This policy explains how we collect and use your personal data, the lawful bases we rely on, and the rights you have. It applies to vuemedics.com, the clinician dashboard, the review process, the procedure guides, the appraisal toolkit and our embeddable reviews widget.
We have written it in plain English so that a patient or a clinician can actually read it. Where the law requires precision we have included the relevant references (for example the UK GDPR Article we rely on), but you do not need to understand those to use your rights — just contact us using the details in section 1.
A short note on what we measure: Vuemedics records patients' experience of private care — how they were treated, communicated with and looked after. We do not measure, score or publish clinical quality or medical outcomes.
This policy sits alongside our Terms of Service, our Cookie Policy, our Clinician Removal & Objection Policy and our Review Dispute & Notice-and-Action Policy, which together govern how the service works.
1. Who we are and how to contact us
Vuemedics is operated by Adept Surgical Ltd (trading as Vuemedics), a company registered in England & Wales under company number 09731047, with its registered office at The Lexicon, Second Floor, Mount Street, Manchester M2 5NT.
Adept Surgical Ltd is the data controller for the personal data described in this policy. We are registered with the Information Commissioner's Office (ICO) under reference ZB280884.
Our Privacy Lead, Mr Masha Singh, is responsible for data protection at Vuemedics and is your single point of contact for any privacy question, request or complaint:
Post: Mr Masha Singh (Privacy Lead), Adept Surgical Ltd, The Lexicon, Second Floor, Mount Street, Manchester M2 5NT
We have assessed whether we are required to appoint a statutory Data Protection Officer (DPO) under Article 37 of the UK GDPR, and we consider that, at our current scale, we are not currently required to do so. We keep this under active review and will re-test the threshold as our health-data processing grows — in particular if it reaches "large scale" — and will appoint a DPO if that becomes required. In the meantime the Privacy Lead carries out the equivalent role, and you can raise any data-protection matter with them using the details above.
2. The people whose data we process, and what we collect
We collect different information depending on how you interact with Vuemedics. This section is grouped by who you are.
2.1 If you are a clinician (listed, or using the platform)
We hold:
Professional and registration details: name, professional title, GMC number, specialty, registration status and Specialist-Register status, CQC-registered location(s), society memberships, biography, optional photo, and your fees and consultation details.
Identity-verification evidence: for example an @nhs.net email verification, or an uploaded GMC certificate, used to confirm you are who you say you are when you claim or manage a listing.
Account and contact details: your login email, password (stored only in strongly hashed form, never in plain text), and the access you grant to delegated staff such as a secretary or PA.
Secretary / PA contact details: where you provide these, they are visible only to you and are never published.
Subscription status: whether you are on a free or paid plan, and the related billing references. Card payments are handled by our payment processor (Stripe) — we do not store card numbers.
Activity on the platform: dashboard use, replies you post to reviews, and similar records needed to run your account securely.
Much clinician data is built initially from public registers before you engage with us — see section 6.
2.2 If you are a patient leaving a review (a reviewer)
Reviews on Vuemedics are invitation-only: a clinician issues a single-use link after real care. If you leave a review we collect:
Your review: your structured ratings, the procedure or reason for care, your answer to the "felt no pressure" question, your written headline and review text.
A single-use invitation token that ties your review to a genuine episode of care.
The contact detail you were invited on (email or mobile number), where you were invited electronically.
A record of your consent: the purpose, the version of the wording you agreed to, and the time.
A review that describes your own treatment is health information ("special category data") about you — see section 4 for how we handle it.
We publish you only as "Verified patient". Your name is never published.
2.3 If you give appraisal (multi-source) feedback
The appraisal toolkit lets a clinician collect confidential patient and colleague feedback as portfolio evidence for their GMC appraisal and revalidation. If you take part we collect:
Your questionnaire responses, and (for colleague feedback) your professional role.
The contact detail you were invited on, used only to send the invitation and any reminder.
This feedback is held anonymously to the clinician — it is shown to them only as aggregates, and only once a minimum number of responses has been reached, so that individual responses cannot be singled out. Your contact detail is never shown to the clinician. Appraisal feedback is kept strictly separate ("firewalled") from public reviews and is never turned into a public review.
2.4 If you send an enquiry to a practice
If you contact a clinician's practice through Vuemedics, we collect your name, the contact details you provide, and your message, and pass them to that practice so they can respond. We ask you not to include detailed medical information in an enquiry; if you choose to share any health detail, see section 4.
2.5 If you are a site visitor
When you simply browse Vuemedics (for example reading procedure guides or viewing profiles):
We count profile and widget views in a privacy-safe way using a daily-rotating, salted hash. We do not store your IP address for this, and we set no analytics cookies for it. These records cannot be joined together into a browsing history.
We keep limited server logs for security and to keep the service running.
Any optional analytics stay switched off until you opt in via our cookie banner. See section 11 and our Cookie Policy.
2.6 Enquirers and correspondents
If you email us, use a contact form, or otherwise get in touch (for example a press, partnership or support query), we hold your contact details and the content of your message so that we can respond and keep a record of the matter.
3. Why we use your data, and our lawful bases
Under the UK GDPR we must have a lawful basis for everything we do with your personal data. The table below sets out each purpose, the data involved and the basis we rely on. Where we rely on legitimate interests we have carried out and recorded a Legitimate Interests Assessment (LIA), which concluded that our interests (and the public interest) are not overridden by your rights and freedoms, given the safeguards described in this policy.
What we do
Data involved
Our lawful basis (UK GDPR)
List clinicians and run the directory
Clinician professional and registration data
Legitimate interests — Art 6(1)(f). The interest is transparent, verified information about registered professionals so patients can make informed private-care choices, and clinicians' interest in a fair, portable reputation. Supported by our LIA.
Legitimate interests — Art 6(1)(f) — in accuracy, trust and fraud prevention (verifying we list genuine, registered professionals). Supported by our LIA. This is not a statutory legal obligation: we verify as a self-imposed quality and integrity measure. Where the evidence reveals special-category data relating to the clinician's profession (for example regulatory or employment status), we rely on Art 9(2)(b) (employment, social security and social protection) and/or Art 9(2)(g) (substantial public interest), under the Data Protection Act 2018, as set out in our Appropriate Policy Document.
Publish a review
The review and the invitee contact detail
Consent — Art 6(1)(a); and for any health detail in the review, explicit consent — Art 9(2)(a), supported by Art 9(2)(e) (information manifestly made public by you, the data subject, when you choose to publish your own experience). See section 4.
A separate, explicit consent — Art 6(1)(a), and Art 9(2)(a) for any health detail — kept confidential and firewalled from public reviews.
Pass your enquiry to a practice
Your name, contact details and message
Legitimate interests — Art 6(1)(f) — in connecting patients with clinicians, supported by our LIA. Any health detail you volunteer rests on your explicit consent — Art 9(2)(a).
Take subscription payments
Billing and subscription data
Contract — Art 6(1)(b) — to provide the paid service to subscribing clinicians.
Moderate content, prevent fraud, keep the service secure, and keep audit records
Whatever is needed for each task
Legitimate interests — Art 6(1)(f) — in a safe, fair, abuse-free platform. Where a genuine statutory duty applies (for example complying with a court order, or HMRC/tax record-keeping), we rely on legal obligation — Art 6(1)(c). Where this touches health data we rely on Art 9(2)(g) (substantial public interest) and/or Art 9(2)(f) (establishment, exercise or defence of legal claims), as set out in our Appropriate Policy Document.
Send marketing emails to clinicians
Business contact details
Consent — Art 6(1)(a) — or, for our own existing clinician customers, a soft opt-in under PECR, always with an easy one-click opt-out.
Where we rely on consent, you can withdraw it at any time; this does not affect any processing we carried out lawfully before you withdrew. Where we rely on legitimate interests, you have the right to object (see section 9).
We do not make decisions about you by solely automated means that produce legal or similarly significant effects. Our moderation of reviews is carried out (or finally decided) by people, against published guidelines — see section 12.
4. Health information (special-category data)
A review or an appraisal response that reveals a person's own health or treatment is "special category" data under Article 9 of the UK GDPR, which needs extra protection.
For the live published review and the appraisal response, we process this health data on the basis of your explicit consent (Article 9(2)(a)), captured at the point you submit your review or feedback, alongside the Article 6(1)(a) consent for the processing itself. Because you choose to publish your own experience, we also rely on Article 9(2)(e) (information manifestly made public by you, the data subject) as a supporting condition for the published-review health data.
For retaining health-related records where this is necessary for moderation, fraud prevention, audit and the defence of legal claims — including after you withdraw consent — we additionally rely on Article 9(2)(g) (substantial public interest) and Article 9(2)(f) (establishment, exercise or defence of legal claims). This is what allows us to keep a minimal accountability record even after a review is withdrawn (see below and section 9).
We minimise what we ask for — we collect only what is needed to make the review or feedback meaningful, and no more.
We ask you not to disclose other people's health information, and our moderation removes content that identifies third parties.
You can withdraw your consent and withdraw or correct your own review at any time (see sections 8 and 9). If you withdraw a review, we remove it from public view and delete its content within 30 days. For accountability we keep only a minimal, non-content audit record — that a review existed and was withdrawn, with no health content — for up to 6 years, relying on Article 9(2)(g)/(f) rather than on your consent. Withdrawing your consent ends our reliance on consent, but it does not by itself erase this minimal accountability stub.
We maintain an Appropriate Policy Document governing our processing of special-category and criminal-offence data, as required by the Data Protection Act 2018 where we rely on certain Article 9 conditions (for example the substantial-public-interest condition for moderation, fraud prevention and audit, and the employment/regulatory condition for clinician verification). It explains how we comply with the data-protection principles and our retention and erasure policies for that data, and is available on request from the Privacy Lead.
5. How and why we protect reviewer anonymity
Because reviews can reveal health information and because reviewers are often patients in a position of trust, anonymity is central to how Vuemedics works:
Reviewers are shown publicly only as "Verified patient" — never by name.
A reviewer's contact details are never shown to the clinician.
We will disclose a reviewer's identity only where we are compelled to by a valid court order (for example a Norwich Pharmacal order), or where the reviewer themselves consents. We never disclose it to a clinician simply because they ask.
Where a clinician brings a formal defamation complaint under our Review Dispute & Notice-and-Action Policy, the reviewer may be asked whether they consent to their details being passed to the complainant. If the reviewer declines, we do not identify them: the disputed content is removed instead. See that policy for the full process.
6. Where we obtain clinicians' data
We build clinician listings from public information — principally the GMC register and the CQC register of regulated locations (CQC data is used under the Open Government Licence v3, with attribution). This means some listings are created before the clinician engages with us.
To meet our transparency duty under Article 14 of the UK GDPR, this privacy policy is publicly available from the moment a listing is created, so the information is accessible to any listed clinician from the outset. In addition, when we first contact a clinician directly, we tell them about the listing and link to this policy. A clinician can object to the listing, and a clinician with no published reviews who objects will be removed (a pre-review opt-out). See section 9 and our Clinician Removal & Objection Policy.
7. Who we share your data with
We share personal data only where we need to, and we do not sell personal data.
7.1 Processors acting on our instructions
The following service providers process personal data on our behalf and under our instructions, each bound by a written data-processing agreement that requires them to keep your data secure, use it only for the agreed purpose, and assist us with your rights and with any breach:
Provider
What they do for us
Where
DigitalOcean
Hosting and managed database
London (UK) region
Stripe, Inc.
Payment processing (we store no card numbers)
USA — transfer protected by the UK Addendum to the EU Standard Contractual Clauses / IDTA, with a transfer risk assessment on file (see section 8)
Postmark (Wildbit / ActiveCampaign)
Sending invitations, account and service emails
USA — transfer protected by the UK IDTA / Addendum to the EU SCCs, with a transfer risk assessment on file. See section 8
Google Analytics (Google Ireland Ltd / Google LLC)
Aggregate website usage statistics — loaded only if you opt in to analytics; IP addresses are anonymised
USA — transfer protected by Google's certification under the UK Extension to the EU–US Data Privacy Framework and the SCCs / UK IDTA in Google's data-processing terms (see section 8)
OpenStreetMap (map tiles, served via Fastly CDN)
Displays the map on consultant profiles and the directory — to load the map, your IP address and the area you are viewing are sent to the tile server
EU / global CDN — no cookies are set; used only to show the map
7.2 Sources we obtain data from (not recipients)
The GMC and CQC are sources from which we obtain verification data — they are not recipients of your data.
7.3 Other disclosures
We may disclose data to regulators, law-enforcement or other authorities where the law requires us to, or to establish, exercise or defend legal claims.
We disclose a reviewer's identity only as set out in section 5.
We do not syndicate reviews to third parties. Reviews appear on Vuemedics and, where a clinician chooses, on that clinician's own website through our embeddable widget.
8. Where your data is held, and international transfers
We host in the UK (DigitalOcean, London) and we aim to keep your personal data in the UK or the EEA. Some processing, however, necessarily involves a transfer outside the UK/EEA, and we want to be plain about this:
Payments are handled by Stripe, Inc., which processes data in the United States. This involves a transfer of personal data to the US.
Transactional email is handled by Postmark (Wildbit / ActiveCampaign), which processes data in the United States — again a US transfer.
Website analytics use Google Analytics (Google, USA), loaded only after you opt in to analytics via the cookie banner — so a US transfer occurs only for opted-in visitors, and only of anonymised, aggregate usage data.
For every such transfer we make sure it is protected by an appropriate safeguard recognised under UK law — UK adequacy regulations where they apply, or the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — and we record a transfer risk assessment for that provider. You can ask the Privacy Lead for more detail about the safeguard relied on for a particular provider.
9. How long we keep your data
We keep personal data only as long as necessary for the purpose it was collected for, or as the law requires, under a documented Data Retention Schedule which we review annually. "Delete" means hard-delete or irreversible anonymisation. The main periods are:
Data
How long we keep it
Published reviews
Kept while published — there is no fixed expiry. They are patients' own experiences and are information in the public interest, so we are not asked to delete genuine reviews simply because a clinician dislikes them. You can withdraw or correct your own review at any time.
Clinician listings (claimed/active)
Kept while the listing is active. A clinician with no published reviews who objects is removed; we keep only a minimal suppression record (GMC number, date and reason) for 24 months so the listing is not recreated by accident.
Withdrawn reviews
Removed from public view immediately; content deleted within 30 days; a minimal non-content audit stub (that a review existed and was withdrawn, with no health content) is kept per the moderation-audit period (6 years), relying on Art 9(2)(g)/(f) — see section 4.
Review invitations and tokens
The recipient's contact detail is deleted 90 days after the invite is used or expires; invitation metadata (no contact) is kept for 24 months.
Enquiries to practices
Up to 12 months, then deleted (sooner on request).
Appraisal — individual responses
Raw individual responses deleted about 13 months after a round closes; respondent contact deleted within 30 days of the round closing.
Appraisal — aggregate report
Up to 5 years (the revalidation cycle) or until the clinician deletes it.
Identity-verification evidence
Deleted within about 3 months of verification completing; we keep only the fact and date of verification.
Moderation audit log
6 years (supports our defence under the Defamation Act 2013 and our duties under the Online Safety Act 2023 and DMCC Act 2024).
Consent records
Duration of the related processing plus 3 years.
Billing and financial records
6 years from the end of the relevant accounting period, to meet HMRC / VAT record-keeping requirements. (Card data is held by Stripe, not by us.)
Profile/widget view analytics
Already privacy-safe (no IP, no cookie); raw rows kept up to 25 months; non-personal aggregates may be kept indefinitely.
Accounts, sessions and security tokens
Accounts deleted/anonymised within 30 days of closure (except records held under another row, such as billing); session and reset tokens expire and are purged promptly.
Server / security logs
About 90 days (up to 6 months if needed for an active security investigation).
Encrypted backups
A rolling 35-day cycle. When we delete data from the live service, the same data drops out of backups as the cycle rolls over.
Rights requests and decisions
3 years, as evidence that we handled your request properly.
If data is subject to a legal hold (actual or reasonably anticipated litigation, a regulatory request, or a court order), we keep it until the hold is lifted, overriding the periods above.
10. Your rights
Under the UK GDPR you have the right to:
Access — get a copy of the personal data we hold about you.
Rectification — have inaccurate data corrected and incomplete data completed.
Erasure — have your data deleted in certain circumstances.
Restriction — ask us to limit how we use your data while a query is resolved.
Object — object to processing we carry out on the basis of legitimate interests, and object to direct marketing at any time.
Portability — receive certain data you provided to us in a structured, commonly used, machine-readable format.
Withdraw consent — at any time, where we rely on your consent (without affecting earlier lawful processing).
Some rights are qualified. In particular, the right to erasure does not apply where we need to process the data for freedom of expression and information — for example, genuine published reviews, which we are not obliged to delete simply because a clinician objects to them. Where a right is limited in your case we will explain why.
How to exercise a right: contact the Privacy Lead at [email protected], or write to us at the registered office in section 1. We respond within one month (we can extend this by up to two further months for complex requests, and we will tell you if so). It is normally free of charge. We may first need to verify your identity so we don't disclose someone's data to the wrong person.
Making a request on behalf of someone else: you can exercise these rights for another person if you are authorised to — for example as an attorney under a Lasting or Enduring Power of Attorney, a court-appointed deputy, or a parent or carer acting for a child or for an adult who lacks capacity. Contact the Privacy Lead in the same way and we will ask for evidence of your authority (such as the LPA, court order, or other proof that you may act for the person) and proof of both your and their identity, before we act. If a person can make the request themselves we may ask for their confirmation. We handle these requests within the same one-month timeframe.
Requests about someone who has died: data-protection law does not apply to the personal data of a deceased person, so this is not a legal right — but if you are a close relative or the executor of someone who has died and you are concerned about a review connected to them, please contact the Privacy Lead. We will consider such requests compassionately and sensitively, case by case (we may ask for proof of death and of your relationship).
Clinicians: for listing-specific requests (objection to, or removal of, a listing), please use our Clinician Removal & Objection Policy, which operates your Article 21 objection right and the qualified Article 17 erasure right through a recorded balancing decision. For subscription cancellation and related contract rights, see our Terms of Service.
Complaints: if you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, by their helpline, or in writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
11. Cookies
We set only strictly necessary cookies and similar technologies by default (for example to keep you signed in, to protect against fraud and abuse, and to remember your cookie choices). Non-essential cookies and technologies — such as any optional analytics — are off until you opt in, and you can accept, reject by category, or change your mind at any time using the cookie banner and the "Cookie settings" link in the footer.
For the full list of what we use, how long each item lasts, and how to manage your choices, see our Cookie Policy.
12. Automated decision-making and moderation
We do not carry out automated decision-making that produces legal or similarly significant effects about you. We use automated checks only to assist (for example to flag possible spam, abuse or rule-breaking content, and to verify registration data), but moderation decisions affecting whether a review is published, edited or removed are made or finally decided by a person, against our published moderation guidelines. There is a free right of reply for clinicians and a notice-and-action route for disputed content (see our Review Dispute & Notice-and-Action Policy).
13. How we protect your data
We protect your data with technical and organisational measures including: encryption in transit (TLS 1.2+); strongly hashed passwords; role-based access control and least-privilege; a strict data firewall around appraisal feedback; audit logging; encrypted backups; abuse and rate limiting; secure-by-default production configuration; and a documented breach procedure. If a personal data breach occurs we assess it and, where required, we notify the ICO without undue delay and within 72 hours of becoming aware, and we tell affected individuals without undue delay where the breach is likely to result in a high risk to them.
14. Children
Vuemedics is intended for adults. You must be 18 or over to hold an account, leave a review, or give appraisal feedback, and the service is not directed at children. We do not knowingly collect data about under-18s; if you believe a child's data has reached us, please contact the Privacy Lead.
15. Changes to this policy
We may update this policy from time to time. We will show an updated version number and effective date at the top, and we will notify you of material changes (for example by email to account holders or a prominent notice on the site) before they take effect. This policy should be read together with our Terms of Service and Cookie Policy.
16. Contact
For any privacy question, request or complaint, contact our Privacy Lead: