Privacy Policy
Effective date: 22 July 2026
This Privacy Policy explains how DoulaOne (“we”, “us”, or “our”) collects, uses, stores, and protects personal data when you use our website and practice-management platform at doulaone.com.
1. Who we are
Data controller: Aku Online Limited, 167-169 Great Portland Street, Greater London, England, W1W 5PF
ICO registration: ZC202516
Contact: contact@doulaone.com
DoulaOne is a software platform for birth and postpartum doulas to manage their practice. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Roles: controller and processor
Your account data. When you sign up for DoulaOne, we act as the data controller for your account information (name, email, workspace settings, and related usage data).
Your clients' data. When you store client records, notes, contracts, birth preferences, invoices, and documents in DoulaOne, you are the data controller for that information and we act as your data processor. You are responsible for having a lawful basis to collect and process your clients' personal data, for providing appropriate privacy notices to your clients, and for obtaining any required consents.
Our processing of your clients' data on your behalf is governed by our Data Processing Agreement. If you have questions about data we process on your behalf as a processor, contact us at contact@doulaone.com.
3. What data we collect
Account and authentication data
- Name and email address
- Password (stored securely via our authentication provider)
- Google account information if you choose “Continue with Google” (email and basic profile data from Google)
- Workspace name, team membership, and role
Practice and client data you enter
- Client names, contact details, and due dates
- Pipeline stage, appointments, and calendar information
- Clinical and care notes (prenatal, birth, postpartum), birth preferences, and follow-up records
- Contracts, intake form responses, and e-signatures
- E-signature audit information captured when a client signs a document (signer name, IP address, browser/user-agent, the signature image, and a tamper-evidence hash of the signed document)
- Invoices, service packages, and payment records. You can log payments you collect outside the platform, or, if you enable online payments, we record payment status and Stripe payment references (see Section 8). Card details are handled by Stripe, not stored by DoulaOne.
- Documents and files you upload (e.g. agreements, resources, branding)
- Documents we generate on your behalf (e.g. signed agreement PDFs)
- Messages and communications you record in the platform
Technical and usage data
- IP address, browser type, device information, and access logs
- Session and authentication cookies (see Section 15)
- Error and performance data necessary to operate the service
- Approximate region derived from your IP address (country and timezone) on our public pages, so we can show relevant pricing and default settings. We use hosting-provider location headers and, where needed, a geolocation lookup via ipapi.co (see Section 8).
- First-party interaction counts on public profile and directory pages (e.g. page views and link clicks) so doulas can see how their public pages perform. These aggregate counts do not store your IP address or otherwise identify you, and we do not use third-party advertising or analytics trackers (see Section 15).
Optional integrations
- Stripe: online payments and subscription billing. When you enable online payments or subscribe to a paid plan, Stripe processes your and your clients' payment details and we store Stripe references and payment status. See Section 8.
- Google Calendar: optional integration; see Section 6 for how we access and use Google user data.
- Zoom: optional integration; see Section 7 for how we access and use Zoom user data. When connected, we store your Zoom account email and OAuth tokens so we can create meeting links for your appointments.
- Calendly: optional integration. When connected, we store your Calendly account email and OAuth tokens, and receive booking details (such as an invitee's name, email, and meeting time) via webhook so we can create matching clients and appointments in DoulaOne. See Section 7.
- Email delivery: recipient addresses and message content for transactional emails (e.g. appointment reminders) you send through the platform
Demo and sales-lead data
When you request a demo on our public demo page, we (DoulaOne, acting as controller) collect the details you submit: your name, email, optional phone number, company or practice, job title, team size, and how you plan to use DoulaOne. If you book a live demo we also store your chosen time. We record whether you agreed to this policy and whether you opted in to product updates.
- Lawful basis: our legitimate interest in responding to demo requests and running our business, and your consent for any optional marketing updates (which you can withdraw at any time).
- Retention: demo and sales-lead records are kept only as long as needed to follow up and are then automatically deleted. You can ask us to erase your demo data sooner by contacting us (see Section 13).
Marketing and mailing lists
If you join our waitlist, sign up for our directory newsletter, or opt in to product updates (for example, when requesting a demo), we add your name and email to a marketing contact list managed through Brevo so we can send you updates. We send these messages on the basis of your consent, and you can unsubscribe at any time using the link in each email or by contacting us. Unsubscribing does not affect the transactional emails required to operate your account.
4. Sensitive personal data
Birth work often involves information that may qualify as sensitive personal data under GDPR Article 9, including health-related notes, pregnancy and birth details, and other confidential care information.
You should only enter such data where you have a lawful basis and, where required, explicit consent from the data subject. DoulaOne provides access controls (workspace isolation, confidential notes, private document storage) to help you protect this information, but you remain responsible for how you collect and use your clients' data.
5. How and why we use your data
We use personal data to:
- Provide, maintain, and improve the DoulaOne platform
- Create and manage your account and workspace
- Authenticate you and keep your session secure
- Store and display the practice data you enter
- Enable client-facing features (e.g. contract signing, intake forms)
- Process subscription billing and, where you enable it, online client payments through Stripe
- Detect your approximate region to show relevant pricing and defaults
- Provide aggregate performance insights for your public pages, and send marketing emails where you have opted in
- Understand how you use the app so we can improve it (product analytics on feature usage only — never your clients' content or health data; see below)
- Send transactional emails you request (e.g. reminders)
- Sync appointments to Google Calendar when you opt in
- Create Zoom meeting links for appointments when you connect Zoom
- Import Calendly bookings as clients and appointments when you connect Calendly
- Respond to support requests and enforce our Terms of Service
- Comply with legal obligations
Legal bases (GDPR Article 6)
- Contract: processing necessary to provide the service you signed up for
- Legitimate interests: security, fraud prevention, service improvement, and support — balanced against your rights
- Consent: optional integrations (e.g. Google Calendar) and, where applicable, sensitive data you choose to store as a controller
- Legal obligation: where we must retain or disclose data under applicable law
Product analytics. To improve DoulaOne, we collect privacy-conscious analytics about how you (the doula) use the app — for example that an invoice was created or an appointment was scheduled. This is collected server-side and includes only feature-usage metadata tied to a pseudonymous account identifier. It does notinclude your clients' names, contact details, notes, or any health data, and it does not set cookies on your device. We process this data on the basis of our legitimate interest in understanding and improving the product, balanced against your rights. You can turn it off at any time under Settings → Privacy.
6. Google user data
This section describes how DoulaOne accesses, uses, stores, shares, and deletes information received from Google when you use Continue with Google to sign in or when you choose to connect Google Calendar in Settings. These features are optional and require your consent.
Data accessed. With your permission, DoulaOne may access:
- Google account email (
userinfo.email) — to create or identify your DoulaOne account when you sign in with Google, and to show which Google account is connected when you link Google Calendar. - Basic profile information (when signing in with Google via our authentication provider) — such as your name and profile picture, only if you choose Continue with Google.
- Google Calendar events (
calendar.events) — only when you connect Google Calendar. We use this scope to create, update, and delete appointments you schedule in DoulaOne on your primary Google Calendar, and to optionally add Google Meet links. We do not read or import your existing Google Calendar events. - OAuth tokens — access and refresh tokens issued by Google when you connect Google Calendar, stored so the integration can operate until you disconnect.
Data usage. We use Google user data only to:
- Authenticate you when you choose Continue with Google
- Sync appointments you create or manage in DoulaOne to your Google Calendar (one-way sync)
- Display the connected Google account email so you can verify or disconnect the integration
- Operate, maintain, and troubleshoot these features
We do not use Google user data for advertising, profiling, or to train artificial intelligence or machine learning models.
Data sharing. We do not sell Google user data. We do not share it with third parties except:
- Infrastructure providers that host or store data on our behalf and only as needed to operate the service (e.g. Supabase for encrypted database storage, Vercel for application hosting)
- Google, when you interact directly with Google's sign-in or OAuth consent screens
- Where required by applicable law or to protect our legal rights
DoulaOne's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data storage and protection. Google OAuth tokens and related connection data are stored in our database (Supabase, EU — Paris region). We protect data using encryption in transit (HTTPS/TLS), workspace-level row-level security, access-controlled file storage, server-side authentication, and restricted access to production systems and secrets.
Data retention and deletion. We retain Google OAuth tokens and calendar connection data only while your Google Calendar integration is connected. You can revoke access at any time by clicking Disconnectunder Settings → Integrations, which deletes the stored tokens from DoulaOne. You can also revoke DoulaOne's access in your Google Account at myaccount.google.com/permissions. To request deletion of your DoulaOne account and associated Google connection data, email contact@doulaone.com.
7. Zoom and Calendly user data
This section describes how DoulaOne accesses, uses, stores, and deletes information received from Zoom and Calendly when you connect these optional integrations in Settings → Integrations. Both integrations require your consent and can be disconnected at any time.
Zoom. When you connect Zoom, with your permission DoulaOne accesses:
- Your Zoom account email (scope
user:read:user) — to show which Zoom account is connected. - Meeting creation (scope
meeting:write:meeting) — to create scheduled Zoom meetings for appointments you book in DoulaOne and save the resulting join link on the appointment. - OAuth tokens — access and refresh tokens Zoom issues when you connect, stored so the integration can operate until you disconnect.
We use Zoom data only to create and manage meeting links for your appointments and to display the connected account. We do not read your existing Zoom meetings, join meetings on your behalf, or access recordings or transcripts. We do not sell Zoom data or use it for advertising, profiling, or to train artificial intelligence or machine learning models.
Calendly.When you connect Calendly, with your permission DoulaOne accesses your Calendly account email and OAuth tokens, and registers a webhook so Calendly can notify us of new and cancelled bookings. For each booking we receive the invitee's name, email address, event name, and scheduled time, which we use to create or update a matching client and appointment in DoulaOne. We do not sell Calendly data or use it for advertising or model training.
Storage and protection. Zoom and Calendly OAuth tokens and related connection data are stored in our database (Supabase, EU — Paris region), protected by encryption in transit (HTTPS/TLS), workspace-level row-level security, server-side authentication, and restricted access to production systems and secrets.
Retention and deletion. We retain each integration's tokens and connection data only while it is connected. You can revoke access at any time by clicking Disconnectunder Settings → Integrations, which deletes the stored tokens from DoulaOne (and, for Calendly, removes the booking webhook). You can also revoke DoulaOne's access from your Zoom or Calendly account settings. To request deletion of your account and associated connection data, email contact@doulaone.com.
8. Payments (Stripe)
We use Stripe to process payments. Stripe acts as an independent controller of the payment card and transaction data it collects, under its own privacy policy. DoulaOne does not receive or store full card numbers.
Subscription billing. When you subscribe to a paid plan, Stripe processes your payment method and billing details. We store references such as your Stripe customer and subscription IDs, plan, billing status, and renewal dates so we can manage your subscription.
Online client payments (Stripe Connect). If you enable online payments, you connect a Stripe account (Stripe Connect) and become the merchant for payments your clients make to you. When a client pays an invoice online, Stripe collects their payment details directly, and we record the payment status and Stripe references against the invoice. For these payments you are the controller of your clients' data and Stripe is your payment processor; where a platform fee applies, we facilitate the payment as described in our Terms.
We do not sell payment data or use it for advertising, profiling, or to train artificial intelligence or machine learning models.
9. Sub-processors and third parties
We use trusted third-party providers to operate DoulaOne. They process data only on our instructions and under appropriate agreements:
- Supabase — database, authentication, and file storage (hosted in the EU, Paris region)
- Vercel — website and application hosting
- Brevo — transactional email delivery and, where you opt in, marketing and newsletter email
- Stripe — subscription billing and optional online client payments (see Section 8)
- Mapbox — map display on our public doula directory
- NHS Website Content API — used, for UK workspaces, to fetch and cache NHS health content in the resources library
- ipapi.co — IP-based region lookup on our public pages, used only where hosting-provider location data is unavailable
- Google — optional Sign-in with Google and Google Calendar / Meet integration
- Zoom — optional integration to create meeting links for appointments
- Calendly — optional integration to import bookings as clients and appointments
- OpenAI — optional AI assists. Only used when a workspace owner turns on AI features. When enabled, the content you choose to process is sent to OpenAI to generate a draft you review — for example a contract, package, or intake-form draft, structured client details extracted from an intake response, or a birth-plan narrative drawn from notes you select, which may include health-related information. OpenAI does not use data submitted through its API to train its models, and we do not enable AI features by default.
- Mixpanel — privacy-conscious analytics, stored in the EU. We use it in two ways: on our public pages, only after you opt in through the cookie banner (see Section 15); and inside the app to measure how doulas use features (server-side, feature-usage metadata only). No client details, notes, or health data are ever sent to Mixpanel, and the in-app analytics can be turned off under Settings → Privacy (see Section 5).
We do not sell your personal data and we do not use third-party advertising trackers. For how we handle information received from Google APIs, see Section 6.
10. International transfers
Your data is primarily stored in the European Union (Supabase eu-west-3, Paris). Some sub-processors may process data in countries outside the UK and EEA that are not covered by a UK or EU adequacy decision (for example, the United States). Where that is the case, we rely on appropriate safeguards recognised under UK and EU data protection law — such as the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or an adequacy mechanism such as the UK Extension to the EU-US Data Privacy Framework where the recipient is certified — and we carry out a transfer risk assessment before relying on them.
You can request a copy of the safeguards we rely on for a particular transfer by emailing contact@doulaone.com.
11. Data retention
We retain your account and workspace data for as long as your account is active. If you close your account, we will delete or anonymise your data within a reasonable period, except where we must retain it for legal, security, or dispute-resolution purposes.
As a processor, we retain client data you store in DoulaOne according to your instructions and our Terms of Service. You can export or delete your data through the platform where those features are available, or by contacting us.
12. Security
We implement technical and organisational measures to protect data, including:
- Row-level security isolating each workspace's data
- Private, access-controlled file storage with signed URLs
- Encryption in transit (HTTPS/TLS)
- Server-side authentication and access controls
- Restricted access to production systems and secrets
DoulaOne is designed for confidential doula practice data. Most US doulas are not HIPAA-covered entities, and DoulaOne is not currently offered as a HIPAA-compliant or BAA-covered service. If you require HIPAA-grade controls, contact us before storing regulated health information.
13. Your rights
Under GDPR and UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request erasure (“right to be forgotten”)
- Restrict or object to certain processing
- Data portability (receive your data in a structured format)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office)
To exercise your rights, email contact@doulaone.com. We will respond within one month, as required by law.
If you are a client of a doula who uses DoulaOne, please contact that doula directly to exercise your rights regarding data they control. We will assist our customers (doulas) in responding to such requests as their processor.
14. Children
DoulaOne is intended for professional use by doulas and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. For material changes, we will provide notice through the platform or by email where appropriate.
17. Contact us
For privacy questions, data subject requests, or processor enquiries:
See also our Terms of Service.
