Legal
How we handle personal data — and, just as importantly, which data is ours to answer for and which belongs to the clinic treating you.
Version 1.0 · Last updated 10 August 2026
Surgerly is a practice management and patient portal platform used by private healthcare organisations in the United Kingdom. Clinics use Surgerly to manage bookings, appointments, patient records, correspondence, payments and their own internal governance.
This policy is published by [LEGAL ENTITY] (“Surgerly”, “we”, “us”), a company registered in England and Wales under company number [COMPANY NUMBER], whose registered office is at [REGISTERED ADDRESS]. We are registered with the Information Commissioner’s Office under number [ICO REG NUMBER].
This is the most important section of this policy, because which row applies to you determines who you should contact about your data.
| What it covers | Who decides | Who to contact | |
|---|---|---|---|
| We are the controller | Our own website, enquiries and demo requests, live chat on our own site, our business contacts at client clinics, our own staff, and our platform security and billing records. | Surgerly | Us — see section 3 |
| We are a processor | Everything a clinic stores in Surgerly about its patients: names, contact details, appointments, clinical and procedure information, correspondence, documents and payments. | The clinic | The clinic — see section 7 |
If you are a patient of a clinic that uses Surgerly, the second row applies to you. We do not decide what information your clinic collects about you, why it collects it, who it shares it with, or how long it keeps it. Your clinic decides all of that; we provide the software it uses, and we act only on its instructions. Your clinic has its own privacy notice, and that notice — not this one — governs your care records.
White-label services. Many clinics use Surgerly under their own branding and web address. If you booked an appointment or logged into a portal carrying a clinic’s branding, you were using Surgerly software operated on that clinic’s behalf, and the clinic’s privacy policy applies.
| Data protection enquiries | privacy@surgerly.co.uk |
|---|---|
| Security and incident reports | security@surgerly.co.uk |
| Data protection lead | [NAME] |
| Post | [TRADING ADDRESS] |
You can complain to the Information Commissioner’s Office at any time — see section 12. We’d appreciate the chance to resolve it first.
This section covers data we process for our own purposes. It does not cover patient records held on behalf of a clinic — that is section 5.
We process identity and contact data (name, job title, employer, work email and phone); the content of enquiries you send us; account and authentication data for staff users at client clinics; technical data such as IP address, browser and pages viewed; usage and audit records of actions taken in the platform; billing data for client clinics; and recruitment data where you apply to work with us.
We do not seek health data or criminal offence data for our own purposes. Please don’t send health information about yourself or anyone else through our general website enquiry forms or live chat.
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry, demo request or chat message | Legitimate interests; steps prior to entering a contract |
| Providing, supporting and billing for the platform | Performance of contract; legitimate interests |
| Staff user accounts, authentication and MFA | Performance of contract; legal obligation (Art. 32) |
| Maintaining audit logs of platform activity | Legal obligation (Art. 32); legitimate interests in detecting misuse |
| Detecting and responding to security incidents, fraud and abuse | Legitimate interests; legal obligation |
| Improving the platform, diagnosing faults, monitoring performance | Legitimate interests |
| Service messages about outages, changes and security | Performance of contract; legitimate interests |
| Marketing our services to businesses | Legitimate interests, subject to your right to object |
| Accounting, tax and corporate obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
We market to businesses, not patients. We never use patient data held on behalf of a clinic to market anything — not our services, not a clinic’s services, not anyone else’s. You can opt out of our business marketing at any time via the unsubscribe link or by emailing privacy@surgerly.co.uk.
When a clinic uses Surgerly it stores personal data about its patients in our system. The clinic is the controller of that data. We are its processor.
Depending on what the clinic records and which modules it has enabled, that can include identity data (name, date of birth, gender, NHS number); contact details; appointments, procedures, episodes of care and pathway status; health data such as clinical notes, treatment details, questionnaire responses, investigations and clinical documents and images; consent records and marketing preferences; correspondence including email, SMS, chat transcripts and telephone call records; invoices, payments and refunds; and enquiry and marketing attribution data.
Card details are handled by our payment provider and are not stored in Surgerly.
We process this data only on the clinic’s documented instructions — storing it and making it available to their authorised staff, delivering the correspondence they send, running the automations and reports they configure, taking backups, maintaining security, providing technical support where access is necessary and logged, and passing data to the clinic’s own third-party systems where the clinic has configured that.
We do not use patient data for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train artificial intelligence models.
Some clinics operate as part of a group, or refer patients between one another. Where this happens, Surgerly can link the same patient record to more than one clinic, and can let a participating clinic check whether a patient already exists elsewhere on the platform before creating a duplicate record.
These features are off by default. They operate only where we have enabled them for a clinic, and the clinic has instructed us to and has confirmed it has its own lawful basis and a data sharing arrangement with the other clinics involved.
Where a search across participating clinics runs, the searching clinic sees only a minimal indication that a possible match exists — initials and year of birth — and no clinical information. Full details become visible only once the patient is properly registered with that clinic. Every such search is logged, rate limited and reviewable, and a patient can be excluded from it entirely on request to their clinic.
We are the processor for these features. The decision to share patient data between clinics is the clinics’ decision, not ours, and the lawfulness of that sharing is their responsibility. Section 7 explains what to do if you think this has happened to you without a proper basis.
Our sub-processors. These help us run Surgerly, apply to all customers, and are contractually bound to process data only on our instructions.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Microsoft Azure | Hosting, database, file storage, real-time messaging | United Kingdom |
| Microsoft Azure AI Translator | Optional web chat translation, where a clinic enables it | United Kingdom (UK South) |
| Stripe | Card payments, where a clinic enables it | UK / EEA, with safeguards for onward transfer |
| Twilio | SMS delivery, where a clinic enables it | Routed internationally by the mobile network |
| [EMAIL PROVIDER] | Transactional and bulk email delivery | [LOCATION] |
| Tailscale | Secure administrative access by our engineers | Coordination only; no patient data content |
A current list is maintained for clinics, who are notified before we add or replace a sub-processor.
Integrations a clinic switches on. Surgerly connects to practice management and clinical systems, CRMs, marketing platforms, telephony, and a clinic’s own Microsoft 365 tenant. These are not our sub-processors — they are the clinic’s own suppliers, and data flows to them only because the clinic configured that connection. Ask your clinic which it uses.
We may also share data with professional advisers under duties of confidentiality, with regulators where required, and with an acquirer if we sell or merge part of our business. We do not sell personal data to anyone, in any circumstances.
Because your clinic is the controller of your records, your rights are exercised against the clinic, not against us. That includes your rights to access a copy of your data, to have it corrected, to have it erased where there is no longer a valid reason to keep it, to restrict or object to processing, to portability, and to withdraw consent. Contact your clinic directly — clinics can fulfil these requests themselves through Surgerly.
If you contact us instead, we will not action the request ourselves — we are not permitted to. We will acknowledge you, tell you which clinic holds a record matching your details where we can identify it and it is appropriate to do so, forward your request to them promptly so their statutory clock isn’t wasted, and confirm we have done so. Email privacy@surgerly.co.uk.
We take this seriously, and we want to know about it.
We require every clinic using Surgerly to confirm, as a contractual condition, that it has a lawful basis for every record it enters and has given the patient the required privacy information. We specifically prohibit clinics from:
If you believe this has happened, tell us at privacy@surgerly.co.uk. We will record it, raise it with the clinic, and where an instruction appears to us to breach data protection law we will say so in writing — as we are required to under UK GDPR Article 28(3) — and we may suspend the feature or the account. We will also tell you which organisation to direct a formal complaint to. We cannot decide the dispute for you, and we cannot delete a clinic’s records on your say-so, but we will not ignore it.
Your clinic created your account and decides your access. For your account and authentication data, your name, and the audit record of your actions, we act as controller for security and accountability purposes and as processor for everything else. Contact your clinic about your employment record; contact us about your account or the audit log.
Patient data is hosted in UK regions of Microsoft Azure. Backups are held in the same region. We do not replicate patient records to overseas regions.
Two limited exceptions apply, and we state them plainly. SMS delivery hands the message to the mobile network, and routing is international by nature — we cannot confine it to the UK. Some corporate and support tooling we use for our own operations may be hosted outside the UK; where it is, transfers are covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment.
Where a clinic switches on an integration to a system hosted outside the UK, that transfer is the clinic’s decision and the clinic is responsible for the safeguards.
Traffic is served over HTTPS using TLS 1.2 or above, and data is encrypted at rest using AES-256, with backups encrypted under separately managed keys. Every action is authenticated and tied to a named user, with role-based permissions controlling access. Multi-factor authentication is available for staff accounts; patient logins use one-time codes and signed session tokens, and we do not store patient passwords. We keep an append-only audit trail of reads, writes, logins and administrative actions, and engineering access to customer data is itself logged and reviewable. The database is backed up continuously with point-in-time recovery within the previous 30 days, and we run restore drills.
No system is perfectly secure, and data sent over the internet is never entirely risk-free. If we suffer a personal data breach we will notify affected clinics without undue delay so they can meet their own obligations, in line with UK GDPR Article 33, with a written summary once root cause is established. Report a suspected vulnerability to security@surgerly.co.uk. More detail is on our security page.
As controller. Enquiry and marketing data for up to 24 months from your last engagement with us; customer contract and billing records for 7 years from the end of the relationship; security and audit records for the life of the account plus a defined retention period; recruitment data for 12 months unless you agree to longer.
As processor. Retention is the clinic’s decision, set out in our agreement with them. On termination we return or delete their data on their instruction, subject to anything we are legally required to retain. Backups age out on their own cycle.
Our website uses only strictly necessary cookies — those needed to keep you logged in, maintain your session and protect against cross-site request forgery. We do not use advertising or tracking cookies on our website, and we do not run third-party analytics on it. Because we set no non-essential cookies, we do not show a consent banner.
Our website loads stylesheets and fonts from third-party content delivery networks (jsDelivr and Google Fonts), which discloses your IP address to those providers. They do not set cookies through this use, but a content blocker will prevent those requests if you would rather avoid it.
Within the platform, staff and patient portals use strictly necessary session and authentication cookies. Where a clinic enables it, emails it sends can record opens and link clicks, and campaign parameters in a link you followed may be recorded against your enquiry — that is the clinic’s processing, under its own lawful basis and privacy notice.
Contact us first at privacy@surgerly.co.uk and we will try to put it right. You can also complain to the Information Commissioner’s Office:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline 0303 123 1113 — ico.org.uk
If your complaint is about how a clinic has handled your records, the ICO will normally expect you to raise it with that clinic first.
Third party links. Our website and clinic portals may link to third-party sites. We don’t control them and aren’t responsible for their privacy practices.
Children. Our own website and marketing are not directed at children. Clinics may lawfully treat patients under 18 and may store data about children in Surgerly; where they do, the clinic is the controller.
Keeping information accurate. Please tell your clinic if your contact details change. If you are a business contact of ours, tell us at privacy@surgerly.co.uk.
Changes. We may update this policy. When we make a material change we update the version number and date above, and notify clinics directly where it materially affects them. Previous versions are available on request.
Procurement
Email security@surgerly.co.uk and we’ll send what you need.