Privacy Policy
Last updated: 4th July 2026
1. Who we are
CQCflow is operated by Patientflow Systems Limited (company number 16565156). This policy explains what information we collect, why, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018).
2. Information we collect
- Account data — your name, email address, and the organisation you belong to.
- Content you create — audit forms, completed audits, and evidence (files, links, and notes) you upload to manage your CQC compliance.
- Billing data — handled by our payment provider, Stripe. We store only the identifiers needed to manage your subscription, not your full card details.
- Usage data — technical information such as log data and cookies needed to keep you signed in and to operate the service securely.
3. How and why we use your data
We process your personal data to:
- provide, maintain, and secure the service (our contract with you);
- manage your subscription and take payment (our contract with you);
- respond to support requests and communicate with you about the service;
- meet our legal obligations and protect against fraud or misuse (our legitimate interests).
4. Sharing and processors
We do not sell or share your data. We use trusted third-party service providers to host and process personal data on our behalf. These providers act as our data processors and include: Supabase (database hosting, authentication, and file storage), Stripe (payment processing), and Vercel (application hosting). Each provider is engaged under appropriate data processing agreements and is permitted to process personal data only in accordance with our instructions. We may also disclose personal data where required by law.
5. Storage and security
Your data is logically separated and protected by access controls so that only members of your organisation can see it. We use encryption at rest and in transit and rely on our infrastructure providers' security measures. We take reasonable steps to protect your data from unauthorised access.
6. Data retention
We keep your data for as long as your account is active and for as long afterwards as we need it to meet legal, accounting, or reporting obligations. You can ask us to delete your data at any time, subject to those obligations.
7. Your rights
Under UK data protection law you have the right to access, correct, delete, or restrict the use of your personal data, to object to certain processing, and to data portability. To exercise any of these rights, contact us using the details below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
We use only the cookies necessary to keep you signed in and to operate the service. We do not use advertising or third-party tracking cookies.
9. Contact us
If you have any questions about this policy or how we handle your data, contact Patientflow Systems Limited at info@patientflow.co.uk.