Back to BasiCare
Legal information

Privacy Policy

How OTEO Health handles personal data across the BasiCare clinic platform, oCare patient portal, public booking, payments, communications and support services.

Last updated: 7 May 2026

This policy is written to help patients, clinics and website visitors understand how personal data is handled across BasiCare and oCare.

Products covered

BasiCare and oCare

BasiCare supports healthcare organisation operations. oCare supports patient access, booking, billing and communication. The same legal pages explain both journeys so clinics and patients can understand their responsibilities.

Patient identifiers, tokens and raw clinical resource identifiers should not be exposed in public website content.

1. Scope of this notice

This Privacy Policy explains how OTEO Health handles personal data when you use our website, BasiCare clinic platform, oCare patient portal, public practitioner search, public booking, online consultations, billing, payments, documents, messages, support and related services.

This notice is written for patients, website visitors, public booking users, practitioners, clinic users, customer administrators, suppliers and other people who interact with us. It should be read alongside any privacy notice provided by your healthcare organisation.

2. Controller and processor roles

Healthcare organisations using BasiCare will usually be the controller for patient care records, appointments, clinical documents, communications, prescriptions, laboratory results, imaging information, billing records and related health or social care processing. In that context, we usually act as their processor or technology provider.

For oCare, the healthcare organisation will usually remain the controller for patient health records and clinical communications made available through the portal. We may be a controller for our own website operations, account security, platform administration, support, commercial communications, service analytics, fraud prevention, payment reconciliation and legal compliance.

The exact role may depend on the contract, feature and processing purpose. If you are a patient and want to exercise rights relating to clinical records, we may need to pass your request to the relevant healthcare organisation.

3. Personal data we may collect

  • Identity data: name, date of birth, gender, NHS or local identifiers where provided, patient identifiers, staff identifiers, organisation role and account details.
  • Contact data: email address, phone number, postal address, emergency contact details and communication preferences.
  • Health and care data: appointments, encounters, observations, diagnoses, allergies, medications, prescriptions, clinical notes, referrals, documents, lab results, imaging references, uploaded files, messages and online consultation metadata.
  • Billing and payment data: invoices, balances, payment status, receipts, Stripe customer references, payment intent identifiers, charge identifiers and reconciliation details. We do not store full card numbers.
  • Technical data: device, browser, IP address, session identifiers, authentication events, audit logs, security logs, error logs and usage data.
  • Public profile data: practitioner name, title, photograph, languages, biography, areas of interest, organisation, specialty, location and public booking settings where published by an organisation.
  • Support and communications: demo requests, contact forms, emails, chat or support tickets and responses to surveys or product feedback.

4. Special category health data

Health data is special category data under UK GDPR and needs additional protection. We process it only where there is a lawful basis under Article 6 and a special category condition under Article 9, usually because processing is necessary for health or social care, legal obligations, vital interests, explicit consent for specific optional features, or another lawful condition chosen by the controller.

Where we act as processor for a healthcare organisation, that organisation decides the lawful basis and special category condition. We process health data under their instructions, subject to security, confidentiality and data processing terms.

5. How we use personal data

  • To create, secure and administer accounts.
  • To let healthcare organisations manage appointments, clinics, rooms, devices, practitioner roles, messages, documents, invoices and care workflows.
  • To let patients use oCare, search public profiles, book appointments, join online consultations, view selected records, upload documents and manage profile settings.
  • To process payments, reconcile invoices, create receipts and investigate disputed transactions.
  • To send operational communications such as appointment confirmations, reminders, cancellations, payment status updates, security notices and service messages.
  • To provide customer support, diagnose errors, maintain audit trails, investigate security incidents and improve reliability.
  • To comply with legal, regulatory, contractual, accounting, tax, safeguarding, information governance and dispute resolution obligations.
  • To improve the product using aggregated, de-identified or minimised analytics where possible.

6. Lawful bases we may rely on

Depending on the context, we or the relevant healthcare organisation may rely on contract, legal obligation, legitimate interests, public task, vital interests, explicit consent, health or social care, public health, legal claims or other lawful bases available under UK GDPR and the Data Protection Act 2018.

Where consent is used, you can withdraw it for future processing. Withdrawal does not affect processing that has already happened or processing that must continue for another lawful reason, such as clinical record keeping, legal obligations or safeguarding.

7. Sharing personal data

We may share personal data with the healthcare organisation responsible for your care, authorised users within that organisation, payment processors, hosting providers, FHIR infrastructure providers, authentication providers, storage providers, email or SMS providers, online consultation providers, support tools, professional advisers, regulators, law enforcement or courts where necessary.

We do not sell patient health records. We do not allow advertising networks to use patient health records for their own advertising purposes.

8. International transfers

Where personal data is transferred outside the United Kingdom, we use appropriate safeguards where required, such as adequacy decisions, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, contractual controls, security measures and transfer risk assessments.

9. Retention

Retention periods depend on the type of data, the healthcare organisation instructions, clinical record keeping requirements, legal obligations, accounting rules, dispute risks and security needs. Patient clinical records are commonly retained by healthcare organisations under applicable clinical and legal retention schedules.

We retain website enquiries and demo requests for as long as needed to respond and manage business relationships. Security logs and audit logs may be retained to protect the service and evidence authorised access. Payment records may be retained for accounting, reconciliation and dispute handling.

10. Security

We use technical and organisational measures designed to protect personal data, including access controls, authentication, encryption in transit where appropriate, role-based permissions, audit logs, monitoring, backups, secure development practices and supplier due diligence.

No online service can be guaranteed completely secure. You must protect your credentials, use secure devices, avoid sharing accounts and tell us or your healthcare organisation promptly if you suspect unauthorised access.

11. Cookies and similar technologies

Our website and applications may use strictly necessary storage for login, security, language preference, session continuity, public booking state and fraud prevention. We may also use analytics or similar technologies where enabled and lawful.

Where PECR or UK GDPR requires consent for non-essential cookies, tracking pixels or similar storage and access technologies, we will ask for consent or provide controls. You can also manage cookies through your browser settings, although some features may not work without necessary storage.

12. Your rights

Depending on the context and lawful basis, you may have rights to be informed, access your personal data, request rectification, request erasure, restrict processing, object to processing, request data portability, withdraw consent and avoid certain solely automated decisions with legal or similarly significant effects.

These rights are not absolute. For example, clinical records, audit logs, safeguarding records, legal claims, accounting records or data about other people may need to be retained or handled carefully. If we act as processor, we may refer your request to the relevant healthcare organisation.

13. Automated decision-making and AI

The services may include automation to support routing, reminders, slot generation, validation, security monitoring, billing reconciliation, search, translation or administrative workflows. We do not intend the platform to make solely automated clinical decisions that produce legal or similarly significant effects on patients without appropriate human involvement.

If a healthcare organisation configures tools or integrations that use AI or automated processing, that organisation is responsible for ensuring the use is lawful, clinically appropriate, transparent and governed by suitable safeguards.

14. Children and representatives

Some services may be used for children or vulnerable patients where a healthcare organisation supports this and legal authority is in place. Parents, guardians, carers and authorised representatives must use the service only within the scope of their authority.

We encourage organisations to configure access carefully for minors, safeguarding contexts, proxy access and confidentiality-sensitive services.

15. How to contact us or complain

For privacy questions about our own processing, contact info@oteohealth.com. For BasiCare sign-in support, contact support@basicare.co.uk. If your question is about your clinical record or care provider, contact the relevant healthcare organisation first because they will usually be the controller.

You can complain to the UK Information Commissioner Office if you are unhappy with how your personal data is handled. The ICO website is https://ico.org.uk/ and its helpline is 0303 123 1113.

16. Changes to this policy

We may update this Privacy Policy to reflect new features, law, regulatory guidance, suppliers, operational changes or risk controls. The latest version will be published on this website with an updated date.

If anything on this page is unclear, contact us before using the service. Healthcare organisations may also provide their own notices, policies or contract terms for services they deliver through BasiCare or oCare.