← Back to home

Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Atlacare Ltd ("we", "us") collects and uses personal data, and your rights over that data. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


Controller or processor — which applies

When a clinic uses Atlacare to manage its patients, the clinic is the data controller of patient data and Atlacare acts as a data processor on the clinic's behalf, under our Data Processing Addendum.

This Privacy Policy describes the data for which Atlacare itself is the controller — data about website visitors, clinic account holders, and people who contact us.

If you are a patient, please contact your clinic about their handling of your records. Atlacare also controls a small amount of data about patients who use the patient portal (such as sign-in and security logs); that is explained in our separate Patient Privacy Notice.


1. Who we are

Atlacare provides practice-management software for allied-health clinics.

For data we control, the controller is ATLACARE LTD, a company registered in England and Wales (company number 17284670), registered office 96 Sirius Close, Wokingham, England, RG41 3DT.

You can contact us about privacy at privacy@atlacare.com.


2. What we process, and why

DataPurposeLegal basisRecipientsRetention
Account data — name, work email, password hash, clinic name, role, two-factor settingsCreating and administering accounts; authentication and access managementContract; legitimate interests (securing accounts)Hosting providerWhile the account is active, then a limited period for security and legal purposes
Billing data — billing contact, subscription and payment records. Card details are handled by our payment provider and never stored by AtlacareTaking payment; accounting and tax complianceContract; legal obligationPayment providerAs required by accounting and tax law
Security data — access logs, technical and security event logs, IP addressProtecting the service; detecting and investigating incidents; preventing fraud and misuseLegitimate interests (security of the service)Hosting and error-monitoring providersA limited period set by security investigation needs
Support and communications data — messages you send usAnswering questions; providing supportContract; legitimate interestsEmail providerWhile needed for the enquiry, then a limited period
Usage and analytics data — general page-usage information on public marketing pages, public booking pages and the patient portal, with record identifiers removed. Never collected on the clinic dashboard or admin areaUnderstanding how the service is used and improving itConsentAnalytics providerPer the retention setting described in our Cookies and Similar Technologies Policy
Marketing data — clinic account-owner name, email, plan status, product engagementSending product updates and onboarding email to business customersLegitimate interests, with opt-out at any timeMarketing email providerUntil you opt out, then suppression-list only

We do not use patient clinical records for our own purposes. That data is processed solely on behalf of clinics under the Data Processing Addendum.

We do not use your data, and we do not permit others to use it, to train artificial intelligence models.


3. Special category data

Where patient health data (special-category data under Article 9) is processed within the platform, the clinic acting as controller is responsible for identifying the Article 9 condition and, where relevant, the Data Protection Act 2018 Schedule 1 condition. As processor, we apply appropriate technical and organisational measures and act only on the clinic's documented instructions.


4. Sharing and sub-processors

We share data with vetted third-party providers only as needed to run the service — for hosting, file storage, email, payments and error monitoring. Depending on the service and the data involved, a provider may act as our processor or as an independent controller.

Our current providers, with their purpose, region and role, are listed at atlacare.com/sub-processors.

We never sell personal data.


5. International transfers and data residency

Patient and clinical data is hosted and stored within the European Economic Area, subject to limited remote access from outside the UK/EEA where necessary for support, security or incident response and protected by appropriate safeguards.

Where a provider operates outside the UK/EEA, or where limited remote access from outside the UK/EEA is necessary, transfers are protected by appropriate safeguards such as the Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.


6. How long we keep data

Retention is set out per data type in the table in section 2.

Patient clinical records are retained according to the legal, regulatory and professional requirements applicable to the relevant healthcare provider. The provider is responsible for determining the appropriate retention period for its records. The platform supports configurable retention to help providers apply the period they have determined.


7. Automated decisions and profiling

We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you, and we do not use your personal data for automated profiling.


8. Providing your data

Where we act as controller, providing your account and billing details is a contractual requirement — we need them to open your account, provide the Service and take payment. If you do not provide them, we cannot provide the Service to you. Providing analytics data is entirely optional.


9. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, object to processing, and data portability, and the right to withdraw consent where you gave it.

To exercise any right over data we control, email privacy@atlacare.com.

If you are a patient, contact your clinic, who is the controller of your records. Where we hold those records as the clinic's processor, we will assist the clinic in responding.


10. Security

We use encryption in transit and at rest, role-based access controls, tiered clinical-note visibility, optional two-factor authentication, and audit logging. Uploaded files are never publicly accessible and are served only to authorised users for a limited time. We filter patient health information out of error reports.

No system can be guaranteed secure, but we work to protect your data to a high standard.

Reporting a security issue. If you believe you have found a security vulnerability in Atlacare, please report it to us at security@atlacare.com. We will acknowledge your report and keep you informed while we investigate. Please give us a reasonable opportunity to resolve the issue before disclosing it publicly.


11. Cookies

See our Cookies and Similar Technologies Policy. Non-essential cookies, including analytics, load only after you consent, and analytics never run on the clinic dashboard or admin area.


12. Complaints

If you have concerns we have not resolved, you can complain to the UK supervisory authority, the Information Commissioner's Office (ICO) at ico.org.uk.


13. Changes

We may update this policy and will revise the date above when we do. Material changes affecting clinics will be notified in line with our agreement with them.


Questions about this policy: privacy@atlacare.com.