Meta Developer Platform & WhatsApp Business Cloud API Compliant• GDPR & CCPA Aligned Data Protection
Back to DoclyDocly
Doctor Sign In
Privacy PolicyTerms of ServiceUser Data Deletion
Official Policy Document•Effective: January 15, 2026•Last Updated: September 11, 2026

Privacy Policy

Docly is committed to protecting the privacy, confidentiality, and security of healthcare providers and patients who interact with our AI-powered WhatsApp booking assistant.

Meta Developer Platform & WhatsApp Business Cloud API Notice

This policy explicitly complies with the Meta Developer Platform Terms and WhatsApp Business Messaging Policy. Docly uses official Meta WhatsApp Cloud API webhooks solely to coordinate appointments between doctors and their patients. We do not sell user data, nor do we use private messaging data for marketing, profiling, or public AI model training.

1. Overview & Introduction

Docly (“Docly,” “we,” “our,” or “us”) operates a specialized multi-tenant software-as-a-service (SaaS) platform allowing registered medical doctors and healthcare practices (“Practitioners”) to connect their official WhatsApp Business phone number to an automated, AI-assisted appointment management assistant.

This Privacy Policy explains how we collect, store, process, and protect information when:

  • Practitioners register for, configure, and use the Docly administrative dashboard.
  • Practitioners authorize Meta WhatsApp Cloud API and Google Calendar integrations.
  • Patients and end-users (“Patients”) send WhatsApp messages to a Practitioner's connected WhatsApp Business number to inquire about clinic timings, book slots, reschedule, or cancel consultations.

2. Data Controller & Contact Information

Depending on your relationship with Docly:

For Practitioners (Doctors):

Docly acts as the Data Controller regarding your account registration, billing data, profile settings, and dashboard configuration.

For Patients (End-Users on WhatsApp):

The Practitioner or clinic whose WhatsApp Business number you are messaging acts as the Data Controller. Docly acts as a secure Data Processor handling messages solely according to the Practitioner's instructions.

If you have questions or wish to exercise data rights, contact our Data Protection Officer at: privacy@docly.health

3. Information We Collect

We only collect information strictly required to facilitate appointment coordination and ensure system reliability:

A. Information Received via Meta WhatsApp Cloud API

  • WhatsApp Phone Number & WhatsApp ID: Unique phone number of the patient initiating the conversation.
  • WhatsApp Profile Name: The public display name configured on the user's WhatsApp account.
  • Inbound Message Content: Text strings sent to request booking dates, available hours, service inquiries, or cancellations.
  • Message Metadata: Message delivery timestamps, message IDs (wamid), read receipts, and webhook delivery status.

B. Information Collected from Practitioners

  • Account Details: Full name, medical clinic/practice name, email address, password hash, phone number, and clinical specialty.
  • Practice Availability & Services: Weekly working hours, appointment durations, consultation fees, buffer times, and clinic address.
  • Integration Credentials: WhatsApp Business Phone Number ID, WhatsApp Business Account ID (WABA ID), and OAuth tokens for Google Calendar synchronization.

C. Appointment & Booking Records

  • Scheduled Consultations: Patient name, chosen clinic service, appointment start/end time, status (Confirmed, Rescheduled, Cancelled, Completed).
  • Patient Administrative Notes: Any specific non-clinical notes provided during booking (e.g., “first-time consultation”).

4. How We Use Collected Information

We use collected data solely for the following explicit purposes:

1. Automated Appointment Scheduling

Parsing patient scheduling requests in WhatsApp, checking doctor availability, reserving calendar slots, and confirming bookings.

2. Real-Time Calendar Sync

Syncing confirmed, updated, or canceled appointments directly into the doctor's authorized Google Calendar to prevent double-booking.

3. Automated Reminders & Notices

Sending automated WhatsApp appointment reminders (e.g., 24 hours and 2 hours prior) to minimize clinic no-shows.

4. Security, Audit & Fail-Closed Verification

Verifying Meta HMAC-SHA256 webhook signatures and ensuring strict tenant isolation so data never leaks between different doctors.

5. Artificial Intelligence & Large Language Model (LLM) Processing

Strict Commercial API Zero-Data-Retention Commitment

Docly utilizes enterprise-grade AI models (such as OpenAI GPT-4o API) solely to understand natural language booking inquiries (e.g. “Can I book Dr. Smith for Thursday 4pm?”) and generate polite responses.

  • No Public Model Training: Under our enterprise API agreements, your inputs, messages, and outputs are never used by OpenAI or any third party to train or fine-tune public foundational models.
  • Ephemeral Processing: Inquiries sent to the AI API are processed ephemerally solely for the purpose of answering the immediate scheduling inquiry.
  • Deterministic Safeguards: Real-time booking decisions, slot availability, and doctor credentials are strictly controlled and verified by our backend server database, not by unsupervised AI.

6. Third-Party Service Providers & Data Processors

We share data with trusted third-party subprocessors strictly to operate our platform infrastructure:

ProviderPurposeData SharedPrivacy Link
Meta Platforms, Inc.WhatsApp Business Cloud API messaging & webhooksWhatsApp phone numbers, message payloads, statusMeta Terms
OpenAI, LLCNatural language intent extraction & response generationMessage text of appointment inquiry (API zero-retention)OpenAI Enterprise
Google LLCGoogle Calendar API event synchronizationAppointment times, summary title, patient identifierGoogle Privacy
Secure Cloud InfrastructureEncrypted PostgreSQL database, Redis queues & hostingEncrypted application databases and audit trailsSOC2 / ISO27001

7. Data Retention & Storage

We adhere to strict data minimization principles:

  • Appointment Records: Maintained for the duration of the Practitioner's active account subscription to allow appointment tracking and historical clinic reporting, or until deleted upon request.
  • WhatsApp Message Transcripts: Stored securely to provide conversation context during active scheduling dialogues. Transcripts are purged in accordance with clinic retention policies or within 30 days of an approved data deletion request.
  • Account Termination: If a doctor closes their Docly account, all associated clinic data, WhatsApp webhook bindings, and calendar integration tokens are permanently eradicated from active databases within 30 days.

8. Your Rights & How to Exercise Them (GDPR & CCPA)

Under data protection laws and Meta developer guidelines, you have guaranteed rights regarding your personal data:

Right to Access & Portability:You can request a copy of the personal data held about you in a standard, machine-readable format.
Right to Rectification:You can request correction of inaccurate or incomplete contact or scheduling information.
Right to Erasure (“Right to be Forgotten”):You may request complete deletion of your phone number, message history, and appointment records.
Right to Withdraw Consent:You may withdraw consent to receive WhatsApp notifications at any time by replying “STOP”.
Need to delete your data immediately?

Follow our Meta-compliant instructions or submit an instant deletion ticket.

Go to Data Deletion Page

9. Technical & Operational Security Measures

We implement rigorous defense-in-depth technical safeguards to secure customer data:

  • HMAC-SHA256 Webhook Verification: Every incoming Meta WhatsApp webhook is cryptographically validated against our Meta App Secret. Unsigned or invalid requests are instantly rejected.
  • Fail-Closed Tenant Isolation: Every database query is strictly scoped to the verified doctor_id associated with the destination WhatsApp phone number. Cross-tenant queries are structurally disallowed by architecture.
  • Encryption: All data in transit is encrypted using TLS 1.3. Sensitive tokens (Google OAuth refresh tokens, WhatsApp access tokens) and database volumes are encrypted at rest using AES-256.
  • Authentication & JWT Rotation: Secure short-lived JSON Web Tokens (15-minute access tokens) with rotating refresh tokens for dashboard practitioners.

10. Children's Privacy

Docly is intended for use by certified healthcare practitioners and adult patients. We do not knowingly solicit or collect personal information directly from children under the age of 13 (or under 16 in the European Union) without parental or guardian consent. When appointments are booked for pediatric patients, the booking must be conducted by the parent or legal guardian.

11. Contact & Regulatory Inquiries

For privacy inquiries, Data Protection Officer contact, or compliance verification by Meta App Review teams:

Docly Platform Privacy Office
Email: privacy@docly.health
Technical Support: support@docly.health
Response SLA: All privacy and data deletion inquiries are acknowledged within 48 business hours and processed within 30 calendar days.
Docly

Docly provides automated AI appointment management for healthcare practitioners connecting Google Calendar with WhatsApp Business.

Legal & Compliance

  • Privacy Policy
  • Terms of Service
  • User Data Deletion Instructions

Contact & DPO

Privacy & Data Rights:

privacy@docly.health

Platform Support:

support@docly.health
© 2026 Docly. All rights reserved. Meta and WhatsApp are registered trademarks of Meta Platforms, Inc.
Strictly not for acute medical emergencies.