1. Send a deletion request
Email founder@flowrahq.com with the subject “Flowra data deletion request”. Include only the information needed to find the record:
- Your name and preferred reply email.
- The clinic or Flowra workspace involved.
- The phone number or work email connected to the record.
- Whether you want an account disconnected, a record deleted, or both.
Protect your privacy: do not send medical records, diagnosis details, access tokens, passwords, or Meta app secrets by email.
Start a deletion request2. We verify authority
ERA verifies that the requester is authorized to act for the account or record. Patients may be referred to their clinic because the clinic normally controls its patient records. ERA will not disclose unrelated patient or clinic information during verification.
3. We disconnect and delete
After verification, ERA will identify the applicable account, message, appointment, integration, log, and backup records. ERA will remove, anonymize, restrict, or return data as required by the clinic instructions, the UAE Personal Data Protection Law, Egyptian Law No. 151 of 2020 where it applies, applicable healthcare rules, and other binding legal obligations.
Deletion may be limited where information must be retained for legal claims, security, fraud prevention, a healthcare retention requirement, or another lawful obligation. ERA will restrict retained information to the applicable purpose and retention period.
For WhatsApp connections, ERA can revoke or delete stored credentials and unsubscribe Flowra from the clinic’s WhatsApp Business Account webhooks. The clinic can also remove the app from its Meta business settings.
4. We confirm the result
ERA works to the following timeframes:
- Acknowledgement — within 5 business days of receiving the request. ERA confirms receipt and explains any identity or clinic authorization still needed.
- Completion — within 30 calendar days of a verified request. ERA confirms what was disconnected, deleted, anonymized, restricted, or retained.
- Extension — a further 30 calendar days where a request is complex or involves more than one clinic workspace. ERA will explain the reason before the first period ends.
Where an applicable law sets a shorter statutory period for a particular type of request, ERA follows the statutory period. If a record must be retained or the request is routed to the controlling clinic, the response will explain that boundary.
This public page may be used as Meta’s user-facing data-deletion instructions URL. A production Meta data-deletion callback still requires a live server endpoint and signed-request handling before submission.
Questions
Services Licence No. 47016643 · Ras Al Khaimah Economic Zone (RAKEZ)
VUET0040, Compass Building, Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates