Last updated: September 2026
This Privacy Policy explains how Atlacare Ltd ("we", "us") collects and uses personal data, and your rights over that data. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
When a clinic uses Atlacare to manage its patients, the clinic is the data controller of patient data and Atlacare acts as a data processor on the clinic's behalf, under our Data Processing Addendum.
This Privacy Policy describes the data for which Atlacare itself is the controller — data about website visitors, clinic account holders, and people who contact us.
If you are a patient, please contact your clinic about their handling of your records. Atlacare also controls a small amount of data about patients who use the patient portal (such as sign-in and security logs); that is explained in our separate Patient Privacy Notice.
Atlacare provides practice-management software for allied-health clinics.
For data we control, the controller is ATLACARE LTD, a company registered in England and Wales (company number 17284670), registered office 96 Sirius Close, Wokingham, England, RG41 3DT.
You can contact us about privacy at privacy@atlacare.com.
| Data | Purpose | Legal basis | Recipients | Retention |
|---|---|---|---|---|
| Account data — name, work email, password hash, clinic name, role, two-factor settings | Creating and administering accounts; authentication and access management | Contract; legitimate interests (securing accounts) | Hosting provider | While the account is active, then a limited period for security and legal purposes |
| Billing data — billing contact, subscription and payment records. Card details are handled by our payment provider and never stored by Atlacare | Taking payment; accounting and tax compliance | Contract; legal obligation | Payment provider | As required by accounting and tax law |
| Security data — access logs, technical and security event logs, IP address | Protecting the service; detecting and investigating incidents; preventing fraud and misuse | Legitimate interests (security of the service) | Hosting and error-monitoring providers | A limited period set by security investigation needs |
| Support and communications data — messages you send us | Answering questions; providing support | Contract; legitimate interests | Email provider | While needed for the enquiry, then a limited period |
| Usage and analytics data — general page-usage information on public marketing pages, public booking pages and the patient portal, with record identifiers removed. Never collected on the clinic dashboard or admin area | Understanding how the service is used and improving it | Consent | Analytics provider | Per the retention setting described in our Cookies and Similar Technologies Policy |
| Marketing data — clinic account-owner name, email, plan status, product engagement | Sending product updates and onboarding email to business customers | Legitimate interests, with opt-out at any time | Marketing email provider | Until you opt out, then suppression-list only |
We do not use patient clinical records for our own purposes. That data is processed solely on behalf of clinics under the Data Processing Addendum.
We do not use your data, and we do not permit others to use it, to train artificial intelligence models.
Where patient health data (special-category data under Article 9) is processed within the platform, the clinic acting as controller is responsible for identifying the Article 9 condition and, where relevant, the Data Protection Act 2018 Schedule 1 condition. As processor, we apply appropriate technical and organisational measures and act only on the clinic's documented instructions.
We share data with vetted third-party providers only as needed to run the service — for hosting, file storage, email, payments and error monitoring. Depending on the service and the data involved, a provider may act as our processor or as an independent controller.
Our current providers, with their purpose, region and role, are listed at atlacare.com/sub-processors.
We never sell personal data.
Patient and clinical data is hosted and stored within the European Economic Area, subject to limited remote access from outside the UK/EEA where necessary for support, security or incident response and protected by appropriate safeguards.
Where a provider operates outside the UK/EEA, or where limited remote access from outside the UK/EEA is necessary, transfers are protected by appropriate safeguards such as the Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable.
Retention is set out per data type in the table in section 2.
Patient clinical records are retained according to the legal, regulatory and professional requirements applicable to the relevant healthcare provider. The provider is responsible for determining the appropriate retention period for its records. The platform supports configurable retention to help providers apply the period they have determined.
We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you, and we do not use your personal data for automated profiling.
Where we act as controller, providing your account and billing details is a contractual requirement — we need them to open your account, provide the Service and take payment. If you do not provide them, we cannot provide the Service to you. Providing analytics data is entirely optional.
Under UK GDPR you have the right to access, rectify, erase, restrict, object to processing, and data portability, and the right to withdraw consent where you gave it.
To exercise any right over data we control, email privacy@atlacare.com.
If you are a patient, contact your clinic, who is the controller of your records. Where we hold those records as the clinic's processor, we will assist the clinic in responding.
We use encryption in transit and at rest, role-based access controls, tiered clinical-note visibility, optional two-factor authentication, and audit logging. Uploaded files are never publicly accessible and are served only to authorised users for a limited time. We filter patient health information out of error reports.
No system can be guaranteed secure, but we work to protect your data to a high standard.
Reporting a security issue. If you believe you have found a security vulnerability in Atlacare, please report it to us at security@atlacare.com. We will acknowledge your report and keep you informed while we investigate. Please give us a reasonable opportunity to resolve the issue before disclosing it publicly.
See our Cookies and Similar Technologies Policy. Non-essential cookies, including analytics, load only after you consent, and analytics never run on the clinic dashboard or admin area.
If you have concerns we have not resolved, you can complain to the UK supervisory authority, the Information Commissioner's Office (ICO) at ico.org.uk.
We may update this policy and will revise the date above when we do. Material changes affecting clinics will be notified in line with our agreement with them.
Questions about this policy: privacy@atlacare.com.