Privacy Policy
SMART Clinical Solutions ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring compliance with the UK Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR).
This Privacy Policy explains what data we collect, how we use it, and your rights under data protection law.
SMART Clinical Solutions is the Data Controller for this Service and responsible for your data.
We have appointed a Data Protection Officer. Contact details are provided in Section 12.
To access the Service, we collect and process:
| Data Type | Purpose | Retention |
|---|---|---|
| Practice login credentials (email/password) | Authentication and access control | For duration of subscription + 12 months after termination |
| Practice name and registration details | Practice identification and billing | For duration of subscription + 7 years (tax requirement) |
| Practice contact information | Service notifications and support | For duration of subscription + 12 months |
| IP address and login timestamps | Security and fraud prevention | 90 days |
Payment processing is handled by Stripe Payment Services. We do not collect or store:
Stripe retains payment data according to their privacy policy. We receive only a payment reference and outcome. See Section 8 for Stripe's data handling.
The Service does not collect, transmit, or store:
We do not use cookies, analytics tracking, or similar technologies to monitor patient data. We may collect:
This data cannot identify patients or individual clinicians.
The SMART Fit Note Assistant is built as a static web application. All clinical processing occurs within your browser using JavaScript:
This architecture provides strong data protection:
We use sessionStorage only to store your authentication token. This is:
We do not use persistent cookies for patient data tracking. We do not use:
Our hosting provider (Netlify) may use minimal technical cookies for:
These are technical necessities and do not track user behavior.
We process your data on the following legal bases under UK GDPR:
| Data Type | Legal Basis |
|---|---|
| Practice authentication credentials | Contract performance (subscription agreement) |
| Billing and payment information | Contract performance and legal obligation (tax law) |
| IP address for security | Legitimate interest (fraud prevention and system security) |
| Service support communications | Contract performance |
We share data only with:
Stripe processes payment card information. We share:
We do not share patient data with Stripe. Stripe's Privacy Policy governs payment data: https://stripe.com/privacy
The Service is hosted on Netlify, which may process:
Netlify does not have access to patient data or clinical content. Their Privacy Policy: https://www.netlify.com/privacy/
We do not sell, rent, trade, or otherwise disclose your data to:
We may disclose data if required by law (court order, regulatory investigation). We will notify you unless legally prohibited.
For payment card information, both SMART Clinical Solutions and Stripe are joint Data Controllers under UK GDPR. Stripe's complete Privacy Policy is available at: https://stripe.com/privacy
Stripe processes:
Stripe retains payment data according to their processing requirements and legal obligations. We do not store full card details.
Stripe may use subprocessors for payment processing. See their Privacy Policy for current list.
Your data is processed and stored in the United Kingdom. We do not transfer data outside the UK unless:
Where transfers occur, we ensure adequacy through standard contractual clauses or other legal mechanisms compliant with UK GDPR.
Under UK GDPR, you have the following rights:
You may request a copy of all personal data we hold about your practice. We will provide this within 30 days in a structured, commonly-used format.
You may correct inaccurate practice data. Log in to your account to update information, or contact us for assistance.
You may request deletion of your data, subject to legal obligations. Tax records may be retained for 7 years as required by law.
You may ask us to limit how we use your data while a dispute is being resolved.
You may request your data in a portable, machine-readable format to transfer to another provider.
You may object to processing for legitimate interest purposes (e.g., security logging).
The Service does not use automated decision-making that has legal effects on you.
To exercise any of these rights, contact our Data Protection Officer (Section 12). We will respond within 30 days.
We implement technical and organizational measures to protect your data:
If a data breach occurs, we will notify affected individuals and relevant regulators within 72 hours as required by UK GDPR, unless the breach poses no risk.
You are responsible for:
If you believe we have violated your privacy rights, you may lodge a complaint with the Information Commissioner's Office (ICO):
We may update this Privacy Policy to reflect changes in law or our practices. Material changes will be notified to you at least 30 days before taking effect. Continued use constitutes acceptance.
| Data Category | Retention Period | Reason |
|---|---|---|
| Practice login credentials | Active subscription + 12 months | Support and dispute resolution |
| Billing records | 7 years after termination | Tax and accounting requirements |
| IP addresses and login logs | 90 days | Security and fraud prevention |
| Payment transaction references | 7 years | Tax and financial audit |