GDPR Compliance

Curofyx is built around UK GDPR and the Data Protection Act 2018 as a first principle, not an afterthought — patient data handled by UK clinics stays subject to UK law, supervised by the Information Commissioner's Office (ICO). For clinics operating in the US, our practices are also designed to align with HIPAA — see our HIPAA Compliance page.

1. Lawful Processing

We process personal data only when there is a valid legal basis under UK GDPR — typically consent from the clinic and their patient, or a legitimate interest in delivering the reputation-management service the clinic has signed up for.

  • Transparent data collection practices, explained in plain English at the point of collection
  • Clear, specific purpose for every category of data we hold
  • Patients can opt out of review-request communications at any time — opt-outs are enforced automatically, not manually

2. Data Subject Rights

Every patient whose data passes through Curofyx has the rights UK GDPR guarantees them, and our platform gives clinics the tools to action these requests directly rather than relying on manual processes:

  • Right of access (Article 15) — clinics can generate a complete data export for any patient on request
  • Right to rectification — patient records can be corrected directly in the clinic dashboard
  • Right to erasure (Article 17) — a built-in erasure workflow anonymises a patient's personal data on request while preserving the minimum audit record UK law requires
  • Right to restrict or object to processing, including opting out of further review requests

3. Subject Access Requests (SARs)

Curofyx includes a dedicated SAR tracking system so clinics can log, action, and evidence every subject access request within the statutory one-month response window the UK GDPR requires — with a full audit trail of who handled the request and when.

4. Data Minimisation

We collect and process only the data necessary to run the reputation-management service a clinic has signed up for — patient contact details for sending review requests, and the reviews themselves. We do not collect clinical or diagnostic records.

5. Data Retention

Personal data is retained only for as long as it is needed, with an automated retention-policy tool clinics can apply to their own patient records — not an indefinite, manual process.

6. Breach Notification

In the event of a personal data breach that poses a risk to patients, we commit to notifying the ICO within 72 hours as UK GDPR requires, and to notifying affected clinics without undue delay.

7. Data Processing Agreement

A Data Processing Agreement (DPA) covering Curofyx's role as a data processor on behalf of your clinic is available on request — contact us below.

8. Contact

Email: info@curofyx.com