Legal

Privacy Policy

Privacy Policy

Effective Date: August 16, 2026

We respect your privacy and are committed to protecting the personal information you provide when using our website, services, and related platforms. This Privacy Policy explains how we collect, use, store, and protect your information.

1. Information We Collect

We may collect information that you voluntarily provide to us, including your name, email address, phone number, business information, billing details, and other information submitted through forms, account registration, service requests, or direct communication.

We may also automatically collect certain technical information, such as your IP address, browser type, device information, pages visited, and general website usage data.

2. How We Use Your Information

We may use collected information to:

  1. Provide and manage our accounting and financial services.
  2. Process requests, appointments, payments, and transactions.
  3. Communicate with you regarding our services and your account.
  4. Prepare reports, invoices, and other service-related documentation.
  5. Improve our website, services, and customer experience.
  6. Maintain security and prevent fraud or unauthorized activity.
  7. Comply with applicable legal, regulatory, and accounting requirements.

3. Sharing of Information

We do not sell or rent your personal information. We may share information with trusted service providers, professional advisers, payment processors, technology providers, or other third parties when necessary to provide our services, operate our business, or comply with legal obligations.

Where appropriate, we require third parties handling personal information on our behalf to maintain reasonable safeguards and confidentiality.

4. Data Security

We take reasonable administrative, technical, and organizational measures to protect personal information against unauthorized access, alteration, disclosure, loss, or misuse. However, no method of transmitting or storing information electronically can be guaranteed to be completely secure.

5. Data Retention

We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, provide our services, maintain business records, resolve disputes, and satisfy applicable legal or regulatory obligations.

6. Cookies and Tracking Technologies

Our website may use cookies and similar technologies to remember preferences, understand website usage, improve functionality, and analyze traffic. You may be able to control or disable cookies through your browser settings, although certain website features may not function properly as a result.

7. Your Rights

Depending on applicable law, you may have rights to request access to, correction of, deletion of, or restrictions on the processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.

To make a privacy-related request, please contact us using the contact details provided on our website.

8. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of those third parties. We recommend reviewing their privacy policies before providing personal information.

9. Children's Privacy

Our services are not intentionally directed toward children. We do not knowingly collect personal information from children where prohibited by applicable law.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, legal requirements, or privacy practices. Any updated version will be posted on this page with a revised effective date.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or the way we handle personal information, please contact us through the contact information available on our website.

Note: This is general-purpose privacy policy text for testing and demonstration purposes and should be reviewed and customized to your business, jurisdiction, data practices, and applicable laws before being used as a legal policy.

Third parties your browser contacts

We host our own fonts, scripts and default images, so viewing this website does not, by itself, tell another company that you visited.

Transfers outside the UK

There is no default transfer of a visitor IP address to a US image host. If staff later link a photograph stored outside the UK, that host will be named here and on the processor list in the privacy notice.

Analytics

We do not use Google Analytics, Google Tag Manager, Meta Pixel, or any similar tracking service. We count how often our calculators are opened, on our own server and only if you allow analytics in the cookie banner; those counts are anonymous and cannot be linked to you. See our Cookie Policy for the full detail.

Who we are

The controller of personal data collected through this website and the client portal is HealthcarePartners Limited.

Registered office: United Kingdom. Enter the full registered office in CMS → GDPR..

Privacy contact: privacy@healthcarepartners.co.uk.

You can ask us about your data, or exercise your rights, on our privacy rights page.

Why we use your information

We only use personal data for the purposes below, and only on the lawful basis shown.

  • Responding to enquiries and booking consultations — Legitimate interests / steps prior to a contract (Art 6(1)(b) and 6(1)(f)). Name, contact details, practice information and the message you send so we can reply and arrange a call.
  • Client portal, documents and messaging — Contract (Art 6(1)(b)). Account details, messages and files needed to deliver the accounting service you asked us for.
  • Electronic marketing (newsletter and resource updates) — Consent (Art 6(1)(a); PECR reg 22). Only if you tick an unticked opt-in. Confirmed by email. You can withdraw at any time.
  • Site security, fraud prevention and audit — Legitimate interests / legal obligation (Art 6(1)(c) and 6(1)(f)). Login events, IP addresses in audit logs, and security cookies required to keep the service safe.
  • Cookies that are not strictly necessary — Consent (PECR regs 6–7). Optional analytics or marketing cookies, if we ever add them, stay off until you accept them in the banner.

What we collect and where

Every field the website currently asks for is listed below. If staff add a custom contact-form field in the CMS, it appears here automatically.

  • Your name — Required. Collected on the contact form (including any extra field staff have added in the CMS).
  • Email — Required. Collected on the contact form (including any extra field staff have added in the CMS).
  • Phone — Required. Collected on the contact form (including any extra field staff have added in the CMS).
  • Practice / company — Optional. Collected on the contact form (including any extra field staff have added in the CMS).
  • What are you interested in? — Optional. Collected on the contact form (including any extra field staff have added in the CMS).
  • Message — Required. Collected on the contact form (including any extra field staff have added in the CMS).
  • Portal registration — name, email, phone and password, on the basis of a contract.
  • Resource downloads — name, email and optional specialty, on legitimate interests, so we can send the file and keep a short download log.
  • Marketing opt-in — email and the wording you agreed to, only if you tick the box and confirm the address.

Who we share data with

We use the following processors and international transfers. We do not sell your data.

  • Unsplash (United States) — Only if staff later link a photograph hosted by Unsplash. The default homepage image is self-hosted and does not contact Unsplash. Transfer tool: Adequacy / contractual clauses as published by Unsplash.
  • Microsoft (Graph / Exchange Online) (United Kingdom / European Economic Area / United States (Microsoft tenant region)) — Optional outbound email when staff enable Microsoft Graph in CMS settings. Transfer tool: UK IDTA / EU SCCs as provided by Microsoft.
  • SMTP email provider (As configured by the firm) — Sends transactional and (if you consented) marketing email when SMTP is configured. Transfer tool: DPA and, if outside the UK, UK IDTA or adequacy.
  • Pusher / Soketi (Pusher Cloud (typically United States) or self-hosted Soketi) — Optional real-time messaging in the client portal and CMS. Transfer tool: Pusher DPA / SCCs, or none if Soketi is hosted in the UK.
  • Amazon Web Services (S3) (AWS region chosen by the firm) — Optional file storage if the firm switches document disks to S3. Transfer tool: AWS DPA and SCCs where the region is outside the UK.

How long we keep it

  • Enquiry / consultation leads: 24 months after last contact (Delete).
  • Marketing subscribers: Until you unsubscribe, then 24 months as a suppression record (Suppress, then delete).
  • Resource download logs: 24 months (Delete).
  • Calculator usage events: 13 months (Delete).
  • Client portal accounts and files: 7 years after the engagement ends (UK accountancy record-keeping) (Delete or anonymise).
  • Messages and attachments: 7 years after the conversation closes (Delete).
  • Audit logs (including IP address): 24 months (Anonymise, then delete).
  • Data-subject request records: 24 months after completion (Delete).

Your rights

You can ask for a copy of your data, a portable export, a correction, deletion, a restriction, or to object to processing. You can also withdraw marketing consent at any time. Use our privacy rights form, email privacy@healthcarepartners.co.uk or write to us from the contact page.

You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint.

Who this service is for

This website and client portal are for adults and healthcare professionals only. We do not knowingly collect personal data about children.