpose Data used Legal basis
Providing the Wakten service: creating and managing accounts, signing you in, running the features your clinic subscribes to Account, Google sign-in, practitioner data Performance of our contract with our customer (Art. 6(1)(b)). For staff who are not themselves party to the contract: our and our customer's legitimate interests in providing the service the customer has subscribed to (Art. 6(1)(f))
Sending service emails, such as invitations, password resets and account notifications Account data Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Keeping the platform and the data on it secure: sign-in protection, rate limiting, account lockout, audit logs, detecting misuse Activity, audit and technical data Legitimate interests in protecting our customers, their patients and our platform (Art. 6(1)(f)), and our legal obligation to keep data secure (Art. 6(1)(c), Art. 32)
Customer support Communications, account data Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Billing, accounting and tax Business and billing data Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Improving and developing Wakten using aggregated usage information Activity and technical data Legitimate interests in improving our service (Art. 6(1)(f))
Marketing Wakten to clinics and health professionals: newsletters, offers, product news, event invitations and messages on social media Marketing data Legitimate interests in promoting our business to professional contacts (Art. 6(1)(f)), or your consent where the law requires it (Art. 6(1)(a)). You can opt out at any time
Meeting legal requirements and establishing, exercising or defending legal claims Any relevant data Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can ask us for more information about this balancing, and you can object at any time (see section 12).

8. Who we share personal data with

We do not sell personal data. We share it only with:

  • Service providers who process data for us, under contracts that require them to protect it and use it only on our instructions. These include providers of hosting and infrastructure, email delivery, sign-in services (such as Google, if you choose to sign in with it), customer support and communication tools, and email marketing and customer relationship management tools;

  • Other users of your clinic's account: staff at your clinic or business can see your name, role and work information, as allowed by the permissions your clinic sets;

  • Professional advisers, such as accountants, auditors and lawyers;

  • Authorities, courts and regulators, where the law requires it or to protect our rights;

  • A buyer or investor, if Wakten is involved in a merger, acquisition or sale of assets, under confidentiality terms.

An up-to-date list of the service providers (sub-processors) that process data on behalf of our customers is published on our Sub-processors page.

9. Where your data is stored and international transfers

We host the Wakten app and database in the European Union.

Some of our service providers, and members of our team who access the platform remotely to provide support and maintain the service, may be located outside the United Kingdom and the European Economic Area. This means personal data may be accessed or processed in other countries, whose data protection laws may differ from those in the UK and EU.

Where personal data is transferred to a country that is not recognised as providing an adequate level of protection (by the European Commission or, for the UK, by the UK Government), we protect it with appropriate safeguards, such as standard contractual clauses approved by the European Commission or the UK authorities, or recognised certification frameworks. You can ask us for more information about these safeguards, or a copy of them, by writing to contact@wakten.com.

10. How long we keep personal data

We keep personal data only for as long as we need it for the purposes described in this policy. To decide how long that is, we consider the purpose we hold it for, the amount, nature and sensitivity of the data, the risk of harm from unauthorised use or disclosure, whether we can achieve the purpose in other ways, and our legal, accounting and reporting obligations. In practice:

Data How long
Account data While the account is active, and for a limited period after it is closed or our contract with your clinic ends, to deal with any remaining questions. It is then deleted or anonymised
Patient data processed for clinics As instructed by the clinic. When the contract ends, we return it to the clinic or delete it, as set out in our agreement with the clinic
Activity and audit logs As long as needed to keep the platform secure, investigate incidents and show who accessed or changed data. Audit entries about a clinic's patients are deleted together with that clinic's data
Server and security logs For a short period, as needed to detect and investigate security issues
Marketing data Until you unsubscribe or object, or until you have not engaged with us for an extended period
Cookies and browser storage As set out in section 14 and our Cookie Policy
Support communications As long as needed to handle your request and any follow-up, and to keep a record of the service we provided
Billing and accounting records 6 years after the end of the financial year they relate to, as required by UK law
Backups Overwritten in our normal backup cycle

We may keep data for longer where we need it to resolve a dispute, establish or defend legal claims, or comply with the law.

11. How we protect personal data

We use technical and organisational measures appropriate to the sensitivity of the data, including:

  • encryption of data in transit (HTTPS/TLS), including between our application and our database;

  • passwords stored only as secure hashes, and short-lived sign-in tokens that are not stored in the browser's local storage;

  • role-based permissions, so staff see only what their role allows;

  • separation of each clinic's data from other clinics' data;

  • audit logs of sensitive actions, including every access to clinical notes;

  • protection against password guessing through rate limiting and account lockout; and

  • access to production systems limited to authorised Wakten personnel bound by confidentiality.

However, no method of transmitting or storing data over the internet is completely secure, so we cannot guarantee absolute security. If you believe your account or your data is no longer secure, please contact us immediately at contact@wakten.com.

12. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;

  • rectification of data that is inaccurate or incomplete;

  • erasure of your data in certain circumstances;

  • restrict how we use your data in certain circumstances;

  • data portability: receive data you gave us in a structured, machine-readable format, or have it sent to another organisation;

  • object to processing based on our legitimate interests, and to object at any time to direct marketing, including any profiling related to it;

  • withdraw consent at any time, where we rely on consent (for example for marketing where the law requires it), without affecting processing that took place before; and

  • not be subject to a decision based solely on automated processing that significantly affects you. Wakten does not make such decisions.

You can unsubscribe from marketing emails using the link in each email.

To exercise any of your other rights, email contact@wakten.com (or our EU representative, if you are in the EU). We will respond within one month. For complex requests this can be extended by up to two further months, and we will tell you if so. Exercising your rights is free. We may ask you to confirm your identity before we act on a request.

If your request concerns patient data that we process for a clinic, we will forward it to that clinic, as the clinic is the controller (see section 4.2).

13. Complaints

We would appreciate the chance to address your concerns first, so please contact us at contact@wakten.com. You also have the right to complain to a data protection supervisory authority:

  • United Kingdom: the Information Commissioner's Office (ICO), ico.org.uk, telephone 0303 123 1113.

  • European Union: the supervisory authority in the EU country where you live, work or where the alleged infringement took place. In Italy, this is the Garante per la protezione dei dati personali (garanteprivacy.it); in France, it is the Commission nationale de l'informatique et des libertés (CNIL, cnil.fr). A list of all EU authorities is available at edpb.europa.eu.

14. Cookies and similar technologies

We only use cookies and similar technologies, such as browser storage, that are strictly necessary for our website and app to work or to provide a feature you ask for. These do not require your consent:

Name Purpose Duration
refresh_token (cookie, app) Keeps staff securely signed in to the app Up to 30 days
NEXT_LOCALE (cookie, app) Remembers your chosen language, if you change it Session only: deleted when you close your browser
Google sign-in cookies (app) Temporary security cookies used during Google sign-in Deleted when sign-in completes
wakten-theme (browser storage, website) Remembers whether you chose the light or dark theme, if you change it Until you clear your browser storage

We do not use analytics or advertising cookies, and our emails do not contain tracking pixels. If we decide to use them in the future, we will update this policy and our Cookie Policy, and we will ask for your consent before using them.

15. Children

Wakten is a service for businesses and is not directed at children. Wakten staff accounts are only for people aged 18 or over. We do not knowingly collect personal data from children for our own purposes, and if we learn that we have, we will delete it.

Appointments for children are made by a parent or guardian through the clinic, and the clinic is responsible for that data as controller.

16. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top shows when it was last changed. If we make significant changes, we will tell our customers and users by email or in the app before the changes take effect.

17. Contact us

WAKTEN LTD, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Email: contact@wakten.com.

EU representative: Fatine Benhammou, Via Marzabotto 40, 20099 Sesto San Giovanni (MI), Italy, eu-rep@wakten.com.

Wakten © 2026 WAKTEN LTD
Legal Privacy Policy Terms of Service Cookie Policy Contact