Legal
Privacy Notice
Clarity Practice Management Limited — Version 1.5, September 2026
1.About this notice
This notice explains how Clarity Practice Management Limited ("Clarity", "we", "us") collects and uses personal data, and what rights you have over that data. It covers people who enquire about our services, our clients and their staff, our suppliers, and visitors to our website.
It does not cover patients of the practices we work with. Where we handle patient data, we do so on behalf of the practice concerned — see section 3.
Our details
2.The short version
We collect only what we need to respond to enquiries, deliver our services, meet our legal obligations and run the business. We do not sell personal data, and we do not use it for automated decision-making or profiling. Where we handle patient data, we act only on the written instructions of the practice that holds it.
3.Controller or processor — which applies
This distinction matters, because it determines who is responsible for what.
We are the controller for personal data about: people who contact us through the website, by email or by telephone; our clients and the individuals within them we deal with; consultants, contractors and suppliers we work with; and visitors to our website.
We are a processor for personal data held in a client practice's own systems — including patient data — which we access in the course of migrating, configuring, reconciling or operating those systems. In that role: the practice remains the controller and decides the purposes of processing; we act only on the practice's documented instructions; the terms are set out in a written data processing agreement with the practice, not in this notice; and the practice, not Clarity, is responsible for informing its patients about how their data is used.
If you are a patient of a practice we support and have a question about your data, please contact the practice directly. We will assist them in responding.
4.What we collect, why, and on what legal basis
4.1 Enquiries
4.2 Clients and prospective clients
4.3 Anti-money laundering and identity checks
4.4 Suppliers and contractors
4.5 Website visitors
5.Special category data
Health data is "special category" data under UK GDPR and attracts additional protection.
As a processor, we may access patient health data held in a client practice's systems. The lawful basis and Article 9 condition for that processing are the practice's to establish — typically Article 9(2)(h), the management of health care services. We apply the safeguards set out in our data processing agreement with them, including access on a need-to-know basis, and we do not use patient data for any purpose of our own.
As a controller, we do not routinely collect special category data about the people we deal with directly. Where you volunteer it — for example, an accessibility requirement for a meeting — we use it only for that purpose, with your consent.
6.Who we share data with
We share personal data only where necessary, and only with:
- Our team. Clarity personnel and contractors, on a need-to-know basis, bound by confidentiality obligations.
- Service providers acting on our instructions, including our IT, email and cloud hosting providers; practice management software providers; accounting software providers; and telephony providers. Each is bound by a written contract.
- Our professional advisers — accountants, insurers, legal advisers — where they need it to advise us.
- Regulators and authorities where we are required or permitted to disclose, including HMRC, the Information Commissioner's Office, our anti-money laundering supervisor, and law enforcement.
We do not sell personal data, and we do not share it for anyone else's marketing.
- A note on suspicious activity reports. Where we are required to report a suspicion under the money laundering regulations, we are prohibited by law from telling you that we have done so.
7.Transfers outside the UK
When some of our team or some of our service providers are located outside the United Kingdom, if personal data is transferred there, we have in place: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses; a documented transfer risk assessment; and technical measures including access controls, encryption in transit and at rest, and restrictions on local storage.
Where we access a client practice's patient data, any transfer outside the UK is subject to that practice's prior written authorisation in the data processing agreement.
You can request a copy of the safeguards we rely on by contacting us.
8.Cookies
Our website uses cookies that are strictly necessary for it to function.
9.How long we keep it
Patient data held in client systems is retained according to the practice's own retention policy, not ours. On termination we return or delete the data as the practice instructs.
10.How we protect it
We apply access controls and multi-factor authentication, encrypt data in transit and at rest, restrict access to those who need it, keep client data separated, take regular backups, and require confidentiality undertakings from everyone who works with us. We review these measures periodically and following any incident.
No system is entirely secure, but we take these obligations seriously and we report notifiable breaches to the ICO within 72 hours, and to affected individuals or controllers where required.
11.Your rights
Under UK data protection law you have the right to:
- Be informed about how we use your data — this notice
- Access the personal data we hold about you
- Rectification of inaccurate or incomplete data
- Erasure, where we no longer have a lawful reason to keep it
- Restrict processing in certain circumstances
- Data portability for data you gave us, where processing is by consent or contract and carried out by automated means
- Object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent at any time, where consent is the basis we rely on
Some rights are qualified. We cannot, for example, delete records we are legally required to retain under the money laundering regulations.
To exercise any of these, contact [email protected]. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are a patient of a practice we support, please direct your request to the practice. If you send it to us, we will pass it to them promptly.
12.Complaints
If you are unhappy with how we have handled your personal data, please tell us first at [email protected] so we can put it right.
You also have the right to complain to the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113
13.Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The version number and date at the top show when it was last updated. Material changes affecting clients will be notified directly.
Clarity Practice Management Limited · Company no. 11724459 · Registered in England and Wales