Cookie Consent

Necessary cookies are always active. Analytics and performance cookies remain disabled until you grant consent.

GDPR Privacy Policy

Privacy Policy

Last updated: June 16, 2026

Data Controller

CreatoraWave AI / Clinical Workspace acts as data controller for account, usage, billing, and support data processed through the platform. Privacy requests: creatorflowai@gmail.com.

Clinical Workspace Patient Data Restriction

Clinical Workspace must not be used to submit personally identifiable patient information.

The platform is not intended to store, manage, or process identifiable patient records. Do not enter patient names, dates of birth, addresses, telephone numbers, email addresses, insurance numbers, medical record numbers, photographs, or other identifiable patient data.

Types of Data Collected

  • User account data, including name, email address, role, language, and workspace preferences.
  • Login and authentication information managed by the platform authentication service.
  • Usage analytics, feature usage, generated content metadata, and support communications.
  • IP addresses, device/browser information, security logs, and approximate location data.
  • Cookies and consent preferences, including necessary, analytics, and performance categories.
  • Billing/subscription metadata processed through Stripe; full payment card details are not stored by Clinical Workspace.

Purpose of Processing

  • Provide AI-powered healthcare communication tools.
  • Manage accounts, authentication, subscriptions, billing, support, and security.
  • Store user-generated anonymized materials and workspace settings.
  • Improve platform performance, reliability, and user experience where consent or legitimate interest applies.
  • Comply with legal obligations and enforce terms of service.

Legal Basis under GDPR

  • Contract performance for account access and service delivery.
  • Consent for optional marketing and non-essential cookies.
  • Legitimate interests for security, fraud prevention, service reliability, and limited operational analytics.
  • Legal obligation for billing, tax, accounting, and compliance records.

Data Retention

  • Account data: retained while the account is active and normally removed or anonymized within 90 days after deletion, unless legal retention applies.
  • Generated anonymized content: retained while the account is active or until deleted by the user.
  • Billing records: retained for up to 7 years where required for tax/accounting.
  • Security logs and analytics: typically retained for 12–24 months, then deleted or aggregated.
  • Cookie consent records: retained to evidence consent until replaced or no longer needed.

User Rights

Under GDPR, users may request access, correction, deletion, data portability, restriction of processing, objection to processing, and withdrawal of consent where processing is based on consent.

International Transfers and Processors

Where service providers process data outside the EEA, appropriate safeguards such as Standard Contractual Clauses, security controls, and processor agreements are used where required.

Contact

creatorflowai@gmail.com

Please include “Privacy Request” in the subject line.