Data Protection Statement

Data Protection Statement – medical letters service

Who we are and what we do.

ZoomDoc Pro Limited (“ZoomDoc Pro”) is a supplier of specialist software that helps GP practices provide healthcare services to patients. We have provided below an outline of how we use information about individuals when providing our medical letters services to GP practices. 

ZoomDoc Pro (referred to as “we”, “us” or “our”) is registered in England and Wales under company number 016114012 and have our registered office at 2 Chanin Mews, London NW2 4AQ. Our main trading address is at Unit 2A, NW Works, 135 Salusbury Road, London, NW6 6RJ.

ZoomDoc Pro role as Data Processor

When providing services to GP practices via our medical letter platform, we act as “processor”. This means we will only process information about individuals in accordance with instructions from the GP practice and strict contractual requirements.

Usually, the GP practice will be the “controller” in respect of information about their patients. If you have any concerns regarding the processing of your personal data by ZoomDoc Pro, you should contact your GP practice. We recommend you review your practice’s Privacy Policy.

Information we may use when providing our services to GP practices

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you when we provide our medical letter platform to GP practices, which we have grouped together follows:

Identity Data which may include your first name, last name, date of birth and NHS number and account details.

Contact Data including e-mail address, phone number, postal address

Health Data which may include any information about your health including your medical history and/or current health status including but not limited to data regarding test results, diagnoses and medications.

Ethnicity Data – information revealing your ethnic origin. 

Financial Data, which may includes your bank account and payment card details, to administer payments on behalf of GP practices.

Transaction Data, which may include information about payments by you patients and other details of products and services purchased by you

We use data concerning ethnicity because this is necessary for the provision of certain medical certificates including Covid-19 tests and results. The UK Health Security Agency request this additional information from all medical providers of Covid-19 testing services.

How your data is collected

We receive information from GPs, through the GP entering it onto our platform.

We also receive information from patients, such as payment information, through the patient entering the information on to our platform and the account created for them.

Keeping your data secure

We have put in place appropriate security measures to prevent any personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, access personal data is limited to those employees, agents, contractors and other third parties who have a business need to know. These staff are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

© ZoomDoc Pro LTD 2025