Medicasimple Healthcare Technologies Limited Privacy Policy
Introduction
Your privacy is important to us. It is Medicasimple Healthcare Technologies Limited’s (“Medicasimple”, “we”, “us”) policy to respect your privacy and comply with applicable data-protection law when we collect, use or share personal information.
This Privacy Notice applies to:
(a) patients and end-users of our clinic/practice customers who use the Medicasimple platform and those patients’ authorised representatives (where relevant);
(b) our employees, contractors and volunteers; and
(c) visitors and registered users of our websites and mobile applications, including https://medicasimple.com and any other sites we own and operate.
Personal information is any information about you which can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and information about how you use a website or online service.
In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.
Our role (Controller vs Processor)
When we provide the Medicasimple platform to clinics and practices, the clinic/practice is the Data Controller and Medicasimple acts as a Data Processor, processing personal data only on the clinic/practice’s documented instructions. In that context, our processing is governed by the customer contract and our Data Processing Addendum (DPA).
For our own business purposes (for example, operating our website, handling enquiries, marketing, billing, and managing staff and contractors), Medicasimple acts as a Data Controller.
This policy is effective as of August 9, 2024.
Last updated: 11 December 2025.
1. Patients (Service Users) of our clinic/practice customers
If you are a patient of a clinic or practice that uses the Medicasimple platform, that clinic/practice is the Data Controller for your patient record. Medicasimple processes your information as a Data Processor on the clinic/practice’s instructions in order to provide the platform.
What data may be processed?
The types of information processed depend on what the clinic/practice enters into the platform and may include:
- basic identification and contact details (for example name, date of birth, contact information, identifiers used by the clinic/practice);
- appointment, treatment and clinical record information (including notes, documents, and images) where entered by the clinic/practice;
- billing/transaction references relating to the clinic/practice relationship; and
- platform audit logs (for example user ID, time-stamps and IP address recording actions in the platform).
Why is it processed?
Your clinic/practice determines the lawful basis for processing your information (including any special category data such as health data) and provides the relevant privacy information to you. Medicasimple processes the data to provide, secure, maintain, and support the platform for that clinic/practice.
Who should you contact?
If you have questions about your patient information (including access, correction, or deletion requests), please contact your clinic/practice directly. If we receive a request from you relating to a clinic/practice customer’s data, we will, where legally permitted, direct you to the relevant clinic/practice.
Sharing and transfers
Medicasimple uses trusted suppliers and service providers to operate the platform (for example hosting, communications, support tooling and security services) under contract and strict data-protection controls. Where international transfers are required, we apply appropriate safeguards in line with applicable law (for example, the UK International Data Transfer Agreement (IDTA) or other lawful mechanisms as applicable).
We do not sell patient data and do not use patient records for advertising.
Retention
Patient record retention is determined by the clinic/practice as Data Controller and is typically governed by clinical and regulatory requirements applicable to that clinic/practice. Medicasimple retains patient data only for as long as necessary to provide the Services and as instructed by the clinic/practice, subject to limited backup and security log retention.
2. Staff (including clinicians & contractors where applicable)
What data do we collect?
We may collect and process staff/contractor information such as:
- identification and contact details (name, phone, e-mail and address)
- right-to-work and onboarding information
- payroll and pension information (where applicable)
- training and professional-development records
- role-related checks and compliance records where required for the role (for example background check outcomes)
Why do we process this data?
We process staff data for legitimate workforce management and compliance purposes. Our lawful bases include legal obligation and legitimate interests (and for special category data, the relevant employment-law conditions where applicable).
Where do we get/share it?
We may share staff data with payroll providers, HMRC, benefits providers, professional advisers, and statutory bodies where required. Records are retained in line with applicable legal and regulatory requirements and then securely destroyed.
3. Emergency contacts (friends/relatives of service users)
We may hold basic contact details (such as name and phone number) of a person nominated as an emergency contact by an end-user or as part of a clinic/practice customer’s use of the platform. In most cases, the clinic/practice customer determines the purposes and lawful basis for this information (as Data Controller), and Medicasimple processes it as Data Processor on their instructions.
4. Information we collect (website and business interactions)
Information we collect falls into two categories: “voluntarily provided” information and “automatically collected” information.
Log data
When you visit our website, our servers may automatically log standard data provided by your web browser. This may include your IP address, browser type and version, the pages you visit, the time and date of your visit, time spent on pages, and other details. We may also collect error and diagnostic information when you encounter issues.
Device data
We may collect data about your device such as device type, operating system and unique device identifiers. Data collected may depend on your device settings and software.
Personal information you provide to us
We may ask for personal information, for example when you contact us, request a demo, create an account, or purchase a subscription. This may include name, email address, phone number, company/clinic details and billing information.
Special category data
For our website and business interactions, we do not intentionally request special category data. If such information is provided to us, we will handle it in accordance with applicable law and only as necessary for the purpose for which it was provided.
Within the Medicasimple platform, special category data (such as health data) may be processed depending on how a clinic/practice customer uses the platform; in that context the clinic/practice is the Data Controller and Medicasimple acts as the Data Processor on their instructions.
5. Collection and use of information (Medicasimple as Controller)
Where Medicasimple acts as a Data Controller (for example website and business operations), we may collect, hold, use and disclose personal information for purposes including:
- providing, operating and improving our website and services
- responding to enquiries and providing customer support
- managing accounts, subscriptions, billing and payments
- security and fraud prevention
- analytics and performance monitoring for our website and business operations
- marketing communications where permitted and in accordance with your preferences
- compliance with legal obligations and defending legal claims
Where we use service providers to support these activities, they act under appropriate contractual and security controls.
6. Security of your personal information
When we collect and process personal information, we protect it using commercially reasonable technical and organisational measures designed to prevent loss, theft, unauthorised access, disclosure, copying, use or modification. No method of electronic transmission or storage is 100% secure and we cannot guarantee absolute data security.
You are responsible for selecting any password and keeping it secure.
7. How long we keep your personal information
We keep personal information only for as long as needed for the purposes for which it is processed, unless a longer retention period is required by law or necessary to establish, exercise or defend legal claims.
For patient records hosted in the Medicasimple platform, retention is determined by the clinic/practice customer as Data Controller, subject to limited backup and security log retention.
8. Your rights and controlling your personal information
Your rights depend on the context and whether Medicasimple is acting as Data Controller or Data Processor.
If you are a patient/end-user of a clinic/practice customer
Please contact your clinic/practice directly to exercise your rights over your patient record, since they are the Data Controller. We support our customers in responding to such requests where required.
If Medicasimple is acting as Data Controller (website and business interactions)
You may have rights to request access, correction, deletion, restriction, objection, and data portability (where applicable). You can contact us using the details below. We may need to verify your identity before responding.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
9. Disclosure of personal information to third parties
We may disclose personal information (where Medicasimple is acting as Data Controller) to:
- our employees and contractors (on a need-to-know basis)
- third-party service providers supporting our website and business operations (for example hosting, analytics, communications, payment providers, professional advisers)
- regulators, courts, tribunals or law enforcement where required by law
- a buyer or successor in the event of a business transfer, subject to appropriate safeguards
We do not sell personal information.
10. International transfers
Personal information we process may be stored and/or processed primarily in the United Kingdom and the European Economic Area, and may also be processed in other locations where our approved suppliers and service providers operate.
Where international transfers are required, we use appropriate safeguards in line with applicable law (for example standard contractual clauses and/or the UK International Data Transfer Agreement (IDTA), as applicable) and we apply security controls designed to protect the transferred information.
11. Use of cookies
We use cookies to collect information about you and your activity across our site. Please refer to our Cookie Policy for more information.
12. Business transfers
If we or our assets are acquired, personal information may be transferred to the acquiring party as part of the transaction, subject to applicable law and appropriate safeguards. Where required, we will provide notice of material changes.
13. Limits of our policy
Our website may link to external sites that are not operated by us. We have no control over the content and policies of those sites and cannot accept responsibility or liability for their privacy practices.
14. Changes to this policy
We may change this Privacy Policy to reflect updates to our business processes, current practices, or legal/regulatory changes. If we make significant changes, we will post the updated policy and, where required, provide additional notice.
15. Additional disclosures for GDPR / UK GDPR compliance
The GDPR distinguishes between organisations that process personal information for their own purposes (“data controllers”) and organisations that process personal information on behalf of others (“data processors”). As explained in the “Our role” section above, Medicasimple may act as a Data Controller or Data Processor depending on the context.
16. Contact (Privacy / DPO)
If you have questions about this Privacy Policy or our handling of personal information in contexts where Medicasimple acts as Data Controller, or if you wish to raise a concern, contact our Data Protection Officer:
Name: Umran Dogan
Email:umran.dogan@dgn-law.com
If we fail to resolve your concern to your satisfaction, you may also contact the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.
Changelog
29 April 2025 – added National Data Opt-out link and phone number (removed in later revision due to scope clarification)
06 December 2025 – DPO information changed
11 December 2025 – clarified Controller/Processor roles for clinic customers and aligned with our public DPA