Legal
Privacy Policy
What data Resoclinx collects, why we collect it, how it is stored, and the rights you have over it.
Last updated 7 October 2026
Who we are
Resoclinx is the data controller for personal data collected through resoclinx.com and the Resoclinx platform. For all data requests contact contact@resoclinx.com.
What data we collect
From website visitors: only what you choose to give us, plus visit statistics if you accept cookies.
- Enquiry form on the advert page (/clinic-website-offer/): your first name, website, email and phone, plus the advert campaign tags in the link you arrived on. It is saved in our customer records system, GoHighLevel, so we can show you call times and follow up.
- Booking calendar (on /book-a-call/ and the advert page): your name, email, phone and any answers you give when you book. The calendar is run by GoHighLevel and the booking is stored there.
- Payment: when you pay, you leave this site for Stripe's own page. Stripe collects your name, email, billing address and card details. Card details go to Stripe only; we never see them.
- Onboarding survey (after you sign up): details about your business, services, opening hours, branding and logins you choose to share so we can build your site. It is a GoHighLevel form and the answers are stored there.
- The Tuesday email: your first name and email, if you sign up. Held by AWeber, our email service. Every email has an unsubscribe link.
- Emails and calls: whatever you send us.
- Visit statistics, only if you accept cookies: pages visited, how you arrived, rough location (town level), device and browser, through Google Analytics. See Cookies below.
From clients (paying customers): Business contact details, billing information, integration credentials (encrypted), team member logins, service lists, calendar data, and the enquiry data we process on your behalf as a data processor.
From your customers and patients (processed on your behalf): Name, contact details, enquiry content, call records, text messages sent through the follow-up system, and booking records.
Lawful basis for processing
- Contract performance for delivering the service to paying clients.
- Legitimate interest for replying to an enquiry you have made.
- Consent for analytics and advertising cookies (Google Analytics, and the Meta pixel on the advert page), for telling Meta about an enquiry or booking that came from an advert, for marketing emails, and for any optional data collection. You can withdraw it at any time.
- Data processor agreement with each client for processing their customers' data.
How long we store data
- Enquiries that do not become clients: 24 months from last contact, then deleted.
- Active client data: for the duration of the contract plus 6 months for billing reconciliation.
- Enquiry data processed on a client's behalf: per that client's retention policy, default 24 months.
- Call records: 12 months unless the client configures otherwise.
Third-party processors we use
- Cloudflare (UK, EU, US) for hosting and DDoS protection.
- Resend for transactional email delivery.
- Twilio for SMS and voice.
- Stripe for payment processing.
- GoHighLevel (HighLevel) for CRM and platform infrastructure.
- Google for Business Profile and review integration only, where the client has authorised it.
- Google Analytics (Google) to count visits, only if you accept cookies.
- Meta (Facebook and Instagram) to measure our adverts, only on the advert page and only if you accept cookies. If you then fill in the enquiry form or book a call, we also tell Meta that an enquiry or booking happened, with your email, phone and first name scrambled (hashed) first, so Meta can match it to the advert you saw. If you reject cookies, Meta is told nothing.
- AWeber for the Tuesday email.
- YouTube (Google) for the videos on /watch/ and /onboarding/, embedded in privacy-enhanced mode.
All processors are bound by data processing agreements and operate under appropriate safeguards for international transfers.
Your rights
Under GDPR you have the right to:
- Access the data we hold on you.
- Rectify inaccurate data.
- Erase data (subject to lawful retention requirements).
- Restrict or object to processing.
- Data portability.
- Withdraw consent at any time.
- Lodge a complaint with the UK ICO or your local supervisory authority.
To exercise any right, email contact@resoclinx.com. We respond within 30 days.
Cookies
Cookies are small files a website saves in your browser. On your first visit a banner asks whether you accept analytics and advertising cookies. Reject is as easy as Accept, and nothing beyond the strictly necessary is set until you choose. You can change your mind at any time with Cookie settings at the bottom of every page; if you switch from Accept to Reject, the page reloads and those cookies are deleted.
Always set (strictly necessary):
- rx_consent (Resoclinx): remembers whether you accepted or rejected, so the banner does not ask on every page. Kept for 6 months.
- On the advert page, the campaign tags in the link you arrived on are held in your browser for the visit only (session storage), so they reach us with the enquiry form if you send it. They are not sent anywhere unless you submit the form, and they are cleared when you close the tab.
Only if you accept:
- _ga and _ga_* (Google Analytics): tell one visit from another so we can count visitors and see which pages are useful. Kept for up to 2 years. We use Google Consent Mode, and Google Analytics is not loaded at all unless you accept.
- _fbp and _fbc (Meta pixel): only on the advert page, /clinic-website-offer/. They let Meta measure whether our Facebook and Instagram adverts led to an enquiry or a booking. Kept for 90 days. The pixel is not loaded at all unless you accept.
Set by other services when you use them:
- Booking calendar and onboarding survey (GoHighLevel, shown from links.resoclinx.com): may set cookies of their own that the calendar or form needs to work, and they load some third-party code of their own, including a Meta script library. We have checked that they set no Meta cookie and send Meta no visit or booking event. The calendar and the enquiry form work whether you accept or reject.
- Stripe: sets cookies on its own payment page for security and fraud prevention, under Stripe's privacy policy.
- YouTube: videos are embedded in privacy-enhanced mode (youtube-nocookie.com), which sets no cookies until you press play. Once you play a video, YouTube may store data in your browser under Google's privacy policy.
You can also block or delete cookies in your browser settings. We do not try to work around a browser's tracking protection.
Changes to this policy
We update this policy when our processing changes. Significant changes are notified by email to active clients. The last updated date at the top reflects the most recent revision.