Velastria
    • Small aesthetic clinicsNot registered with a regulator · Pro
    • CQC & HIS registered practicesGovernance you have to evidence · Business
    • Surgical hospitalsRunning your own operating theatres · Enterprise
    • The consultation workspaceClinical notes without the typing
    • Theatre managementLists, admissions, status board, rotas
    • Everything it replacesThe full feature list
    • In detailModule by module
  • Pricing
    • How switching worksDone for you, signed off before cutover
    • From Pabau
    • From Clinic Office
    • From Salesforce
    • Compare alternativesSourced and dated
    • Security & your dataWhere it lives, and how you get it back
    • Case studyA registered hospital that moved across
    • Who builds itA surgeon who ran his own hospital
    • Getting startedLive and seeing patients in under an hour
    • Product updatesWhat shipped, every month
  • Enquire
  • Get Started

Privacy Policy

Last updated: 19 July 2026

1. Introduction

Velastria ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website or use our services.

This policy applies to information we collect through:

  • Our website (velastria.app and subdomains)
  • Our software-as-a-service (SaaS) platform
  • Email, text, and other electronic communications
  • Contact form submissions and enquiries

2. Information We Collect

2.1 Personal Information

We may collect the following types of personal information:

  • Identity Data: Name, title, professional qualifications
  • Contact Data: Email address, telephone number, postal address
  • Professional Data: Clinic name, specialty, number of staff, professional registration numbers
  • Technical Data: IP address, browser type, device information, operating system
  • Usage Data: Information about how you use our website and services
  • Communications Data: Your preferences in receiving marketing from us and your communication preferences

2.2 Special Categories of Data

When you use our platform to manage patient records, you will process special category data (patient health information). We act as a data processor in this context, and you (the clinic) are the data controller. Our obligations as a processor are detailed in our Data Processing Agreement.

2.3 How We Collect Information

We collect information through:

  • Direct interactions: When you fill out forms, sign up for an account, or contact us
  • Automated technologies: Cookies, server logs, and analytics tools
  • Third parties: Analytics providers, advertising networks (if applicable)

3. How We Use Your Information

We use your information for the following purposes:

3.1 Provision of Services

  • To provide access to our platform and services
  • To process your account registration
  • To provide customer support and technical assistance
  • To send service-related notifications and updates

3.2 Business Operations

  • To administer our business operations
  • To improve our website and services
  • To conduct analytics and research
  • To detect and prevent fraud or security issues

3.3 Marketing (With Your Consent)

  • To send you information about new features and updates
  • To provide relevant marketing communications
  • You may opt out of marketing communications at any time

3.4 Legal Obligations

  • To comply with legal and regulatory requirements
  • To respond to lawful requests from public authorities
  • To protect our rights, property, and safety

4. Legal Basis for Processing (GDPR)

Under the UK General Data Protection Regulation (UK GDPR), we rely on the following legal bases:

  • Consent: For marketing communications and optional data processing
  • Contract: To provide our services and fulfil our obligations to you
  • Legal Obligation: To comply with legal and regulatory requirements
  • Legitimate Interests: To operate our business, improve our services, and prevent fraud

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

We may share your data with trusted third parties who provide services on our behalf:

  • Cloud hosting providers: Amazon Web Services (AWS)
  • Payment processors: Stripe
  • Email services: For transactional and marketing emails
  • Analytics providers: To understand website usage

All third parties are required to maintain appropriate security measures and process data only as instructed.

5.2 Legal Requirements

We may disclose your information if required by law, court order, or regulatory authority, or to protect our rights and safety.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and penetration testing
  • Staff training on data protection and security
  • Incident response procedures

While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

Authentication and Security Logging

To keep accounts secure and to maintain a reliable audit trail, we record events relating to how our platform and website are accessed. We carry out this logging as a controller in our own right, for our own security purposes. It is separate from, and additional to, the clinical audit trail your clinic keeps as controller of its own patient records.

For sign-in attempts and certain security-relevant actions, we may record:

  • the account involved, and the date and time of the event;
  • whether the attempt succeeded or failed;
  • the IP address, and basic browser and device information;
  • the type of action — for example a login, a logout, a failed password attempt, or a two-factor authentication challenge.

Why we do this, and our legal basis. We rely on our legitimate interests in the security of our network and information systems: detecting and investigating unauthorised access, brute-force attempts and account misuse, and being able to reconstruct what happened if there is a security incident. Keeping a record of authentication activity is expressly recognised by the Information Commissioner's Office as a legitimate security measure. We do not use these logs to monitor staff productivity, and no decision affecting you is made automatically from them.

Who can see them. Access to security and authentication logs is restricted to authorised Velastria personnel who need them to operate and protect the service.

How long we keep them. We keep security and authentication logs for as long as necessary for the security purposes described above and in line with our record-keeping obligations. We do not keep them for longer than we need to; where a specific record must be kept longer — to investigate a security incident or to meet a legal obligation — we retain only that record, for only as long as required.

7. Data Retention

We retain your personal data only for as long as necessary:

  • Active users: For the duration of your subscription plus 6 years (in line with UK medical record retention requirements)
  • Enquiry data: For 2 years from submission date
  • Marketing data: Until you opt out or 3 years of inactivity
  • Legal obligations: As required by law (typically 6-7 years for tax and accounting records)

After the retention period, we securely delete or anonymise your data.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for marketing purposes
  • Right to Withdraw Consent: Withdraw consent at any time (where consent is the legal basis)
  • Right to Lodge a Complaint: Complain to the Information Commissioner's Office (ICO)

To exercise any of these rights, contact us at t.shoaib@doctors.org.uk. We will respond within 30 days.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to:

  • Remember your preferences and settings
  • Analyse website traffic and usage patterns
  • Improve user experience

Types of Cookies We Use:

  • Essential Cookies: Required for website functionality (e.g., session management) and to remember your cookie choice.
  • Analytics Cookies (with your consent): We use our own first-party analytics to understand how visitors use our site. We do not use Google Analytics or any third-party advertising trackers on this site. These cookies set a random visitor identifier so we can distinguish new from returning visitors and measure page visits; they store no name, email, or other directly identifying information, and your IP address is never stored. They are set only after you click Accept on our cookie banner.

When you first visit, we ask for your consent before setting any analytics cookies. You can decline, and you can withdraw consent at any time by clearing your browser cookies for this site. Disabling cookies may affect some website functionality.

10. International Data Transfers

Your data may be transferred to and stored in countries outside the UK and European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the UK ICO
  • Adequacy decisions by the UK Government
  • Binding corporate rules or certification schemes (where applicable)

Our primary data hosting is with Amazon Web Services (AWS) in the EU and UK regions.

11. Children's Privacy

Velastria is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at t.shoaib@doctors.org.uk.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting a notice on our website
  • Sending an email to registered users
  • Updating the "Last updated" date at the top of this policy

Your continued use of our services after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: t.shoaib@doctors.org.uk

Data Protection Officer: Taimur Shoaib

Postal Address:
Kirklee Comms Ltd (trading as Velastria)
154 Clyde Street, Glasgow, G1 4EX
United Kingdom

15. Supervisory Authority

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we have not handled your data appropriately:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline: 0303 123 1113
Website: ico.org.uk

Velastria

Practice management for aesthetic and plastic surgery clinics. Built by a surgeon.

Product

  • Features
  • Details
  • Consultation workspace
  • Theatre
  • For small clinics
  • For CQC / HIS practices
  • Pricing
  • Switching
  • Compare
  • Case study
  • Product updates
  • Contact

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • GDPR Compliance
  • Trust & Security

© 2026 Velastria. All rights reserved.