01
About Us
GetPlenta Ltd (referred to throughout as "GetPlenta Ltd," "we," "us," or "our") is a company incorporated and registered in England and Wales with registered office at 128 City Road, London, EC1V 2NX. We provide AI-powered voice agent technology and automation services, including inbound and outbound call handling, appointment booking, patient lead qualification, 21-day automated lead conversion sequences, and front-desk automation — specifically designed for Med Spa practices operating in the United States.
This Privacy Policy is a business-to-business (B2B) document directed at Med Spa owners, clinic directors, practice managers, and their authorised representatives (collectively, "Clients" or "Business Clients") who engage GetPlenta Ltd's services. It is not directed at individual consumers or patients of any Med Spa.
02
Scope & Applicability
This Policy applies to all personal data and Protected Health Information (PHI) that GetPlenta Ltd accesses, processes, or transfers in the course of delivering its services to Business Clients. This includes:
- Data exchanged via API integrations with Client booking systems and electronic health records (EHRs)
- Caller identity and scheduling data processed during live AI voice interactions
- Contact and company data of Business Clients and their authorised staff
- Technical and usage data generated through the operation of GetPlenta Ltd's AI infrastructure
If you are a patient of a Med Spa that uses GetPlenta Ltd's services and wish to understand how your personal data is handled, you should refer to the privacy notice published by that Med Spa directly. GetPlenta Ltd processes patient data solely on behalf of, and under the instruction of, the relevant Med Spa Client.
This Policy does not constitute legal advice. Med Spa Clients remain independently responsible for ensuring their own HIPAA compliance, state-level healthcare privacy obligations, and applicable consumer privacy laws (including CCPA) in respect of their patient relationships.
03
Who We Are Under UK GDPR
GetPlenta Ltd is incorporated in England and Wales and is therefore subject to the UK General Data Protection Regulation (UK GDPR) as retained and amended by the Data Protection Act 2018 (DPA 2018). The UK Information Commissioner's Office (ICO) is our lead supervisory authority.
Data Controller vs. Data Processor
| Data Category | GetPlenta Ltd's Role | Basis |
|---|---|---|
| Business Client Data | Independent Data Controller | We determine purposes and means of processing contact details, account information, and correspondence of Business Clients and their staff. |
| Patient / End-User Data | Data Processor & HIPAA Business Associate | We process patient data only on documented instruction from the Business Client. No independent right to use this data for our own purposes. |
| Technical & Log Data | Data Controller | Anonymised or aggregated technical data used solely for infrastructure security, performance monitoring, and service improvement. |
Lawful Basis for Processing
- Contract performance (Article 6(1)(b) UK GDPR): Processing necessary to perform our service agreements with Business Clients.
- Legitimate interests (Article 6(1)(f) UK GDPR): Processing for fraud prevention, system security, and service improvement.
- Legal obligation (Article 6(1)(c) UK GDPR): Processing required to comply with applicable law.
04
How We Use Your Business & Commercial Data
When you engage with GetPlenta Ltd to explore our services, book a discovery call, or enter into a service agreement, we collect and process business and commercial data. This section explains what we collect, why we process it, and which third parties we share it with.
What Commercial Data We Collect
Your business and commercial information is collected through multiple touchpoints:
- Contact & Scheduling Information: Your name, corporate email address, phone number, and appointment notes you provide via Cal.com when booking a discovery or demo call.
- Business Process Information: Operational details, internal workflows, system configurations, and business challenges you share before or during discovery conversations to help us evaluate service fit and tailor our pitch.
- Financial & Contractual Data: Your business registration details, registered address, billing address, and transaction records necessary to issue invoices, process payments, facilitate international bank transfers, or generate secure payment links.
- Account Administration Data: API credentials, dashboard access logs, support tickets, and onboarding documentation required to deliver and manage your GetPlenta Ltd subscription.
Our Lawful Basis for Processing Your Commercial Data
Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal frameworks to process your commercial data:
- Contractual Necessity (Article 6(1)(b)): We process your scheduling data, business process details, and account administration information because it is necessary to take steps at your request prior to entering into a formal service agreement with us, and to perform the contract once executed. Without this data, we cannot evaluate your requirements, deliver our services, or manage your account.
- Legal Obligation (Article 6(1)(c)): We retain invoicing, financial records, and transactional data to comply with UK statutory accounting requirements, tax obligations (HMRC), and company law (Companies House).
- Legitimate Interests (Article 6(1)(f)): We process your business details to tailor our service delivery, improve our advisory and onboarding processes, maintain professional commercial communications, prevent fraud, and enhance service quality based on aggregated usage patterns. These interests are balanced against your rights and do not override your reasonable expectations of privacy.
Third-Party Data Processors & Data Sharing
GetPlenta Ltd does not sell, rent, or trade your commercial data. To deliver our services, process payments, and comply with legal obligations, we securely share minimal, necessary data with the following trusted third parties who act as our data processors or service providers under Data Processing Agreements:
| Processor | Purpose | Data Shared |
|---|---|---|
| Cal.com, Inc. | Scheduling and managing business discovery, demo, and assessment calls | Name, email, phone number, appointment preferences, meeting notes |
| Stripe, Inc. | Processing credit and debit card payments, generating secure billing links, and managing subscription billing | Billing name, email, business address, transaction history (not raw card data — PCI-DSS compliant) |
| Wise Payments Limited | Facilitating international business-to-business bank transfers and US ACH payments for invoicing and business payments | Business name, registered address, banking details, transaction records |
| GoHighLevel (Keap, Inc.) | CRM, workflow automation, client account management, and infrastructure for AI voice and messaging services | Account details, contact information, service usage logs, integration credentials (encrypted) |
| HM Revenue & Customs (HMRC) | UK corporate tax reporting, VAT compliance, and statutory business filings where legally required | Company registration details, transaction records, invoicing data (as required by law) |
Data Security & Processor Obligations
All third-party processors are contractually obligated to:
- Maintain data security standards equivalent to or exceeding those described in Section 10 (Security & Encryption)
- Process your data only on our documented instructions
- Not use your data for any purpose other than delivering the contracted service
- Implement appropriate technical and organisational safeguards (encryption, access controls, audit logging)
- Notify us immediately of any suspected data breach or unauthorized access
- Delete or return data upon termination of the service relationship
Your Rights Regarding Commercial Data
As the subject of commercial data processing, you have the following rights under UK GDPR:
- Right of Access: Request a copy of the commercial and financial data we hold about your business.
- Right to Rectification: Request correction of inaccurate business or billing information.
- Right to Erasure: Request deletion of your data where there is no ongoing legal basis for processing (subject to statutory accounting retention obligations).
- Right to Data Portability: Request your business data in a structured, machine-readable format suitable for transfer to another service provider.
- Right to Object: Object to processing for legitimate interest purposes, though we may retain data where legally required for tax or contract purposes.
To exercise any of these rights, contact us at privacy@getplenta.ai. We will respond within 30 days.
05
HIPAA Compliance
GetPlenta Ltd operates on GoHighLevel's HIPAA-enabled platform, which includes a Business Associate Agreement (BAA) with GoHighLevel. This means all client data — including any Protected Health Information (PHI) — is stored and processed within a HIPAA-compliant environment by default.
GetPlenta Ltd processes data on behalf of medical spa clients using HIPAA-compliant infrastructure. All client data (including any Protected Health Information, or PHI) is stored and processed within sub-accounts on GoHighLevel's HIPAA-enabled platform, which operates under a Business Associate Agreement (BAA) with us.
When GetPlenta Ltd provides services to a medical spa that involves processing PHI, we act as a "business associate" under HIPAA and enter into a Business Associate Agreement (BAA) directly with the medical spa client. This agreement governs how PHI is collected, used, stored, and protected.
Our HIPAA Compliance Posture
- End-to-end encrypted data storage through our HIPAA-compliant infrastructure provider (GoHighLevel)
- Restricted access controls and audit logging on all PHI
- Signed BAAs with all sub-processors that may access PHI
- Administrative, technical, and physical safeguards as required under HIPAA
- Breach notification protocols compliant with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414)
What Constitutes PHI in Our Context
In the context of GetPlenta Ltd's AI voice operations, PHI may include: a patient's name, phone number, appointment date and time, treatment type (e.g., Botox, dermal fillers, laser treatment), medical history mentioned on a call, and any other individually identifiable health information created, received, or transmitted by our systems on behalf of a Covered Entity.
Business Associate Agreement (BAA) Requirement
No GetPlenta Ltd service that involves the processing of PHI shall be activated for a Client until a fully executed Business Associate Agreement (BAA) is in place. The BAA is a pre-condition to service commencement, not an optional addendum.
Breach Notification
In the event of a suspected or confirmed breach involving PHI, GetPlenta Ltd will notify the affected Business Client without undue delay and in any event within 48 hours of becoming aware of the breach — more stringent than HIPAA's 60-day minimum — providing sufficient information for the Client to meet its own HIPAA Breach Notification Rule obligations.
If you are a medical spa client and require a BAA before engagement, please contact us at privacy@getplenta.ai and we will provide one prior to onboarding.
06
CCPA — California Privacy Rights
GetPlenta Ltd serves Med Spa clients across the United States, including in California. To the extent that GetPlenta Ltd collects personal information about California residents in the course of its business operations, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may apply.
Categories of Personal Information Collected
In the preceding 12 months, GetPlenta Ltd has collected the following categories of personal information from or about Business Clients and their staff:
- Identifiers: Name, email address, business phone number, IP address
- Commercial information: Service agreements, billing records, account activity
- Internet or network activity: Dashboard usage logs, API access logs
- Professional or employment information: Job title, business name, role within the Med Spa
- Inferences: Service usage patterns used solely for account management and service improvement
GetPlenta Ltd does not sell personal information. GetPlenta Ltd does not share personal information for cross-context behavioural advertising.
Sources of Personal Information
Personal information is collected directly from Business Clients during onboarding, account management, and ongoing service delivery. Technical data is collected automatically through system logs associated with dashboard and API access.
Business or Commercial Purposes for Collection
- Delivering and managing contracted AI voice agent services
- Billing and account administration
- Security monitoring and fraud prevention
- Improving service performance and reliability
- Complying with legal obligations
California Consumer Rights
California residents whose personal information GetPlenta Ltd holds as a Data Controller have the following rights under the CCPA/CPRA:
- Right to Know: The categories and specific pieces of personal information collected about you, the sources, business purposes, and categories of third parties with whom it is shared — covering the preceding 12 months.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions (e.g., ongoing service delivery, legal obligations).
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: GetPlenta Ltd does not sell or share personal information for advertising purposes. No opt-out is required, but you may contact us to confirm this.
- Right to Limit Use of Sensitive Personal Information: GetPlenta Ltd does not use sensitive personal information for purposes beyond those necessary to provide requested services.
- Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any CCPA/CPRA right.
12-Month Lookback Disclosure
This disclosure covers GetPlenta Ltd's personal information practices for the 12-month period preceding the effective date of this Policy. GetPlenta Ltd has not sold or shared the personal information of California residents during this period.
How to Submit a California Privacy Request
To exercise any CCPA/CPRA right, submit a verifiable consumer request to: privacy@getplenta.ai. We will respond within 45 days. If we require more time (up to 90 days), we will notify you of the reason and extension in writing.
07
AI Voice Agent Disclosures
Two-Party Consent & Call Recording
GetPlenta Ltd deploys AI voice agents that conduct outbound and inbound telephone calls on behalf of Med Spa clients. Several US states — including California, Florida, Pennsylvania, Massachusetts, Illinois, and others — operate under two-party (or all-party) consent laws that require all parties to a telephone conversation to consent to recording.
All voice calls made by GetPlenta Ltd's AI agents include a disclosure at the start of every call notifying the recipient that the call is being recorded and conducted by an AI assistant, in accordance with two-party consent laws applicable in certain US states.
This disclosure is delivered as the opening statement of every call, prior to any substantive conversation. By continuing the call after this disclosure, the recipient provides implied consent to recording in jurisdictions where such consent is required.
AI Identity Disclosure
GetPlenta Ltd's AI voice agents will not deny being an AI when sincerely asked by a recipient. If a call recipient directly asks whether they are speaking with an automated system or AI, the agent will confirm this truthfully.
HIPAA and Call Content
GetPlenta Ltd's AI voice agents are designed to handle booking logistics only. Agents do not solicit, collect, or store medical records, treatment histories, diagnosis information, or any PHI beyond what is strictly necessary to facilitate appointment scheduling on behalf of the Client.
Where GetPlenta Ltd or its Med Spa clients collect mobile telephone numbers via web forms for the purpose of sending marketing or operational text messages, the following consent language must appear adjacent to the phone number form field at the point of collection:
This language satisfies Twilio A2P 10DLC registration requirements and TCPA compliance obligations.
08
What Data We Process
A. Business Client Data (Controller)
- Full name, job title, and business email address of the Med Spa owner, director, or designated account contact
- Business name, registered address, and business telephone number
- API credentials and system access tokens (stored in encrypted vaults, never in plain text)
- Billing information (processed via PCI-DSS-compliant payment processors; GetPlenta Ltd does not store raw card data)
- Communications, support tickets, and onboarding documentation
B. Patient & Caller Data (Processor / Business Associate)
This data is processed strictly under Client instruction to execute the real-time booking function. It includes:
- Caller name and phone number (inbound call identification)
- Appointment type, preferred date, and scheduling preferences
- Existing patient status as retrieved from the Client's booking system
- Treatment category requested (e.g., injectable consultation, laser treatment, facial)
- Relevant medical screening information volunteered by the caller, where necessary to process the booking
- Call recordings or transcripts, where the Client has enabled this feature and applicable consents have been obtained
C. Technical & Infrastructure Data (Controller)
- API request and response logs (retained per the schedule in Section 11)
- System performance metrics, latency records, and error logs
- IP addresses and user-agent strings associated with dashboard access
09
How Our AI Systems Access & Process Data
Real-Time API Read Operations
When an inbound call is received, our AI system authenticates with the Client's booking platform (such as Mindbody, Boulevard, or Zenoti) using OAuth 2.0 or API key credentials supplied by the Client. The system queries availability in real time — fetching open appointment slots, provider schedules, and where relevant, confirming whether the caller exists as a patient in the booking system. This read operation is scoped to the minimum data required to execute the call.
Real-Time API Write Operations
Upon the caller confirming their preferred appointment, our AI system creates or updates a booking record directly within the Client's booking platform. This may involve creating a new patient profile, scheduling the appointment, and triggering automated confirmation messages.
| Specification | Detail |
|---|---|
| Supported Platforms | Mindbody, Boulevard, Zenoti, and other RESTful API platforms |
| Authentication | OAuth 2.0 / API Key (Client-provisioned, rotated per security schedule) |
| Transport Protocol | HTTPS (TLS 1.3 minimum, TLS 1.2 where required) |
| Data-at-Rest Encryption | AES-256 for all temporarily cached session data |
| Scope of Access | Read: availability and patient lookup only. Write: booking creation and patient profile update only. No bulk export. |
| Session Duration | API session scoped to active call. Ephemeral data discarded upon call completion. |
10
Data Minimization Principle
GetPlenta Ltd operates under a strict data minimization architecture, consistent with Article 5(1)(c) of the UK GDPR and the HIPAA minimum necessary standard (45 CFR § 164.502(b)).
- No bulk data ingestion: We do not ingest or replicate entire patient databases. API calls are scoped to individual patient lookups triggered by a live caller interaction.
- No persistent PHI storage: Caller PHI is held in ephemeral, in-memory processing only for the duration of the call. It is not written to GetPlenta Ltd's permanent storage unless call recording is enabled by the Client under the terms of the BAA.
- No secondary use: Data accessed on behalf of one Client will never be used for model training, marketing, or any purpose benefiting another Client or GetPlenta Ltd's commercial activities without explicit, documented consent.
- Field-level access control: API integrations are configured to request only the data fields required for booking functionality. Sensitive clinical fields not relevant to scheduling are excluded from all API query scopes.
11
Security & Encryption
Scheduling Platform — Cal.com
Cal.com is used solely for scheduling business discovery and demo calls with prospective and current Business Clients. Data processed includes the Client contact name, email, and phone number. This data is not shared with any other third party and is used exclusively to facilitate appointment scheduling and confirmation for business purposes.
Encryption in Transit
All data transmitted between GetPlenta Ltd's AI infrastructure and Client booking platforms is protected using HTTPS with TLS 1.3 (minimum TLS 1.2). Unencrypted HTTP connections are blocked at the infrastructure level.
Encryption at Rest
All data held on GetPlenta Ltd's infrastructure is encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management system with mandatory rotation.
Additional Security Controls
- Access control: Role-based access control (RBAC) limits data access to personnel with a documented operational need.
- Multi-factor authentication (MFA): Required for all GetPlenta Ltd staff accessing production systems.
- Vulnerability management: Annual third-party penetration testing minimum. Critical vulnerabilities patched within 72 hours.
- Intrusion detection: Automated monitoring for anomalous API activity and unauthorized access attempts.
- PHI Breach Notification: 48-hour Client notification from point of discovery.
12
Data Retention
| Data Category | Retention Period |
|---|---|
| Ephemeral session data (PHI) | Discarded upon call completion. Not written to permanent storage unless call recording is enabled by Client. |
| Voice recordings / transcripts | 12 months from date of recording, unless compliance obligations or Client BAA require a longer period, then securely deleted. |
| API access & security logs | Operational logs: 90 days. Security and audit logs: 12 months minimum (HIPAA Security Rule). |
| Marketing & lead data | 24 months from last engagement, then deleted or anonymised. |
| Business Client account data | 7 years from end of contract (UK statutory accounting and tax retention requirement). |
| Website analytics data | 26 months from collection, consistent with Google Analytics default and ICO guidance. |
| BAA and contractual documents | Duration of contract plus 6 years (HIPAA) / 7 years (UK contract law), whichever is longer. |
Upon termination of a service agreement, GetPlenta Ltd will, within 30 days and at the Client's election, either securely return all Client data in a machine-readable format or confirm its secure destruction in accordance with NIST SP 800-88 guidelines.
13
Third-Party Sub-Processors
GetPlenta Ltd uses a limited number of trusted third-party sub-processors to deliver its services. All sub-processors are subject to:
- A written Data Processing Agreement (DPA) or equivalent contractual instrument
- Security due diligence prior to engagement and annually thereafter
- Contractual restrictions prohibiting use of Client or patient data outside of service delivery
- HIPAA Business Associate Agreements where required
Categories of sub-processors include: cloud hosting and infrastructure providers, AI voice processing services (including GoHighLevel), telephony carriers, CRM platforms, and payment processors. A current list of sub-processors is available upon written request to privacy@getplenta.ai.
GetPlenta Ltd will provide Business Clients with not less than 30 days' prior written notice of any intended change to its sub-processor list that could materially affect the processing of PHI.
14
International Data Transfers
UK-to-US Transfers
Transfers of personal data from the UK to the United States are conducted pursuant to the UK-US Data Bridge (adequacy decision adopted October 2023) where the US recipient participates in the UK Extension to the EU-US Data Privacy Framework. Where a recipient is not covered by the UK-US Data Bridge, transfers are protected by International Data Transfer Agreements (IDTAs) incorporated into our agreements with relevant sub-processors.
HIPAA and Cross-Border PHI
PHI transferred from US Clients to GetPlenta Ltd's UK-based infrastructure remains subject to HIPAA protections in full. The territorial location of GetPlenta Ltd's servers does not diminish its obligations as a Business Associate. All PHI is processed under the terms of the executed BAA regardless of where processing occurs.
15
Your Rights
Rights of Business Clients (UK GDPR)
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your data where there is no lawful basis for continued processing.
- Right to restriction (Article 18): Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Article 20): Request your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests.
- Right to lodge a complaint: Lodge a complaint with the UK ICO at ico.org.uk.
Rights of Med Spa Patients
GetPlenta Ltd processes patient data only as a Data Processor and Business Associate under Client instruction. Patients seeking to exercise rights under UK GDPR, HIPAA, or applicable US state privacy laws should direct requests to the Med Spa that holds their records as the primary Data Controller and Covered Entity.
To exercise your rights as a Business Client, contact us at privacy@getplenta.ai. We will respond within 30 days.
16
Business Client Obligations
By engaging GetPlenta Ltd's services, Business Clients warrant and agree to:
- Execute a Business Associate Agreement and Data Processing Agreement with GetPlenta Ltd prior to service activation involving PHI
- Ensure all necessary patient notices, consents, and authorizations required under HIPAA, applicable state law, and other privacy regulations have been obtained before patient data is processed by GetPlenta Ltd's systems
- Notify GetPlenta Ltd promptly of any changes to HIPAA Covered Entity status, business structure, or applicable regulatory obligations
- Implement and maintain appropriate physical and organizational security measures at the Client's own premises and systems
- Notify GetPlenta Ltd within 24 hours of becoming aware of any actual or suspected unauthorized access to API credentials or booking system integrations used by GetPlenta Ltd
- Ensure that API credentials provided to GetPlenta Ltd maintain appropriate access privileges
- Display required SMS consent language adjacent to all telephone number form fields on Client-operated websites and landing pages where GetPlenta Ltd's messaging services may be used
17
Cookies & Website Data
GetPlenta Ltd's public-facing website and client portal may use cookies and similar tracking technologies, used exclusively for:
- Session authentication and security (strictly necessary cookies)
- Website performance analytics using privacy-respecting tools configured with IP anonymization and without cross-site tracking
- Your preferences and settings within the client portal
We do not use third-party advertising cookies, behavioral tracking pixels, or social media tracking technology on any page that handles Client data. A dedicated cookie notice is presented on first visit where consent is obtained for non-essential cookies in accordance with the UK Privacy and Electronic Communications Regulations 2003 (PECR).
18
Children's Privacy
GetPlenta Ltd's services are directed exclusively at business clients and are not intended for use by, or directed at, individuals under the age of 16. We do not knowingly collect personal information from individuals under 16 years of age. In accordance with the UK GDPR and the Age Appropriate Design Code (UK Children's Code), if we become aware that personal information has been collected from a person under the age of 16 without appropriate parental or guardian consent, we will take immediate steps to delete such information.
If you believe we may have inadvertently collected information from or about a person under 16, please contact us immediately at privacy@getplenta.ai.
19
Changes to This Policy
GetPlenta Ltd reserves the right to update this Privacy Policy at any time to reflect changes in law, regulatory guidance, or operational practices. Where changes are material — particularly where they affect the processing of PHI or the rights of Business Clients — we will provide not less than 30 days' advance written notice by email to the designated account contact on file, prior to the changes taking effect.
The current version of this Policy, including its effective date and version history, will at all times be available at our website. Continued use of GetPlenta Ltd's services following the effective date of any revised Policy constitutes acceptance of that revised Policy.
20
Contact & Data Protection
All data protection enquiries, subject access requests, BAA requests, and privacy complaints should be directed to:
| Entity | GetPlenta Ltd |
| Jurisdiction | England & Wales |
| Registered Address | 128 City Road, London, EC1V 2NX |
| Privacy Email | privacy@getplenta.ai |
| General Contact | hello@getplenta.ai |
| BAA Requests | privacy@getplenta.ai |
| Supervisory Authority | UK Information Commissioner's Office (ICO) — ico.org.uk |
We aim to acknowledge all data-related enquiries within 2 business days and resolve them substantively within 30 calendar days, in line with our UK GDPR and HIPAA obligations.
Governing Law: This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any dispute arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.