← Back to home
Draft — pending legal review. This document is a working draft and is not yet a final, legally approved policy.

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Atlacare(“we”, “us”) collects and uses personal data, and your rights over that data. We are committed to processing data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (“DPA 2018”).

Controller vs processor — important. When a clinic uses Atlacare to manage their patients, the clinic is the data controller of patient data and Atlacare acts as a data processor on the clinic’s behalf, under our Data Processing Agreement. This Privacy Policy describes the data for which Atlacare itself is the controller — i.e. data about website visitors, clinic account holders and people who contact us. If you are a patient, please contact your clinic about their handling of your records.

1. Who we are

Atlacare provides practice-management software for allied-health clinics. For data we control, the data controller is Atlacare. You can contact us about privacy at hello@atlacare.com.

2. The data we collect (as controller)

  • Account data — name, work email, password (hashed), clinic name, role, and authentication data (including two-factor settings) for clinic staff who hold an Atlacare account.
  • Billing data — billing contact and subscription details. Payment card details are handled by our payment processor and never stored by Atlacare.
  • Usage & device data — limited analytics on our public marketing and patient-portal pages only (never on clinical screens), and technical logs needed to run and secure the service.
  • Communications — messages you send us (support, sales, email).

We do not use patient clinical records for our own purposes — that data is processed solely on behalf of clinics under the Data Processing Agreement.

3. Lawful bases (UK GDPR Article 6)

  • Contract — to provide the service to clinics that subscribe.
  • Legitimate interests — to run, secure and improve the service, and for limited B2B marketing (you can opt out at any time).
  • Consent — for non-essential cookies/analytics, and where otherwise required.
  • Legal obligation — to meet our accounting, tax and regulatory duties.

Where patient health data (special-category data under Article 9) is processed within the platform, the clinic acting as controller is responsible for the Article 9 condition and, where relevant, the DPA 2018 Schedule 1 condition. As processor, we apply appropriate technical and organisational measures and act only on the clinic’s documented instructions.

4. How we use data

To create and manage accounts; to deliver the service and support; to take payment; to send service emails (e.g. confirmations, security notices); to secure the platform and prevent abuse; to meet legal obligations; and, on a legitimate-interests basis, to tell business customers about relevant product updates.

5. Sharing & sub-processors

We share data with vetted third-party providers (“sub-processors”) only as needed to run the service — for hosting, file storage, email and payments. Each operates under a data processing agreement. See our full sub-processor list. We never sell personal data.

6. International transfers & data residency

All patient and clinical data is stored within the EU. Where any sub-processor operates outside the UK/EEA, transfers are protected by appropriate safeguards (such as the UK International Data Transfer Agreement or adequacy regulations).

7. How long we keep data

We keep account and billing data for as long as a clinic has an account, and afterwards only as needed to meet legal, accounting and tax obligations. Patient clinical records are retained according to each clinic’s legal retention obligations (in the UK, typically a minimum of 8 years from the last episode of care, longer for certain categories) — configured per clinic and enforced by the platform. See our internal retention schedule for detail.

8. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, object to processing, and data portability, and the right to withdraw consent. To exercise any right over data we control, email hello@atlacare.com. If you are a patient, contact your clinic, who is the controller of your records.

9. Security

We use encryption in transit (HTTPS/TLS) and at rest, role-based access controls, tiered clinical-note visibility, optional two-factor authentication, short-lived signed URLs for files, audit logging, and we exclude patient health information from error logs. No system is perfectly secure, but we work to protect your data to a high standard.

10. Cookies

See our Cookie Policy. Non-essential cookies (including analytics) load only after you consent, and analytics never run on clinical screens.

11. Complaints

If you have concerns we haven’t resolved, you can complain to the UK supervisory authority, the Information Commissioner’s Office (ICO).

12. Changes

We may update this policy and will revise the date above when we do. Material changes affecting clinics will be notified in line with our agreement with them.

Questions about this policy: hello@atlacare.com.