Privacy policy
Last updated 29 September 2026
This policy explains how RELENTX LTD (trading as ManagePatients, “we”, “us”) handles personal data. It covers two different roles we play: as a controller of the account data of the clinics and businesses that subscribe to ManagePatients, and as a processor of the patient data those clinics store on the platform.
1. Who we are
ManagePatients is a trading name of RELENTX LTD, a company registered in England & Wales (company number 17179152), registered office 128 City Road, London, EC1V 2NX.
For any privacy question or to exercise your rights, contact us at hello@managepatients.com.
2. Our two roles
Controller — clinic account data
When a clinic, practitioner or business (a “customer”) signs up, we decide how and why their account data is used. For that data we are the controller and this policy applies in full.
Processor — patient data
Clinics use ManagePatients to store and manage data about their own patients and clients: bookings, contact details, consultation forms, clinical notes, images and invoices. For that data the clinic is the controller and we act only on its instructions, under our Data Processing Agreement. If you are a patient, the clinic you booked with is responsible for telling you how it uses your data (many clinics publish their own privacy notice on their booking page) and is the right first contact for requests about your records. We will pass on any request we receive to the relevant clinic and help them respond.
3. Data we collect as controller
| Category | Examples | Source |
|---|---|---|
| Account & contact | Name, business name, email, phone, job role, login credentials (passwords are hashed) | You, at sign-up and in settings |
| Business details | Trading address, Companies House number, VAT number, locations, services, opening hours | You |
| Billing | Plan, subscription status, invoices, last four digits and expiry of your card (full card details are held by Stripe, not us) | You and Stripe |
| Usage & technical | IP address, browser and device type, pages visited in the dashboard, error logs, security and audit logs | Automatically |
| Communications | Support messages, contact-form submissions, emails you send us | You |
| Marketing site visitors | Contact-form details and basic technical data | You and automatically |
4. Why we use it and our lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; providing the service; support | Contract |
| Taking subscription payments; keeping accounting and tax records | Contract; legal obligation |
| Security, fraud prevention, rate limiting, error monitoring and audit logs | Legitimate interests (keeping the platform and your data safe) |
| Service emails about your account, billing, trials, changes to terms or this policy | Contract; legitimate interests |
| Product news and offers to existing customers (you can opt out at any time) | Legitimate interests / soft opt-in under PECR |
| Improving the product using aggregated usage data | Legitimate interests |
| Responding to legal claims or requests from authorities | Legal obligation; legitimate interests |
We do not sell personal data and we do not use patient data for our own marketing or to train any models.
5. Patient data we process for clinics
On behalf of clinics we process the categories below. The clinic decides what it collects.
- Identity and contact details — name, email, phone, address, date of birth.
- Appointment details — services booked, dates, staff, locations, home-visit addresses, notes.
- Health data (special category data) — consultation and consent form answers, clinical notes, images and documents. Clinics rely on their own Article 9 condition for this (typically health or social care provision under Art. 9(2)(h) with the associated DPA 2018 Schedule 1 condition, or explicit consent).
- Payment data — deposits and invoice payments (card details are handled by Stripe).
- Communications — SMS and email messages sent and received through the platform, and delivery status.
- Consent and preference records — marketing consent, SMS opt-outs, erasure requests.
Clinics may also add their own analytics or advertising tags (for example a Meta Pixel or Google tag) to their booking pages. Those tags are configured by the clinic, which is responsible for them and for any cookie consent they require.
6. Who we share data with
We use the service providers below to run ManagePatients. Each is bound by a written contract requiring it to protect personal data and use it only to provide its service to us.
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and file storage (all account and patient data) | EU — Ireland (AWS eu-west-1) |
| Vercel Inc. | Application hosting, serverless functions and content delivery | Global edge network; US-headquartered |
| Stripe Payments Europe / Stripe Inc. | Subscription billing for clinics; card payments and deposits taken by clinics from patients | EU / UK / US |
| Twilio Inc. | SMS delivery (reminders, confirmations, two-way messages) | US / global carrier network |
| Resend (Plus Five Five Inc.) | Transactional email delivery | US |
| Google LLC (Google Maps Platform) | Address lookup, geocoding and travel-distance calculation for home visits | US / global |
| Easy Postcodes | UK postcode and address lookup | UK |
| Functional Software Inc. (Sentry) | Error monitoring and diagnostics (limited technical data) | US |
| Upstash Inc. | Rate limiting to protect booking and sign-in forms (IP address only) | Region to be confirmed |
We may also share data with professional advisers (lawyers, accountants) under a duty of confidentiality, with a buyer of our business if it is sold (the buyer would be bound by this policy), or where required by law.
7. International transfers
Our primary database is hosted in the EU (Ireland), which the UK recognises as providing adequate protection. Some providers above are based in, or may access data from, the United States or other countries. Where personal data leaves the UK we rely on UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework where the provider is certified) or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where needed.
8. How long we keep data
- Account data — for as long as your account is open, then for up to 6 years after it closes where needed to deal with legal claims, after which it is deleted or anonymised.
- Patient data held for clinics— for as long as the clinic’s subscription is active. It is deleted 30 days after the subscription is cancelled or ends, unless the clinic asks us to delete it sooner. Clinics can export their data before cancelling.
- Invoices and billing records — retained for as long as required by UK tax and company law (currently 6 years from the end of the financial year they relate to).
- Security and error logs — kept for a limited period and then deleted on a rolling basis.
- Support correspondence — for up to 2 years after the matter is closed.
9. Security
Data is encrypted in transit (TLS) and at rest. Access is restricted by role, protected by row-level security in the database so one clinic cannot see another’s data, and logged. Our staff access customer data only where needed to provide support or keep the service running. See the DPA for more detail.
10. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing, including objecting to direct marketing at any time;
- data portability — receive your data in a machine-readable format;
- withdraw consent where we rely on consent.
Email hello@managepatients.com to make a request. We will respond within one month. If your request concerns records a clinic holds about you as a patient, we will refer it to that clinic, as it is the controller.
12. Complaints
Please contact us first at hello@managepatients.comso we can try to put things right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, telephone 0303 123 1113.
13. Changes to this policy
We may update this policy from time to time. We will tell customers about material changes by email or in the dashboard before they take effect. The date at the top shows when it was last updated.