Legal
Consumer Health Data Privacy Policy
Effective date: October 8, 2026
This policy applies only to consumer health data. It is published separately from our Privacy Policy because Washington's My Health My Data Act and Nevada's SB 370 require a distinct policy for this category of information. It describes what consumer health data Guwy Software LLC ("Guwy," "we") processes, where it comes from, why, who receives it, and how you can exercise your rights.
1. Our Role
Guwy provides appointment and record-keeping software to independent beauty, permanent makeup, tattoo, lash, esthetics, barbering, and spa businesses.
We process consumer health data on behalf of those businesses, not for our own purposes. The business decides which health questions to ask, which forms to use, and why. We store that information, show it to the staff the business authorizes, and keep it available to the business. We do not decide what is collected, and we do not use it for anything other than operating the Service for that business.
If you filled in a form or received a service, your relationship is with that business. This policy tells you what happens to the information inside our platform, and how to reach us if the business cannot help you.
2. Categories of Consumer Health Data We Process
What is actually collected depends on the form each business builds. Across the forms in use, these categories appear:
- Health history the business asks about: allergies, medications, medical conditions, pregnancy or breastfeeding status, skin type, and prior reactions.
- Treatment records: the service received, date, professional, products or settings used, aftercare instructions acknowledged, and observations the business records about a session.
- Notes about you written by the business, including notes it marks as medical.
- Handwritten signatures captured on consent and aftercare forms.
- Identity documents, where a business requires one: a photograph of a government-issued ID, and its number when the form asks for it.
- Information about a minor and their parent or legal guardian, where a business serves minors with guardian consent.
- Appointment records that show you sought a particular service.
We do not derive health information from data that is not health information. We do not collect location data through our website or the pages where you fill in a form. Our mobile app, which is used by business staff and not by clients, requests device location only because the card reader it supports requires it to process in-person payments; that location describes the business's own device, not you.
3. Where It Comes From
- From you, when you complete a form we host on the business's behalf.
- From the business, when its staff enter information or upload a document on your behalf.
- From your use of the Service, such as the record created when an appointment is booked or completed.
4. Why We Process It
Only to operate the Service for the business that collected it:
- Store the completed form and make it available to the staff the business authorizes.
- Generate the signed document the business keeps as its record.
- Link the record to the correct client and appointment.
- Record who viewed or downloaded each consent document, and when, so the business has an access trail.
- Keep encrypted backups so the business does not lose its records.
- Provide support when the business asks us to look into a problem.
5. What We Do Not Do
- We do not sell consumer health data. We have never sold it, and selling it would require your signed authorization, which we do not seek.
- We do not use it for advertising, ours or anyone else's, and we do not share it for cross-context behavioral advertising.
- The page where you fill in and sign a form loads no analytics, advertising, or session-recording code of any kind. No pixel, tag, or third-party script observes what you type there. Apart from our own servers, that page loads only a typeface and an icon set from Google Fonts and a content delivery network. Because your browser requests those files directly, those providers receive your IP address and browser details — and nothing about the form or about what you enter in it.
- We do not use it to train artificial intelligence models, and our in-product AI assistant cannot reach health forms, medical notes, signatures, identity documents, or uploaded files. The assistant is technically restricted to a fixed set of database views that expose appointments, services, staff, payments, and client names and contact details, and it cannot query anything else.
- We do not send it by email or text message. The contents of a health form are never attached to a message we send.
- We do not use geofencing to identify or track anyone near a health care facility.
- We do not use it to profile you or to make automated decisions about you.
6. Who Receives It
Consumer health data is shared only with the providers that make the Service run, and only for that purpose. We do not share it with data brokers or advertisers. Guwy Software LLC has no affiliates or subsidiaries.
- The business that collected it, and the staff it authorizes. This is the point of the Service.
- Our hosting provider, which operates the server in Dallas, Texas, United States where the Service runs.
- Cloudflare, which carries and protects network traffic between your browser and our server.
- Amazon Web Services and Cloudflare R2, which store our backups. Backups are encrypted on our own servers before they are uploaded, so these providers hold only encrypted files they cannot read.
- Google, only if the business chooses to connect its Google Calendar. In that case we send Google the calendar entry for each appointment: your name, the name of the service, the professional, the price, and the date and time. Because the service name can reveal what you sought, we treat this as a sharing of consumer health data, and it happens only when the business turns the integration on. The contents of health forms, signatures, identity documents and medical notes are never sent to Google. If you do not want your appointments on the business's Google Calendar, tell the business, which can turn the integration off or remove the entry.
- Providers that deliver the business's messages and notifications — text messages, email, and notifications to the phones of the business's staff. An appointment notification sent to staff identifies you and the service booked.
- Payment providers, which receive the amount and a reference to the appointment. They do not receive the contents of your forms.
- An artificial-intelligence provider, if the business uses the assistant in its dashboard. It can receive appointment and client information. The contents of health forms, medical notes, signatures, identity documents and uploaded files are never sent to it.
- Optional services the business connects — for example a calendar, a marketing tool, or a destination it chooses to receive appointment events. These receive information only if the business turns them on, and the business chooses the destination.
These providers act only on our instructions, or on the business's, and only to deliver the part of the Service they provide. They are service providers, not parties with whom we share your information for their own purposes. A business using Guwy can request the current list of our service providers under its agreement with us.
We do not sell consumer health data, and we do not share it with advertisers or data brokers.
We may also disclose consumer health data if we are legally required to, for example in response to a valid subpoena or court order.
7. Your Rights
You have the right to:
- Confirm whether we process consumer health data about you, and access it, including a list of all third parties and affiliates that have received it and an active email address or other online mechanism you can use to contact each of them.
- Withdraw your consent to our collection and sharing of it.
- Ask us to review your data and request changes to it.
- Delete it.
Exercising these rights is free, and we will not treat you differently for doing so.
How to exercise them
Start with the business that served you. It holds the records and can act immediately: a business can correct a client's information, and can erase a client's health data — including the signed forms, signatures, identity photographs, and medical history — directly from its own account, at any time.
If you cannot reach the business, or it does not respond, write to privacy@guwy.com with enough detail for us to find the record. Because we act on the business's behalf, we will forward your request to it and follow its instruction, and we will tell you what happened. We will respond within 45 days, and may extend once by another 45 days where reasonably necessary, telling you why.
We may need to verify who you are before acting. If we cannot verify you, we will tell you.
If we decline
If we decline your request, we will tell you why and how to appeal. To appeal, reply to our decision or write to privacy@guwy.com with the word "Appeal." We will respond to the appeal within 45 days. If we deny the appeal, we will give you a way to contact your state attorney general to submit a complaint.
8. Deletion and Retention
We keep consumer health data while the business's account is active, because the record is the product the business pays for. A business can delete an individual client's data at any time, and is responsible for meeting any record-keeping obligations that apply to it.
When data is deleted, we remove it from our live systems and delete the stored files under our control. Encrypted backups may still contain the information until those backups expire and are destroyed, which happens no later than six months after the deletion. We cannot selectively erase a single record from inside an existing encrypted backup. If we ever have to restore a backup, we re-apply every deletion request we received after that backup was made.
One thing is deliberately kept: the appointment and payment record itself, with your identity removed. The business needs it for its accounting and tax records, and once your name, contact details, notes and forms are gone, that record no longer identifies you.
If a business closes its account, we keep its data for 90 days so it can export its records, and delete it after that.
9. How We Protect It
- TLS 1.2/1.3 encryption in transit.
- Encryption at rest (LUKS2, AES-256-XTS) on the volume holding our database and uploaded documents. This protects the data if the physical disk is removed, replaced, or retired.
- Backups encrypted on our servers before upload.
- Role-based access controls and data isolation between businesses.
- Access logging on consent documents: we record who viewed or downloaded each record, and when, including downloads by staff.
10. Minors
Minors do not create accounts with Guwy. A business may record a form for a minor client with the consent of a parent or legal guardian; that information, and the guardian's own details recorded alongside it, are treated exactly as described in this policy.
11. Changes to This Policy
We will not collect, use, or share consumer health data in ways not described here. If we intend to, we will update this policy first, publish it with a new effective date, notify businesses by email at least 15 days before the change takes effect so they can inform their clients, and obtain consent where the law requires it before the new practice begins.
12. Contact
Guwy Software LLC — Georgia, United States
privacy@guwy.com
