Ten questions to ask any clinic software vendor, including us
Building software has never been easier, which means the gap between software that looks finished and software that is finished has never been wider. Ten questions worth asking before you move your clinic onto any system, with our own honest answers to all ten.

There is a lot of new clinic software about. Building a web app has got dramatically easier in the last couple of years, and that is genuinely good news: more competition, more ideas, better prices. It also means the gap between software that looks finished and software that is finished has never been wider.
That matters more in aesthetics than in most industries. You are not storing shopping baskets. You are storing medical histories, consent signatures, photographs of people's faces, and in many clinics prescribing records. If that leaks, it is not an inconvenience. It is an ICO matter, an insurance matter, and a conversation with every patient on your list.
So here are ten questions worth asking any vendor before you move your clinic onto their system. We have answered all ten for ourselves underneath, honestly, including the places we are still working. Ask us the same questions. Ask everyone the same questions.
The ten questions
1. Are you registered with the ICO as a data controller or processor?
Any UK business processing personal data at this scale should be on the ICO register. It is a public register, so you can check in under a minute. If a vendor is not on it, that tells you something about how seriously they have thought about data protection.
Us: registration number ZC066513. Look it up.
2. Who is the actual company, and where is it registered?
You are trusting this company with your patient records. You should be able to find out who they are. A company number, a registered office, a real trading name. If the only contact route is a web form and a first-name email, be careful.
Us: Companies House number 16902276. Our name is a registered UK trade mark, UK00004373777.
3. Where are permissions enforced, in the browser or on the server?
This is the most important technical question on the list and almost nobody asks it. Anything enforced only in the browser is not enforced at all, because a browser is a piece of software on someone else's computer and they can change it. A receptionist should not be able to reach clinical notes, and that has to be decided by the server, every single time.
Us: every permission is enforced server-side, in database security rules and in the functions that handle each request. We have an automated test suite that tries to break those rules from the outside, currently over three hundred tests. We run it before a release goes out, and a failure stops that release. To be precise about it, that is a process we follow rather than a robot that enforces it, and turning it into an automatic gate is on our list.
4. Where is my data hosted, and what leaves the UK?
"In the cloud" is not an answer. Ask which region, and ask specifically what crosses a border, because in a hosted platform something usually does.
Us: your clinic's records, documents and photographs are held in London. Several supporting services do sit outside the UK, each under Standard Contractual Clauses: sign-in, email, text messaging, payments, error monitoring, bot protection and live chat. That is ordinary for a cloud platform, and we are not going to bury it. Every one is named, with what it does, where it is and a link to its own data agreement, in our privacy notice, our data protection impact assessment and the sub-processor list inside the app, because you cannot do your own compliance paperwork properly if your supplier hides theirs.
5. Can I see a named list of every third party my data touches?
Under UK GDPR you are the controller and the vendor is your processor, which means you are entitled to know who they pass data to. A vague "trusted partners" line is not enough for your own records.
Us: Settings, then Legal & Compliance, gives you every sub-processor by name, what they do, where they are and a link to their own data agreement. Nine of them at the time of writing this.
6. Do you store card numbers?
The correct answer is no. Card data should go straight to a payment provider and never touch the clinic system at all.
Us: no. Card payments are handled by Stripe, and card numbers never reach our servers. Money settles directly into your own Stripe account and we never hold your funds. We do take a 0.1% platform fee on payments taken through the system, which is shown in your billing settings.
7. Is there two-factor authentication, and what kind?
Ask what kind, because text-message codes are the weakest common option and are vulnerable to someone taking over the phone number.
Us: yes, using an authenticator app rather than text messages, with recovery codes. On prescribing, it is not optional: the prescriptions area requires it.
8. Is there an audit trail I can actually read, and how long is it kept?
If a record changes, you need to be able to answer who changed it and when, sometimes years later. Ask whether you can read it yourself or whether you have to email support and hope.
Us: there is an audit log in your own settings that you can read and search without asking us. Clinical-record entries are retained for eight years, matching the clinical record lifecycle rather than whatever was convenient to build.
9. What happens to my data if I leave?
Ask before you join, not after. Can you export everything, in a usable format, without paying for the privilege or waiting a fortnight?
Us: your data is yours. You can export your patient list and every report to CSV yourself, and there is a full per-patient export for subject access requests. What does not exist yet is a single button that exports absolutely everything including clinical notes and photographs, so if you leave we do that extraction for you, at no charge, and we will put that in writing before you sign anything. We would rather you leave cleanly than feel trapped.
10. Who is actually responsible when something goes wrong?
Software fails sometimes. Ours has. What matters is whether the vendor tells you, fixes it, and writes down what changed so it does not recur, or whether it quietly disappears.
Us: we tell the clinics affected, we fix it, and the fix comes with a test so the same fault cannot come back. That is genuinely the whole standard, and any vendor who claims their software never breaks is either very new or not being straight with you.
Two more, if you prescribe
If your clinic handles prescription-only medicines, two extra questions are worth asking, because getting these wrong has consequences well beyond a data breach.
Does the system stop you advertising prescription-only medicines to the public? Advertising a prescription-only medicine to the public is unlawful in the UK, and it is very easy to do by accident in a marketing email. Ours screens marketing: email campaigns, text campaigns, automated sequences and anything our AI assistant drafts are all checked on the server before they send, and a match is blocked outright rather than warned about. Ask about the limits too, including ours. Our list covers botulinum toxin brand names, and a one-to-one message you type to a single patient is not screened, because that is correspondence with an existing patient rather than advertising. The useful question for any vendor is which sends are covered and which are not.
Can you trace a batch back to the patients who received it? If a product is recalled, you need to know who had it, quickly. That should be a report, not an afternoon with a spreadsheet.
What we are not going to tell you
We are not going to tell you we are certified to standards we do not hold. We do not currently hold ISO 27001 or Cyber Essentials. If a vendor does hold one, that counts for something, and it is worth asking which certification, when it was last assessed and what scope it actually covers, because scope varies a great deal.
We are also not going to show you a five-star average built on a handful of reviews. When we have enough from real clinics to mean something, we will show them, and not before.
Ask us anything, even if you are not buying
Genuinely. If you are weighing up two systems and want a second opinion on a technical answer you have been given, send it over and we will tell you what we think, including when the honest answer is that the other option is a better fit for you.
We are a small UK company that spends its days inside aesthetic clinic operations, so we tend to know where the traps are. If that saves you from a bad eighteen months on the wrong system, that is a decent day's work whether or not you end up with us.
Get in touch, or book a demo and bring your hardest questions.
See CallidusOS® for your clinic
The calm, all-in-one platform for UK aesthetic clinics. From £15 a month, with a 14-day free trial.
Start free trial