1.The short version
Feedbacker does not collect any information about patients. When a patient scans one of your QR codes, we record that a scan happened, from which code, and at what time. We do not record who scanned, we store nothing on their phone, and we cannot connect a scan to a person. The patient is then sent to a third party site such as Google, and anything that happens after that is between the patient and that platform.
The personal data we do hold is about the staff at subscribing organisations: names, work email addresses, and billing details.
The rest of this policy sets that out properly.
2.Who we are
Refearly Ltd is the data controller for the personal data described in section 4.
- Company number: 17150584
- Registered office: 12 St Botolphs Road, Worthing, United Kingdom, BN11 4JQ
- Contact for data protection: hello@getfeedbacker.com
We are not required to appoint a Data Protection Officer, and have not appointed one. Data protection enquiries go to the address above.
3.Controller and processor
For your account holder's data, for example the email address you register with and your billing details, we are the controller.
For the information you enter into Feedbacker about your organisation, for example staff names and room names, you are the controller and we are the processor. We only use that information to provide the service to you.
4.What we collect
Account data. Organisation name, ODS code and practice address where provided, the name and work email address of the person who registers, and an encrypted version of the password. We never store passwords in a readable form.
Staff and room data. Names of staff members and rooms that you enter so your codes can be labelled. This is business contact information, not clinical information. Only enter what you need.
Billing data. Your subscription status, plan, renewal date, and identifiers issued by Stripe. We never receive or store card numbers, expiry dates, or security codes. Those go directly to Stripe.
Scan and usage data. When a QR code is scanned we record which code it was, the date and time, and the destination the patient was sent to. We do not record the patient's name, IP address, device identifier, location, or anything else that could identify them. We do not place cookies or any other identifier on a patient's device.
Support data. If you email us, we keep the message and our reply.
5.What we do not collect
To be explicit, because this is the question every practice manager asks:
- We do not collect patient names, dates of birth, NHS numbers, or contact details.
- We do not collect any clinical or health information about anyone.
- We do not know which patient left which review, or whether a given patient left one at all.
- We do not track patients across websites.
- The page a patient lands on after scanning makes no request to any third party. Fonts, styles, and images are served from our own systems. Nothing about the patient's visit reaches an advertiser, an analytics company, or any other outside party.
6.Why we use it, and our lawful basis
| What | Why | Lawful basis |
|---|---|---|
| Account data | To create and run your account, authenticate logins, and provide support | Performance of a contract |
| Billing data | To take payment and manage your subscription | Performance of a contract |
| Staff and room data | To label your codes and report scans by location | Performance of a contract, processed on your instructions |
| Scan data | To produce your dashboard reports, and in aggregated anonymous form to improve the product | Legitimate interests: running and improving a service you have asked for |
| Support data | To answer you and keep a record | Legitimate interests: providing support |
| Records of payments | To meet accounting and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have considered your rights and concluded our interest does not override them. You can object at any time: see section 11.
7.Marketing
If you are an existing subscriber we may email you about your account, service changes, and features. These are service communications and you cannot opt out of the essential ones while you hold an account.
If we send you optional marketing, every message will have an unsubscribe link and unsubscribing takes effect immediately.
9.Transfers outside the UK
Some suppliers process data outside the UK. Where they do, transfers are protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by an adequacy decision. You can ask us for details of the safeguards in place.
10.How long we keep it
- Account and staff data: for as long as you have an account, then deleted within 90 days of closure unless you ask for it sooner.
- Scan data: retained while your account is active. After closure it is anonymised or deleted within 90 days.
- Billing and payment records: 6 years from the end of the relevant financial year, as required by UK tax law.
- Support emails: 2 years.
11.Your rights
Under the UK GDPR you have the right to:
- be told what we hold about you and why, which is what this policy is for
- access a copy of your personal data
- have it corrected if it is wrong
- have it erased, subject to any legal obligation on us to keep it
- restrict how we use it while a concern is being resolved
- portability, meaning a copy in a common machine readable format
- object to processing we base on legitimate interests
- withdraw consent, where we relied on consent, without affecting anything done beforehand
To exercise any of these, email hello@getfeedbacker.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
12.Security
Data is transmitted over encrypted connections (HTTPS/TLS). Passwords are stored hashed, never in plain text. Access to production systems is restricted. Card data never touches our systems.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours and tell affected users where required.
13.Children
Feedbacker is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18.
15.Complaints
If you are unhappy with how we have handled your personal data, please tell us first at hello@getfeedbacker.com and we will try to put it right.
You also have the right to complain to the UK's data protection regulator:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline 0303 123 1113. ico.org.uk
16.Changes
We will post any changes on this page and update the "last updated" date. If a change is significant we will email account holders.