Curofyx is built around UK GDPR and the Data Protection Act 2018 as a first principle, not an afterthought — patient data handled by UK clinics stays subject to UK law, supervised by the Information Commissioner's Office (ICO). For clinics operating in the US, our practices are also designed to align with HIPAA — see our HIPAA Compliance page.
We process personal data only when there is a valid legal basis under UK GDPR — typically consent from the clinic and their patient, or a legitimate interest in delivering the reputation-management service the clinic has signed up for.
Every patient whose data passes through Curofyx has the rights UK GDPR guarantees them, and our platform gives clinics the tools to action these requests directly rather than relying on manual processes:
Curofyx includes a dedicated SAR tracking system so clinics can log, action, and evidence every subject access request within the statutory one-month response window the UK GDPR requires — with a full audit trail of who handled the request and when.
We collect and process only the data necessary to run the reputation-management service a clinic has signed up for — patient contact details for sending review requests, and the reviews themselves. We do not collect clinical or diagnostic records.
Personal data is retained only for as long as it is needed, with an automated retention-policy tool clinics can apply to their own patient records — not an indefinite, manual process.
In the event of a personal data breach that poses a risk to patients, we commit to notifying the ICO within 72 hours as UK GDPR requires, and to notifying affected clinics without undue delay.
A Data Processing Agreement (DPA) covering Curofyx's role as a data processor on behalf of your clinic is available on request — contact us below.
Email: info@curofyx.com