Controller vs processor — important. When a clinic uses Atlacare to manage their patients, the
clinic is the data controller of patient data and Atlacare acts as a
data processor on the clinic’s behalf, under our
Data Processing Agreement. This Privacy Policy describes the data for which
Atlacare itself is the controller — i.e. data about website visitors, clinic account holders and people who contact us. If you are a patient, please contact your clinic about their handling of your records.
4. How we use data
To create and manage accounts; to deliver the service and support; to take payment; to send service emails (e.g. confirmations, security notices); to secure the platform and prevent abuse; to meet legal obligations; and, on a legitimate-interests basis, to tell business customers about relevant product updates.
6. International transfers & data residency
All patient and clinical data is stored within the EU. Where any sub-processor operates outside the UK/EEA, transfers are protected by appropriate safeguards (such as the UK International Data Transfer Agreement or adequacy regulations).
7. How long we keep data
We keep account and billing data for as long as a clinic has an account, and afterwards only as needed to meet legal, accounting and tax obligations. Patient clinical records are retained according to each clinic’s legal retention obligations (in the UK, typically a minimum of 8 years from the last episode of care, longer for certain categories) — configured per clinic and enforced by the platform. See our internal retention schedule for detail.
8. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, object to processing, and data portability, and the right to withdraw consent. To exercise any right over data we control, email
hello@atlacare.com. If you are a patient, contact your clinic, who is the controller of your records.
9. Security
We use encryption in transit (HTTPS/TLS) and at rest, role-based access controls, tiered clinical-note visibility, optional two-factor authentication, short-lived signed URLs for files, audit logging, and we exclude patient health information from error logs. No system is perfectly secure, but we work to protect your data to a high standard.