Privacy
Taaya is a patient concierge for aesthetics clinics, built by Avedd Limited. This page explains what we do with personal data, in two parts: the data we hold as a business, and the patient conversations we handle on behalf of clinics. Those are different roles under UK data protection law and it matters which is which.
Who we are
Avedd Limited is the company behind Taaya, registered with the Information Commissioner's Office as a data controller, reference ZC202793. Write to hello@taaya.io for anything on this page, including a request to exercise your rights.
Two different roles
For our own business data we are the controller. That means people who contact us, clinics we talk to, and visitors to this website.
For patient conversations we are a processor. When a clinic uses Taaya, the clinic decides why and how patient data is used. They are the controller; we act on their documented instructions under a written data processing agreement. If you are a patient and want your data removed, ask the clinic. If they ask us, we act.
This website
This site sets no cookies, runs no analytics, and makes no third-party requests. We do not track you, profile you, or build an advertising audience. Our hosting provider, Cloudflare, processes your IP address transiently to serve the page and protect against abuse.
If you contact us
We keep your name, email address and what you wrote, so that we can reply and keep track of a conversation. Our lawful basis is legitimate interests: you contacted us and expect an answer. We keep it while the conversation is live and for up to two years after, then delete it.
Patient conversations, handled for clinics
When a clinic runs Taaya, patients may share their name, contact details, the treatment they are asking about, and sometimes information about their health. Health information is special category data under UK GDPR and we treat it that way.
We use it only to answer the enquiry in the clinic's voice, to pass a conversation to clinic staff when it needs a person, and to give the clinic a weekly summary of what happened. We do not sell it, share it for advertising, or use it to train any model outside that clinic's own setup.
Taaya never makes a clinical judgement. It does not decide whether a treatment suits anyone, interpret symptoms, or give medical advice. When a conversation touches those things it stops and hands over to the clinic.
Who else processes data
We use these sub-processors. Clinics are told before we add or change one.
| Provider | What for | Where |
|---|---|---|
| OpenAI | Generating replies | United States |
| n8n | Running the workflow | European Union |
| Airtable | Storing conversations | United States |
| Google (Workspace) | Email, including weekly summaries | United States / EU |
| Cloudflare | Hosting this website | Global edge network |
Where a provider is outside the UK, transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on adequacy where it applies. We have agreements in place that prohibit providers from using clinic or patient data to train their own models.
How long we keep things
Patient conversations are kept for as long as the clinic instructs, and no longer. Where a clinic gives no instruction the default is 24 months, after which conversations are deleted. Business contact data is kept for up to two years after our last exchange. When a clinic stops using Taaya we delete or return their data within 30 days of being asked.
Your rights
You can ask for a copy of your data, ask us to correct or delete it, object to how we use it, or ask us to restrict it. If we hold your data on behalf of a clinic, ask the clinic first and they will instruct us. We respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can fix it.
Security
Data is encrypted in transit and at rest by our providers. Access is limited to those who need it. This site enforces HTTPS and a strict content security policy. We are a small company and do not pretend to hold certifications we do not have: we hold ICO registration, and we will say so plainly if and when that changes.
Changes
If we change anything material here we will tell clinics directly rather than relying on you noticing a new date at the top of this page.