Fedelsoft

Privacy policy

Who we are

Fedelsoft Practice Manager is provided by Fedelsoft Ltd, a company registered in England and Wales (company number 14256263, registered office Grove House, Waltham Road, White Waltham, Maidenhead SL6 3TN, ICO registration ZC268007). You can reach us at support@fedelsoft.com.

We hold personal data in two different roles. For your Fedelsoft account, your subscription and anything you send us through this website, we are the data controller. For the patient, staff and business records that a practice, clinic or hospital keeps in Fedelsoft, that organisation is the controller and we act as its processor, on its instructions and under a written agreement with it.

If you are a patient of an organisation that uses Fedelsoft, your first point of contact about your record is that organisation.

What we collect and why

Your account. Your name, username, email address, mobile number, role and the organisations you work with. We use these to sign you in, to show you only what your role allows and to send you the messages the service depends on. Sign-in secrets are stored in protected form. Our lawful basis is our contract with you or with your organisation.

Your subscription. The organisation's name and billing contact, the plan chosen and a record of payments. Card details are entered with our payment provider and are not stored by Fedelsoft. Our lawful basis is contract, and our legal obligation to keep accounting records.

Records your organisation keeps in Fedelsoft. Patient details, appointments, clinical notes, letters, consents, photographs, documents, invoices, staff rotas and similar records. These include health data. We process them only to provide the service to the organisation that entered them, and we do not use them for our own purposes.

Enquiries. If you write to us or fill in a form on this website, we keep what you send so that we can reply.

Technical records. Sign-in times, the address a request came from and error logs, kept to secure the service and to find faults. Our lawful basis is our legitimate interest in running a secure service.

Questions put to Ask and text sent for drafting. When you use the AI features, the text involved is sent to our AI provider to produce the answer or the draft. It is limited to what your role may already see.

We do not sell personal data, and we do not use it for advertising.

Google user data

Connecting a Google account is optional. If you connect yours from Settings, Fedelsoft asks Google for two things: your Google account email address, and permission to view and edit events on your calendars. It asks for nothing else, and it cannot see your email, contacts or files.

What we access. Your Google account email address, and the events on your primary calendar.

How we use it. Fedelsoft adds your clinics, operating lists, appointments, cases and meetings for the coming 120 days to your calendar, and updates or removes those entries as your Fedelsoft diary changes. So that moving an appointment in Google can move it in Fedelsoft, we ask Google for the changes to your calendar. Google's answer includes your other events. Fedelsoft acts only on the entries it wrote itself, which carry its own mark, and discards everything else without storing it.

What we write to your calendar. A title, a place, a time and a short note. An appointment or case entry shows the patient's initials and Fedelsoft record number, and a case entry shows its title. Patients are never named.

What we store. Your Google account email address; the token that lets Fedelsoft reach your calendar, held in encrypted form; your choices about what to sync; and a list of the calendar entries Fedelsoft wrote, so that it can keep them up to date. We do not store your other calendar events.

Who we share it with. Nobody. Google user data is held by the providers that host Fedelsoft, listed below, and is not passed to anyone else. It is not sold, not used for advertising and not used to train AI models. It is not sent to our AI provider.

How to remove it. Disconnect from Settings at any time. Fedelsoft then revokes its access with Google and deletes the token and its list of entries. The entries already on your calendar stay there as your own record, and you can delete them in Google. You can also remove Fedelsoft's access from your Google account under third-party access.

Fedelsoft's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Connected social accounts

Connecting an Instagram professional account or a Facebook Page is optional, and is done by a Director or the organisation's IT support from Settings. Fedelsoft then publishes the organisation's own before and after posts to the accounts it chooses. It is a connection through Meta, and it acts only for the organisation that made it.

What we access. When someone connects, Meta asks them which Facebook Pages, and which Instagram accounts linked to those Pages, Fedelsoft may use. For each one they grant, Fedelsoft receives its name and Meta's number for it, the Instagram account's username, and an access token that lets Fedelsoft publish to it. The permissions asked for are to list those Pages, read their basic details, publish posts to them, publish to the linked Instagram account, and reach Pages held in a Meta business portfolio. Fedelsoft does not ask for messaging, and does not read messages, comments, followers or anyone's personal profile.

How we use it. Only to publish posts that a person at the organisation has approved, at the time it set for each, and to record the link to each post once it is up. Nothing is published without that approval. A post shows a patient's photographs only where that patient has given the organisation their recorded consent to publish them. Fedelsoft does not add the patient's name to a post. The organisation covers intimate areas before approving a post, and Fedelsoft will not publish a picture while any cover placed on it is unconfirmed. The covering is done on the device the picture is prepared on, so the uncovered picture is never sent to Meta. The finished picture or video is placed at a public web address only for the minutes Meta needs to collect it, and that address stops working once the post is up or is withdrawn.

What we store. For each connected Page or Instagram account: its name, Meta's number for it, who connected it and when; the access token, held in encrypted form; and, for each post, when it was published and Meta's number and link for it. The token used while connecting is not kept.

Who we share it with. Nobody. The data is held by the providers that host Fedelsoft, listed below. It is not sold, not used for advertising and not used to train AI models. Photographs and access tokens are never sent to our AI provider.

How to disconnect. Disconnect from Settings at any time. Fedelsoft deletes the access token at once and publishes nothing more to that account. Posts already published stay on Instagram or Facebook as the organisation's own posts, and the organisation can delete them there. You can also remove Fedelsoft's access in your Facebook settings, under Business integrations.

How to have the data deleted. To have Fedelsoft delete what it holds about a connected Instagram account or Facebook Page, Disconnect it and then Delete it, in Settings. Delete removes the account's name, Meta's number for it and the record of its posts at once. If you cannot sign in to Fedelsoft, email support@fedelsoft.com from the address of a Director of the organisation, naming the organisation and the account, and we will disconnect and delete it within 30 days and confirm by email. A patient who wants their photographs taken down should contact the organisation that published them, which withdraws their consent in Fedelsoft and removes the posts.

Who processes data for us

We use the providers below to run Fedelsoft. Each acts on our instructions under a data processing agreement. Those marked optional are used only when you or your organisation connect them.

ProviderWhat it does, and whenWhere data is heldSafeguard for transfers outside the UK
CloudflareRuns the application, stores files and sign-in sessions, and transcribes consultation recordings. AlwaysFiles in EU data centres; the application and sessions on Cloudflare's global networkUK Addendum to the EU standard contractual clauses
SupabaseHosts the database. AlwaysUnited Kingdom (London)Not needed: held in the United Kingdom
MailerSendSends email. AlwaysEU (Belgium)UK Addendum
ClickSendSends text messages, when your organisation sends themAustralia, where messages are deleted after 120 days; monitoring and support from the United States, the EU and the PhilippinesUK International Data Transfer Addendum
StripeTakes card payments for subscriptions and membershipsUnited States and other countriesUK extension to the Data Privacy Framework, or the UK Addendum
AnthropicAnswers questions put to Ask and drafts text, when you use the AI featuresUnited StatesUK Addendum
GoogleReceives the calendar entries Fedelsoft writes. Optional, per personGoogle's own network, under your own Google accountGoogle's own terms with you
ZoomProvides video consultation links. Optional, per practitionerUnited States by defaultUK Addendum
DropboxHolds older files of an organisation that kept them in its own Dropbox account, until they are moved into Fedelsoft's own storage. Fedelsoft reads them there to show them and stores nothing new in Dropbox. Only for an organisation with such filesUnited States by defaultThe organisation's own agreement with Dropbox
Amazon Web ServicesHolds a second, locked copy of every organisation's files and of the database, kept for 30 days, from which they can be restored if the first copy is lost. Always, once that copy beginsUnited Kingdom (London)Not needed: held in the United Kingdom
MetaReceives the posts Fedelsoft publishes to a connected Instagram account or Facebook Page. Optional, per organisationMeta's own network, under the organisation's own accountsMeta's own terms with the organisation
XeroReceives invoices and payments for bookkeeping. Optional, per organisationUnited StatesUK Addendum
reMarkableSends forms to, and receives drawings from, a person's own tablet. Optional, per personEuropeAdequacy regulations or standard contractual clauses

We will update this list before adding or replacing a provider.

Where data is kept, for how long, and how it is protected

Where. Data is held by the providers listed above, in the places shown. Where a provider keeps or handles data outside the United Kingdom, the transfer is covered by the safeguard shown against it.

How long.

DataKept for
Your accountWhile you work with an organisation that uses Fedelsoft. When that organisation records that you have left, your access ends at once and your sign-in details and connected services are removed. Your name stays on the records you made, which belong to the organisation
Records an organisation keeps in FedelsoftAs that organisation instructs. The default is 8 years after the patient's last contact, and until a child's 25th birthday (26th if they were 17 when treatment ended). After that the organisation reviews the record for disposal
An organisation's data after its subscription endsAvailable to export for 90 days, then deleted; backups are cleared within a further 35 days
Consultation recordingsThe audio is deleted once the transcript is filed. The transcript is kept as part of the record
Billing records6 years after the end of the financial year
Sign-in records (who signed in, when and from which address)3 years
Technical logs, and questions put to Ask with their answers12 months
Enquiries sent to Fedelsoft2 years after the last contact
Text sent to the AI providerDeleted by the provider within 30 days
Google user dataUntil you disconnect
Connected social accountsThe access token until the account is disconnected. The account's name and number, and the record of its posts, until the account is deleted in Settings, or within 30 days of a request by email

How it is protected. All traffic is encrypted in transit. Access is limited by role and by organisation, and every person signs in with their own credentials. Tokens for connected services such as Google, Instagram and Facebook are stored encrypted, under a key held separately from the database. Access by Fedelsoft staff to an organisation's records is limited to what support or maintenance requires.

Your rights, cookies and changes

Your rights. Under UK data protection law you may ask for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop using it, and ask for it in a portable form. Write to support@fedelsoft.com and we will answer within one month. If your request concerns a record held by an organisation that uses Fedelsoft, we will pass it to that organisation, which must answer it. You may complain to the Information Commissioner's Office at ico.org.uk at any time.

Cookies. The application sets only the cookies it needs to keep you signed in and to complete a connection you have started, such as Google Calendar. This website sets no advertising or tracking cookies.

Children. Fedelsoft accounts are for people working in healthcare and are not offered to children.

Changes. We will post any change to this policy on this page with its date, and tell account holders by email before a change that affects how their data is used.

Contact. Fedelsoft Ltd, Grove House, Waltham Road, White Waltham, Maidenhead SL6 3TN. support@fedelsoft.com.

Last updated: 11 October 2026