Privacy Policy
Last updated: 05/08/2026
Welcome to MedPort (accessible at medport.uk, "the Site"). This Privacy Policy explains how MedPort Technologies Limited ("MedPort", "we", "us", or "our") collects, uses, stores, shares, and protects your personal data when you use MedPort ("the Service"), and explains your rights under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we handle your personal data as described here, you should not use the Service. This Privacy Policy forms part of, and should be read alongside, our Terms and Conditions and our Cookies Policy.
1. Who We Are
MedPort is operated by:
MedPort Technologies Limited
Company number: 17284812
Registered office: 88 Whateley Crescent, Birmingham, England, B36 0DP
MedPort Technologies Limited is the data controller responsible for your personal data under the UK GDPR and the Data Protection Act 2018, and is registered with the Information Commissioner's Office (ICO) under registration number ZC212038.
If you have any questions about this policy or your data, contact us at admin@medporttechnologies.com. We have not appointed a formal Data Protection Officer, as we are not required to do so, but the above contact will handle all data protection queries.
2. What Data We Collect
We collect only the information necessary to provide and maintain your account and portfolio, in line with the data minimisation principle under the UK GDPR.
2.1 Information you provide to us:
- Name and email address (for account registration and communication);
- Password (stored in encrypted/hashed form — we cannot view your password);
- Uploaded evidence or portfolio documents (certificates, logbooks, reflections, and similar records of your professional development);
- Subscription and billing information, where you are on a paid plan (processed by Stripe — see Section 5);
- Correspondence you send us, such as support requests.
2.2 We do not require, and you must not upload, any information that identifies a patient or any other third party. MedPort is designed exclusively for recording your own professional development. This is a mandatory condition of use, set out further in Section 4 of our Terms and Conditions, and you are solely responsible for ensuring nothing you upload breaches patient confidentiality or data protection law.
2.3 Automatically collected information:
- Basic technical information, such as browser type, device type, and IP address, collected automatically by our hosting provider for security, fraud prevention, and performance purposes;
- Usage data collected via Google Analytics (pages visited, time on site, general location derived from IP, device/browser type) — only where you have consented via our cookie banner. See our Cookies Policy for full details.
3. How We Use Your Data
3.1 We use your personal data for the following purposes:
- To create and manage your account;
- To store and display your portfolio content within your private workspace;
- To process subscription payments;
- To respond to your queries or support requests;
- To understand how the Service is used and improve it (where you have consented to analytics cookies);
- To comply with legal obligations.
3.2 We do not use your data for advertising, and we do not sell or rent your data to third parties.
4. Legal Basis for Processing
4.1 Under the UK GDPR, we rely on the following legal bases:
- Contract: processing necessary to provide the Service you've signed up for (account management, portfolio storage, billing).
- Consent: for non-essential cookies and analytics (Google Analytics), and for any marketing communications you opt into.
- Legitimate interests: for basic security, fraud prevention, and service performance monitoring.
- Legal obligation: where we must retain or disclose data to comply with the law.
5. How Your Data Is Stored
5.1 Your account data and uploads are securely stored on Supabase servers.
5.2 The website is hosted and served via Vercel.
5.3 Certain media and file assets are stored via Firebase Storage (Google).
5.4 Subscription payments are processed by Stripe.
5.5 All providers use industry-standard encryption and access controls, and we take reasonable steps to protect your data from loss, misuse, or unauthorised access. Your password is encrypted and cannot be viewed by us.
6. Data Sharing
6.1 We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
6.2 We share data only where necessary, with:
- Service providers: Supabase and Firebase (storage), Vercel (hosting), Stripe (payment processing), Google Analytics (analytics, where consented).
- Legal authorities: where required by law, court order, or government request.
6.3 All third-party processors we use are required to comply with UK GDPR and equivalent data protection standards.
7. International Data Transfers
7.1 Some of our service providers (including Supabase, Vercel, Firebase, Stripe, and Google Analytics) may process data on servers located outside the UK or European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, and that the recipient offers an adequate level of data protection.
8. How Long We Keep Your Data
8.1 We retain your data only for as long as necessary to provide the Service or meet legal obligations.
8.2 If you delete your account, your personal data and uploaded files will be permanently deleted within 30 days, except where retention is required by law or for payment recordkeeping (e.g. transaction records retained for tax purposes).
9. Your Rights
9.1 Under the UK GDPR, you have the right to:
- Access a copy of your personal data;
- Correct inaccurate or incomplete information;
- Request deletion of your data ("right to be forgotten");
- Restrict or object to certain processing;
- Withdraw consent at any time, where processing is based on consent (e.g. analytics cookies), without affecting the lawfulness of processing before withdrawal;
- Request transfer of your data to another service (data portability);
- Lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.
9.2 To exercise any of these rights, contact admin@medporttechnologies.com. We will respond within one month, as required by law.
10. Payments
10.1 All subscription payments are handled securely by Stripe, our third-party payment processor. We do not store full payment card details on our servers. Your billing details are processed only to manage your subscription and fulfil legal obligations (such as receipts and refund handling).
11. Children’s Data
11.1 MedPort is intended for users aged 18 and over. We do not knowingly collect data from children. If we discover an account belongs to a minor, it will be deleted.
12. Data Breach Procedure
12.1 In the unlikely event of a data breach, affected users will be notified promptly in accordance with UK data protection law, and we will take appropriate remedial action. Where required, we will also notify the ICO within 72 hours of becoming aware of a breach.
13. Cookies
13.1 We use cookies and similar technologies, including for essential site function, payment processing (Stripe), and analytics (Google Analytics, where you have given consent). Full details, including how to manage your preferences, are set out in our Cookies Policy.
14. Changes to This Policy
14.1 We may update this Privacy Policy periodically to reflect changes to the Service or legal requirements. Any material changes will be notified on this page and, where appropriate, by email.
15. Contact
15.1 If you have questions, requests, or concerns about your data, please contact:
MedPort Technologies Limited
88 Whateley Crescent, Birmingham, England, B36 0DP
admin@medporttechnologies.com