Security

Aesthetic clinics trust iMarketo with thousands of confidential client records every day.
Security isn't a footer link for us — it's a design decision on every feature we ship.

🔒 UK data hosting
🇬🇧 UK GDPR complian
🛡️ End-to-end encryption

Securing your data

You own your data

We're the custodians of your data. You remain the owner. Every design choice in iMarketo respects that distinction.
If you ever decide to leave, your data is held for a minimum of 30 days after cancellation. If you come back in that window, everything is exactly where you left it. If you want your data outside iMarketo at any time, export it in one click from the Settings menu.

Ultra-secure infrastructure

iMarketo runs on infrastructure operated by our platform partner GoHighLevel, hosted on Amazon Web Services (AWS) data centres. Physical access to these facilities is controlled by professional security staff using video surveillance, intrusion detection, biometric access controls, and 24/7 on-site monitoring.

High availability

Our infrastructure is built across multiple availability zones. If one zone experiences an outage, traffic is automatically routed to unaffected zones — you won't know it happened. Historical uptime for the underlying platform runs above 99.9%.

Encryption

Everything sent between you and iMarketo is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256 — the same standard used by banks and government systems.

In plain English: when your client's medical history is being sent from their phone to your CRM, nobody in the middle can read it. When it's stored on our servers, it's encrypted so that even a physical hard drive theft wouldn't expose the contents.

24/7 monitoring

Our platform is monitored around the clock. Automated alerts flag anomalies — traffic spikes, failed logins, unusual data access patterns — the moment they happen. Someone on our team is paged whenever a threshold is crossed, regardless of time zone or day of the week.

Backups

iMarketo data is backed up daily. Backups are stored redundantly across multiple physical locations so a single site failure never puts your data at risk. Databases also stream continuously to replicas, so recovery windows are measured in minutes, not hours.

You can also export your entire client list, treatment history, and enquiry log at any time from your account — creating your own local backups if you want the extra assurance.

Responsible disclosure

If you find a security issue in iMarketo, we want to hear about it. Email info@imarketo.com with a description of the vulnerability and your contact details. We commit to acknowledging every report within 48 hours and working with you toward a fix.

Backups

iMarketo data is backed up daily. Backups are stored redundantly across multiple physical locations so a single site failure never puts your data at risk. Databases also stream continuously to replicas, so recovery windows are measured in minutes, not hours.

You can also export your entire client list, treatment history, and enquiry log at any time from your account — creating your own local backups if you want the extra assurance.

What can you do to
protect your account?

Even the best-built system depends on the humans using it. Here's how to protect your iMarketo account and your clients' data.

Enable two-factor authentication (2FA)

2FA adds a second step when you log in — a code generated on your phone or authenticator app. Even if someone learns your password, they can't get into your account without your device. Turn it on in Settings → Security. It takes 90 seconds and it's the single biggest thing you can do to protect the account.

Use a password manager

Long, unique passwords beat clever ones. Use a manager (1Password, Bitwarden, or your browser's built-in vault) to generate and store passwords you'd never be able to remember. Never reuse a password from any other account.

Set user roles carefully

If your clinic has multiple staff — practitioners, receptionists, aesthetic assistants — set each user's role so they only see what they need to. A receptionist rarely needs full access to treatment records. Set roles in Settings → Team.

Restrict third-party integrations

iMarketo can integrate with Zapier, Meta, Instagram, Stripe, and other apps. Every integration is a doorway. Only connect apps you use, and disconnect ones you don't. Review your connected apps quarterly.

Keep your browser updated

An outdated browser is a security risk on any site, not just iMarketo. Keep Chrome, Safari, or Firefox on the latest version.

Log out on shared devices

If you or your team use the clinic's front-desk computer, log out at the end of every day. Better: use each user's own device where possible.

Log out on shared devices

If you or your team use the clinic's front-desk computer, log out at the end of every day. Better: use each user's own device where possible.

Compliance

We help you stay compliant with the regulations aesthetic clinics operate under in the UK.

UK GDPR

The UK General Data Protection Regulation applies to every aesthetic clinic operating in the UK, regardless of size. iMarketo helps you meet UK GDPR requirements in the following ways:

Lawful basis: iMarketo lets you record the lawful basis for processing each client's data (usually consent for marketing communications, contract for treatment records).

Consent capture: every intake form, booking flow, and marketing subscription captures explicit consent with a timestamp.

Right to access: clients can request their data at any time. iMarketo's export tools deliver a complete data package in a portable format within 30 days (usually within seconds).

Right to erasure: Delete a client's record with one click. Their data is purged from live systems immediately and from backups within 90 days.

Data Processing Agreement (DPA): we sign a UK GDPR-compliant DPA with every clinic. Available from your account settings or by emailing info@imarketo.com.

The Advertising Standards Authority (ASA) & aesthetics

Aesthetic clinics operate in an ASA-monitored category. iMarketo doesn't create ad content on your behalf without your approval, and our templates for automated messages, review requests, and treatment reminders are pre-reviewed for CAP Code compliance. If you write custom content, you're responsible for its compliance — but we flag common issues (POM brand names, before/after photo rules) at the moment you save.

The Joint Council for Cosmetic Practitioners (JCCP)

We follow JCCP guidance on client communication for the aesthetics sector, including cooling-off periods, informed consent, and appropriate marketing to under-18s (which we prevent by default — no marketing communications go to clients under 18 without explicit override).

Useful links:
  • Marketo status page: imarketo.com
  • ICO (Information Commissioner's Office): ico.org.uk
  • JCCP: jccp.org.uk
  • Save Face: saveface.co.uk

The calm CRM built
for UK aesthetic clinics

Everything you need to run the business side of your clinic — bookings, follow-ups, reviews, top-up recalls, and ads. All in one login. £19/month starter. First month of ads managed for you, free.

Book a 15-min demo →