Legal
Privacy Policy
Last updated 10 September 2026
MedWoop is booking software for clinics, operated from Agadir, Morocco. It is used by two different groups of people, and this policy treats them separately: the clinics who hold an account, and the patients who book through a clinic's booking page or WhatsApp number.
For patient data, the clinic is the data controller and MedWoop is a processor acting on its instructions. For clinic account data, MedWoop is the controller.
What we collect from patients
Only what a booking needs. A patient never creates an account.
- Name and phone number, and an email address if one is given. The phone number is required: it is how a booking is confirmed and later found.
- Appointment details — the service chosen, the date and time, and the booking's status.
- Messages you send to the assistant, on the booking page or over WhatsApp, and its replies.
- A verification code sent to your phone, and a record of failed attempts, so a number cannot be guessed at repeatedly.
The service you book can imply something about your health. We treat that as sensitive: it is never used for advertising, never sold, and never shared beyond the clinic and the processors listed below.
The assistant, and what it sends elsewhere
The booking assistant is built on OpenAI's models. What you type is sent to OpenAI to generate a reply, along with the clinic's services, opening hours and any documents the clinic uploaded. Your name and phone number are sent when they are needed to make, move or cancel a booking.
OpenAI processes this on our behalf under its API terms and does not use it to train its models. The assistant will not answer medical questions and is instructed to refuse them; it is a booking tool, not a source of medical advice.
Where a clinic connects a WhatsApp number, messages to and from that number pass through Meta and are stored by us so the assistant can follow a conversation. Your WhatsApp number is treated as verified because Meta has already verified it — we do not send you a separate code. Meta's own handling of your messages is governed by its privacy policy, not this one.
When you book, we send appointment reminders to your phone on WhatsApp: 24 hours and 2 hours before your appointment, and one message 2 hours after it. Reply STOP to a reminder and we send no more.
What we collect from clinics
- Account details — name, email address, and a password stored only as a hash.
- Clinic details — name, timezone, opening hours, services and prices, a logo if uploaded, and any documents added to the knowledge base.
- WhatsApp credentials, where connected, so messages can be sent on the clinic's behalf.
Why we are allowed to hold it
- To perform a contract — making the booking you asked for, and providing the service a clinic pays for.
- Legitimate interests — keeping the service secure, preventing abuse of the verification system, and fixing faults.
- Consent — where you give it, and which you can withdraw at any time.
Who else sees it
We do not sell personal data and we do not share it for advertising. These are the only processors involved, and each sees only what its job requires:
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and file storage | United States / EU |
| OpenAI | Powers the booking assistant's replies | United States |
| Meta Platforms | Delivers WhatsApp messages, where a clinic uses it | United States |
| Resend | Sends appointment emails | United States |
| Vercel | Hosting | United States |
This means your data is transferred outside Morocco and outside the EEA. Those transfers rely on the processors' standard contractual clauses. We may also disclose data where the law requires it.
How long it is kept
- Appointments — kept while the clinic's account is active, because a clinic needs its own history. A cancelled appointment is marked cancelled, not deleted.
- Assistant conversations — kept so a conversation can continue where it left off.
- Verification codes — short-lived, and cleared once used or expired.
- Clinic accounts — deleted on request, along with the patient records held under them.
Cookies
We use no advertising or analytics cookies. The booking page sets one cookie, which records that a phone number has been verified so you are not asked for a code again for thirty days. Clinic accounts use a session cookie to stay signed in. Both are strictly necessary.
Security
Data is encrypted in transit. Every table is protected by row-level security so one clinic cannot read another's data, and the booking page reaches the database only through server-side code that scopes every query to a single clinic. Access to production data is limited to the people who maintain the service.
No system is perfectly secure, and we make no claim of certification under HIPAA, ISO 27001 or any similar standard.
Your rights
Under Morocco's Law 09-08 on the protection of individuals with regard to the processing of personal data — and under the GDPR where it applies to you — you may ask for a copy of your data, ask for it to be corrected or deleted, object to how it is used, or withdraw consent. Write to contact@medwoop.com and we will respond within 30 days.
If you booked with a clinic, that clinic holds your record and you may ask it directly. We will pass any request we receive to the clinic concerned. You also have the right to complain to the CNDP, Morocco's national data protection authority.
Children
MedWoop is not directed at children, and a booking is expected to be made by an adult — including where an adult books on a child's behalf. We do not knowingly collect data directly from children.
Changes
If this policy changes materially we will update the date at the top and, where the change affects clinics, tell them by email.
Contact
MedWoop, Agadir, Morocco — contact@medwoop.com · +212 659 858 123