Privacy
This page is maintained by ScopeFlow to answer common privacy and security questions. It describes how the platform works and is not an independent certification.
What we store
For each patient your practice adds, ScopeFlow stores the details you enter: name, date of birth, contact details, procedure, procedure date, assigned doctor, preparation protocol and your internal notes. We also store the patient's preparation progress and hydration entries. ScopeFlow does not store clinical reports, images or histology.
Who can access it
Clinic records are isolated per practice. A signed-in staff account can only ever read or change data belonging to its own clinic; this is enforced in the database itself, not just in the interface.
Patient access
Patients do not have passwords. Each patient receives a unique, unguessable link, and must additionally confirm their date of birth before any information is shown. Patient requests are verified on the server on every action, and a patient can only ever see their own journey. Archiving a patient immediately revokes their link.
Demo requests
Details submitted through the demo form (name, email, phone and any message) are used solely to contact you about ScopeFlow. No patient data is required to request a demo.
Your responsibilities
Your practice remains the data controller for patient information you enter, and is responsible for lawful basis, patient consent, retention decisions and the accuracy of the preparation instructions you publish. Contact us for a data processing agreement before you enter live patient data.