Legal
Privacy Policy
Effective [date]
Read this first: there are two different relationships in this policy.When a practice signs up for Unclutter Desk, we are thedata controller for that practice's own account information. When a practice uses Unclutter Desk to hold information aboutits clients — bookings, intake forms, assessment scores, clinical notes — the practice is the data controller and Unclutter Desk is only the data processor. We act on the practice's instructions and do not use client health information for our own purposes.
If you are a therapy client, the practice you booked with is responsible for your records. Contact them first; we will support them in responding.
1. Who we are
Unclutter Desk is practice-management and booking software for therapists and clinics, operated by EDGD Media Digital Solutions Ltd (RC 1721185) of 19 Yesufu Sanusi, off Adeniran Ogunsanya, Lagos, Nigeria.
This policy is governed by the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR). Where a practice or client is in the United Kingdom or European Economic Area, we also apply UK GDPR / EU GDPR standards to that data.
Data protection contact: privacy@unclutterdesk.com.
2. Data we handle
Practice and staff accounts (we are the controller)
| Category | Fields |
|---|---|
| Identity and contact | Email address, username, first and last name, phone number, gender, date of birth, profile photo |
| Credentials | Password, stored only as a bcrypt hash. We never store or can retrieve your plain password. We also record failed login attempts and lockout times to detect attacks. |
| Practice profile | Practice name, booking subdomain, custom domain, logo and brand colours, public email and phone, city, address, category, cancellation policy |
| Billing | Subscription tier, payment references, and payout bank subaccount details. Card details are handled by our payment processors and never reach our servers. |
Client and clinical data (the practice is the controller)
| Category | Fields |
|---|---|
| Client profile | Name, email, phone, gender, date of birth |
| Bookings | Service booked, appointment time, status, payment reference, payment date, booking notes, video room identifier |
| Intake and assessments | Responses to intake and consent forms, and responses and scores for standardised assessments including PHQ-9 and GAD-7 |
| Clinical records | SOAP notes — subjective, objective, assessment and plan — plus any diagnosis code recorded by the treating therapist |
| Reviews | Testimonials a client submits after a completed session. These are only shown publicly if the practice chooses to publish them. |
| Notifications | In-app notifications, a log of emails sent, notification preferences, and browser push subscriptions where enabled |
Intake responses, assessment scores and clinical notes aresensitive personal data concerning health. We handle them only to provide the service to the practice.
Technical data
We process IP addresses and request metadata to apply rate limits, block abuse and keep the service available. We do not use this to build profiles of individuals.
3. How we use it, and our legal bases
- To provide the service — creating accounts, publishing booking pages, taking bookings, sending confirmations and reminders, generating session links, storing notes and assessments. Basis: performance of a contract, and the practice's instructions where we act as processor.
- To take payments and pay practices out — via our payment processors. Basis: performance of a contract.
- To keep the service secure — authentication, rate limiting, abuse detection, backups. Basis: legitimate interests.
- To support you — responding to enquiries and troubleshooting, which may require accessing an account. Basis: legitimate interests, and contract.
- To meet legal obligations — retaining financial records, responding to lawful requests. Basis: legal obligation.
We do not sell personal data. We do not use client health information to train machine-learning models. We do not serve advertising.
4. Cookies
Unclutter Desk sets three cookies, all strictly necessary to keep you signed in safely. We set no advertising, analytics or tracking cookies, and we run no third-party analytics on our marketing site or in the application.
| Cookie | Purpose | Lifetime |
|---|---|---|
unclutter_access | Keeps you signed in. Not readable by JavaScript. | 15 minutes |
unclutter_refresh | Renews your session without re-entering your password. Not readable by JavaScript. | 30 days |
unclutter_csrf | Protects against cross-site request forgery. | 30 days |
5. Sub-processors
We use the following providers to deliver the service. Each receives only the data needed for its function.
| Provider | Function | Data shared |
|---|---|---|
| Paystack | Client payments, practice subscriptions and bank payouts | Name, email, amount, booking and subscription references |
| Cloudflare | Hosting of the website and application, CDN, DDoS protection | IP address and request metadata |
| Contabo (Germany) | Application server and database hosting | All data described above |
| Google (Calendar & Meet) | Calendar sync and meeting links, only if a therapist connects their Google account | Appointment time, title and attendee email addresses |
| Google (Gmail SMTP) | Sending transactional email | Recipient email address and message content |
| Jitsi Meet (8x8) | Default video sessions — see section 6 | Room identifier; audio and video pass through their infrastructure |
| Daily.co | Optional branded video rooms, where a practice enables it | Room identifier and session metadata |
| Termii | SMS notifications, where enabled | Phone number and message content |
We will update this list before adding a new sub-processor that handles personal data.
6. Video sessions
By default, session links use Jitsi Meet at meet.jit.si, a free public service operated by 8x8. Sessions are not recorded by Unclutter Desk, and we never receive session audio or video — but the call itself runs on infrastructure we do not control, under8x8's terms.
Practices should tell clients which video service they use and satisfy themselves that it is appropriate for clinical sessions. A practice that needs a dedicated provider can configure Daily.co or use Google Meet instead.
7. Storage, location and retention
Data is stored in a PostgreSQL database hosted on Contabo infrastructure in Germany. Traffic between your browser and our servers is encrypted with TLS. Clinical notes are encrypted by the application before they reach the database: the narrative fields of a note are sealed with AES-256-GCM, so they cannot be read by anyone holding the disk, a backup file, or a database connection. Backups are encrypted with AES-256 before they leave the server. The database volume itself is not encrypted at rest, which is precisely why we encrypt the clinical fields in the application rather than relying on the volume.
Because our servers are in Germany, personal data — including clinical records — leaves Nigeria and is stored in the European Union. The NDPA allows this where the destination country offers adequate protection or another lawful basis applies.[Confirm with counsel which NDPA transfer basis applies, and name it here.]
We take a backup every night, keep it for 14 days on the server, and keep an encrypted copy off-site for 90 days.
We retain data for as long as the practice's account is active.Because a practice is the controller of its clients' records, it decides how long to keep them, subject to the record-retention rules of its profession and regulator. Clinical records generally must be kept for a defined minimum period, so a request to delete a clinical note may lawfully be refused by the practice.
A practice can erase a client's personal data from within the application. Doing so removes the client's name, email address, phone number, gender, date of birth and profile photo, deletes their login and all active sessions, removes notifications, email logs and push subscriptions, and clears free-text booking notes.
Clinical notes and assessment submissions are not deleted by that action, and neither are bookings and payment references. Clinical records carry professional retention obligations that outlast an erasure request, and payment records are kept to meet financial-reporting duties. What changes is that those records are no longer linked to an identifiable person.
A practice can also close its account entirely. Closing it deactivates the practice immediately and ends every session, but deletes nothing at first: the records are kept for 30 days so the practice can export anything it is professionally required to retain. After that window we permanently erase the practice and everything belonging to it — staff and client profiles, bookings, forms, assessment submissions and clinical notes.
A login used at more than one practice survives that erasure, because deleting it would remove the person's access to practices that are still open.
8. How we protect data
- All traffic is served over HTTPS.
- Passwords are stored as bcrypt hashes; we cannot read them.
- Session tokens are held in cookies that JavaScript cannot read, with separate cross-site request forgery protection.
- Each practice's data is isolated by tenant, and every request is scoped to the tenant of the signed-in user rather than to anything the browser supplies.
- Repeated failed logins trigger lockout, and the API applies rate limits.
- Access to production systems is limited to staff who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify the practice, and the Nigeria Data Protection Commission, as required by the NDPA.
9. Your rights
Under the NDPA — and the GDPR where it applies — you may ask to:
- access a copy of your personal data;
- correct data that is wrong or incomplete;
- delete data, where no legal or professional duty requires it to be kept;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent, where processing relies on consent;
- complain to the Nigeria Data Protection Commission.
If you are a therapy client, contact your practice — they hold your records and decide these requests. If you contact us directly, we will pass your request to the practice and help them respond.
If you are a practice or a member of practice staff, email privacy@unclutterdesk.com. We respond within 30 days.
10. Children
Accounts on Unclutter Desk are for adults. A practice may treat clients under 18 and record their information; where it does, the practice is responsible for obtaining consent from a parent or guardian as its professional and legal obligations require.
11. Changes and contact
We will post any change to this policy on this page and update the effective date. If a change materially affects how we handle personal data, we will notify practice account owners by email.
Questions: privacy@unclutterdesk.com · 19 Yesufu Sanusi, off Adeniran Ogunsanya, Lagos, Nigeria.