Information collected
Appointment requests may include name, age, phone, email, consultation preference, scheduling details, a short administrative note and an optional report. Patient feedback may include contact details, rating, experience, publication preference and an optional photo. The patient portal stores a verified email account, sign-in events, secure sessions, change requests and notification history.
Purpose
Information is used to review appointment requests, contact patients, provide administrative status updates, manage teleconsultation details, verify and moderate feedback, process reschedule or cancellation requests, protect the service from abuse and maintain an audit trail.
Passwordless sign-in and cookies
The portal uses a six-digit one-time code sent by email. Codes expire after 10 minutes, are stored as secret-derived hashes and cannot be reused. A successful sign-in creates a secure HTTP-only, Secure and SameSite=Strict session cookie. The cookie is required to keep the patient signed in and is not available to browser JavaScript.
Patient portal access boundaries
After email verification, the portal displays only administrative records connected to that verified email or account. It does not provide a complete medical record and is not a clinical messaging service. Private video-consultation links, when supplied by the clinic, are visible only to the authenticated patient and authorised administrators.
Public feedback
Feedback is never published automatically. Only submissions marked public, carrying explicit publication consent and approved by an authorised clinic administrator may appear. Email, phone and private names are never included in the public response.
Storage and access
When deployed as configured, structured data is stored in a private Cloudflare D1 database. Optional reports and photos are stored in a private Cloudflare R2 bucket. Administrative APIs require a secret administrator token. Patient APIs require a valid secure session. Uploaded files are not placed in the public website directory.
Email delivery
One-time sign-in codes and administrative updates may be sent through the configured email delivery provider. The provider receives the recipient address and the minimum message content needed to deliver the email. Clinical details and uploaded report contents are not included in notification emails.
Security and data minimisation
The service validates inputs, applies rate limits, uses expiring hashed login codes and sessions, restricts file types and sizes, and supports Cloudflare Turnstile with server-side verification. No internet system can guarantee absolute security. Patients should avoid unnecessary medical details, identity documents, financial information or information about other people.
Export, account closure, retention and deletion
Authenticated patients can export a JSON copy of their portal administrative data and close portal access. Account closure revokes sessions and removes the portal profile and account link. Existing appointment, feedback, audit or communication records may still be retained where operational, legal or professional requirements apply. Contact the clinic to request correction, withdrawal of publication consent or deletion review.
Emergency and clinical use
Forms and portal requests are not monitored continuously and are not suitable for emergencies. Submission or portal access does not confirm an appointment, establish a doctor–patient relationship or replace direct clinical consultation.
Third-party services
The site may use Cloudflare hosting, D1, R2 and Turnstile, a configured transactional email provider, web fonts, icons and external WhatsApp links. Each provider applies its own terms and privacy practices.
Preferences and privacy requests
Signed-in patients can choose update preferences and submit access, correction, deletion-review or restriction requests. A request is reviewed by the clinic and is not an automatic deletion command where retention may be required for operational, legal or professional reasons.
Operational exports and audit events
Authorised clinic users may export administrative records for legitimate clinic operations. Security-sensitive administrative actions are recorded in an audit trail. Exported files must be stored and shared according to the clinic’s approved privacy and retention procedures.
Offline use
The website may cache selected public educational pages on the patient’s device for resilience. Patient sign-in, dashboards, appointment forms, private documents and administrative pages are deliberately excluded from offline caching.