Legal & GDPR

Privacy Notice

Last updated 21 June 2026

This Privacy Notice explains how Icletns uses personal data when it acts as a data controller. It also explains Icletns's separate role as a data processor when businesses use the platform to manage their own customer bookings.

1. Who We Are

Icletns is a software-as-a-service booking platform operated through https://iclients.co.uk. References to Icletns, we, us, or our mean the Icletns contracting entity identified in the applicable subscription order and website footer, where its registered name, company number, registered office, and jurisdiction of registration are provided.

Privacy enquiries and data subject requests may be sent to [email protected].

2. Our Data Protection Roles

2.1 Icletns as a Data Controller

Icletns acts as an independent data controller for personal data used to:

  • Create and administer business and staff accounts.
  • Authenticate users and manage access permissions.
  • Manage Icletns subscriptions and billing.
  • Provide support and respond to enquiries.
  • Secure, monitor, troubleshoot, and improve the platform.
  • Prevent fraud, misuse, and security incidents.
  • Establish, exercise, or defend legal claims.
  • Meet legal, regulatory, tax, and accounting obligations.
  • Send Icletns service notices and, where permitted, marketing communications.

2.2 Icletns as a Data Processor

The business using Icletns is normally the data controller for personal data relating to its customers, services, appointments, schedules, staff assignments, booking history, and business-directed booking communications. Icletns processes that data on the business's documented instructions as a data processor.

The business determines why customer booking data is collected, what information is required, how it is used, and how long it should be retained, subject to the platform's technical limits and the Data Processing Agreement.

End customers should first contact the business they booked with to exercise rights concerning booking data. Icletns will assist the business as required by the Data Processing Agreement.

3. Personal Data We Use as Controller

Depending on how you use Icletns, we may collect:

  • Identity and contact data: name, business name, role, email address, telephone number, postal address, and website.
  • Account and authentication data: user identifiers, login events, account status, permissions, authentication tokens, and password-related records maintained by the authentication service. Icletns does not store readable account passwords.
  • Subscription and billing data: subscription plan, billing status, invoices, payment references, billing contact details, and limited payment metadata supplied by the applicable third-party payment provider. Icletns does not store full payment card numbers or card security codes.
  • Support and communication data: enquiries, support requests, feedback, and correspondence.
  • Technical and usage data: IP address, device and browser information, timestamps, diagnostic events, security logs, and use of platform features.
  • Cookie and preference data: consent choices and information described in the Cookie Policy.
  • Fraud and compliance data: records used to investigate suspected misuse, protect accounts, comply with law, and enforce agreements.

4. Customer Booking Data Processed for Businesses

Depending on the business's configuration, customer booking data may include:

  • Customer name, email address, and telephone number.
  • Selected services, staff members, dates, and times.
  • Appointment status, history, and customer-provided booking information.
  • Booking confirmations, reminders, cancellations, and related communications.
  • Technical information required to operate and secure the booking form.

Icletns does not use customer booking data to provide the underlying service, set prices, manage staff, decide availability, resolve appointment disputes, or market Icletns services directly to end customers.

The standard Icletns service is not designed for medical records, clinical notes, diagnoses, treatment histories, or other special-category health data. Businesses must not submit that information through general booking, customer, service, staff, or appointment fields.

Any future support for regulated health data would require separate written terms, documented compliance controls, and an updated privacy assessment before Processing begins.

5. Sources of Personal Data

We receive personal data:

  • Directly from business owners, staff users, and people who contact us.
  • From businesses when they configure accounts, staff, schedules, and booking forms.
  • From end customers through business-controlled booking forms.
  • Automatically from devices, browsers, security systems, and platform logs.
  • From third-party payment providers in connection with Icletns subscription billing.
  • From service providers where necessary to operate, secure, and support the platform.

6. Purposes and Lawful Bases

  • Account creation and administration: contract and legitimate interests.
  • Authentication and account security: contract, legitimate interests, and legal obligation where applicable.
  • Subscription provision and billing: contract and legal obligation.
  • Third-party subscription-payment processing: contract and legal obligation.
  • Support and service communications: contract and legitimate interests.
  • Reliability monitoring, fault diagnosis, and platform improvement: legitimate interests.
  • Fraud, misuse, and security prevention: legitimate interests and legal obligation.
  • Tax, accounting, and legal records: legal obligation and legitimate interests.
  • Legal claims: legitimate interests and legal obligation.
  • Icletns marketing to business contacts: consent or legitimate interests, subject to applicable direct-marketing law.
  • Non-essential device storage or access: consent where required by PECR.

Where we rely on legitimate interests, those interests include operating a secure and reliable SaaS service, supporting users, improving functionality, preventing misuse, and protecting our legal rights. We assess whether those interests are overridden by individuals' rights and freedoms.

7. Required Information

Information marked as required is needed to create an account, enter into a subscription, secure the platform, or provide requested support. If required information is not provided, we may be unable to create an account, supply the subscription, process billing, or respond to the request.

Businesses decide what customer information is necessary for their booking process and must explain the consequences of not providing it in their own privacy notice.

8. Sharing Personal Data

We may share personal data with:

  • The relevant business and its authorised staff.
  • Hosting, database, storage, authentication, communications, support, security, and error-monitoring providers.
  • Third-party payment providers for Icletns subscription billing.
  • Professional advisers, auditors, insurers, and prospective purchasers subject to appropriate confidentiality protections.
  • Courts, regulators, law-enforcement bodies, and public authorities where required or permitted by law.

We do not sell personal data.

9. Subprocessors and Service Providers

Icletns uses service providers for cloud infrastructure, storage, authentication, communications, file delivery, support, security, error monitoring, and subscription payment processing.

Current providers acting as Subprocessors for business-controlled Customer Personal Data are published in the Subprocessor List. Payment service providers may act as independent controllers for parts of their subscription payment services.

Providers may change as the Platform develops. Material changes affecting business-controlled customer data are handled under the Data Processing Agreement.

10. International Transfers

Personal data may be processed outside the United Kingdom or European Economic Area where a service provider or its infrastructure is located elsewhere.

Where required, Icletns will rely on an applicable adequacy regulation or decision, the UK International Data Transfer Agreement or UK Addendum, European Commission Standard Contractual Clauses, or another lawful transfer mechanism. Icletns will conduct transfer risk assessments where required and apply supplementary safeguards appropriate to the risk.

You may request further information about relevant safeguards by contacting [email protected].

11. Retention

Unless a longer period is required by law, needed for a dispute, or agreed with a business, Icletns applies the following controller-data retention periods:

  • Business account and profile data: the Subscription term, then up to 90 days for operational deletion.
  • Subscription, invoice, tax, and payment-reference records: up to 6 years after the relevant financial year or transaction.
  • Authentication and access records: the account term, with inactive records deleted or anonymised within 90 days unless security retention is required.
  • Security, fraud, and diagnostic logs: normally up to 12 months, or longer where an incident or legal claim requires it.
  • Support requests and ordinary correspondence: up to 3 years after closure.
  • Marketing preferences and suppression records: while marketing continues and afterwards as needed to respect an objection.
  • Cookie-consent records: up to 3 years after the preference is replaced or withdrawn.
  • Legal dispute records: until the claim and applicable limitation periods have ended.

Under the standard Platform configuration, appointment records are scheduled to expire approximately 90 days after the appointment date. The Platform is not intended to provide permanent customer-history storage. A different retention period applies only where supported by the Platform and documented in the Business's instructions or agreement with Icletns.

Following subscription termination, the business may request an export for at least 30 days as stated in the Partner Terms. Remaining customer data is then deleted from active systems within 60 days after the export period ends and from backups within a further 90 days, unless law requires otherwise.

12. Security and Personal Data Breaches

Icletns uses technical and organisational measures appropriate to the nature and risk of the processing, including access controls, authentication, logging, data validation, secure communications, service-provider controls, and backup and incident-management procedures.

No system is completely secure. If Icletns becomes aware of a personal data breach affecting data processed for a business, Icletns will notify that business without undue delay and provide information reasonably required for the business to meet its legal obligations. Where Icletns is the controller, Icletns will notify regulators and affected individuals when required by law.

13. Communications

Service messages, such as account, security, billing, booking confirmation, cancellation, and reminder messages, are sent to operate the requested service and are not intended as direct marketing.

Marketing email or SMS will be sent only where permitted by applicable law. Marketing messages will identify the sender and provide a suitable opt-out. Business contacts may opt out of Icletns marketing at any time. Businesses are responsible for the legality and content of marketing they send to their own customers using or outside Icletns.

14. Your Rights

Depending on the processing and lawful basis, you may have rights to:

  • Access personal data.
  • Correct inaccurate personal data.
  • Request deletion.
  • Restrict processing.
  • Receive portable data.
  • Object to processing based on legitimate interests.
  • Object at any time to direct marketing.
  • Withdraw consent at any time where processing relies on consent.
  • Complain to a supervisory authority.

Your right to object: you may object to direct marketing at any time. You may also object to processing based on legitimate interests, although we may continue where compelling legitimate grounds or legal claims apply.

To exercise rights concerning Icletns controller data, email [email protected]. To exercise rights concerning a booking, contact the relevant business first.

You may complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/, telephone 0303 123 1113, or write to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

People in the EEA may also complain to the supervisory authority where they live, work, or believe an infringement occurred.

15. Automated Decision-Making

Icletns does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on account users or end customers. If this changes, this notice will be updated before such processing begins.

16. Children

Icletns business subscriptions are intended for adults acting for a business. A business may offer services to children where lawful, but the business is responsible for establishing an appropriate lawful basis, providing age-appropriate information, and obtaining parental authority where required.

17. Changes to This Notice

We may update this notice to reflect changes in law, providers, or platform functionality. Material changes will be communicated where reasonably practicable. The date at the top identifies the latest version.

© 2026 IClients Limited. All rights reserved.