Privacy Policy

AIVUE LTD ("BookMyMedical") is the data controller for personal data processed through this platform. We handle your data in line with the UK GDPR and Data Protection Act 2018.

What we collect

Identity and contact details, date of birth, employer details (if provided), booking history and payment confirmation tokens. We do not store full card numbers - payments are processed by our PCI-DSS compliant payment partner.

Why we process it

To arrange your medical appointment, issue booking confirmations, share certificate outcomes with your nominated employer, and meet our legal obligations.

Sharing

We share booking details only with the clinic you select and, where you opt in, your employer. We never sell your data.

Google Calendar integration (clinic staff only)

When an authorised clinic staff member connects Google Calendar from the clinic dashboard (Availability → Calendar sync), we request Google OAuth scopes calendar.events and userinfo.email. We access the connected Google account’s email address and calendar event data (event start/end times, titles, and identifiers on the primary calendar connected). We do not access Gmail, Drive, Contacts, or other Google services. Patients and public booking visitors never see a Google sign-in or grant calendar access.

How we use Google Calendar data

We read calendar events to identify when the clinic is already busy and block those times from online booking (events created by BookMyMedical are excluded from busy detection). When a patient booking is confirmed, rescheduled, or cancelled, we create, update, or delete a corresponding event on the clinic’s connected calendar. Google data is used only to operate scheduling and appointment sync for that clinic. We do not use Google user data for advertising, creditworthiness, or profiling, and we do not use it to train AI or machine-learning models.

Google data sharing and transfer

Google Calendar data is not sold or transferred to data brokers, advertisers, or other third parties for their independent use. It is processed only by BookMyMedical (AIVUE LTD) and our infrastructure providers acting strictly as processors to host and run the service (for example encrypted database and server hosting). Booking details inside calendar event titles or descriptions may be visible to the clinic’s own Google account as part of normal calendar use.

Google data security, retention and deletion

OAuth refresh tokens and calendar sync data are stored encrypted on our servers and used only in server-side backend functions — not exposed to browsers beyond the OAuth redirect. When a clinic disconnects Google Calendar, we delete stored OAuth tokens and stop syncing. When a clinic account is deleted or we no longer need the connection, associated Google tokens and cached busy blocks are removed. You may disconnect at any time from Availability → Calendar sync → Disconnect.

Google API Services User Data Policy

BookMyMedical’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Raw and aggregated Google user data is used only to provide or improve the clinic-facing calendar sync features described above.

Your rights

You may request access, rectification, erasure or portability of your data, and may withdraw consent at any time by contacting privacy@bookmymedical.com.

Last updated 21 July 2026 · AIVUE LTD, Company No. 16980109.

We use essential cookies to make BookMyMedical work, and optional analytics cookies to improve it. You can accept or reject optional cookies under UK GDPR & PECR.