Privacy Policy
We collect the minimum data we need to run the service. We never sell it. Here’s exactly what we do and why.
Last updated: 1 June 2026 · GP Automate Ltd · Registered in England & Wales
Who we are
We are GP Automate Ltd (company number 13405991), registered at 116 Chaplin Road, 1st Floor, Wembley Centre For Health And Care, Wembley, England, HA0 4UZ.
We provide MHRA Class I clinical automation software for NHS GP practices, PCNs and ICBs — automating lab reporting, patient registrations and QOF prevalence coding so clinicians spend more time on patient care.
We are registered with the UK’s data protection regulator, the Information Commissioner’s Office (ICO), under registration number ZB326921.
Your trust in our data security and privacy is at the heart of what we do. It’s not enough to ask you to trust us — we have to show that we are trustworthy. Being transparent about what we do with the personal data we need to provide our software is part of how we earn it.
This policy explains how we handle personal data. The sections below cover how we handle data for different groups of people:
- Healthcare professionals
- Patients
- Prospective customers from healthcare organisations
- User research participants
- Job applicants and prospects
This notice may change from time to time and will always be published at gpautomate.com.
Roles
Healthcare professionals
GP Automate is software for healthcare organisations — primarily NHS GP practices, Primary Care Networks (PCNs) and Integrated Care Boards (ICBs). If you work in one of those organisations and you use GP Automate, we receive information about you in three ways:
- When you’re registered for a GP Automate account (usually by your employer)
- Through your ongoing use of the platform
- If you contact us directly — by email, phone, social media or live chat
GP Automate account registration
When your employer requests an account for you, we collect:
- Name
- Work email address
- Telephone number
- Job role
- The healthcare organisation you work for
Why: We collect this on the basis of legitimate interest, so that we’re ready to link your profile to your organisation. Once your account is linked, we process your data as a data processor on behalf of your employer.
Ongoing use of GP Automate
The healthcare organisation you work for is responsible for how your information is used inside our platform — in legal terms, they are the Data Controller. They provide us with information and instruct us how to use it. We act as a Data Processor.
Once your registration is linked to an organisation, we associate your account with information including your job role and the actions you take in the software (results filed, codes applied, messages sent). We have a clear Data Processing Agreement with every healthcare provider setting out what we do with this data and how we keep it safe. You can request a copy of this agreement from your employer.
Email, social media or telephone contact with us
When you contact us through any channel, we may collect:
- Name
- Email address
- Telephone number
- Social media handles
- Anything else you share with us in your message
Why: We collect this on the basis of legitimate interest, to respond to you.
Patients
GP Automate is software used by your GP practice or PCN to automate parts of their administrative and clinical workflow. If you’re a patient at a practice that uses GP Automate, we receive information about you in two ways:
- Via healthcare organisations who use GP Automate software
- If you contact us directly
Via healthcare organisations who use GP Automate software
Your GP practice or PCN is responsible for deciding how your information is used in our software — in legal terms, they are the Data Controller. When they use GP Automate to file a lab result, register you as a new patient, or process QOF data, they provide us with information and instruct us how to use it.
This means we act as a Data Processor, and this clinical processing falls outside the scope of this Privacy Policy. We have a clear Data Processing Agreement with every healthcare provider that sets out what we do with data and how we keep it safe. You can request the full agreement and more information about our role from your healthcare provider.
For full detail on how we process your health data on behalf of NHS organisations, please see our Patient Privacy Notice or contact your GP practice.
Via direct correspondence with you
If you contact us directly — for example with a complaint or question — we’ll collect:
- Name
- Email address
- Telephone number
- Anything else you share with us in your message
Why: We collect this on the basis of legitimate interest, to address your queries quickly and efficiently.
For any clinical data subject request (for example, asking what data your practice holds about you), please contact your GP practice — they are the controller of that data.
Prospective customers from healthcare organisations
If you work for a GP practice, PCN, ICB or other NHS organisation, and we’re talking to you about whether GP Automate is right for you, we collect:
- Name
- Job title and role
- The healthcare organisation you work for, and its ODS code where relevant
- Work email address
- Telephone number
- Content of email communications with you and metadata (including delivery and open status)
- Notes from our conversations, demos and follow-up correspondence
- Any additional information you provide to us through our communications
Why: We collect this on the basis of legitimate interest, to discuss procurement and purchasing decisions about our software with your organisation.
If you’ve consented to receive marketing communications, we’ll also send you product updates, NHS-relevant content and news. You can withdraw consent at any time — every marketing email includes an unsubscribe link, or you can email us directly.
User research participants
We try to build software that our users love. To do that we spend time with healthcare professionals and patients to understand their needs. We may run research to improve existing products or inform the development of new ones.
When you participate in our research, we collect:
- Name
- Job role and organisation
- Email address
- Recordings, transcripts or notes from interviews and usability tests
- Survey responses
- Any other information you provide to us through surveys, interviews or other communications
Why: We collect this on the basis of legitimate interest, to ensure our products are fit for purpose and match your expectations, or — for research involving recording or sensitive topics — on the basis of explicit consent obtained at the beginning of the research project.
In some circumstances we may carefully anonymise your personal data so that it can no longer be associated with you, and we may use that anonymised information indefinitely to analyse and improve our products.
Job applicants and prospects
When you’ve signed up for information about events or job opportunities
If you sign up to receive hiring updates from us:
- Name
- Email address
- Any other information you provide when you sign up (for example, the roles you’re interested in)
Why: To send you event or hiring information, or to process your booking in relation to an event we are organising. We process this on the basis of your consent. You can opt out at any time.
When you apply for a role with us
If you apply for a role at GP Automate, we collect:
- Name
- Email address
- Telephone number
- Employment history and other information in your CV or otherwise submitted to us
- Assessments completed as part of the application process
- Feedback about you from our staff and your referees
Why: We collect this on the basis of legitimate interest, to assess job applications and take the necessary steps to enter into an employment contract with you. We also have a legal obligation to ensure applicants have the right to work.
Email or social media contact
If you contact us about a role over email or social media, or we contact you about an opportunity, we may also collect:
- Email address
- Telephone number
- Login information
- Social media handles and profile URL
- Time-zone setting, browser and operating system information, IP address
We retain information about you as a prospective employee for up to 24 months, so we can improve our hiring process and inform you of future opportunities. If we reach out to you about a role we think you’d be a good match for, we’ll retain your name and social profile URL for up to 24 months for the same purposes. We do this on the basis of our legitimate interest to find great people to work with us.
General questions
How do we collect information?
We collect information about you from a number of sources:
- Email, telephone, social media, live chat and in-person interactions with you
- From healthcare organisations using GP Automate (when you’re a member of their staff or a patient)
- From your employer when you’re set up as a user
- Cookies on our website and pixels in our emails
- Publicly accessible sources, including your employer’s website, LinkedIn profile, or NHS organisation directory entry
Cookies and similar tracking
When you visit gpautomate.com we and our analytics partners use cookies and similar technologies. These include:
- Essential cookies — necessary for the site to function. These do not require your consent.
- Analytics cookies — Plausible Analytics (cookie-less and GDPR-friendly) and Google Analytics 4. Google Analytics loads only with your consent, via our cookie banner.
- Marketing cookies — used to measure the performance of advertising. Loaded only with your consent.
You can change your cookie preferences at any time via the “Cookie preferences” link in our footer.
How long do we retain your personal data?
Our retention periods for different groups are set out below. If you have a question about a category not covered, please contact our Data Protection Officer at the address below.
Type of data | Retention period |
Healthcare professional account data (whilst your employer is a customer) | For as long as necessary to provide the service, plus reasonable period for audit and accounting |
Communications from patients who contact us directly | Up to 24 months after last contact |
Prospective customer data (sales conversations) | Up to 48 months after last meaningful contact with your organisation |
Customer contract records | 7 years after end of contract (tax and accounting compliance) |
User research participant data | Up to 48 months after research concludes, unless otherwise stated in the project’s consent material |
Job applicants and prospective candidates | Up to 24 months after the conclusion of any hiring process |
Marketing email subscribers | Until you unsubscribe |
Which third parties are involved in processing your data?
We work with a small number of carefully chosen sub-processors. The current list:
Service | Role | Where data is stored |
Microsoft Azure | Clinical processing infrastructure | UK |
Microsoft 365 (Teams, OneDrive, Outlook) | Internal communications, file storage, video calls | UK / EU |
Fillout | Online forms (demo requests, contact) | EU |
Attio | Customer Relationship Management (CRM) | EU |
Mailchimp (Intuit) | Marketing email delivery | United States (IDTA) |
Make.com | Workflow automation between business systems | EU |
Plausible Analytics | Cookie-less website analytics | EU |
Google Analytics 4 / Tag Manager | Website analytics (with consent) | United States (IDTA) |
Website hosting (WordPress) | Web hosting | UK / EU |
Where data is transferred outside the UK or EEA, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or equivalent safeguards. Copies of the relevant agreements are available on request from our DPO.
We have contractual agreements in place with NHS GP practices, Primary Care Networks and Integrated Care Boards which govern and protect the data we process on their behalf.
We may also share your data with regulators, professional bodies and law enforcement where we are under a legal obligation to do so.
What rights do you have under data protection laws?
You have a number of rights under UK GDPR. Please note that if you are a patient or a member of staff in an organisation that uses GP Automate, you should contact that organisation (the data controller) to exercise rights relating to clinical data — we cannot action those requests directly because we act as the processor, not the controller, for that data.
For data we control (sales leads, marketing email subscribers, website visitors, job applicants, user research participants), you can ask us to:
- Access — give you a copy of the personal data we hold about you
- Rectification — correct incomplete or inaccurate data
- Erasure — delete personal data we hold about you
- Restrict — limit how we use your personal data
- Portability — transfer your personal data to a third party
- Object — object to how we are using your personal data
- Withdraw consent — where we rely on your consent, you can withdraw it at any time
To exercise any of these rights, please contact our Data Protection Officer using the details below. We aim to respond within one calendar month, in line with UK GDPR.
You also have the right to lodge a complaint with the Information Commissioner’s Office, the supervisory authority for data protection in the UK:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
http://www.ico.org.uk
How to contact us
For any question or request about how we use your personal data, please contact our Data Protection Officer:
Umar Sabat
umar.sabat@ig-health.co.uk
Or write to us at our registered office:
GP Automate Ltd
116 Chaplin Road, 1st Floor
Wembley Centre For Health And Care
Wembley, England HA0 4UZ
United Kingdom
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational or regulatory reasons. We’ll post any updates here and update the “Last reviewed” date at the top of this page.
