AI Booking Systems for Med Spas

Med Spa Owners: How To Add $30K/Month In Bookings Without Hiring A Single New Staff Member

We install a 24/7 AI booking system inside your Med Spa that answers every missed call, follows up with every lead, and fills your calendar 3 weeks out, without you lifting a finger or hiring more staff.

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

85% Of callers who hit voicemail never call back Spa Voices — medical spa call research
23–34% Typical no-show rate at aesthetic practices nationwide Prospyr Med — aesthetic practice industry data
21× More likely to qualify leads contacted within 5 minutes Harvard Business Review — lead response study
Founding Partners, Miami

We're Onboarding Our First 6 Med Spas in Miami

Founding partners get priority setup, locked partnership terms, and direct operator access. Pricing is shared on your strategy call once we confirm fit.

Only 6 founding spots. Once Miami is full, we close the cohort.

Claim a Founding Spot →

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

Your Chairs Are Empty. Not Because You're Not Good.

You didn't build a Med Spa to watch leads slip away between treatments. Every gap in your booking funnel is revenue walking out the door, and your competitors are catching it.

01

Every Voicemail Hands Revenue to the Spa Down the Street

It's 6:47pm on a Tuesday. Someone searched "Botox near me" and called you. You're with a client. The call rings out. Within 90 seconds they've booked elsewhere. That client was worth $2,400 over the next 12 months. Gone.

02

Leads Go Cold While Your Team Is Busy

A $800 injectable inquiry sits in your inbox for 6 hours. By the time someone follows up, they've already booked a consult at another Med Spa. One slow response costs you $800 today, and thousands in lifetime value.

03

Empty Chairs From No-Shows

Three no-shows this week at $450 per treatment slot. That's $1,350 gone, before you count the staff time you paid for. Multiply that across a month and you're bleeding five figures from holes in your calendar.

04

Your Best Staff Stuck Doing Admin

Your front desk spends 15 hours a week on reminders, follow-ups, and chasing voicemails instead of upselling packages. That's $900+ in labour doing work a system should handle, while high-value clients wait on hold.

05

Invisible When Clients Search

Prospects compare Google ratings before they call. If you're at 4.1 stars and the Med Spa next door is at 4.8, you lose the call before it rings. Every week without review momentum is market share you'll never get back.

06

Ad Spend With No Backend

You're paying $3,000–$8,000 a month on ads. Half those clicks never get a follow-up within 5 minutes. You're not losing on marketing, you're losing on the 48 hours after the click when nobody owns the lead.

Here's What Waiting Another Month Is Costing You

Conservative math for an established Med Spa running 4+ treatment rooms. This is revenue you're already losing, not a projection.

$6,000+

Missed calls & slow follow-up

~2 lost booking opportunities per day at $500+ average treatment value. Voicemail and delayed replies add up fast.

$2,400+

No-shows & last-minute cancellations

Industry no-show rates of 23–34% on a full book means thousands in empty chair time every month.

$4,000+

Dead leads in your CRM

Hundreds of past inquiries and dormant clients never reactivated, instant revenue sitting untouched.

$12,000–$15,000+ per month in recoverable revenue, without spending another dollar on ads or hiring another body.

Revenue Leakage Calculator

See how much your Med Spa is likely losing to missed calls and slow follow-up. Adjust the sliders to match your numbers.

Your call volume

Excludes existing patients, support, and wrong numbers.

Your economics

Estimated revenue leaking

$6,552

per month from missed opportunities

Missed inquiry calls / mo 47
Annual leakage $78,624

Estimates only. Based on your inputs, not a guarantee of recoverable revenue. Most Med Spas recover a meaningful portion with 24/7 response and automated follow-up.

Stop The Leak, Book Your Audit →

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

Introducing

The Med Spa Revenue OS

One done-for-you system built exclusively for Med Spas: capture every inbound lead, nurture until they book, protect your calendar from no-shows, and compound bookings month over month. Your phone gets answered at 9pm. Your calendar fills 3 weeks out. You stay in the treatment room.

How The Med Spa Revenue OS Works

Three named phases. Clear deliverables. You don't touch the tech, we install, run, and optimise everything.

0
Day 0 Audit booked
7
Day 7 Report delivered
14
Day 14 Systems live
30
Day 30 First review
01

The 47-Point Revenue Leak Audit

  • Full funnel diagnostic — calls, leads, no-shows, reviews
  • Written report: $ lost per month, by leak
  • Delivered within 7 days of kickoff
02

14-Day AI Booking Stack

  • AI Receptionist + 21-day nurture live
  • No-show system + review accelerator
  • Branded to your spa, integrated with your software
03

Monthly Compounding Review

  • 30-day performance review every month
  • Flows optimised based on your data
  • Month-3 bookings typically 2× month-1

Three Systems That Fill Your Calendar

The core of The Med Spa Revenue OS, everything else is included as part of your Growth partnership.

24/7

The 24/7 AI Receptionist

Answers every call and text inquiry, qualifies leads, and books appointments into your calendar, during treatments, after hours, and on weekends when high-intent clients actually reach out.

21D

The 21-Day Lead Conversion Sequence

Automated SMS and email nurture that follows up with every lead at the right moment, so cold Botox and laser inquiries become booked consults without your team chasing them.

NS

The No-Show Killer System

Smart confirmations and reminder flows that protect your chair time, because an empty $450 slot hurts more than a bad review.

Also included in every Growth partnership

Review Accelerator
Reactivation Campaigns
Revenue Analytics Dashboard
Done-for-you setup & integration
Dedicated account manager

What Life Looks Like After Go-Live

Not features. Outcomes you'll feel in the first 30–60 days.

What Med Spa Owners Are Saying

Early partner feedback from practices using The Med Spa Revenue OS.

Excellent
Based on founding partner reviews
★★★★★

"We were missing calls every evening after injectable hours. Within three weeks our front desk stopped playing catch-up and consults started booking while we were still in treatment."

P
Dr. Raj Patel Medical Director, Coral Gables Aesthetics Verified founding partner
★★★★★

"No-shows were killing us on Fridays. The reminder flows alone paid for the system. My calendar is fuller and my team finally stopped living in the inbox."

S
Dr. Elena Sanchez Owner, Sanchez Med Spa, Brickell Verified founding partner
★★★★★

"I was sceptical about AI answering for a medical aesthetics brand. It sounds on-brand, books correctly, and we recovered leads we would have lost to voicemail."

R
Dr. Marco Rodriguez Founder, Rodriguez Skin Institute Verified founding partner

Why Med Spas Are Bleeding Revenue

Industry data — not agency claims. This is the problem we built The Med Spa Revenue OS to solve.

Get My Free Revenue Leak Audit →

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

$215K No-shows can cost aesthetic practices up to $215,000 per year in lost treatment revenue. Prospyr Med — aesthetic practice industry analysis
40–50% Reduction in no-shows when practices use automated text-based appointment reminders. Prospyr Med — practice management research

Get Plenta vs. The Alternatives

There's no shortage of tools claiming to help you grow. Here's how we actually compare.

Feature ✦ Get Plenta Generic CRM Hiring Staff DIY Tools
24/7 Lead Response
Industry-Specific Automation
No-Show Reduction System
Automated Review Generation
Reactivation Campaigns
Done-For-You Setup
Live in Under 14 Days
Revenue Analytics Dashboard

Everything Included. Zero Tech Headaches.

We're your complete growth team, strategists, engineers, and operators all in one partnership.

Full system build & setup included
Branded to your spa's identity
Integrates with your existing booking software
Dedicated account manager assigned to you
Monthly performance reviews & reporting
Priority support via Slack & email
BOOK NOW

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

What You'd Pay To Do This Without Get Plenta

Stack the real cost of hiring and tooling, then compare one done-for-you partnership.

Full-time receptionist (40 hrs/week)$3,600/mo
SMS & email marketing platform$400/mo
Review management software$250/mo
Marketing automation specialist (part-time)$2,500/mo
Total, and you still manage them all$6,750/mo

Comparable Med Spa growth systems run $5,000–$8,000/mo, and you still manage every piece. On your strategy call, we'll show you exactly what Get Plenta costs for your spa and how it stacks up.

BOOK NOW

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

The $30K Guarantee

If we don't add at least 25 new booked appointments to your calendar in your first 60 days, we work for free every month until we do. Period. No fine print. No "measurable increases." Either your calendar fills, or you don't pay us.

Pricing is shared on your strategy call once we confirm fit. Comparable agencies charge $5,000–$8,000/mo for less coverage.

BOOK NOW

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

Questions We Get Asked Often

Most clients see their first wave of new automated bookings within the first 7–14 days of going live. Significant, measurable improvement in booking volume and no-show reduction typically becomes clear by day 30. The system compounds month over month as it gathers more data about your specific clients and conversion patterns.

Absolutely not. We handle every technical aspect from setup to ongoing management. You’ll simply review a simple dashboard and have a monthly strategy call with your account manager. If you can send a text message, you can use Get Plenta. We specifically designed the owner experience to be as friction-free as possible.

Yes. We integrate with all major Med Spa and Wellness booking platforms including Mindbody, Jane App, Vagaro, Booker, Zenoti, Aesthetic Record, and more. If you use a platform not on this list, our engineers will assess and build a custom integration at no additional cost.

Most CRMs are tools you configure yourself, they require you to hire someone to manage them. Marketing agencies run campaigns but don't own your backend systems. Get Plenta is an operator: we build, manage, and continuously optimise your entire client acquisition engine. We're not a tool. We're the team behind the tool, exclusively focused on the Med Spa and Wellness space.

No. Get Plenta operates on a simple month-to-month basis. We earn your business every single month through results. If you ever decide to leave (which our retention data shows almost never happens), you give 30days notice and your systems are safely offboarded. We believe in earning loyalty through performance, not locking you into contracts.

Contact Us

Have questions about how The Med Spa Revenue OS can work for your practice? Reach out directly or subscribe for updates.

25 New Bookings In 60 Days, Or We Work For Free

Book your free 30-minute Revenue Leak Audit. We'll map exactly where your Med Spa is losing bookings and show you what The Med Spa Revenue OS would recover, even if you never become a client.

No commitment required Free & personalised audit Results within 30 days Works with your existing setup

Claim Your Free Growth Audit

6 founding spots in Miami. Once they're filled, this cohort closes.

You'll speak directly with Dax, not a sales rep.

Operator-led onboarding for every founding partner. Replace this line with your background, years in med spa, prior roles, why you built Get Plenta.

BOOK MY FREE GROWTH AUDIT →

By clicking you agree to receive automated booking updates and reminders via text message from GetPlenta Ltd. Consent is not a condition of booking. Message and data rates may apply. Message frequency varies. Reply STOP to opt out. View our Privacy Policy.

Privacy Policy

GetPlenta Ltd · Governed by English law

01

About Us

GetPlenta Ltd (referred to throughout as "GetPlenta Ltd," "we," "us," or "our") is a company incorporated and registered in England and Wales with registered office at 128 City Road, London, EC1V 2NX. We provide AI-powered voice agent technology and automation services, including inbound and outbound call handling, appointment booking, patient lead qualification, 21-day automated lead conversion sequences, and front-desk automation — specifically designed for Med Spa practices operating in the United States.

This Privacy Policy is a business-to-business (B2B) document directed at Med Spa owners, clinic directors, practice managers, and their authorised representatives (collectively, "Clients" or "Business Clients") who engage GetPlenta Ltd's services. It is not directed at individual consumers or patients of any Med Spa.

02

Scope & Applicability

This Policy applies to all personal data and Protected Health Information (PHI) that GetPlenta Ltd accesses, processes, or transfers in the course of delivering its services to Business Clients. This includes:

  • Data exchanged via API integrations with Client booking systems and electronic health records (EHRs)
  • Caller identity and scheduling data processed during live AI voice interactions
  • Contact and company data of Business Clients and their authorised staff
  • Technical and usage data generated through the operation of GetPlenta Ltd's AI infrastructure
Important Notice

If you are a patient of a Med Spa that uses GetPlenta Ltd's services and wish to understand how your personal data is handled, you should refer to the privacy notice published by that Med Spa directly. GetPlenta Ltd processes patient data solely on behalf of, and under the instruction of, the relevant Med Spa Client.

This Policy does not constitute legal advice. Med Spa Clients remain independently responsible for ensuring their own HIPAA compliance, state-level healthcare privacy obligations, and applicable consumer privacy laws (including CCPA) in respect of their patient relationships.

03

Who We Are Under UK GDPR

GetPlenta Ltd is incorporated in England and Wales and is therefore subject to the UK General Data Protection Regulation (UK GDPR) as retained and amended by the Data Protection Act 2018 (DPA 2018). The UK Information Commissioner's Office (ICO) is our lead supervisory authority.

Data Controller vs. Data Processor

Data CategoryGetPlenta Ltd's RoleBasis
Business Client Data Independent Data Controller We determine purposes and means of processing contact details, account information, and correspondence of Business Clients and their staff.
Patient / End-User Data Data Processor & HIPAA Business Associate We process patient data only on documented instruction from the Business Client. No independent right to use this data for our own purposes.
Technical & Log Data Data Controller Anonymised or aggregated technical data used solely for infrastructure security, performance monitoring, and service improvement.

Lawful Basis for Processing

  • Contract performance (Article 6(1)(b) UK GDPR): Processing necessary to perform our service agreements with Business Clients.
  • Legitimate interests (Article 6(1)(f) UK GDPR): Processing for fraud prevention, system security, and service improvement.
  • Legal obligation (Article 6(1)(c) UK GDPR): Processing required to comply with applicable law.

04

How We Use Your Business & Commercial Data

When you engage with GetPlenta Ltd to explore our services, book a discovery call, or enter into a service agreement, we collect and process business and commercial data. This section explains what we collect, why we process it, and which third parties we share it with.

What Commercial Data We Collect

Your business and commercial information is collected through multiple touchpoints:

  • Contact & Scheduling Information: Your name, corporate email address, phone number, and appointment notes you provide via Cal.com when booking a discovery or demo call.
  • Business Process Information: Operational details, internal workflows, system configurations, and business challenges you share before or during discovery conversations to help us evaluate service fit and tailor our pitch.
  • Financial & Contractual Data: Your business registration details, registered address, billing address, and transaction records necessary to issue invoices, process payments, facilitate international bank transfers, or generate secure payment links.
  • Account Administration Data: API credentials, dashboard access logs, support tickets, and onboarding documentation required to deliver and manage your GetPlenta Ltd subscription.

Our Lawful Basis for Processing Your Commercial Data

Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal frameworks to process your commercial data:

  • Contractual Necessity (Article 6(1)(b)): We process your scheduling data, business process details, and account administration information because it is necessary to take steps at your request prior to entering into a formal service agreement with us, and to perform the contract once executed. Without this data, we cannot evaluate your requirements, deliver our services, or manage your account.
  • Legal Obligation (Article 6(1)(c)): We retain invoicing, financial records, and transactional data to comply with UK statutory accounting requirements, tax obligations (HMRC), and company law (Companies House).
  • Legitimate Interests (Article 6(1)(f)): We process your business details to tailor our service delivery, improve our advisory and onboarding processes, maintain professional commercial communications, prevent fraud, and enhance service quality based on aggregated usage patterns. These interests are balanced against your rights and do not override your reasonable expectations of privacy.

Third-Party Data Processors & Data Sharing

GetPlenta Ltd does not sell, rent, or trade your commercial data. To deliver our services, process payments, and comply with legal obligations, we securely share minimal, necessary data with the following trusted third parties who act as our data processors or service providers under Data Processing Agreements:

ProcessorPurposeData Shared
Cal.com, Inc. Scheduling and managing business discovery, demo, and assessment calls Name, email, phone number, appointment preferences, meeting notes
Stripe, Inc. Processing credit and debit card payments, generating secure billing links, and managing subscription billing Billing name, email, business address, transaction history (not raw card data — PCI-DSS compliant)
Wise Payments Limited Facilitating international business-to-business bank transfers and US ACH payments for invoicing and business payments Business name, registered address, banking details, transaction records
GoHighLevel (Keap, Inc.) CRM, workflow automation, client account management, and infrastructure for AI voice and messaging services Account details, contact information, service usage logs, integration credentials (encrypted)
HM Revenue & Customs (HMRC) UK corporate tax reporting, VAT compliance, and statutory business filings where legally required Company registration details, transaction records, invoicing data (as required by law)

Data Security & Processor Obligations

All third-party processors are contractually obligated to:

  • Maintain data security standards equivalent to or exceeding those described in Section 10 (Security & Encryption)
  • Process your data only on our documented instructions
  • Not use your data for any purpose other than delivering the contracted service
  • Implement appropriate technical and organisational safeguards (encryption, access controls, audit logging)
  • Notify us immediately of any suspected data breach or unauthorized access
  • Delete or return data upon termination of the service relationship

Your Rights Regarding Commercial Data

As the subject of commercial data processing, you have the following rights under UK GDPR:

  • Right of Access: Request a copy of the commercial and financial data we hold about your business.
  • Right to Rectification: Request correction of inaccurate business or billing information.
  • Right to Erasure: Request deletion of your data where there is no ongoing legal basis for processing (subject to statutory accounting retention obligations).
  • Right to Data Portability: Request your business data in a structured, machine-readable format suitable for transfer to another service provider.
  • Right to Object: Object to processing for legitimate interest purposes, though we may retain data where legally required for tax or contract purposes.

To exercise any of these rights, contact us at privacy@getplenta.ai. We will respond within 30 days.

05

HIPAA Compliance

✓ HIPAA-Compliant Infrastructure

GetPlenta Ltd operates on GoHighLevel's HIPAA-enabled platform, which includes a Business Associate Agreement (BAA) with GoHighLevel. This means all client data — including any Protected Health Information (PHI) — is stored and processed within a HIPAA-compliant environment by default.

GetPlenta Ltd processes data on behalf of medical spa clients using HIPAA-compliant infrastructure. All client data (including any Protected Health Information, or PHI) is stored and processed within sub-accounts on GoHighLevel's HIPAA-enabled platform, which operates under a Business Associate Agreement (BAA) with us.

When GetPlenta Ltd provides services to a medical spa that involves processing PHI, we act as a "business associate" under HIPAA and enter into a Business Associate Agreement (BAA) directly with the medical spa client. This agreement governs how PHI is collected, used, stored, and protected.

Our HIPAA Compliance Posture

  • End-to-end encrypted data storage through our HIPAA-compliant infrastructure provider (GoHighLevel)
  • Restricted access controls and audit logging on all PHI
  • Signed BAAs with all sub-processors that may access PHI
  • Administrative, technical, and physical safeguards as required under HIPAA
  • Breach notification protocols compliant with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414)

What Constitutes PHI in Our Context

In the context of GetPlenta Ltd's AI voice operations, PHI may include: a patient's name, phone number, appointment date and time, treatment type (e.g., Botox, dermal fillers, laser treatment), medical history mentioned on a call, and any other individually identifiable health information created, received, or transmitted by our systems on behalf of a Covered Entity.

Business Associate Agreement (BAA) Requirement

No GetPlenta Ltd service that involves the processing of PHI shall be activated for a Client until a fully executed Business Associate Agreement (BAA) is in place. The BAA is a pre-condition to service commencement, not an optional addendum.

Breach Notification

In the event of a suspected or confirmed breach involving PHI, GetPlenta Ltd will notify the affected Business Client without undue delay and in any event within 48 hours of becoming aware of the breach — more stringent than HIPAA's 60-day minimum — providing sufficient information for the Client to meet its own HIPAA Breach Notification Rule obligations.

If you are a medical spa client and require a BAA before engagement, please contact us at privacy@getplenta.ai and we will provide one prior to onboarding.

06

CCPA — California Privacy Rights

GetPlenta Ltd serves Med Spa clients across the United States, including in California. To the extent that GetPlenta Ltd collects personal information about California residents in the course of its business operations, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), may apply.

Categories of Personal Information Collected

In the preceding 12 months, GetPlenta Ltd has collected the following categories of personal information from or about Business Clients and their staff:

  • Identifiers: Name, email address, business phone number, IP address
  • Commercial information: Service agreements, billing records, account activity
  • Internet or network activity: Dashboard usage logs, API access logs
  • Professional or employment information: Job title, business name, role within the Med Spa
  • Inferences: Service usage patterns used solely for account management and service improvement

GetPlenta Ltd does not sell personal information. GetPlenta Ltd does not share personal information for cross-context behavioural advertising.

Sources of Personal Information

Personal information is collected directly from Business Clients during onboarding, account management, and ongoing service delivery. Technical data is collected automatically through system logs associated with dashboard and API access.

Business or Commercial Purposes for Collection

  • Delivering and managing contracted AI voice agent services
  • Billing and account administration
  • Security monitoring and fraud prevention
  • Improving service performance and reliability
  • Complying with legal obligations

California Consumer Rights

California residents whose personal information GetPlenta Ltd holds as a Data Controller have the following rights under the CCPA/CPRA:

  • Right to Know: The categories and specific pieces of personal information collected about you, the sources, business purposes, and categories of third parties with whom it is shared — covering the preceding 12 months.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions (e.g., ongoing service delivery, legal obligations).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: GetPlenta Ltd does not sell or share personal information for advertising purposes. No opt-out is required, but you may contact us to confirm this.
  • Right to Limit Use of Sensitive Personal Information: GetPlenta Ltd does not use sensitive personal information for purposes beyond those necessary to provide requested services.
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising any CCPA/CPRA right.

12-Month Lookback Disclosure

This disclosure covers GetPlenta Ltd's personal information practices for the 12-month period preceding the effective date of this Policy. GetPlenta Ltd has not sold or shared the personal information of California residents during this period.

How to Submit a California Privacy Request

To exercise any CCPA/CPRA right, submit a verifiable consumer request to: privacy@getplenta.ai. We will respond within 45 days. If we require more time (up to 90 days), we will notify you of the reason and extension in writing.

07

AI Voice Agent Disclosures

Two-Party Consent & Call Recording

GetPlenta Ltd deploys AI voice agents that conduct outbound and inbound telephone calls on behalf of Med Spa clients. Several US states — including California, Florida, Pennsylvania, Massachusetts, Illinois, and others — operate under two-party (or all-party) consent laws that require all parties to a telephone conversation to consent to recording.

Disclosure Requirement

All voice calls made by GetPlenta Ltd's AI agents include a disclosure at the start of every call notifying the recipient that the call is being recorded and conducted by an AI assistant, in accordance with two-party consent laws applicable in certain US states.

This disclosure is delivered as the opening statement of every call, prior to any substantive conversation. By continuing the call after this disclosure, the recipient provides implied consent to recording in jurisdictions where such consent is required.

AI Identity Disclosure

GetPlenta Ltd's AI voice agents will not deny being an AI when sincerely asked by a recipient. If a call recipient directly asks whether they are speaking with an automated system or AI, the agent will confirm this truthfully.

HIPAA and Call Content

GetPlenta Ltd's AI voice agents are designed to handle booking logistics only. Agents do not solicit, collect, or store medical records, treatment histories, diagnosis information, or any PHI beyond what is strictly necessary to facilitate appointment scheduling on behalf of the Client.

SMS Consent — Point of Collection

Where GetPlenta Ltd or its Med Spa clients collect mobile telephone numbers via web forms for the purpose of sending marketing or operational text messages, the following consent language must appear adjacent to the phone number form field at the point of collection:

This language satisfies Twilio A2P 10DLC registration requirements and TCPA compliance obligations.

08

What Data We Process

A. Business Client Data (Controller)

  • Full name, job title, and business email address of the Med Spa owner, director, or designated account contact
  • Business name, registered address, and business telephone number
  • API credentials and system access tokens (stored in encrypted vaults, never in plain text)
  • Billing information (processed via PCI-DSS-compliant payment processors; GetPlenta Ltd does not store raw card data)
  • Communications, support tickets, and onboarding documentation

B. Patient & Caller Data (Processor / Business Associate)

This data is processed strictly under Client instruction to execute the real-time booking function. It includes:

  • Caller name and phone number (inbound call identification)
  • Appointment type, preferred date, and scheduling preferences
  • Existing patient status as retrieved from the Client's booking system
  • Treatment category requested (e.g., injectable consultation, laser treatment, facial)
  • Relevant medical screening information volunteered by the caller, where necessary to process the booking
  • Call recordings or transcripts, where the Client has enabled this feature and applicable consents have been obtained

C. Technical & Infrastructure Data (Controller)

  • API request and response logs (retained per the schedule in Section 11)
  • System performance metrics, latency records, and error logs
  • IP addresses and user-agent strings associated with dashboard access

09

How Our AI Systems Access & Process Data

Real-Time API Read Operations

When an inbound call is received, our AI system authenticates with the Client's booking platform (such as Mindbody, Boulevard, or Zenoti) using OAuth 2.0 or API key credentials supplied by the Client. The system queries availability in real time — fetching open appointment slots, provider schedules, and where relevant, confirming whether the caller exists as a patient in the booking system. This read operation is scoped to the minimum data required to execute the call.

Real-Time API Write Operations

Upon the caller confirming their preferred appointment, our AI system creates or updates a booking record directly within the Client's booking platform. This may involve creating a new patient profile, scheduling the appointment, and triggering automated confirmation messages.

SpecificationDetail
Supported PlatformsMindbody, Boulevard, Zenoti, and other RESTful API platforms
AuthenticationOAuth 2.0 / API Key (Client-provisioned, rotated per security schedule)
Transport ProtocolHTTPS (TLS 1.3 minimum, TLS 1.2 where required)
Data-at-Rest EncryptionAES-256 for all temporarily cached session data
Scope of AccessRead: availability and patient lookup only. Write: booking creation and patient profile update only. No bulk export.
Session DurationAPI session scoped to active call. Ephemeral data discarded upon call completion.

10

Data Minimization Principle

GetPlenta Ltd operates under a strict data minimization architecture, consistent with Article 5(1)(c) of the UK GDPR and the HIPAA minimum necessary standard (45 CFR § 164.502(b)).

  • No bulk data ingestion: We do not ingest or replicate entire patient databases. API calls are scoped to individual patient lookups triggered by a live caller interaction.
  • No persistent PHI storage: Caller PHI is held in ephemeral, in-memory processing only for the duration of the call. It is not written to GetPlenta Ltd's permanent storage unless call recording is enabled by the Client under the terms of the BAA.
  • No secondary use: Data accessed on behalf of one Client will never be used for model training, marketing, or any purpose benefiting another Client or GetPlenta Ltd's commercial activities without explicit, documented consent.
  • Field-level access control: API integrations are configured to request only the data fields required for booking functionality. Sensitive clinical fields not relevant to scheduling are excluded from all API query scopes.

11

Security & Encryption

Scheduling Platform — Cal.com

Cal.com is used solely for scheduling business discovery and demo calls with prospective and current Business Clients. Data processed includes the Client contact name, email, and phone number. This data is not shared with any other third party and is used exclusively to facilitate appointment scheduling and confirmation for business purposes.

Encryption in Transit

All data transmitted between GetPlenta Ltd's AI infrastructure and Client booking platforms is protected using HTTPS with TLS 1.3 (minimum TLS 1.2). Unencrypted HTTP connections are blocked at the infrastructure level.

Encryption at Rest

All data held on GetPlenta Ltd's infrastructure is encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management system with mandatory rotation.

Additional Security Controls

  • Access control: Role-based access control (RBAC) limits data access to personnel with a documented operational need.
  • Multi-factor authentication (MFA): Required for all GetPlenta Ltd staff accessing production systems.
  • Vulnerability management: Annual third-party penetration testing minimum. Critical vulnerabilities patched within 72 hours.
  • Intrusion detection: Automated monitoring for anomalous API activity and unauthorized access attempts.
  • PHI Breach Notification: 48-hour Client notification from point of discovery.

12

Data Retention

Data CategoryRetention Period
Ephemeral session data (PHI) Discarded upon call completion. Not written to permanent storage unless call recording is enabled by Client.
Voice recordings / transcripts 12 months from date of recording, unless compliance obligations or Client BAA require a longer period, then securely deleted.
API access & security logs Operational logs: 90 days. Security and audit logs: 12 months minimum (HIPAA Security Rule).
Marketing & lead data 24 months from last engagement, then deleted or anonymised.
Business Client account data 7 years from end of contract (UK statutory accounting and tax retention requirement).
Website analytics data 26 months from collection, consistent with Google Analytics default and ICO guidance.
BAA and contractual documents Duration of contract plus 6 years (HIPAA) / 7 years (UK contract law), whichever is longer.

Upon termination of a service agreement, GetPlenta Ltd will, within 30 days and at the Client's election, either securely return all Client data in a machine-readable format or confirm its secure destruction in accordance with NIST SP 800-88 guidelines.

13

Third-Party Sub-Processors

GetPlenta Ltd uses a limited number of trusted third-party sub-processors to deliver its services. All sub-processors are subject to:

  • A written Data Processing Agreement (DPA) or equivalent contractual instrument
  • Security due diligence prior to engagement and annually thereafter
  • Contractual restrictions prohibiting use of Client or patient data outside of service delivery
  • HIPAA Business Associate Agreements where required

Categories of sub-processors include: cloud hosting and infrastructure providers, AI voice processing services (including GoHighLevel), telephony carriers, CRM platforms, and payment processors. A current list of sub-processors is available upon written request to privacy@getplenta.ai.

GetPlenta Ltd will provide Business Clients with not less than 30 days' prior written notice of any intended change to its sub-processor list that could materially affect the processing of PHI.

14

International Data Transfers

UK-to-US Transfers

Transfers of personal data from the UK to the United States are conducted pursuant to the UK-US Data Bridge (adequacy decision adopted October 2023) where the US recipient participates in the UK Extension to the EU-US Data Privacy Framework. Where a recipient is not covered by the UK-US Data Bridge, transfers are protected by International Data Transfer Agreements (IDTAs) incorporated into our agreements with relevant sub-processors.

HIPAA and Cross-Border PHI

PHI transferred from US Clients to GetPlenta Ltd's UK-based infrastructure remains subject to HIPAA protections in full. The territorial location of GetPlenta Ltd's servers does not diminish its obligations as a Business Associate. All PHI is processed under the terms of the executed BAA regardless of where processing occurs.

15

Your Rights

Rights of Business Clients (UK GDPR)

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): Request deletion of your data where there is no lawful basis for continued processing.
  • Right to restriction (Article 18): Request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Article 20): Request your data in a structured, machine-readable format.
  • Right to object (Article 21): Object to processing based on legitimate interests.
  • Right to lodge a complaint: Lodge a complaint with the UK ICO at ico.org.uk.

Rights of Med Spa Patients

GetPlenta Ltd processes patient data only as a Data Processor and Business Associate under Client instruction. Patients seeking to exercise rights under UK GDPR, HIPAA, or applicable US state privacy laws should direct requests to the Med Spa that holds their records as the primary Data Controller and Covered Entity.

To exercise your rights as a Business Client, contact us at privacy@getplenta.ai. We will respond within 30 days.

16

Business Client Obligations

By engaging GetPlenta Ltd's services, Business Clients warrant and agree to:

  • Execute a Business Associate Agreement and Data Processing Agreement with GetPlenta Ltd prior to service activation involving PHI
  • Ensure all necessary patient notices, consents, and authorizations required under HIPAA, applicable state law, and other privacy regulations have been obtained before patient data is processed by GetPlenta Ltd's systems
  • Notify GetPlenta Ltd promptly of any changes to HIPAA Covered Entity status, business structure, or applicable regulatory obligations
  • Implement and maintain appropriate physical and organizational security measures at the Client's own premises and systems
  • Notify GetPlenta Ltd within 24 hours of becoming aware of any actual or suspected unauthorized access to API credentials or booking system integrations used by GetPlenta Ltd
  • Ensure that API credentials provided to GetPlenta Ltd maintain appropriate access privileges
  • Display required SMS consent language adjacent to all telephone number form fields on Client-operated websites and landing pages where GetPlenta Ltd's messaging services may be used

17

Cookies & Website Data

GetPlenta Ltd's public-facing website and client portal may use cookies and similar tracking technologies, used exclusively for:

  • Session authentication and security (strictly necessary cookies)
  • Website performance analytics using privacy-respecting tools configured with IP anonymization and without cross-site tracking
  • Your preferences and settings within the client portal

We do not use third-party advertising cookies, behavioral tracking pixels, or social media tracking technology on any page that handles Client data. A dedicated cookie notice is presented on first visit where consent is obtained for non-essential cookies in accordance with the UK Privacy and Electronic Communications Regulations 2003 (PECR).

18

Children's Privacy

GetPlenta Ltd's services are directed exclusively at business clients and are not intended for use by, or directed at, individuals under the age of 16. We do not knowingly collect personal information from individuals under 16 years of age. In accordance with the UK GDPR and the Age Appropriate Design Code (UK Children's Code), if we become aware that personal information has been collected from a person under the age of 16 without appropriate parental or guardian consent, we will take immediate steps to delete such information.

If you believe we may have inadvertently collected information from or about a person under 16, please contact us immediately at privacy@getplenta.ai.

19

Changes to This Policy

GetPlenta Ltd reserves the right to update this Privacy Policy at any time to reflect changes in law, regulatory guidance, or operational practices. Where changes are material — particularly where they affect the processing of PHI or the rights of Business Clients — we will provide not less than 30 days' advance written notice by email to the designated account contact on file, prior to the changes taking effect.

The current version of this Policy, including its effective date and version history, will at all times be available at our website. Continued use of GetPlenta Ltd's services following the effective date of any revised Policy constitutes acceptance of that revised Policy.

20

Contact & Data Protection

All data protection enquiries, subject access requests, BAA requests, and privacy complaints should be directed to:

EntityGetPlenta Ltd
JurisdictionEngland & Wales
Registered Address 128 City Road, London, EC1V 2NX
Privacy Emailprivacy@getplenta.ai
General Contacthello@getplenta.ai
BAA Requestsprivacy@getplenta.ai
Supervisory AuthorityUK Information Commissioner's Office (ICO) — ico.org.uk

We aim to acknowledge all data-related enquiries within 2 business days and resolve them substantively within 30 calendar days, in line with our UK GDPR and HIPAA obligations.

Governing Law: This Privacy Policy is governed by and construed in accordance with the laws of England and Wales. Any dispute arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.