Draft — pending legal review.This document is being reviewed by our solicitor and may change before it is finalised.
Legal

Privacy policy

Last updated 29 September 2026

This policy explains how RELENTX LTD (trading as ManagePatients, “we”, “us”) handles personal data. It covers two different roles we play: as a controller of the account data of the clinics and businesses that subscribe to ManagePatients, and as a processor of the patient data those clinics store on the platform.

1. Who we are

ManagePatients is a trading name of RELENTX LTD, a company registered in England & Wales (company number 17179152), registered office 128 City Road, London, EC1V 2NX.

For any privacy question or to exercise your rights, contact us at hello@managepatients.com.

2. Our two roles

Controller — clinic account data

When a clinic, practitioner or business (a “customer”) signs up, we decide how and why their account data is used. For that data we are the controller and this policy applies in full.

Processor — patient data

Clinics use ManagePatients to store and manage data about their own patients and clients: bookings, contact details, consultation forms, clinical notes, images and invoices. For that data the clinic is the controller and we act only on its instructions, under our Data Processing Agreement. If you are a patient, the clinic you booked with is responsible for telling you how it uses your data (many clinics publish their own privacy notice on their booking page) and is the right first contact for requests about your records. We will pass on any request we receive to the relevant clinic and help them respond.

3. Data we collect as controller

CategoryExamplesSource
Account & contactName, business name, email, phone, job role, login credentials (passwords are hashed)You, at sign-up and in settings
Business detailsTrading address, Companies House number, VAT number, locations, services, opening hoursYou
BillingPlan, subscription status, invoices, last four digits and expiry of your card (full card details are held by Stripe, not us)You and Stripe
Usage & technicalIP address, browser and device type, pages visited in the dashboard, error logs, security and audit logsAutomatically
CommunicationsSupport messages, contact-form submissions, emails you send usYou
Marketing site visitorsContact-form details and basic technical dataYou and automatically

4. Why we use it and our lawful bases

PurposeLawful basis (UK GDPR Art. 6)
Creating and running your account; providing the service; supportContract
Taking subscription payments; keeping accounting and tax recordsContract; legal obligation
Security, fraud prevention, rate limiting, error monitoring and audit logsLegitimate interests (keeping the platform and your data safe)
Service emails about your account, billing, trials, changes to terms or this policyContract; legitimate interests
Product news and offers to existing customers (you can opt out at any time)Legitimate interests / soft opt-in under PECR
Improving the product using aggregated usage dataLegitimate interests
Responding to legal claims or requests from authoritiesLegal obligation; legitimate interests

We do not sell personal data and we do not use patient data for our own marketing or to train any models.

5. Patient data we process for clinics

On behalf of clinics we process the categories below. The clinic decides what it collects.

  • Identity and contact details — name, email, phone, address, date of birth.
  • Appointment details — services booked, dates, staff, locations, home-visit addresses, notes.
  • Health data (special category data) — consultation and consent form answers, clinical notes, images and documents. Clinics rely on their own Article 9 condition for this (typically health or social care provision under Art. 9(2)(h) with the associated DPA 2018 Schedule 1 condition, or explicit consent).
  • Payment data — deposits and invoice payments (card details are handled by Stripe).
  • Communications — SMS and email messages sent and received through the platform, and delivery status.
  • Consent and preference records — marketing consent, SMS opt-outs, erasure requests.

Clinics may also add their own analytics or advertising tags (for example a Meta Pixel or Google tag) to their booking pages. Those tags are configured by the clinic, which is responsible for them and for any cookie consent they require.

6. Who we share data with

We use the service providers below to run ManagePatients. Each is bound by a written contract requiring it to protect personal data and use it only to provide its service to us.

ProviderPurposeLocation
Supabase Inc.Database, authentication and file storage (all account and patient data)EU — Ireland (AWS eu-west-1)
Vercel Inc.Application hosting, serverless functions and content deliveryGlobal edge network; US-headquartered
Stripe Payments Europe / Stripe Inc.Subscription billing for clinics; card payments and deposits taken by clinics from patientsEU / UK / US
Twilio Inc.SMS delivery (reminders, confirmations, two-way messages)US / global carrier network
Resend (Plus Five Five Inc.)Transactional email deliveryUS
Google LLC (Google Maps Platform)Address lookup, geocoding and travel-distance calculation for home visitsUS / global
Easy PostcodesUK postcode and address lookupUK
Functional Software Inc. (Sentry)Error monitoring and diagnostics (limited technical data)US
Upstash Inc.Rate limiting to protect booking and sign-in forms (IP address only)Region to be confirmed

We may also share data with professional advisers (lawyers, accountants) under a duty of confidentiality, with a buyer of our business if it is sold (the buyer would be bound by this policy), or where required by law.

7. International transfers

Our primary database is hosted in the EU (Ireland), which the UK recognises as providing adequate protection. Some providers above are based in, or may access data from, the United States or other countries. Where personal data leaves the UK we rely on UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework where the provider is certified) or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where needed.

8. How long we keep data

  • Account data — for as long as your account is open, then for up to 6 years after it closes where needed to deal with legal claims, after which it is deleted or anonymised.
  • Patient data held for clinics— for as long as the clinic’s subscription is active. It is deleted 30 days after the subscription is cancelled or ends, unless the clinic asks us to delete it sooner. Clinics can export their data before cancelling.
  • Invoices and billing records — retained for as long as required by UK tax and company law (currently 6 years from the end of the financial year they relate to).
  • Security and error logs — kept for a limited period and then deleted on a rolling basis.
  • Support correspondence — for up to 2 years after the matter is closed.

9. Security

Data is encrypted in transit (TLS) and at rest. Access is restricted by role, protected by row-level security in the database so one clinic cannot see another’s data, and logged. Our staff access customer data only where needed to provide support or keep the service running. See the DPA for more detail.

10. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to our processing, including objecting to direct marketing at any time;
  • data portability — receive your data in a machine-readable format;
  • withdraw consent where we rely on consent.

Email hello@managepatients.com to make a request. We will respond within one month. If your request concerns records a clinic holds about you as a patient, we will refer it to that clinic, as it is the controller.

11. Cookies

The ManagePatients dashboard and patient portal use strictly necessary cookies to keep you signed in and to secure your session. We do not use advertising cookies on managepatients.com. Clinic booking pages may use cookies or tags the clinic has added (see section 5).

12. Complaints

Please contact us first at hello@managepatients.comso we can try to put things right. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, telephone 0303 123 1113.

13. Changes to this policy

We may update this policy from time to time. We will tell customers about material changes by email or in the dashboard before they take effect. The date at the top shows when it was last updated.