Version 2.2 · Last updated June 2026 · UK GDPR & Data Protection Act 2018 compliant
Intellicons Technology Ltd · getclinic.io · Last updated: June 2026 · Version 2.2
1. Introduction
Intellicons Technology Ltd, operating the GetClinic platform ("GetClinic", "we", "us", or "our"), provides the platform available at getclinic.io. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our platform, services, and website.
This policy applies to all users of the GetClinic platform including independent prescribers, clinic staff, pharmacy users, laboratory users, and patients. Please read it carefully. If you disagree with its terms, please discontinue use of the platform.
2. Data Controller and Data Protection Officer
Intellicons Technology Ltd is the Data Controller for personal data collected through getclinic.io and the GetClinic platform. We are registered with the Information Commissioner's Office (ICO) as required by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
ICO Registration: Intellicons Technology Ltd is registered with the Information Commissioner's Office as a data controller and data processor. Our ICO registration number will be displayed here upon confirmation. To verify our registration status independently, visit ico.org.uk/ESDWebPages/Search and search for “Intellicons Technology Ltd”.
Data Protection Officer (DPO): GetClinic has appointed a Data Protection Officer responsible for overseeing our data protection strategy and compliance. Contact: compliance@getclinic.io
For prescribers using the platform: GetClinic acts as a Data Processor for patient clinical data you enter. You (the prescriber or clinic) are the Data Controller for that patient data. A Data Processing Agreement is available on request.
3. Personal Data We Collect
3.1 Prescriber and Clinical Staff Data
- Full name, professional title, and registration credentials (GMC/GPhC/NMC number)
- Email address, phone number, and professional address
- Hashed prescriber PIN used for Advanced Electronic Signatures — the PIN itself is never stored in plaintext
- Billing and payment details (processed via Stripe — we do not store card numbers)
- Platform usage logs, login records, and audit trails for regulatory compliance
- Identity verification documents submitted during registration
3.2 Patient Data (processed as Data Processor on behalf of prescribers)
- Full name, date of birth, gender identity, and contact details
- Medical history, current medications, allergies, clinical notes, and consultation records
- Prescription records, medication history, and dispensing status
- Pre-consultation questionnaire responses and consent records
- Laboratory test requests and results
- Payment information for patient-pay prescriptions (processed by Stripe)
- IP address and device information for fraud prevention and security purposes
3.3 Website and Platform Usage Data
- IP addresses, browser type and version, pages visited, and time on site
- Cookie data — see our Cookie Policy for full details
- Diagnostic data submitted via error reporting
4. Special Category Data
Health data is "special category" personal data under Article 9 UK GDPR and receives the highest level of protection. We process health data under Article 9(2)(h) — processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care, or the management of health or social care systems, carried out by or under the responsibility of a professional subject to professional secrecy obligations.
A Data Protection Impact Assessment (DPIA) has been conducted for the systematic processing of health data on the GetClinic platform, as required under Article 35 UK GDPR. The DPIA is available to regulators on request.
5. Legal Bases for Processing
We process personal data under the following lawful bases as defined by UK GDPR:
- Contract (Article 6(1)(b)): processing necessary to provide the GetClinic platform to prescribers under our Terms of Service
- Legal Obligation (Article 6(1)(c)): processing required for compliance with MHRA, GPhC, NMC, GMC, and NHS record-keeping obligations
- Legitimate Interests (Article 6(1)(f)): fraud prevention, platform security, and service improvement where our interests do not override your rights
- Vital Interests (Article 6(1)(d)): processing necessary to protect patient safety in urgent clinical contexts
6. How We Use Your Data
- To provide, operate, maintain, and improve the GetClinic platform
- To generate, process, and store electronic prescriptions in compliance with the Human Medicines Regulations 2012
- To facilitate pharmacy fulfilment through our partner networks
- To process payments via Stripe and send payment receipts
- To provide customer support, respond to queries, and resolve complaints
- To send essential service communications (billing, compliance alerts, policy updates)
- To comply with regulatory obligations under MHRA, GPhC, NMC, GMC, and CQC guidelines
- To conduct fraud detection and prevention
- To maintain audit trails as required by UK prescribing regulations
- To improve platform security through penetration testing and vulnerability assessments
We do not use patient health data for marketing purposes. We do not sell personal data to third parties.
7. Data Sharing and Sub-Processors
We share data only where necessary and with appropriate contractual safeguards. Our sub-processors and data-sharing arrangements include:
- Stripe Inc: payment processing — data subject to Stripe's Privacy Policy and Standard Contractual Clauses for international transfers
- Amazon Web Services (AWS): cloud hosting and infrastructure — patient data stored in UK/EU regions only (eu-west-1 / eu-west-2); data transfer safeguarded under UK IDTA
- Vercel Inc: application hosting and content delivery — Standard Contractual Clauses apply for US-based data processing
- Pharmacy partners: partner pharmacies receive only the minimum prescription data necessary to dispense medication, under data-sharing agreements
- Regulatory authorities: MHRA, CQC, GPhC, NMC, GMC, or ICO where we have a legal obligation to disclose
All sub-processors are contractually bound via Data Processing Agreements to process data only as instructed and in compliance with UK GDPR. A full list of sub-processors is available on request at compliance@getclinic.io.
8. International Data Transfers
Some of our sub-processors (including Stripe and Vercel) are based outside the UK. Where we transfer personal data to countries not deemed adequate by the UK Secretary of State, we rely on:
- UK International Data Transfer Agreements (UK IDTA) incorporating the UK Addendum to EU Standard Contractual Clauses
- Adequacy decisions made under the UK GDPR framework
Patient clinical data is hosted exclusively in AWS UK/EU regions and does not leave the UK/EEA.
9. Data Retention
- Prescription records: minimum 8 years from date of prescription in line with GPhC and NHS record-keeping requirements; minimum until patient turns 25 if they were under 18 at time of prescribing
- Patient clinical records: 8 years from last interaction (or until age 25 for records created when patient was a minor)
- Prescriber account data: duration of subscription plus 7 years for legal, regulatory, and audit trail purposes
- Financial records: 7 years in compliance with HMRC requirements
- Identity verification documents: duration of account plus 2 years
- Marketing and consent data: until withdrawal of consent or opt-out request
- Website analytics data: 26 months (Google Analytics standard)
10. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of Access (Article 15): request a copy of the personal data we hold about you (Subject Access Request)
- Right to Rectification (Article 16): request correction of inaccurate or incomplete data
- Right to Erasure (Article 17): request deletion ("right to be forgotten"), subject to legal retention obligations for clinical records
- Right to Data Portability (Article 20): receive your data in a structured, commonly used, machine-readable format
- Right to Restrict Processing (Article 18): request that we limit processing of your data in certain circumstances
- Right to Object (Article 21): object to processing based on legitimate interests
- Rights Related to Automated Decision-Making (Article 22): GetClinic does not make solely automated decisions with significant effects on individuals. All clinically relevant processes involve human review by a qualified prescriber
To exercise any right, contact support@getclinic.io with your request. We will respond within 30 days (or within the 1-month statutory period). Requests are free of charge for the first copy; we may charge a reasonable fee for repetitive or manifestly unfounded requests.
Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time: ico.org.uk/make-a-complaint · ICO Helpline: 0303 123 1113
11. Security Measures
We implement appropriate technical and organisational measures (TOMs) to protect personal data, including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest on AWS infrastructure
- Role-based access controls (RBAC) ensuring each user can access only the data necessary for their role
- Bcrypt hashing for all passwords and prescriber PINs (plaintext credentials are never stored)
- Multi-factor authentication available for all accounts
- Regular penetration testing and vulnerability assessments
- Comprehensive audit logging of all prescription and clinical data access events
- Advanced Electronic Signatures (AES) for all prescriptions, creating a tamper-evident record
- Automated session timeouts and IP-based fraud detection
12. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, GetClinic will:
- Notify the ICO within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR
- Where the breach is likely to result in a high risk to individuals, notify affected data subjects without undue delay (Article 34 UK GDPR)
- Document all breaches internally, including those that do not require notification
To report a suspected security incident: support@getclinic.io
13. Cookies
GetClinic uses cookies and similar tracking technologies to operate the platform, remember your preferences, and analyse usage. For full details including how to manage your cookie preferences, see our Cookie Policy.
14. Note on HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is United States federal legislation and does not directly apply to GetClinic as a UK-registered company operating primarily within the United Kingdom. The UK GDPR and Data Protection Act 2018 provide equivalent or higher standards of protection for health information than HIPAA in most respects. Prescribers treating patients outside the UK should satisfy themselves of any additional data protection obligations that may apply in those jurisdictions.
15. Complaints Handling
If you are dissatisfied with how we have handled your personal data, you may:
- Contact our Data Protection Officer at compliance@getclinic.io. We will acknowledge your complaint within 3 working days and aim to resolve it within 28 calendar days.
- If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time: ico.org.uk/make-a-complaint · ICO Helpline: 0303 123 1113
For clinical complaints relating to prescribing decisions (which are the responsibility of the individual prescriber, not GetClinic as a software platform), please contact the prescriber's relevant regulatory body (GMC, GPhC, or NMC) directly.
16. Data Processing Agreements
If you are a prescriber or clinic using GetClinic to process patient data, you are the Data Controller and GetClinic is your Data Processor for that patient data. A Data Processing Agreement (DPA) is incorporated into our Terms of Service and is available in full at getclinic.io/dpa or on request at support@getclinic.io. The DPA sets out the subject matter, duration, nature, and purpose of the processing, and our obligations to you under Article 28 UK GDPR.
17. Changes to This Policy
We may update this Privacy Policy periodically. We will notify registered users by email and post the updated policy at getclinic.io/privacy with the revision date. For material changes, we will provide at least 30 days' notice. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
18. Contact
Data Protection / Privacy: compliance@getclinic.io
General & Subject Access Requests: support@getclinic.io
ICO: ico.org.uk · 0303 123 1113
Company: Intellicons Technology Ltd · Company No: 17267394
Registered Address: 14/2E Docklands Business Centre, 10-16 Tiller Road, London, E14 8PX