Auptician Portal

Privacy notice

This notice explains how Auptician uses information about patients referred for LumiThera treatment and about the optometrists who refer them.

Who we are

[Auptician legal entity name], [registered address], is the data controller for information held in this portal. ICO registration number: [number]. Contact for data protection questions: [name], [email].

The referring optometrist is a separate controller for their own practice records. They decide to refer and share the patient's information with us.

Information about patients

Patients do not use the portal; their optometrist enters their details. We hold their name, date of birth and contact details; health information such as eye findings, visual acuity, images, treatment results and follow-up findings; the referral record; and confirmation that the patient agreed to their details being shared. We use it to contact the patient about a LumiThera assessment, provide treatment, share results with the referring optometrist and manage follow-up care.

Information about optometrists

We hold your name, GOC number, practice and contact details, login details (passwords are stored only as secure hashes), bank details (encrypted), the agreement versions you accepted, payment records and a log of changes. We use them to run your account, check your registration, pay collaboration fees and keep the portal secure.

Our lawful bases

For patients: legitimate interests in providing and coordinating eye care the patient has asked about, and contract once treatment is agreed (UK GDPR Article 6(1)(f) and (b)); for health data, the provision of health care by or under a health professional bound by confidentiality (Article 9(2)(h) and DPA 2018 Schedule 1 paragraph 2). For optometrists: contract, legal obligation for payment records, and legitimate interests for security and audit. The patient's agreement recorded on the referral form meets the professional duty of confidentiality; it is not the legal basis under data protection law.

Who we share information with

The referring optometrist, for their own patients only; our hosting and email providers, under written contracts; and professional advisers, insurers or regulators where required. We do not sell information or use it for marketing. Our emails never contain patient details.

Where it is stored and how long we keep it

Information is stored on servers in the UK. Clinical records are kept for 10 years after the patient was last seen. Optometrist and payment records are kept for 6 years after the account closes or the payment is made.

How we protect it

Access is limited to authorised Auptician staff and to each referring optometrist for their own patients. Data is encrypted in transit, bank details are encrypted at rest, uploaded files are never publicly accessible, and changes to important records are logged.

Your rights and complaints

You can ask to see, correct or delete your information, restrict or object to its use, or receive a copy. Some rights are limited for health records we must keep. Contact [email]; we respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

The portal uses only essential cookies for login and security.

Last updated: [date]. Version [1.0].

Privacy notice