Velastria
    • Small aesthetic clinicsNot registered with a regulator · Pro
    • CQC & HIS registered practicesGovernance you have to evidence · Business
    • Surgical hospitalsRunning your own operating theatres · Enterprise
    • The consultation workspaceClinical notes without the typing
    • Theatre managementLists, admissions, status board, rotas
    • Everything it replacesThe full feature list
    • In detailModule by module
  • Pricing
    • How switching worksDone for you, signed off before cutover
    • From Pabau
    • From Clinic Office
    • From Salesforce
    • Compare alternativesSourced and dated
    • Security & your dataWhere it lives, and how you get it back
    • Case studyA registered hospital that moved across
    • Who builds itA surgeon who ran his own hospital
    • Getting startedLive and seeing patients in under an hour
    • Product updatesWhat shipped, every month
  • Enquire
  • Get Started

GDPR Compliance

How Velastria complies with UK GDPR and protects your data

Our Commitment to Data Protection

Velastria is committed to the highest standards of data protection and privacy. We fully comply with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and healthcare-specific regulations including CQC, HIS, and GMC requirements.

This page explains how we implement GDPR principles and protect the personal data and patient health information processed through our platform.

1. GDPR Principles

We adhere to all seven GDPR principles:

1.1 Lawfulness, Fairness, and Transparency

  • We process data only on lawful bases (consent, contract, legal obligation, legitimate interests)
  • We provide clear, plain-language privacy notices
  • We maintain transparency about data processing activities

1.2 Purpose Limitation

  • Data is collected for specified, explicit, and legitimate purposes
  • We do not process data for purposes incompatible with the original purpose
  • Each processing activity has a documented purpose

1.3 Data Minimisation

  • We collect only data adequate, relevant, and necessary for the specified purpose
  • Optional data fields are clearly marked
  • We regularly review data collection practices to minimise data capture

1.4 Accuracy

  • Customers can update and correct their data at any time
  • Inaccurate data is deleted or rectified without delay
  • We maintain audit trails of data changes for accountability

1.5 Storage Limitation

  • Personal data is retained only as long as necessary
  • We follow medical record retention guidelines (6 years minimum)
  • Data deletion policies are automated where possible
  • See our Data Retention Policy for details

1.6 Integrity and Confidentiality (Security)

  • Appropriate technical and organisational measures protect data
  • Encryption in transit (HTTPS) and at rest (AES-256)
  • Security review is continuous and vulnerabilities are remediated as identified
  • Access controls, authentication, and role-based permissions

1.7 Accountability

  • We maintain comprehensive records of processing activities
  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Personnel with data access are bound by data-protection and confidentiality obligations
  • Regular compliance audits and reviews

2. Data Controller vs Data Processor

2.1 When We Are the Data Controller

Velastria acts as the data controller for:

  • Marketing and sales data (contact forms, enquiries)
  • Account holder information (clinic details, billing information)
  • Website usage data and analytics

As controller, we determine the purposes and means of processing and are responsible for GDPR compliance.

2.2 When We Are the Data Processor

Velastria acts as a data processor for:

  • Patient health records entered by clinics
  • Patient communications managed through the platform
  • Clinical data, photos, and documentation

As processor, you (the clinic) are the data controller and determine the purposes and means of processing patient data. We process data only on your documented instructions.

2.3 Data Processing Agreement (DPA)

All customers receive a comprehensive Data Processing Agreement that details:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Types of personal data and categories of data subjects
  • Obligations and rights of the controller (you)
  • Security measures and breach notification procedures
  • Sub-processor agreements
  • Data deletion and return procedures

3. Data Subject Rights

We facilitate the exercise of all GDPR data subject rights:

3.1 Right of Access (Article 15)

  • Individuals can request copies of their personal data
  • We provide data within 30 days (1 month) of request
  • First copy is free; reasonable fees may apply for additional copies

3.2 Right to Rectification (Article 16)

  • Individuals can request correction of inaccurate data
  • We rectify data without undue delay
  • Clinics can update patient records directly through the platform

3.3 Right to Erasure / "Right to be Forgotten" (Article 17)

  • Individuals can request deletion of their data
  • We delete data unless legal obligations require retention
  • Medical records are subject to 6-year minimum retention under UK law

3.4 Right to Restrict Processing (Article 18)

  • Individuals can request limitation of processing
  • We mark restricted data and process only with consent or for legal claims

3.5 Right to Data Portability (Article 20)

  • Individuals can receive their data in a machine-readable format
  • We provide exports in CSV, JSON, or PDF format
  • Exports are provided in a portable format that can be passed to another controller

3.6 Right to Object (Article 21)

  • Individuals can object to processing based on legitimate interests
  • Individuals can opt out of marketing communications at any time
  • We cease processing unless compelling legitimate grounds exist

3.7 Rights Related to Automated Decision-Making (Article 22)

  • We do not make solely automated decisions with legal or significant effects
  • AI features provide suggestions; clinical decisions remain with clinicians

4. Technical and Organisational Measures

4.1 Encryption

  • In Transit: HTTPS/TLS encryption for all data transmission
  • At Rest: AES-256 encryption of the database via AWS KMS, including automated backups
  • Backups: Daily backups held in AWS, with additional encrypted offsite copies

4.2 Access Controls

  • Role-based access control (RBAC) with least privilege principle
  • Regular access reviews and revocation procedures
  • Segregation of duties for administrative functions

4.3 Authentication and Password Security

  • Strong password requirements (minimum 12 characters, complexity rules)
  • Password hashing using bcrypt with salting
  • Session management with automatic timeout
  • Account lockout after failed login attempts

4.4 Network Security

  • Firewalls and network segmentation
  • DDoS protection and traffic filtering via Cloudflare
  • Automated alerting on suspicious activity
  • Regular security patching and updates

4.5 Application Security

  • Secure coding practices and code reviews
  • Input validation and output encoding
  • Protection against OWASP Top 10 vulnerabilities
  • Dependency and vulnerability remediation as part of the regular release cycle

4.6 Audit Logging

  • Comprehensive audit trails of all data access and changes
  • Log retention aligned with medical-record requirements (6 years minimum)
  • Regular log review and monitoring for suspicious activity

5. Data Breach Procedures

5.1 Detection and Containment

  • Automated monitoring and alerting for security incidents
  • A documented incident-response procedure with defined escalation
  • Containment measures to limit breach impact

5.2 Notification

In the event of a data breach:

  • To ICO: Within 72 hours of becoming aware (Article 33)
  • To Customers: Without undue delay, with details of the breach
  • To Data Subjects: If high risk to rights and freedoms (Article 34)

5.3 Documentation

  • All breaches are documented regardless of severity
  • Records include facts, effects, and remedial action taken
  • Post-incident reviews to prevent recurrence

6. International Data Transfers

6.1 Data Location

  • Primary data storage: AWS UK (London / eu-west-2), encrypted at rest
  • Backups: held in AWS, with additional encrypted offsite copies
  • We minimise transfers outside the UK/EEA

6.2 Transfer Safeguards

When data transfers outside the UK/EEA are necessary, we use:

  • Standard Contractual Clauses (SCCs) approved by UK ICO
  • Adequacy decisions by UK Government
  • Binding corporate rules (where applicable)
  • Transfer Impact Assessments to ensure adequate protection

6.3 Sub-Processors

We use sub-processors for specific services:

  • AWS: Cloud hosting (UK/EU regions)
  • Stripe: Payment processing (adequacy decision)
  • Cloudflare: CDN and security services

All sub-processors are contractually bound to GDPR compliance.

7. Healthcare-Specific Compliance

7.1 CQC Compliance (England)

  • Supports CQC Fundamental Standards
  • Audit trails for regulatory inspections
  • Document management for policies and procedures
  • Staff training records and CPD tracking

7.2 HIS Compliance (Scotland)

  • Aligns with Healthcare Improvement Scotland standards
  • Quality improvement metrics and reporting
  • Patient safety incident tracking

7.3 GMC Good Medical Practice

  • Supports GMC record-keeping requirements
  • Consent management and documentation
  • Professional revalidation support

7.4 Caldicott Principles

  • Justify the purpose of using confidential information
  • Use confidential information only when necessary
  • Use the minimum necessary confidential information
  • Access on a strict need-to-know basis
  • Everyone with access understands their responsibilities
  • Comply with the law
  • The duty to share information for individual care is as important as the duty to protect confidentiality

8. Personnel and Confidentiality

Velastria is founder-operated. All personnel with data access complete data-protection training and are bound by confidentiality obligations; the same requirements will apply to every future hire before access is granted.

9. Data Protection Impact Assessments (DPIAs)

We conduct DPIAs for:

  • New features involving patient health data
  • AI and automated decision-making features
  • Large-scale processing of special category data
  • New technologies or innovative uses of existing technologies
  • Data sharing with third parties

DPIAs assess risks to data subjects and identify mitigating measures.

10. Accountability and Governance

10.1 Data Protection Lead

  • Name: Taimur Shoaib
  • Email: t.shoaib@doctors.org.uk
  • Responsibilities: Oversee GDPR compliance, conduct audits, liaise with ICO

10.2 Records of Processing Activities (ROPA)

We maintain detailed records including:

  • Name and contact details of controller/processor
  • Purposes of processing
  • Categories of data subjects and personal data
  • Recipients of data
  • International transfers
  • Retention periods
  • Security measures

10.3 Compliance Audits

  • Annual internal GDPR compliance audits

11. Your Rights and Contact

11.1 Exercising Your Rights

To exercise any GDPR rights, contact us at t.shoaib@doctors.org.uk. We will respond within 30 days.

11.2 Complaints

If you believe we have not handled your data appropriately, you can:

  1. Contact our Data Protection Lead at t.shoaib@doctors.org.uk
  2. Lodge a complaint with the UK Information Commissioner's Office (ICO)

Information Commissioner's Office (ICO)

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113
Website: ico.org.uk
Report a concern: ico.org.uk/make-a-complaint

12. Updates to This Page

We review and update this GDPR Compliance page annually or when significant changes occur to our processing activities. Last updated: 10 July 2026.

13. Additional Resources

  • Trust & Security - Where your data lives and how it's protected
  • Privacy Policy - How we collect and use personal data
  • Terms of Service - Legal agreement for using Velastria
  • Data Processing Agreement (DPA) - Available upon subscription
  • Security Whitepaper - Available upon request

Velastria

Practice management for aesthetic and plastic surgery clinics. Built by a surgeon.

Product

  • Features
  • Details
  • Consultation workspace
  • Theatre
  • For small clinics
  • For CQC / HIS practices
  • Pricing
  • Switching
  • Compare
  • Case study
  • Product updates
  • Contact

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR Compliance
  • Trust & Security

© 2026 Velastria. All rights reserved.