Last updated: 02.02.2026
This Privacy Policy explains how Policy Now Ltd(“we”, “us”, “our”) collects, uses, stores, and protects personal data when you use Policy Now, a software-as-a-service policy management system for independent healthcare providers in the United Kingdom (the “Platform”).
This Privacy Policy should be read together with our Terms and Conditions.
1. Who We Are
Policy Now Ltd is a company incorporated in England and Wales with registered number 16942214 and registered office at 25 Thirlmere, Macclesfield, Cheshire SK11 7XY.
For the purposes of UK data protection law:
- We act as a data controller for personal data relating to our business operations and Platform users.
- We act as a data processor for personal data uploaded to the Platform by our customers.
2. Scope of This Policy
This Privacy Policy applies to:
- visitors to our website;
- users of the Platform; and
- representatives of organisations that subscribe to the Platform.
It does not cover third-party services, including payment providers or app marketplaces, which have their own privacy policies.
3. Personal Data We Collect
3.1 Information You Provide to Us
We may collect:
- name, job title, and organisation name;
- email address and contact details;
- account login credentials;
- support requests and correspondence.
3.2 Information Processed on Behalf of Customers
When you upload or manage content on the Platform, this may include personal data relating to:
- staff members;
- contractors;
- service users or patients (where included within policies or procedures).
In these cases, you are the data controller and we act as your data processor.
3.3 Technical and Usage Data
We may automatically collect:
- IP address;
- device and browser information;
- usage logs and activity data;
- cookies and similar technologies.
4. How We Use Personal Data
We use personal data to:
- provide and operate the Platform;
- manage accounts and subscriptions;
- communicate with users and provide support;
- improve and secure the Platform;
- comply with legal and regulatory obligations.
We do not use personal data for automated decision-making or profiling.
5. Legal Bases for Processing
Under the UK GDPR, we rely on the following lawful bases:
- Contract – where processing is necessary to provide the Platform;
- Legitimate interests – for platform security, improvement, and business operations;
- Legal obligation – where required by law;
- Consent – where explicitly obtained (e.g. marketing communications).
6. Data Sharing and Disclosure
We may share personal data with:
- trusted service providers (e.g. hosting, analytics, support tools);
- professional advisers (legal, accounting);
- regulators or authorities where required by law.
All service providers are required to implement appropriate data protection and security measures.
We do not sell personal data.
7. International Data Transfers
Personal data is primarily processed within the UK.
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations; or
- International Data Transfer Agreements (IDTAs).
8. Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
- access controls;
- encryption where appropriate;
- regular security reviews.
Despite these measures, no system can be guaranteed to be completely secure.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.
Customer data processed on behalf of subscribers is retained in accordance with our contractual arrangements and data retention policies.
10. Your Data Protection Rights
Under UK data protection law, individuals have the right to:
- access their personal data;
- request rectification or erasure;
- restrict or object to processing;
- data portability;
- withdraw consent at any time (where applicable);
- lodge a complaint with the Information Commissioner’s Office (ICO).
Requests can be made using the contact details below.
11. Cookies
We use cookies and similar technologies to operate and improve the Platform.
Further details are provided in our Cookie Policy (if applicable).
12. Third-Party Payment Providers
Payments and subscriptions are handled through a third-party app or marketplace.
We do not receive or store full payment card details. Please refer to the privacy policy of the relevant third-party provider for further information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be effective when published on our website or within the Platform.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact:
Email: admin@policynow.uk
Company: Policy Now Ltd