Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how QIRO Hub ("we", "us") handles personal data in connection with the QIRO Hub platform (the "Platform"). It should be read together with our Terms & Conditions.

QIRO Hub is provided to organizations (businesses, clinics and practices) on a business-to-business basis. This Policy uses "Organization" to mean the customer that uses the Platform, and "End Clients" to mean the Organization's own clients, customers and patients.

1. Controller and processor roles

Understanding who is responsible for personal data is important:

  • For End Client and Authorised User data entered into or generated through the Platform (such as client records, bookings, medical information, prescriptions and payments), the Organization is the data controller and decides why and how that data is processed. QIRO Hub acts only as a data processor, processing that data on the Organization's documented instructions in order to provide the Platform.
  • For the Organization's own account and billing data (the details provided when registering and paying for the Platform), QIRO Hub acts as a controller for the limited purpose of operating and billing the service.

As controller of End Client and Authorised User data, the Organization is solely responsible for establishing a lawful basis for processing, obtaining all necessary consents, providing privacy notices to its End Clients and Authorised Users, and responding to their data subject requests. QIRO Hub does not have a direct relationship with End Clients and is not responsible for the Organization's compliance.

2. Data we process

  • Account data: name, business details, email, phone and login credentials of the Organization and its Authorised Users.
  • Billing data: subscription, plan and payment-related information (card details are handled by our payment provider, not stored by us).
  • Organization Data: the records the Organization submits, which may include End Client contact details, booking and purchase history, and — where the Organization operates in medical mode — health and clinical information.
  • Usage and technical data: log data, device and browser information, and cookies (see section 9).

3. How we use data

We process personal data to:

  • provide, maintain, secure and improve the Platform;
  • authenticate users and administer accounts;
  • process subscription payments and send service communications;
  • provide support and respond to enquiries; and
  • comply with our legal obligations.

We process Organization Data only as needed to provide the Platform and on the Organization's instructions. We do not sell personal data, and we do not use End Client data for our own marketing.

4. Security

We implement technical and organisational measures designed to protect personal data, including encryption of sensitive fields at rest using industry-standard AES-256 encryption, encrypted transport, access controls and audit logging. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. The Organization is responsible for managing its own user access, keeping credentials confidential, and maintaining its own backups and contingency arrangements. Our personnel and sub-processors who have access to personal data are bound by obligations of confidentiality.

5. Sub-processors and third parties

We use trusted third-party providers to deliver the Platform — for example for hosting, database services, payment processing, email delivery, calendar, accounting and analytics. These providers process data on our behalf under appropriate contractual terms, or directly as independent controllers under their own policies (for example payment processors). We are not responsible for the independent processing or the acts or omissions of third-party services.

Our current key providers include:

  • Hosting and infrastructure — secure server and database hosting for the Platform and the data stored in it.
  • Stripe — payment processing for subscription billing and, where the Organization enables it, the Organization's own transactions; Stripe acts as an independent controller for payment data under its own privacy policy.
  • Postmark — delivery of transactional and service emails (such as receipts and notifications) on our behalf; see its privacy policy.
  • Cloudflare Turnstile — bot and abuse protection on our sign-in and enquiry forms; see its privacy policy.
  • Google Analytics — provided by Google LLC, and used only to understand usage of our public marketing and legal pages. It is loaded only after you accept analytics cookies, and it is never loaded or sent any information while you are using the clinical, client-portal or platform admin areas of the Platform. See its privacy policy.

We use Cloudflare Turnstile to protect our sign-in and enquiry forms against automated abuse and bots. When you interact with these forms, Turnstile processes limited technical information (such as your IP address and browser characteristics) to distinguish genuine users from automated traffic. This processing is carried out by Cloudflare, Inc. in accordance with its Turnstile Privacy Policy.

A current list of sub-processors is available on request, and we will take reasonable steps to notify the Organization of material changes.

6. Automated features and AI

Where the Platform offers automated, algorithmic or AI-assisted features (for example suggestions, summaries, reminders, flags or analytics), any personal data those features process is processed as part of providing the Platform — as a processor acting on the Organization's instructions. Their output is draft only and must be reviewed by a suitably qualified person before any reliance, as set out in our Terms & Conditions. We do not use End Client personal data to train models for our own independent purposes without a lawful basis or the Organization's instructions. Where such a feature relies on a third-party provider, that provider is engaged as a sub-processor under appropriate terms.

7. Anonymised and aggregated data

We may create de-identified and aggregated data from the operation of the Platform. Once data has been aggregated or anonymised so that it no longer identifies, and is not reasonably capable of identifying, any individual, it is no longer personal data, and we may use it to operate, secure, analyse, benchmark, improve and develop the Platform and our services, as described in our Terms & Conditions. We do not attempt to re-identify anonymised data.

8. Data subject rights

Individuals have rights under applicable data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018, such as the rights to access, rectify, erase, restrict and object to processing of their personal data, and to data portability.

End Clients and Authorised Users should direct such requests to the Organization, which is the controller of their data. Where we receive a request relating to data we process on an Organization's behalf, we will refer it to, or assist, that Organization rather than acting on it directly. For account data for which we are the controller, individuals may contact us using the details below.

How an End Client makes a request. If you have a client portal account, you can exercise these rights in the product without writing to anyone: sign in and go to My Data. From there you can see and change your marketing preference, and raise a request to access, rectify, erase, restrict or port your data, or to object to a particular use. You will see the status of each request and the date by which the Organization must respond.

Requests raised this way go to the Organization you are currently signed in to, because that Organization — not QIRO Hub — is the controller of the records it holds about you and decides how to answer. If you are registered with more than one Organization, each holds a separate record and answers separately; switch Organization in the portal and raise the request again for each one.

The Organization must respond within one month of receiving your request. It may extend that period by up to two further months for complex or numerous requests, in which case it must tell you, and tell you why, within the first month. It may also ask you to confirm your identity before it discloses anything. If you are not signed in, or you would rather not use the portal, contact the Organization directly by any means — a request does not have to be made in a particular form to be valid. If you are unhappy with how a request was handled, you may complain to the Information Commissioner's Office at ico.org.uk.

9. Cookies

We use cookies and similar technologies that are strictly necessary to operate the Platform (for example to keep users logged in and secure their session). We also use optional analytics cookies (Google Analytics), but only where all of the following are true:

  • you have actively chosen Accept on our cookie banner — nothing analytics related is loaded, and no analytics cookie is set, before that choice is made; and
  • you are on one of our public pages (our home page, sign-in pages and these legal pages). Analytics is not loaded, and no page address is reported to Google, anywhere in the clinical, client-portal, web store or platform admin areas.

Choosing Reject is a genuine choice: the Platform continues to work in full, and your refusal is remembered so you are not asked again. You can change your mind at any time using the button below or your browser settings, and withdrawal is as easy as giving consent. Disabling essential cookies may prevent the Platform from working. Our bot-protection provider (Cloudflare Turnstile) may also set a strictly necessary challenge cookie when you use our sign-in and enquiry forms. A web store operated by an Organization may load that Organization's own analytics tag, again only after you accept.

10. Data retention

We retain account and billing data for as long as the Organization maintains an account and as required for legal, tax and accounting purposes. Organization Data is retained for the duration of the subscription and is handled on termination in accordance with the Terms and the Organization's instructions, subject to legal retention requirements.

11. International transfers

Where personal data is transferred outside the UK or European Economic Area, we take steps to ensure an appropriate level of protection, such as relying on adequacy decisions or standard contractual clauses.

12. Children

The Platform is intended for use by businesses and their authorised personnel. Where an Organization processes data relating to minors (for example paediatric patients), the Organization is responsible for ensuring it has the appropriate lawful basis and consents.

13. Limitation of liability

To the fullest extent permitted by law, QIRO Hub and its owners, directors, officers, employees and agents accept no liability for the Organization's compliance with data protection law, for the Organization's instructions, or for any loss arising from the Organization's processing of personal data. Our liability is limited as set out in the Terms & Conditions.

14. No third-party rights

This Privacy Policy forms part of, and is subject to, the Terms & Conditions between QIRO Hub and the Organization. It does not create any contractual relationship between QIRO Hub and any End Client or other individual. QIRO Hub processes personal data only as a processor on the documented instructions of the Organization, which is the controller. Any request, complaint or claim by a data subject (including any End Client) in respect of their personal data must be directed to the relevant Organization as controller. To the fullest extent permitted by law, QIRO Hub owes no duty and accepts no liability directly to any End Client or other data subject, and no such person has any right under the Contracts (Rights of Third Parties) Act 1999 or otherwise to enforce this Policy against QIRO Hub. Responsibility for compliance with data protection law in respect of the Organization's processing, and for any personal data breach caused by the Organization's acts, omissions or instructions, rests with the Organization as controller.

15. Changes to this Policy

We may update this Policy from time to time. The "last updated" date above reflects the latest version, and material changes will be notified by reasonable means.

16. Contact

For questions about this Policy or about data we control, contact us at [email protected]. For data held by an Organization about you as an End Client, please contact that Organization directly.

© 2026 QIRO Hub. All rights reserved.

We use cookies that are strictly necessary to run this service, and — only if you accept — optional analytics cookies on our public marketing and legal pages. Analytics is never used in the clinical, client-portal or admin areas. Choosing Reject keeps everything working and is remembered. See our Privacy Policy.