Privacy Policy
Privacy Policy
Last updated: 14 September 2026
At Agilio, we take the privacy of everyone we deal with seriously — our customers, the people who use our products, and everyone else whose personal data we come across along the way. This policy explains what personal data we collect, why, and how you can exercise your rights, across every Agilio Group product. We act as a controller for some of the personal data we handle, and as a processor for other personal data — both roles are explained below, since which one applies changes what rights you have and who to contact.
1. Our role: controller or processor
We act in two different capacities, depending on the personal data in question. (a) We’re the controller — the one deciding why and how personal data is processed — for our website visitors, sales/marketing/support contacts, job applicants, and individuals who subscribe to our services directly, in their own capacity, as a sole trader or individual practitioner. (b) We’re the processor, not the controller, when we handle personal data on behalf of an organisation that subscribes to our services — for example, data about a practice’s staff or patients, including where you personally use our services as a member of that organisation’s team; in that case, the organisation is the controller and decides how the data is handled, and we process it under our Data Processing Agreement with that organisation. If you’re an employee, team member or patient of one of our customers, see the clause about ‘If you’re an employee, team member or patient of one of our customers’ below for what that means for you and how to find your employer’s or practice’s own privacy notice.
This policy is a transparency notice about how we handle personal data, required by data protection law — it doesn’t form part of, and doesn’t vary, any services contract you have with us. Where you’re a customer, see our General Terms for what makes up your services contract, and our Data Processing Agreement for how we handle personal data in our processor capacity.
2. Who we are
References to "we," "us" and "Agilio" mean the Agilio Group company associated with the product or service you’re using — see your order form or sign-up confirmation for the entity that applies to your subscription. Both which Agilio Group entity you’re dealing with, and whether that entity is acting as controller or processor for a given set of your personal data, can depend on the specific product and the capacity in which you’re using it.
3. When and how we collect your data
We collect personal data directly from you — for example, when you register for an account, fill in a form on our website, get in touch with our support team, or apply for a job with us. If you apply for a job with us through a third-party job board or applicant tracking system, you may see that provider’s own privacy notice as well as, or instead of, this one. Some Agilio Group products and brands also publish their own separate privacy notice for the personal data processed through that specific product or service; where that applies, the notice shown or referred to you when you use that product or service is the one that governs it. We also collect data automatically, through cookies and similar technology, when you visit our website or use our products (see our Cookie Policy for details). And where your employer or practice is our customer, we collect the data they and their staff input into our products as part of using them — see the clause about ‘If you’re an employee, team member or patient of one of our customers’ below if that’s you. Where you or your practice connects a third-party system to our products — for example, a practice management system — we also receive the personal data that system shares with us as part of that connection. Occasionally, we also receive information about a potential customer from an existing customer, for example as part of a referral scheme.
We don’t knowingly collect personal data directly from children, and our services aren’t directed at them. Where personal data about a child is processed through our products — for example, patient data recorded by a dental or GP practice we work with — that happens under our processor relationship with that practice, described in the clause about ‘If you’re an employee, team member or patient of one of our customers’ below.
4. Types of data we collect
Depending on how you interact with us, we collect:
-
-
- Contact details — your name, job title, and contact details (email, phone, postal address).
- Account and billing details — as relevant, your account registration details, and your billing and payment details.
- Training and professional data — as relevant, your CPD and training records, course completions, certificates, and, where you provide it, your professional registration number.
- Application data — if you apply for a job with us, your application, CV and interview notes.
- Communications data — a record of your enquiries and communications with us, including support requests.
- Technical and usage data — if you visit our website or use our products, usage data, device and browser information, and cookies (see our Cookie Policy for details).
- Data from connected third-party systems — where a third-party platform is connected to our products, the personal data it shares with us, such as patient or appointment records.
-
5. How and why we use your data
We use your personal data for the following purposes, and rely on the legal basis stated for each:
-
-
- Providing our services — setting up and administering your account, and providing the products and features you’ve subscribed to. Legal basis: performance of our contract with you.
- Responding to enquiries and providing support — answering your questions and providing customer support. Legal basis: performance of our contract with you, or our legitimate interest in responding to you if you’re not yet a customer.
- Recruitment — assessing your job application. Legal basis: steps taken at your request before entering into a contract, and our legitimate interest in recruitment.
- Marketing — telling you about our products and services. Legal basis: your consent, or our legitimate interest in promoting our products to existing contacts.
- Improving our website and products — understanding how our website and products are used, and making them better. Legal basis: our legitimate interest in improving our services.
- Security and fraud prevention — protecting our systems, your account, and our other customers. Legal basis: our legitimate interest in keeping our services secure, and complying with our legal obligations.
- Running promotions — administering prize draws, discounts and other promotions, including recording entries, selecting and contacting winners, and delivering prizes. Legal basis: our legitimate interest in running the promotion.
-
6. Special category data
We don’t generally collect special category data about you (for example, data about your health, racial or ethnic origin, religious beliefs, or trade union membership) if you subscribe to us directly. Where we do need to — because it’s necessary to provide the services to you, or because you’ve given us your explicit consent — we apply extra security measures appropriate to its sensitivity. This can include special category data we receive from a connected third-party system, as well as data you give us directly.
7. Sharing your personal data
We share personal data with the recipients below, for the reasons given. We don’t sell your personal data.
| Who we share it with | Why |
|---|---|
| Other Agilio Group companies | Helping us provide and improve our products and services across the group, and for internal administration |
| Sub-processors and other service providers who help us deliver our services (see the current list on our Sub-Processors page) | Hosting, cloud storage, payment processing, communications, and other services that support the products and services you use |
| Professional advisers and auditors | Seeking professional advice, or meeting our audit and assurance obligations |
| Regulators, law enforcement and government bodies | Complying with our legal and regulatory obligations |
| A buyer (or prospective buyer) of our business or assets | In the context of a sale, merger or restructuring of our business |
| Your employer or practice, where we’re their processor (see the clause about ‘If you’re an employee, team member or patient of one of our customers’) | Sharing data with the organisation that’s the controller of it, as part of performing our contract with them |
8. If you’re an employee, team member or patient of one of our customers
If you personally use our services because your employer, practice or another organisation is our customer, we process your personal data — including data about you that they manage through the product, data shared with us by a connected third-party system on their behalf, and your own account, login and support activity — as their processor, not as controller. Your employer or practice remains the controller throughout, and its own privacy notice is the right place to look for how and why your data is processed, how long it’s kept, and how to exercise your rights.
We process that data on our customer’s instructions, including instructions built into how they configure and use our products. Some of our products let your employer record more sensitive information about you if it chooses to (for example, equality and diversity monitoring data); if it does, its own policies explain why, and we apply extra security safeguards to this kind of data. If you contact us directly about your data in this situation, we’ll usually redirect you to your employer or practice, but we’ll assist them in responding to you — the same applies if you want to raise a complaint about how your data has been handled (see the clause about ‘Your rights’ below).
9. Artificial Intelligence
Some of our products use Artificial Intelligence (AI) to provide new functionality. We don’t use personal data processed through our AI-enabled features to train, fine-tune or otherwise develop any AI model, and we, ourselves, don’t make solely automated decisions about you that have a legal or similarly significant effect without meaningful human involvement. Our Product-Specific Terms set out the fuller position on AI-enabled products, including data ownership, human oversight, and the AI infrastructure providers we use.
10. Where we store your data, and international transfers
We and our sub-processors store and process personal data at various locations, including in the UK, the EEA and Switzerland, depending on the product you use, the personal data in question, and where you’re based — a current list of our sub-processors and their locations is on our Sub-Processors page. Where we transfer personal data outside the UK, EEA or Switzerland to a country that isn’t subject to an adequacy decision, we carry out a transfer risk assessment and put a binding contract in place with the recipient — generally the European Commission’s Standard Contractual Clauses, supplemented as needed by the UK’s International Data Transfer Addendum or equivalent Swiss safeguards — and we keep this transfer mechanism under review. Where we act as processor for personal data of individuals in the EU and have no establishment there, we’ve appointed Agilio Software Netherlands BidCo B.V. as our representative under Article 27 of the EU GDPR.
11. How we keep your data secure
We maintain technical and organisational security measures appropriate to the personal data we handle — including access controls, encryption, network security, and incident response procedures — to protect it against unauthorised access, loss or misuse. Our Data Processing Agreement sets out these measures in more detail. If you believe your data has been affected by a security incident, contact us straightaway using the details in the clause about ‘Contact us’ below.
12. How long we keep your data
We keep personal data only for as long as necessary. The criteria we use to decide how long include: how long our relationship with you continues; any statutory retention period that applies (for example under tax, company, or healthcare records legislation); the limitation period for a legal claim relating to that data; and periodic review of whether we still need it for the purpose it was collected for. Where your employer or practice is our customer, its own retention decisions apply to the data it manages through our products.
13. Using your data for a new purpose
If we want to use your personal data for a new purpose we hadn’t originally told you about, we’ll only do so where that new purpose is compatible with the one we originally collected it for. If it isn’t, we’ll get in touch to explain the new purpose and the legal basis that lets us do this, before we start that new processing.
14. Your rights
Data protection law gives you the right to access, correct, delete or restrict the personal data we hold about you as controller, to object to certain processing, to ask for your data in a portable format, and to withdraw consent where we rely on it. This includes the right to object to us using your data for marketing at any time — just contact us and we’ll stop. To exercise these rights, contact us using the details in the clause about ‘Contact us’ below.
We may need to ask you for information to confirm your identity before responding to a request, to make sure we don’t disclose your personal data to the wrong person. You won’t normally have to pay a fee to exercise any of these rights — but if your request is clearly unfounded, repetitive, or excessive, we may charge a reasonable fee or decline to act on it.
Where a significant decision about you is ever made solely by automated means, you also have the right to request human intervention, express your point of view, and contest that decision — though as the clause about ‘Artificial Intelligence’ above explains, we, ourselves, don’t make this kind of decision without meaningful human involvement. If you think an organisation using one of our products has configured an AI feature in a way that makes this kind of decision about you, that organisation, not us, is responsible for these rights as controller — see the clause about ‘If you’re an employee, team member or patient of one of our customers’ above.
If you think we haven’t complied with data protection law, you have the right to complain. Where we’re the controller of the data in question (see the clause about ‘Our role: controller or processor’ above), you can complain to us directly — see our Complaints Policy for how to raise a complaint and what happens next — and you can also complain to your data protection supervisory authority at any time, whether or not you’ve complained to us first (in the UK, this is the Information Commissioner’s Office, ico.org.uk). Where we’re the processor of the data in question, because your employer, practice or another organisation is our customer (see the clause about ‘If you’re an employee, team member or patient of one of our customers’ above), that organisation is the controller responsible for responding to your complaint; you’re still welcome to raise it with us, and, as with other requests about your data in that situation, we’ll assist them and make sure it reaches them. We’ll also remind you of this right whenever we respond to a subject access request or other data protection rights request.
15. Updates to this policy
We update this policy from time to time and encourage you to review it periodically. We’ll post any changes on this page and, if they’re material, notify you directly too — for example, by email.
16. Contact us
If you have any questions about this policy or want to exercise your rights, contact us at [email protected]. This is also how to reach our Data Protection Officer.