Legal

Privacy Policy

Entrizo  |  Effective Date: 1 April 2026  |  Version 1.0

This Privacy Policy explains how Entrizo ("we", "us", "our") collects, uses, stores, and shares information when you use the Entrizo patient scheduling platform ("Service"). We are committed to protecting personal data and operating in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Entrizo is a patient scheduling platform. We operate as a data processor on behalf of healthcare organisations (our clients) who use the Entrizo platform to manage patient appointment scheduling.

For enquiries regarding this policy, please contact:

Data Protection Lead

Email: privacy@entrizo.com

Website: entrizo.com

2. Information We Collect

2.1 Patient Information

When a healthcare organisation uses Entrizo to manage appointments, we process the following categories of patient data on their behalf:

  • Full name
  • Date of birth
  • Mobile phone number and/or email address
  • NHS number or patient reference number
  • Appointment details (type, date, time, location)
  • Exam or procedure codes
  • Communication preferences and responses to SMS/digital notifications

2.2 Healthcare Organisation Data

When a healthcare organisation registers to use Entrizo, we collect:

  • Organisation name and contact details
  • Names and email addresses of authorised staff
  • Scheduling system integration credentials (handled securely)
  • Usage data and activity logs

2.3 Technical Data

When users access the Entrizo platform or patient-facing portal, we may collect:

  • IP addresses
  • Browser type and version
  • Device identifiers
  • Session data and access logs

4. How We Use Information

We use the data we process to:

  • Send appointment confirmations, reminders, and notifications to patients on behalf of healthcare organisations
  • Enable patients to self-book, reschedule, or cancel appointments
  • Connect with healthcare scheduling systems to display real-time availability
  • Provide administrative dashboards to booking teams
  • Monitor system performance and resolve technical issues
  • Comply with legal and regulatory obligations
  • Improve and develop the Entrizo platform

5. SMS and Digital Communications

Entrizo sends SMS messages to patients on behalf of healthcare organisations using Twilio and ClickSend as SMS gateway providers. These messages are initiated by the healthcare organisation and relate solely to the patient's appointment. Patients may respond to SMS messages to confirm, reschedule, or cancel appointments. SMS delivery is subject to network availability and the terms of our gateway providers.

Entrizo does not use patient contact details for marketing purposes and does not sell patient data to third parties.

6. Data Sharing

6.1 Healthcare Organisations

Patient data processed through Entrizo is shared with the healthcare organisation that referred the patient. This sharing is governed by a Data Processing Agreement (DPA) between Entrizo and the healthcare organisation.

6.2 Sub-processors

Entrizo works with a limited number of trusted sub-processors to deliver the Service. Our current sub-processors are:

  • Microsoft Azure (United Kingdom) — cloud infrastructure, hosting, and data storage
  • Twilio Inc — SMS gateway provider for delivering patient appointment notifications
  • ClickSend — SMS gateway provider for delivering patient appointment notifications

All sub-processors are required to implement appropriate technical and organisational security measures. Entrizo relies on each provider's standard data processing terms, which include commitments to handle personal data in accordance with applicable data protection law.

6.3 Legal Disclosure

We may disclose data if required to do so by law, court order, or a regulatory authority with jurisdiction over Entrizo or its clients.

7. Data Retention

Entrizo retains patient data only for as long as necessary to deliver the Service and as directed by the healthcare organisation. Standard retention periods are:

  • Appointment data: retained for 7 years from the date of the appointment, in line with NHS Records Management Code of Practice. A different retention period may be agreed with the healthcare organisation where required.
  • Communication logs (SMS delivery records): retained for 12 months
  • Client account data: retained for the duration of the contract and up to 7 years thereafter in line with NHS and legal obligations

Healthcare organisations remain responsible for their own data retention obligations under the NHS Records Management Code of Practice and any applicable regulatory guidance.

8. Data Security

Entrizo implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, loss, or destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and role-based permissions
  • Secure API integrations with scheduling systems
  • Regular security assessments
  • Staff training on data protection

In the event of a personal data breach affecting patient data, Entrizo will notify the relevant healthcare organisation within 72 hours of becoming aware of the breach, in accordance with Article 33 UK GDPR. Notifications will include details of the nature of the breach, the categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address it.

9. International Transfers

All patient data processed through Entrizo is stored and processed exclusively within the United Kingdom, hosted on Microsoft Azure infrastructure in UK data centres. We do not transfer patient data outside of the United Kingdom. Where our SMS providers (Twilio and ClickSend) process delivery metadata, this may involve infrastructure outside the UK; however, message content and patient identifiable data is handled in accordance with each provider's data protection commitments.

10. Rights of Data Subjects

Patients whose data is processed through Entrizo have rights under UK GDPR. As Entrizo acts as a data processor, requests from patients to exercise their rights should be directed to the relevant healthcare organisation (the data controller). Entrizo will cooperate with healthcare organisations to facilitate the exercise of data subject rights, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object

11. Cookies and Website Tracking

The Entrizo website (entrizo.com) uses essential cookies required for the platform to function correctly, such as session management and security. A cookie consent banner is displayed to all website visitors. We do not currently use analytics or advertising cookies. If this changes, this policy will be updated accordingly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify healthcare organisations and update the effective date above. Continued use of the Service following notification of changes constitutes acceptance of the updated policy.

13. Contact

For any questions about this Privacy Policy or how your data is handled, please contact:

Email: privacy@entrizo.com

Website: entrizo.com