Seventy3 OS — Privacy Policy
Seventy3 Group Ltd Effective date: 13 July 2026 · Last updated: 13 July 2026 · Version 1.0
This Privacy Policy explains how Seventy3 Group Ltd handles personal data in connection with the Seventy3 OS platform. It is written to be read by our customers (clinics), by the people who work at those clinics, and — where relevant — by patients who want to understand how their information is handled. If anything here is unclear, contact us using the details in Section 13 and we will be glad to help.
1. Who we are
Seventy3 Group Ltd ("Seventy3", "we", "us", "our") is a company incorporated in England and Wales (company number 16392260), with registered office at Suite 21, Call House, Enfield Street, Leeds, England, LS7 1RF.
We operate the Seventy3 OS platform ("the Platform"), a clinic operating system used by therapy and performance clinics.
- Privacy contact / data subject requests: Hamayoon Kasser — hamayoon@seventy3.co
- ICO registration number: ICO:00014031429
2. Scope of this Policy
This Policy describes how we handle personal data in two distinct capacities:
- As data controller — for the personal data of clinic account holders, authorised users, billing contacts, and visitors to our website. This is described from Section 4 onwards.
- As data processor — for the personal data of patients ("Patients") that clinics process through the Platform on their own behalf. The clinic is the data controller for Patient data; we process it under their instructions, governed by our Data Processing Agreement. This is described in Section 5.
3. Definitions
- "Personal data" has the meaning given by Article 4 UK GDPR.
- "Special category data" means data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life, or sexual orientation, as defined by Article 9 UK GDPR.
- "UK GDPR" means the UK General Data Protection Regulation as applied by the Data Protection Act 2018.
4. Personal data we process as controller
4.1 Categories of data subject
- Clinic owners and account holders (the people who sign up for Seventy3 OS).
- Authorised Users at customer clinics (e.g., therapists, receptionists).
- Prospective customers and website visitors.
4.2 Types of data
- Identity and contact data — name, email, phone, business address, job role.
- Account credentials — username, hashed password, multi-factor authentication settings.
- Billing and payment data — Stripe customer ID, subscription status, billing history. We do not store full card numbers.
- Usage data — pages viewed, features used, log-in times, IP address, device and browser information.
- Communications — support tickets, emails to and from us, sales enquiries.
- Marketing data — website analytics, marketing email engagement.
4.3 Lawful bases (UK GDPR Article 6)
- Contract (Art. 6(1)(b)) — to provide the Platform to you and administer our agreement.
- Legitimate interests (Art. 6(1)(f)) — service improvement, security, analytics, fraud prevention, and direct marketing to existing customers (subject to your right to object).
- Legal obligation (Art. 6(1)(c)) — to comply with HMRC, anti-money-laundering, and other legal requirements.
- Consent (Art. 6(1)(a)) — for marketing emails to non-customers and for non-essential cookies.
4.4 Sources
We obtain personal data from you directly (sign-up, account use, support contact), from your device (cookies, log files), and from limited third-party sources (e.g., Companies House lookups for billing or due diligence).
4.5 How we use it
- Provide, operate, and improve the Platform.
- Process payments and manage subscriptions.
- Communicate with you about your account, support requests, and service updates.
- Monitor security, prevent fraud, and investigate misuse.
- Send marketing communications where lawful (you can opt out at any time).
- Comply with legal and regulatory obligations.
5. Personal data we process as processor (Patient data)
5.1 Roles
When a clinic uses the Platform to manage Patient communications, appointments, payments, and clinical records, the clinic is the data controller and Seventy3 is the data processor. We process Patient data only on the clinic's documented instructions and as set out in the Data Processing Agreement that forms part of every customer agreement.
5.2 Categories of Patient data
- Identity and contact data — name, email, phone, address, date of birth.
- Appointment data — booking history, attendance, cancellations.
- Payment data — transactions handled via Stripe; deposit and treatment payments.
- Communications data — call recordings or transcripts, SMS messages, emails.
- Special category health data — clinical notes, treatment history, exercise prescriptions, symptom descriptions captured during inbound calls or messages, and other clinical information.
5.3 Lawful basis
The clinic, as controller, is responsible for establishing and documenting the lawful bases under Articles 6 and 9 UK GDPR for the processing it instructs us to carry out. We process Patient data only on the basis of those instructions.
5.4 Patient rights
If you are a Patient and wish to exercise your rights under UK GDPR (access, rectification, erasure, restriction, portability, objection, or withdrawal of consent), please contact your clinic in the first instance, as they are the controller of your personal data. We will assist your clinic in responding to your request as required by the DPA. If you cannot reach your clinic, you may contact us at hamayoon@seventy3.co and we will route your request appropriately.
6. Sub-processors
We use the following sub-processors to help us provide the Platform. Each is bound by a written data processing agreement that imposes substantively the same data protection obligations as those we owe to clinics.
| Sub-processor | Purpose | Legal entity / location | Transfer mechanism |
|---|---|---|---|
| Stripe | Payment processing (acts as independent controller, not processor — see note below) | Stripe Payments UK Ltd, United Kingdom | Within UK |
| Vercel | Frontend application hosting | Vercel Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Supabase | Database hosting (configured to UK/EU region) | Supabase Inc., United States (data hosted in UK/EU region) | UK IDTA / EU SCCs + UK Addendum |
| AssemblyAI | Speech-to-text transcription of call and voice audio | AssemblyAI, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Anthropic | AI-assisted clinical documentation and summarisation (Claude API) | Anthropic Ireland Limited | UK IDTA / EU SCCs + UK Addendum where applicable |
| Retell AI | Inbound voice AI receptionist (real-time transcription, conversational AI, voice synthesis) | Retell AI, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Twilio | SMS delivery and inbound telephony | Twilio Ireland Limited, Ireland (with possible US transit) | EU SCCs + UK Addendum |
| Resend | Transactional email delivery | Resend Inc., United States | UK IDTA / EU SCCs + UK Addendum |
| Acuity Scheduling | Appointment scheduling | Squarespace, Inc., United States | UK IDTA / EU SCCs + UK Addendum |
Note on Stripe: Stripe processes payment data as an independent controller in respect of fraud prevention, regulatory compliance, and its own internal purposes, in addition to its role as our payment processor. See Stripe's own privacy notice at https://stripe.com/privacy.
Note on fallback transcription engines: Our transcription pipeline integrates Deepgram (Deepgram, Inc., United States) and OpenAI (OpenAI, L.L.C., United States) as optional fallback speech-to-text engines. These are not enabled in our production configuration and do not currently process Patient data. If we activate either as an operational sub-processor, we will add it to the list above and notify customer clinics in advance in accordance with the DPA.
We notify customer clinics in advance of any new sub-processor or material change to the sub-processor list, in accordance with the DPA.
7. International data transfers
Several of our sub-processors are based outside the UK, primarily in the United States and EU. Where personal data is transferred to a country outside the UK that does not have an "adequacy decision" from the UK Government, we rely on the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, together with supplementary technical and organisational measures (encryption in transit and at rest, access controls, and audit logging).
Where adequacy applies (e.g., transfers to the EU/EEA under the UK adequacy regulations), no additional transfer mechanism is required.
8. Data retention
- Clinic account, billing, and accounting records — retained for the duration of the contract and 6 years thereafter, to comply with HMRC and Limitation Act 1980 requirements.
- Patient data processed on behalf of clinics — retained for the duration of the customer's subscription, plus a 60-day export window after termination, after which Patient data is deleted from production systems within 30 days and expunged from backups within the standard 90-day rotation cycle, in accordance with the DPA.
- Marketing data — retained until you unsubscribe, plus 12 months thereafter for suppression-list purposes.
- Website analytics — aggregated and anonymised, retained indefinitely; identifiable analytics retained for 13 months.
- Security logs — retained for 12 months.
9. Your rights
Under UK GDPR you have the following rights, which you can exercise by contacting hamayoon@seventy3.co:
- The right to be informed (this Policy).
- The right of access (a copy of the personal data we hold about you).
- The right to rectification (correction of inaccurate data).
- The right to erasure (deletion of your data, subject to exceptions).
- The right to restrict processing.
- The right to data portability.
- The right to object (including to direct marketing and to processing based on legitimate interests).
- Rights in relation to automated decision-making and profiling.
- The right to withdraw consent at any time, where consent is the lawful basis.
We will respond within one month, in line with UK GDPR. If you are a Patient of a Seventy3 OS clinic, please contact your clinic first (see Section 5.4).
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk or 0303 123 1113.
10. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Multi-factor authentication for administrative accounts.
- Role-based access control and the principle of least privilege.
- Audit logging of access to sensitive data.
- Regular patching and dependency monitoring.
- Regular backups, encrypted and access-controlled.
- Incident response procedures, including a 48-hour breach notification commitment to customer clinics.
- Personnel confidentiality obligations and data protection awareness.
11. Cookies
We use cookies and similar technologies on our website. Strictly necessary cookies are set by default; analytics and marketing cookies are set only with your consent (via our cookie banner). You can change your cookie preferences at any time.
12. Changes to this Policy
We may update this Policy from time to time. The current version is always available on our website with the date last updated. For material changes, we will notify customer clinics by email at least 30 days in advance.
13. How to contact us
- Email: hamayoon@seventy3.co
- Post: Seventy3 Group Ltd, Suite 21, Call House, Enfield Street, Leeds, England, LS7 1RF
