Data Protection Statement

Data Protection Statement – medical letters service

Who we are and what we do.

ZoomDoc Pro Limited (“ZoomDoc Pro”) is a supplier of specialist software that helps GP practices provide healthcare services to patients. We have provided below an outline of how we use information about individuals when providing our medical letters services to GP practices. 

ZoomDoc Pro (referred to as “we”, “us” or “our”) is registered in England and Wales under company number 016114012 and have our registered office at 2 Chanin Mews, London NW2 4AQ. Our main trading address is at Unit 2A, NW Works, 135 Salusbury Road, London, NW6 6RJ.

ZoomDoc Pro role as Data Processor

When providing services to GP practices via our medical letter platform, we act as “processor”. This means we will only process information about individuals in accordance with instructions from the GP practice and strict contractual requirements.

Usually, the GP practice will be the “controller” in respect of information about their patients. If you have any concerns regarding the processing of your personal data by ZoomDoc Pro, you should contact your GP practice. We recommend you review your practice’s Privacy Policy.

Information we may use when providing our services to GP practices

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you when we provide our medical letter platform to GP practices, which we have grouped together follows:

Identity Data which may include your first name, last name, date of birth and NHS number and account details.

Contact Data including e-mail address, phone number, postal address

Health Data which may include any information about your health including your medical history and/or current health status including but not limited to data regarding test results, diagnoses and medications.

Ethnicity Data – information revealing your ethnic origin. 

Financial Data, which may includes your bank account and payment card details, to administer payments on behalf of GP practices.

Transaction Data, which may include information about payments by you patients and other details of products and services purchased by you

We use data concerning ethnicity because this is necessary for the provision of certain medical certificates including Covid-19 tests and results. The UK Health Security Agency request this additional information from all medical providers of Covid-19 testing services.

How your data is collected

We receive information from GPs, through the GP entering it onto our platform.

We also receive information from patients, such as payment information, through the patient entering the information on to our platform and the account created for them.

Keeping your data secure

We have put in place appropriate security measures to prevent any personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, access personal data is limited to those employees, agents, contractors and other third parties who have a business need to know. These staff are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.


Cookies

The ZoomDoc Pro Medical Letter Platform uses cookies to distinguish you from other users of the ZoomDoc Pro Medical Letter Platform . This helps us to provide you with a good experience when you browse the platform and also allows us to improve our site.

A cookie is a small file of letters and numbers stored on your browser or the hard drive of your computer in order to enhance your experience and to provide functionality on the Site.

We use the following cookies:

Strictly necessary cookies

These are cookies that are required for the operation of the ZoomDoc Pro Medical Letter Platform. They include, for example, cookies that enable you to log into secure areas of the platform, such as your personal records and on-line payment services.

Analytical/performance cookies

These allow us to recognise and count the number of visitors and to see how visitors move around the ZoomDoc Pro Medical Letter Platform when they are using it. This helps us to improve the way the platform works, for example, by ensuring that users are finding what they are looking for easily.

Functionality cookies

These are used to recognise you when you return to the ZoomDoc Pro Medical Letter Platform. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).

We may also use:

Targeting cookies

These cookies record your visit to the ZoomDoc Pro Medical Letter Platform , the pages you have visited and the links you have followed. We will use this information to make the ZoomDocPro Medical Letter Platform and any content displayed on it more relevant to your interests.

You can find more information about the individual cookies we use and the purposes for which we use them in the table below:

  1. PHP session ID (used to identify the user by the application)
  2. Cloudflare
  3. Ryft
  4. Google Analytics


Please note that third parties (including, for example, providers of external services like web traffic analysis services) may also use cookies, over which we have no control.

You may block cookies by activating the relevant settings on your browser. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of the ZoomDoc Pro Medical Letter Platform.

Except for essential cookies, all cookies will expire after no more than 30 days.


© ZoomDoc Pro LTD 2025