Legal & GDPR
Last updated 21 June 2026
This Privacy Notice explains how Icletns uses personal data when it acts as a data controller. It also explains Icletns's separate role as a data processor when businesses use the platform to manage their own customer bookings.
Icletns is a software-as-a-service booking platform operated through https://iclients.co.uk. References to Icletns, we, us, or our mean the Icletns contracting entity identified in the applicable subscription order and website footer, where its registered name, company number, registered office, and jurisdiction of registration are provided.
Privacy enquiries and data subject requests may be sent to [email protected].
Icletns acts as an independent data controller for personal data used to:
The business using Icletns is normally the data controller for personal data relating to its customers, services, appointments, schedules, staff assignments, booking history, and business-directed booking communications. Icletns processes that data on the business's documented instructions as a data processor.
The business determines why customer booking data is collected, what information is required, how it is used, and how long it should be retained, subject to the platform's technical limits and the Data Processing Agreement.
End customers should first contact the business they booked with to exercise rights concerning booking data. Icletns will assist the business as required by the Data Processing Agreement.
Depending on how you use Icletns, we may collect:
Depending on the business's configuration, customer booking data may include:
Icletns does not use customer booking data to provide the underlying service, set prices, manage staff, decide availability, resolve appointment disputes, or market Icletns services directly to end customers.
The standard Icletns service is not designed for medical records, clinical notes, diagnoses, treatment histories, or other special-category health data. Businesses must not submit that information through general booking, customer, service, staff, or appointment fields.
Any future support for regulated health data would require separate written terms, documented compliance controls, and an updated privacy assessment before Processing begins.
We receive personal data:
Where we rely on legitimate interests, those interests include operating a secure and reliable SaaS service, supporting users, improving functionality, preventing misuse, and protecting our legal rights. We assess whether those interests are overridden by individuals' rights and freedoms.
Information marked as required is needed to create an account, enter into a subscription, secure the platform, or provide requested support. If required information is not provided, we may be unable to create an account, supply the subscription, process billing, or respond to the request.
Businesses decide what customer information is necessary for their booking process and must explain the consequences of not providing it in their own privacy notice.
We may share personal data with:
We do not sell personal data.
Icletns uses service providers for cloud infrastructure, storage, authentication, communications, file delivery, support, security, error monitoring, and subscription payment processing.
Current providers acting as Subprocessors for business-controlled Customer Personal Data are published in the Subprocessor List. Payment service providers may act as independent controllers for parts of their subscription payment services.
Providers may change as the Platform develops. Material changes affecting business-controlled customer data are handled under the Data Processing Agreement.
Personal data may be processed outside the United Kingdom or European Economic Area where a service provider or its infrastructure is located elsewhere.
Where required, Icletns will rely on an applicable adequacy regulation or decision, the UK International Data Transfer Agreement or UK Addendum, European Commission Standard Contractual Clauses, or another lawful transfer mechanism. Icletns will conduct transfer risk assessments where required and apply supplementary safeguards appropriate to the risk.
You may request further information about relevant safeguards by contacting [email protected].
Unless a longer period is required by law, needed for a dispute, or agreed with a business, Icletns applies the following controller-data retention periods:
Under the standard Platform configuration, appointment records are scheduled to expire approximately 90 days after the appointment date. The Platform is not intended to provide permanent customer-history storage. A different retention period applies only where supported by the Platform and documented in the Business's instructions or agreement with Icletns.
Following subscription termination, the business may request an export for at least 30 days as stated in the Partner Terms. Remaining customer data is then deleted from active systems within 60 days after the export period ends and from backups within a further 90 days, unless law requires otherwise.
Icletns uses technical and organisational measures appropriate to the nature and risk of the processing, including access controls, authentication, logging, data validation, secure communications, service-provider controls, and backup and incident-management procedures.
No system is completely secure. If Icletns becomes aware of a personal data breach affecting data processed for a business, Icletns will notify that business without undue delay and provide information reasonably required for the business to meet its legal obligations. Where Icletns is the controller, Icletns will notify regulators and affected individuals when required by law.
Service messages, such as account, security, billing, booking confirmation, cancellation, and reminder messages, are sent to operate the requested service and are not intended as direct marketing.
Marketing email or SMS will be sent only where permitted by applicable law. Marketing messages will identify the sender and provide a suitable opt-out. Business contacts may opt out of Icletns marketing at any time. Businesses are responsible for the legality and content of marketing they send to their own customers using or outside Icletns.
Depending on the processing and lawful basis, you may have rights to:
Your right to object: you may object to direct marketing at any time. You may also object to processing based on legitimate interests, although we may continue where compelling legitimate grounds or legal claims apply.
To exercise rights concerning Icletns controller data, email [email protected]. To exercise rights concerning a booking, contact the relevant business first.
You may complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/, telephone 0303 123 1113, or write to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
People in the EEA may also complain to the supervisory authority where they live, work, or believe an infringement occurred.
Icletns does not currently make decisions based solely on automated processing that produce legal or similarly significant effects on account users or end customers. If this changes, this notice will be updated before such processing begins.
Icletns business subscriptions are intended for adults acting for a business. A business may offer services to children where lawful, but the business is responsible for establishing an appropriate lawful basis, providing age-appropriate information, and obtaining parental authority where required.
We may update this notice to reflect changes in law, providers, or platform functionality. Material changes will be communicated where reasonably practicable. The date at the top identifies the latest version.