Legal

Privacy Notice

Clarity Practice Management Limited — Version 1.5, September 2026

1.About this notice

This notice explains how Clarity Practice Management Limited ("Clarity", "we", "us") collects and uses personal data, and what rights you have over that data. It covers people who enquire about our services, our clients and their staff, our suppliers, and visitors to our website.

It does not cover patients of the practices we work with. Where we handle patient data, we do so on behalf of the practice concerned — see section 3.

Our details

Registered nameClarity Practice Management Limited
Company number11724459
Registered inEngland and Wales
Registered office30 Dulwich Road, London, SE24 0PA
Data protection contactSeth Proctor, [email protected]
Telephone0333 880 8010

2.The short version

We collect only what we need to respond to enquiries, deliver our services, meet our legal obligations and run the business. We do not sell personal data, and we do not use it for automated decision-making or profiling. Where we handle patient data, we act only on the written instructions of the practice that holds it.

3.Controller or processor — which applies

This distinction matters, because it determines who is responsible for what.

We are the controller for personal data about: people who contact us through the website, by email or by telephone; our clients and the individuals within them we deal with; consultants, contractors and suppliers we work with; and visitors to our website.

We are a processor for personal data held in a client practice's own systems — including patient data — which we access in the course of migrating, configuring, reconciling or operating those systems. In that role: the practice remains the controller and decides the purposes of processing; we act only on the practice's documented instructions; the terms are set out in a written data processing agreement with the practice, not in this notice; and the practice, not Clarity, is responsible for informing its patients about how their data is used.

If you are a patient of a practice we support and have a question about your data, please contact the practice directly. We will assist them in responding.

4.What we collect, why, and on what legal basis

4.1 Enquiries

WhatName, practice name, email address, telephone number, practice type, current system, number of anaesthetists, and anything you tell us in your message.
WhyTo respond to you, to assess whether we can help, and to prepare a proposal.
Legal basisLegitimate interests — responding to a business enquiry you have initiated. Where we contact you afterwards about our services, we rely on your consent or on the soft opt-in for existing business contacts.

4.2 Clients and prospective clients

WhatContact details of the individuals we deal with; practice and business information; records of the work we carry out; correspondence; billing and payment details; and the due diligence information described at 4.3.
WhyTo provide the services agreed, to manage the relationship, to invoice and collect payment, and to keep proper business records.
Legal basisPerformance of a contract, and legitimate interests in operating and protecting the business.

4.3 Anti-money laundering and identity checks

WhatIdentity documents, proof of address, information about beneficial ownership and source of funds, and the results of any electronic verification checks.
WhyTo meet our obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
Legal basisCompliance with a legal obligation. Where the checks reveal information about criminal offences, we rely on the substantial public interest condition for preventing or detecting unlawful acts.

4.4 Suppliers and contractors

WhatContact details, contract terms, payment details, and where relevant proof of right to work, insurance or professional registration.
WhyTo engage and pay them, and to satisfy ourselves they are suitable.
Legal basisPerformance of a contract and legitimate interests.

4.5 Website visitors

WhatIP address, browser and device information, pages viewed, and how you reached the site.
WhyTo keep the site working and secure, and to understand how it is used.
Legal basisLegitimate interests. Non-essential cookies are set only with your consent — see section 8.

5.Special category data

Health data is "special category" data under UK GDPR and attracts additional protection.

As a processor, we may access patient health data held in a client practice's systems. The lawful basis and Article 9 condition for that processing are the practice's to establish — typically Article 9(2)(h), the management of health care services. We apply the safeguards set out in our data processing agreement with them, including access on a need-to-know basis, and we do not use patient data for any purpose of our own.

As a controller, we do not routinely collect special category data about the people we deal with directly. Where you volunteer it — for example, an accessibility requirement for a meeting — we use it only for that purpose, with your consent.

6.Who we share data with

We share personal data only where necessary, and only with:

  • Our team. Clarity personnel and contractors, on a need-to-know basis, bound by confidentiality obligations.
  • Service providers acting on our instructions, including our IT, email and cloud hosting providers; practice management software providers; accounting software providers; and telephony providers. Each is bound by a written contract.
  • Our professional advisers — accountants, insurers, legal advisers — where they need it to advise us.
  • Regulators and authorities where we are required or permitted to disclose, including HMRC, the Information Commissioner's Office, our anti-money laundering supervisor, and law enforcement.

We do not sell personal data, and we do not share it for anyone else's marketing.

  • A note on suspicious activity reports. Where we are required to report a suspicion under the money laundering regulations, we are prohibited by law from telling you that we have done so.

7.Transfers outside the UK

When some of our team or some of our service providers are located outside the United Kingdom, if personal data is transferred there, we have in place: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; a documented transfer risk assessment; and technical measures including access controls, encryption in transit and at rest, and restrictions on local storage.

Where we access a client practice's patient data, any transfer outside the UK is subject to that practice's prior written authorisation in the data processing agreement.

You can request a copy of the safeguards we rely on by contacting us.

8.Cookies

Our website uses cookies that are strictly necessary for it to function.

9.How long we keep it

Data
Retention period
Enquiries that do not become clients
12 months from last contact
Client records and correspondence
6 years from the end of the relationship
Anti-money laundering records
5 years from the end of the business relationship, then deleted unless we are required to keep them longer
Accounting and tax records
6 years from the end of the financial year
Supplier records
6 years from the end of the contract
Website and security logs
12 months

Patient data held in client systems is retained according to the practice's own retention policy, not ours. On termination we return or delete the data as the practice instructs.

10.How we protect it

We apply access controls and multi-factor authentication, encrypt data in transit and at rest, restrict access to those who need it, keep client data separated, take regular backups, and require confidentiality undertakings from everyone who works with us. We review these measures periodically and following any incident.

No system is entirely secure, but we take these obligations seriously and we report notifiable breaches to the ICO within 72 hours, and to affected individuals or controllers where required.

11.Your rights

Under UK data protection law you have the right to:

  • Be informed about how we use your data — this notice
  • Access the personal data we hold about you
  • Rectification of inaccurate or incomplete data
  • Erasure, where we no longer have a lawful reason to keep it
  • Restrict processing in certain circumstances
  • Data portability for data you gave us, where processing is by consent or contract and carried out by automated means
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time, where consent is the basis we rely on

Some rights are qualified. We cannot, for example, delete records we are legally required to retain under the money laundering regulations.

To exercise any of these, contact [email protected]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are a patient of a practice we support, please direct your request to the practice. If you send it to us, we will pass it to them promptly.

12.Complaints

If you are unhappy with how we have handled your personal data, please tell us first at [email protected] so we can put it right.

You also have the right to complain to the Information Commissioner's Office:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

0303 123 1113

ico.org.uk

13.Changes to this notice

We review this notice at least annually and whenever our processing changes materially. The version number and date at the top show when it was last updated. Material changes affecting clients will be notified directly.

← Back to contact

Clarity Practice Management Limited · Company no. 11724459 · Registered in England and Wales