ClinicOS Publisher Privacy Policy
Effective date: August 5, 2026
ClinicOS Publisher is a social media publishing application operated by WellPlanet (“WellPlanet,” “we,” “us,” or “our”). It allows authorized users to connect Facebook accounts and Facebook Pages, select approved Pages, prepare content, and publish that content to those Pages.
This Privacy Policy explains what information ClinicOS Publisher processes, why it is processed, how it is protected, and the choices available to authorized users.
1. Who this policy applies to
This policy applies to people who:
- authorize a Facebook connection for use with ClinicOS Publisher;
- administer Facebook Pages connected to ClinicOS Publisher;
- use ClinicOS Publisher to create or publish content;
- contact WellPlanet regarding ClinicOS Publisher; or
- request access to, correction of, or deletion of information associated with the application.
ClinicOS Publisher is intended for authorized business use. It is not intended for use by children or for storing patient records, medical records, or sensitive health information.
2. Information we process
Depending on the connection and features used, ClinicOS Publisher may process the following information.
Facebook account and connection information
We may receive or process:
- the name and identifier of the Facebook account authorizing the connection;
- the connection type, such as a personal, business, or system-user connection;
- the date and status of the connection;
- Facebook access credentials required to perform authorized actions;
- information about whether a connection remains available or has been disconnected; and
- technical information returned by Meta when a connection or publishing request succeeds or fails.
Facebook access credentials are stored in encrypted form where retained by ClinicOS Publisher. They are not displayed in ordinary administrative screens.
Facebook Page information
We may process:
- Page name;
- Page ID;
- Page category;
- Page profile image URL;
- Page tasks or permissions available to the connected user;
- the business or client record associated with a Page;
- Page connection status; and
- non-secret information identifying which authorized connection is used for publishing.
Publishing content and history
We may process:
- text submitted for publication;
- images submitted for publication;
- website links included in content;
- the Pages selected to receive a post;
- customized clinic or business details inserted into a post;
- the time and result of a publishing request;
- Facebook provider post or photo IDs;
- publishing status and error information; and
- operational logs used to diagnose failures and confirm delivery.
Images submitted through ClinicOS Publisher may be validated, re-encoded, resized or rotated when necessary, and stripped of ordinary embedded metadata before publishing.
WordPress and business information
Where ClinicOS Publisher operates within a managed WordPress Multisite network, it may process business information already stored for participating sites, such as:
- business or clinic name;
- website address;
- telephone number;
- email address;
- street address;
- city, state, region, and postal code; and
- the relationship between a website, client record, and Facebook Page.
Technical and security information
We may process limited technical information needed to operate and protect the application, including:
- WordPress user identifier;
- timestamps;
- security and authorization checks;
- submission identifiers used to prevent duplicate publishing;
- API response status;
- redacted diagnostic information; and
- records of connection, disconnection, publishing, and deletion actions.
3. How we use information
We use the information described above to:
- authenticate authorized connections;
- identify Facebook Pages that an authorized account may manage;
- connect Pages with the correct business or client;
- display available publishing destinations;
- publish approved text and images to selected Pages;
- personalize content using approved business details;
- record publishing results and Facebook provider IDs;
- prevent accidental duplicate submissions;
- diagnose publishing failures;
- protect access credentials and application security;
- respond to support or deletion requests;
- comply with legal and platform obligations; and
- maintain and improve the reliability of ClinicOS Publisher.
We do not use Facebook data obtained through ClinicOS Publisher for unrelated advertising, data brokerage, or the creation of consumer profiles.
4. Legal bases for processing
Where applicable data-protection law requires a lawful basis, information may be processed because:
- it is necessary to provide the ClinicOS Publisher service requested by an authorized user or business;
- it is necessary to perform or prepare to perform a contract;
- WellPlanet or the participating business has a legitimate interest in securely administering its authorized social media publishing;
- the user has provided authorization or consent where required; or
- processing is necessary to meet a legal obligation.
The correct lawful basis depends on the nature of the information and the relationship between WellPlanet, the participating business, and the affected individual. Data-protection guidance requires organizations to determine and document the lawful basis and explain the purposes for which personal information is used.
5. Our role and the role of participating businesses
For information relating to ClinicOS Publisher accounts, security, service administration, and support, WellPlanet may act as a data controller.
When WellPlanet processes information solely to publish content or administer Facebook Pages on the instructions of a participating business, WellPlanet may act as a service provider or data processor, while that participating business remains responsible for deciding what content and personal information it submits.
Whether an organization acts as a controller or processor depends on who determines the purposes and means of processing. Controllers retain broader responsibility for demonstrating compliance, while processors must act on the controller’s documented instructions and meet their own applicable obligations.
6. How information is shared
Information may be shared with:
Meta Platforms
ClinicOS Publisher communicates with Meta’s Facebook APIs to:
- authenticate connections;
- retrieve authorized Page information;
- publish content;
- receive provider post IDs; and
- receive error or diagnostic information.
Meta processes information under its own terms, policies, and privacy practices.
Participating businesses and authorized administrators
Publishing records, Page relationships, connection labels, and diagnostic information may be visible to authorized WordPress network administrators and other approved personnel responsible for the relevant businesses.
Service providers
We may use hosting, security, backup, email, development, or infrastructure providers that process limited information on our behalf. We require appropriate safeguards where applicable.
Legal and safety disclosures
We may disclose information when reasonably necessary to:
- comply with law, legal process, or regulatory requirements;
- protect the security or integrity of ClinicOS Publisher;
- investigate suspected misuse or fraud; or
- protect the rights, property, or safety of WellPlanet, participating businesses, users, or others.
We do not sell personal information obtained through ClinicOS Publisher.
7. Access credentials and security
We use reasonable technical and organizational measures designed to protect information, including:
- encrypted storage of retained Facebook access credentials;
- restricted administrative access;
- security and authorization checks;
- separation of credential values from ordinary publishing history;
- redaction of tokens, authorization values, and application secrets from diagnostics;
- validation of Meta API destinations;
- duplicate-submission protection; and
- monitoring and testing of publishing behavior.
No internet-based system can guarantee absolute security. Authorized users should never send access tokens, application secrets, passwords, or credential screenshots by email, support ticket, chat, or other unsecured means.
8. Data retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, including:
- maintaining active Facebook and Page connections;
- providing publishing history;
- diagnosing delivery problems;
- preventing duplicate publishing;
- meeting contractual or legal obligations; and
- protecting the security and integrity of the service.
Retention periods may differ by data type. Connection credentials may be invalidated or deleted when a connection is disconnected. Publishing history may be retained for operational, contractual, security, or recordkeeping purposes.
When information is no longer required, we take reasonable steps to delete, anonymize, or securely dispose of it, subject to legal, backup, and legitimate recordkeeping requirements.
9. Disconnecting Facebook
An authorized administrator may disconnect a Facebook connection within ClinicOS Publisher.
Disconnecting a connection is designed to:
- mark that connection as disconnected;
- invalidate or remove its stored connection credential;
- make Pages owned by that connection unavailable for future publishing; and
- preserve historical publishing records where needed for legitimate operational purposes.
Disconnecting ClinicOS Publisher does not automatically delete posts already published to Facebook. Those posts must be managed on the relevant Facebook Page.
10. Data deletion requests
Instructions for requesting deletion are available at:
https://wellplanet.com/clinicos-publisher/data-deletion
A request may include deletion of information associated with a Facebook connection, subject to identity verification and any information we must retain for legal, security, dispute-resolution, or legitimate recordkeeping purposes.
Meta may also notify developers when an app user requests deletion through Meta’s systems.
11. Your rights
Depending on where you live and applicable law, you may have rights to:
- request access to personal information;
- request correction of inaccurate information;
- request deletion;
- restrict or object to certain processing;
- request portability of information;
- withdraw consent where processing relies on consent; and
- complain to an applicable data-protection authority.
These rights may be subject to legal limitations and identity verification. GDPR transparency rules require clear information about processing and provide individuals with rights concerning their personal data.
12. International processing
ClinicOS Publisher, participating businesses, Meta, and service providers may operate in different countries. Information may therefore be processed outside the country in which it was originally collected.
Where required, appropriate safeguards will be used for international transfers.
13. Children’s privacy
ClinicOS Publisher is a business administration and publishing tool and is not directed to children.
Authorized users must not upload or publish children’s personal information unless they have a lawful basis and all necessary permissions to do so.
14. Changes to this policy
We may update this policy to reflect changes in ClinicOS Publisher, legal requirements, security practices, or Meta platform requirements.
The updated policy will be posted on this page with a revised effective date.
15. Contact us
Questions, privacy requests, or data-deletion requests may be submitted to:
WellPlanet
Email: support@wellplanet.com
Website: https://wellplanet.com/
Please include “ClinicOS Publisher Privacy Request” in the subject line. Do not include passwords, access tokens, application secrets, or sensitive health information.