Privacy Notice
Last updated: August 2026
This notice explains how Marlmed Limited handles personal data. It sits alongside our Terms of Service, our Data Processing Agreement, our Sub-processor Register, and our Security & Trust Centre.
1. Who we are
Marlmed Limited ("Marlmed", "we", "us", "our") operates the website at marlmed.com and provides the Marlmed practice management platform.
Marlmed Limited is registered in England and Wales under company number 17127171.
Marlmed Limited is registered with the Information Commissioner's Office (ICO), registration reference ZC223318.
Privacy contact: [email protected]. Our data protection lead is Peter Irvine.
2. Our role: when we are a controller and when we are a processor
Data protection law distinguishes between a "controller" (who decides why and how personal data is processed) and a "processor" (who processes it on a controller's instructions). Our role depends on the data:
- Website visitors and sales enquiries: we are the controller.
- Clinic users, administrators, billing and support contacts: we are normally the controller for account administration, authentication, security, billing and support.
- Patient, clinical, stock, asset and other records our clients enter into the platform ("Customer Data"): our client (the clinic or organisation) is the controller and we act as their processor, under our Data Processing Agreement.
If you are a patient or individual whose records are held by a clinic that uses Marlmed, your request (for example to access or correct your records) should ordinarily be directed to that clinic, which is the controller of those records. We will assist the clinic in responding.
3. Special category (health) data
The platform is used by medical clinics and may hold special category data, including health and clinical information, as part of Customer Data. For that data our client is the controller and determines the lawful basis and any Article 9 condition for processing it; we process it only as their processor on their documented instructions, under the Data Processing Agreement and with the safeguards described in our Security & Trust Centre. We do not use Customer Data for our own purposes.
4. Personal data we process as controller
- Enquiry and demo details: name, role, practice or clinic name, email, and any message.
- Account and profile information: user names, work email, role, and organisation/administrator details.
- Subscription, invoice and payment metadata: plan, amounts, billing contact and payment status (card details are handled by Stripe, not stored by us).
- Authentication, audit and security information: login events, session data, actions taken in the platform, and multi-factor authentication status, logged for audit and security.
- Support requests and correspondence.
- Service email delivery and engagement information for transactional emails.
- Server logs: IP address and browser information, for security and performance.
- Cookie and analytics identifiers (see section 7), where you consent.
We do not sell personal data, and we do not use advertising trackers or advertising cookies.
5. Purposes and lawful bases
Where we act as controller, we rely on the following lawful bases under UK GDPR:
| Processing | Lawful basis |
|---|---|
| Responding to enquiries and arranging demonstrations | Legitimate interests (responding to people who contact us) and pre-contract steps taken at your request |
| Creating and administering accounts | Contract, and legitimate interests (operating the service) |
| Authentication, audit logging and security monitoring | Legitimate interests (keeping accounts and data secure) |
| Subscription billing and accounting | Contract, and legal obligation |
| Transactional service emails | Contract, and legitimate interests |
| Website analytics (Google Analytics) | Consent |
| Preventing fraud and defending legal claims | Legitimate interests, and legal obligation where applicable |
Where we rely on legitimate interests, our interest is to operate, secure, support and improve a reliable service for our clients; we balance that against your rights and only rely on it where appropriate. We will not send unsolicited marketing without your consent.
6. Recipients and processors
We share personal data only with service providers who process it on our instructions to run the platform, and where required by law. Our current sub-processors include DigitalOcean (UK hosting), Resend (transactional email), Stripe (payment processing), Cloudflare (network security and delivery), and Google Analytics (website analytics, on consent). Optional AI features may use Anthropic where a client opts in.
The full, current list, with the data each receives and its location, is maintained in our Sub-processor Register.
Google Workspace and Google Calendar access
Where a clinic chooses to run video consultations through Google Meet, Marlmed asks that clinic to connect a Google account. What we do with that access, in full:
- What we request. A single scope,
calendar.events. It lets us create, move and cancel calendar events. We do not request access to Gmail, Drive, Contacts, or to read anything unrelated to the appointments we create. - What we do with it. When a patient books a video consultation we create one calendar event, attach a Google Meet link to it, and invite the clinician and the patient. If the appointment is moved we move that event. If it is cancelled we delete it. That is the whole of it.
- What we store. The refresh token that keeps the connection working, and the identifier of each event we created so we can move or cancel it later. We do not copy calendar contents into Marlmed, and we do not read events we did not create.
- What we never do. Google user data is never sold, never used for advertising or profiling, never used to train any AI model, and never shared with a third party beyond delivering the appointment itself.
- Disconnecting. A clinic or an individual clinician can disconnect at any time from Settings, which revokes our access immediately. Meetings already in the diary are not cancelled by disconnecting.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7. Cookies and analytics
Our site uses a small number of cookies. Non-essential (analytics) cookies are only set if you accept them in our cookie banner, and you can decline or withdraw consent at any time by clearing the analytics choice in your browser and declining when prompted.
| Cookie | Provider | Purpose | Essential | Expiry |
|---|---|---|---|---|
| Consent preference | Marlmed | Remembers your cookie choice | Yes | Up to 12 months |
| Session / login | Marlmed | Keeps you signed in securely (platform only) | Yes | Session / up to 30 days |
| _ga / _ga_* | Google Analytics | Measures how visitors use marlmed.com | No (consent) | Up to 24 months |
If you accept analytics cookies, we use Google Analytics (GA4) to understand how visitors use our marketing site (pages viewed, referring source, approximate location). For UK visitors, GA4 uses the IP address transiently to derive a coarse location and does not log or store it. Analytics only run after you accept; decline and no analytics cookies are set.
8. Where your data is processed and international transfers
Our core production database, application servers and primary backups are hosted in the United Kingdom. Certain supporting services, including transactional email, network security and delivery, payment processing, and optional AI features, may process limited information outside the UK, as set out in our Sub-processor Register.
Where personal data is transferred outside the UK, we rely on an appropriate safeguard, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. You can request details of the relevant safeguard by emailing [email protected].
9. How long we keep it
- Enquiry and demo data: up to 2 years, or until you request deletion
- Lead and enquiry data for prospective patients who do not proceed: reviewed for continued necessity within 2-3 years of last contact; once deleted, records remain recoverable for up to 180 days before permanent erasure
- Trial accounts and their data: retained during the trial and for up to 90 days after it ends, with a 30-day self-export window, then securely deleted
- Client platform data (Customer Data): for the duration of the subscription and up to 90 days after termination (30-day self-export window), then securely deleted, subject to the client's instructions under the DPA
- Account, authentication and audit records: for the life of the account and a reasonable period afterwards for security and legal purposes
- Billing and accounting records: as required by law (generally up to 6 years)
- Support tickets and correspondence: up to 2 years
- Transactional email delivery logs: up to 12 months
- Server logs: up to 12 months
- Consent and security-incident records: as long as needed to evidence compliance
- Encrypted backups: rotated on a rolling schedule and overwritten in the ordinary course
10. Your rights
Under UK GDPR you may have the right to access your data, to have inaccurate data corrected, to erasure, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Some of these rights are not absolute and depend on the circumstances and the lawful basis; for example, erasure and portability do not apply in every case.
Your right to object: where we process your data on the basis of legitimate interests, you have the right to object at any time. Please tell us and we will stop unless we have compelling legitimate grounds that override your interests.
To exercise any right, email [email protected]. We will respond without undue delay and normally within one month. In certain circumstances we may extend this by up to two further months, in which case we will tell you within the initial one-month period. If your request concerns records held by a clinic (Customer Data), we will direct you to that clinic as the controller and assist them.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
11. Complaints
If you believe we have not handled your data correctly, please contact us first so we can help. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
12. Data Processing Agreement
Clients using the platform are covered by our Data Processing Agreement, which governs our processing of Customer Data on their behalf. A countersigned copy for your organisation is available on request from [email protected].
13. Changes to this notice
We may update this notice from time to time. Where a change materially affects how we use your personal data, we will provide appropriate notice and, where required, obtain fresh consent. The date at the top of this page shows when it was last revised.
14. Contact
For any privacy query: [email protected], or write to us at the registered office above.