Consentz — Privacy Policy
SMARTMATTER LLC (trading as Consentz)
Last updated: 15 August 2026
Previous versions of this policy are available on request — please email privacy@consentz.com.
What this policy covers
This policy covers (1) the Consentz clinical CRM, EHR and consent-management platform, (2) the Consentz patient-facing clinic directory and enquiry service, and (3) professional profiles listed in that directory. It explains when Consentz acts as a controller (including for clinic and practitioner account, business-contact and payment information) and when it acts as a processor for a clinic.
SMARTMATTER LLC ("Consentz", "we", "us" or "our") is registered at 30 N Gould St, Suite R, Sheridan, Wyoming 82801, USA. We are registered with the UK Information Commissioner's Office under registration number ZB678435.
Because Consentz is based in the United States, personal data may be transferred to the US and other countries under the safeguards described in Part D2.
Data protection contact: privacy@consentz.com
UK representative: Under Article 27 UK GDPR we have appointed Data Protection Representative Limited (trading as DataRep) as our UK representative for data-protection matters. If you are in the UK, you may contact DataRep, quoting Consentz / SmartMatter LLC, at:
DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom.
This representative appointment applies to all processing described in this policy.
How this policy is organised
Part A applies to clinics, practitioners and staff who use the Consentz Application.
Part B applies to patients and visitors who use the Directory or submit an enquiry.
Part C applies to clinics and practitioners whose professional details are listed in the Directory. Because we build these listings from public sources, Part C is also our notice to those practitioners under Article 14 UK GDPR. Parts B and C together form the Consentz Directory notice.
Part D contains general terms that apply to everyone this policy covers.
Part E is a supplementary notice for people in the United States.
Our roles at a glance
| Processing activity | Consentz role | Other controller |
|---|---|---|
| Clinic account, billing, support, security and service administration | Controller | Not applicable |
| Patient information entered into the Application by a clinic | Processor, on the clinic's documented instructions | The relevant clinic |
| Directory enquiry collection, validation, routing and lead administration | Controller | Each recipient clinic becomes a separate controller for its own use after receipt |
| Professional profiles and visibility scores in the Directory | Controller | Not applicable |
Important
Consentz and each clinic act as separate controllers, each for their own purposes, and are not joint controllers. Where the law requires consent — including explicit consent for health-related Directory enquiries — we ask for it separately at the relevant point. For how a clinic may process your personal data, please read their own privacy policy.
PART A — Clinics, practitioners and staff using the Consentz Application
A1. Scope and roles
This Part applies when you are a clinic, practitioner or staff member and register for, administer or use the Consentz clinical CRM, EHR, consent-management and related workflow services (the "Application").
A2. Information we collect
We may collect the following categories of information about clinic users, practitioners, staff and business contacts:
identity, professional and contact details — name, role, job title, qualifications, skills, experience, professional registrations and memberships, practice name, business address, email address and telephone number;
account, subscription and commercial information — plan, billing status, invoices and transaction references; our payment providers process full payment-card details unless we expressly state otherwise;
communications, support requests, training records, feedback and survey responses;
marketing preferences and records of engagement with our communications; and
technical, usage and security information — IP address, device and browser details, log-in records, audit logs, features used, referral source and cookie identifiers where permitted.
A3. How we use clinic-user information
We use this information to: provide, administer, secure and support the Application and accounts; process subscriptions and keep financial records; communicate about service changes, incidents, support and training; prevent fraud and unauthorised access; analyse and improve the service; manage relationships, complaints and legal claims; and send relevant B2B marketing where permitted, subject to opt-out.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide, administer and support the Application | Account, contact, configuration and usage data | Performance of a contract (Art 6(1)(b)) |
| Take payment and keep financial records | Billing and payment data | Legal obligation (Art 6(1)(c)) / contract |
| Secure the service, prevent fraud and improve the product | Usage, device and security-log data | Legitimate interests (Art 6(1)(f)) |
| B2B marketing to clinic users | Business-contact data | Legitimate interests (with opt-out); consent where required |
| Non-essential cookies and consent-based marketing | Device and marketing data | Consent (Art 6(1)(a)); PECR |
| Comply with law and handle claims/regulators | Relevant records as needed | Legal obligation / legitimate interests |
We collect this information directly from you, automatically from your use of the Application, and from clinics, payment providers and public professional sources.
A4. How we process Clinic Patient Data
When Consentz processes Clinic Patient Data, it does so only as the clinic's processor, under the clinic's instructions and the data processing agreement in the Terms; this policy does not govern that processing. Consentz does not use Clinic Patient Data to advertise to patients.
A5. Anonymous and aggregated statistics
Where permitted by the clinic agreement, we may create aggregated statistics intended not to identify a patient, practitioner or clinic, and use them to operate, secure, benchmark and improve the services. We do not attempt to re-identify these outputs; where data is only pseudonymised we continue to protect it as personal information.
A6. Marketing
We may send clinic users relevant service and business communications. You can opt out of promotional communications at any time via the unsubscribe link or by emailing support@consentz.com. Operational messages are not marketing. We do not market to patients merely because a clinic has uploaded their details. Where the law requires consent for marketing, we obtain a clear opt-in and you can withdraw it as easily as you gave it.
A7. Retention
Account and service records: normally the account term plus up to six years (or longer where the law requires).
Invoices, payment and tax records: up to seven years or longer where law requires.
Security, access and audit logs: periods appropriate to their purpose and sensitivity.
Full detail is in our Data Retention Policy.
A8. Clinic-user rights
Clinic users may have rights to access, correct, erase, restrict or object to certain processing, and to portability. Requests concerning Clinic Patient Data should be made to the clinic that controls the record. The general information in Part D also applies.
PART B — Patients and visitors using the Directory or submitting an enquiry
B1. Scope and our role
This Part applies when patients and website visitors browse the Consentz clinic directory (the "Directory"), create an account, or submit a request for information, pricing, a consultation or another clinic service (an "Enquiry"). Consentz is the controller of the information it collects for the Directory and Enquiry service. The clinic or practitioner you contact is the separate controller of the information it holds once we pass on your Enquiry (please read their own privacy policy).
Consentz operates a paid introduction service: where you ask to be contacted by a clinic you have chosen, we make your enquiry available to that clinic for a fee. We do not sell your information to multiple clinics or to other third parties. Where a clinic instead receives an enquiry directly through its own Consentz account, that clinic is the controller and Consentz only processes the enquiry on its behalf.
B2. Information we may collect
The exact fields are shown on the relevant form and may include: identity and contact information (name, email, telephone); demographic information (age range, date of birth, sex/gender where clearly requested); location (postcode, town, region, preferred treatment location); Enquiry information (clinic selected, treatment of interest, pricing/consultation request, preferred timing, message content); consent and routing records (choices shown, notice version, time of submission, clinic sent to); communications and records used to administer the Enquiry; and technical/usage information (IP, device, referral source, cookie identifiers where permitted).
We do not currently carry out background or criminal-record checks; if we introduce them we will update this policy first. We do not seek special-category data for our own purposes — please provide only what is relevant to the Enquiry. The Directory is not an emergency service.
B3. How we use Enquiry information
We use it to: collect, validate, administer and transmit the Enquiry; share it with the selected clinic so they can respond; share it with alternative clinics only where you make a separate, clear choice permitting that; communicate about status and outcome; detect fraud and abuse; administer clinic billing and lead disputes; respond to rights requests, complaints and legal obligations; and produce aggregated statistics — never using your health-related Enquiry for unrelated advertising.
An Enquiry may reveal or allow inference of information about your health. For collecting and routing such Enquiries in the UK we rely on your consent under Article 6(1)(a) and, for special-category health data, your explicit consent under Article 9(2)(a). We rely on legitimate interests for limited supporting activities (security, fraud prevention, administration, legal claims, non-intrusive analytics).
We ask for this consent by a clear affirmative action at the point you submit the Enquiry, after telling you who will receive it and why. It is separate from accepting this policy, and you can withdraw it at any time without affecting earlier processing.
B4. Selected clinic and alternative clinics
The form identifies the selected clinic. Your consent to send the Enquiry to that recipient is separate from any optional choice to share it with alternative clinics; refusing alternative sharing will not prevent the selected clinic responding. Where alternative sharing is offered, the form will name the specific additional clinics and let you select them at the point you consent, and we keep a record of the consent wording, time and actual recipients. You may withdraw consent for future sharing at any time.
B5. What happens after a clinic receives the Enquiry
Each recipient clinic becomes a separate controller for its own use of the Enquiry after receipt; its privacy notice applies to its contact with you. Clinics are contractually required to use a lead only for the relevant Enquiry, provide appropriate privacy information, avoid unrelated marketing, protect the information and avoid onward sale. Consentz remains a controller for the copy and records it retains for routing, billing, consent evidence, security and legal purposes.
B6. Commercial arrangements and rankings
A clinic may pay Consentz a subscription, listing fee, introduction fee or lead fee; we do not sell your personal data — the fee is for the introductory service. We disclose paid or sponsored placement where required and do not present payment as evidence of clinical quality. The Directory visibility score is not a clinical-quality, safety or outcomes rating.
B7. Retention
Enquiry content and routing records: normally up to 12 months after submission, unless a shorter or longer period is reasonably required for a complaint, security issue or legal claim.
Consent, recipient and suppression records: up to six years where reasonably necessary to demonstrate compliance.
Financial and lead-billing records: up to seven years.
See our Data Retention Policy for detail.
B8. Your choices and rights
You may withdraw consent for future consent-based processing, ask us not to send the Enquiry to additional clinics, and exercise the rights in Part D and Part E. Where we rely on consent, you can withdraw it as easily as you gave it.
PART C — Clinics and practitioners listed in the Directory (Article 14 notice)
Because we build directory listings from public and published sources rather than from you directly, this Part is also the notice we are required to give you under Article 14 UK GDPR.
C1. Information we hold
Depending on what is available, a listing may include: clinic or trading name; business address; telephone number; email address; social-media handles; professional registrations and accreditations; the services and treatments offered; and a location map where relevant. We also hold profile-completeness and public-web-presence signals used to calculate the visibility score, and any corrections, claims and communications about the listing.
We do not hold photographs, and we do not publish pricing. We do not intentionally publish a practitioner's private home address unless they have used it as a public professional address.
C2. Where we got your information (sources)
We build listings from information that is already publicly available. Our sources fall into these categories:
UK regulatory and accreditation registers, including the CQC, JCCP, GMC, Save Face, Healthcare Improvement Scotland (HIS), Healthcare Inspectorate Wales (HIW) and RQIA;
practitioners' and clinics' own websites;
publicly available business listings, including Google Business listings; and
published industry and awards lists, including the Tatler aesthetics list, the Aesthetics Awards and the CCR Awards.
We compile this using a combination of automated tools and manual research. Where a listing is built from more than one source we may hold it as a single combined profile. Using a public source does not remove our transparency or accuracy obligations.
C3. What we use it for, and our lawful basis
We use listing information only to:
create and publish a directory listing so the public can find practitioners and clinics;
generate a visibility score for the listing;
contact you to invite you to claim, correct or update your profile; and
offer and pass patient enquiries ("leads") to you about your own listing.
Our lawful basis for 1–3 is legitimate interests — our interest in operating a directory that helps patients find and contact qualified practitioners, which cannot be achieved without identifying and listing them. We have carried out a legitimate interests assessment balancing this against your rights. Where you have claimed your profile and we provide lead services, we rely on our contract with you and, where relevant, your consent.
We do not sell or share your profile data with any third party. The only enquiries we pass on are to the practitioner or clinic the enquiry is about.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and publish listings from public sources | Name/clinic, address, contact details, registrations, services | Legitimate interests |
| Generate the visibility score | Public profile signals (accreditations, website, completeness) | Legitimate interests |
| Contact you to claim or correct a profile | Name, business contact details | Legitimate interests |
| Provide lead services to a claimed practitioner | Account data; enquiry data | Contract; consent |
C4. Visibility scores and profiling
The visibility score is our assessment of objective, factual signals — such as whether you hold recognised accreditations, whether you have a website and business listing, the quality of your online discoverability, whether pricing and location are shown, and how complete your public information is. It is not an assessment of medical competence, patient safety, treatment suitability, clinical outcomes or regulatory endorsement. Scores fall within a banded range and are not a negative ranking of individuals.
The score is not made solely by automated means — a member of our team reviews scoring before it is relied upon, so it does not produce legal or similarly significant effects on you. If you believe your score is wrong or unfair, you can ask us to review it at privacy@consentz.com and we will genuinely look into it. You may also object to this processing.
C5. Claiming your profile
If we contact you, you can claim your profile by following the link we send, verifying your identity and that you are the owner, and creating an account. Once claimed, you can edit or remove your listing content and access patient enquiries about your listing (pay-per-lead or by subscription). When you claim, we become the controller of the account information you give us; we remain a controller of the directory listing and score while your listing appears.
C6. Your control, objection and removal
You control whether you appear in the Directory:
You can remove your listing entirely at any time — yourself once you have claimed it, or by emailing privacy@consentz.com.
To protect against misuse, where you ask us to remove or change a listing you have not claimed, we may first take a light step to confirm you are the person the listing is about, so a competitor or third party cannot make a request about your data without authority.
When a listing is removed, we retain only a minimal suppression record needed to ensure we do not list you again, unless the law requires us to keep more.
We will action reasonable objection, correction and erasure requests promptly.
C7. Disclosure and retention
Listings are displayed publicly and may be indexed by search engines. We disclose data to service providers supporting hosting, communications, security and analytics (see Part D1). We keep listings while they remain relevant, and after removal keep only the minimal suppression record described above. See our Data Retention Policy.
PART D — General terms applying across the services
D1. Service providers and other recipients
We use vetted providers, each bound by written confidentiality and data-protection terms and permitted to process information only for the contracted service. These include Amazon Web Services and DigitalOcean for cloud hosting (UK regions), and Twilio and Plevo for email/SMS communications, together with providers for analytics, error monitoring, payment processing and support. A current list naming each processor is available on request. We remain responsible for our processors.
We may also disclose information where reasonably necessary to comply with law, protect people, investigate fraud, enforce agreements, defend legal claims, or support a corporate transaction.
D2. International transfers
SmartMatter LLC is based in the United States, and some access to personal data takes place from outside the UK by our own personnel. Our primary hosting is in the UK, so personal data is not routinely stored outside the UK. Where a restricted transfer to the US does occur, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. SmartMatter LLC is also in the process of self-certifying under the UK Extension to the EU–US Data Privacy Framework; we will update this policy to rely on that framework once certification is finalised. We carry out transfer assessments where required and apply supplementary measures appropriate to the risk.
D3. Security
We use technical and organisational measures maintained under our information security policy (we are ISO 27001 certified and independently audited each year), including role-based access, authentication, encryption in transit, logging, backups, vulnerability management, staff controls and incident-response procedures. No system can eliminate all risk, but we review and improve our safeguards as the services develop.
D4. Cookies and similar technologies
We use strictly-necessary technologies for security, authentication, session management and requested functions. We use analytics, advertising or other non-essential cookies only after obtaining consent. Continuing to browse is not treated as consent; non-essential cookies are off by default and set only if you opt in, and you can reject or withdraw them as easily as you accept them. Full detail — cookie names, providers, purposes and durations — is in the Cookie Notice at Annex A.
D5. Direct marketing
We do not use personal data for direct marketing you have not opted in to receive, and you may opt out at any time. We may keep a limited record to respect your opt-out.
D6. Children
The Directory and Enquiry services are for adults aged 18 or over, and Consentz does not knowingly create Directory accounts or profiles for children. Before submitting an Enquiry you must confirm you are 18 or over, or that you are the parent or legal guardian of the person named and are authorised to provide the information. This is not clinical consent on behalf of a minor.
D7. Your data-protection rights
Depending on the law and circumstances, you may have rights to: be informed and access your information; correct it; request erasure or restriction; object to legitimate-interests processing or to direct marketing; receive certain information in a portable format; withdraw consent where processing relies on it; and complain to a regulator.
To exercise a right or make a data-protection complaint, email privacy@consentz.com. We may need information to verify your identity. We respond to a data-subject request without undue delay and within one month (extendable for complex requests, which we will tell you about). We handle complaints under our Data Protection Complaints Policy at Annex B.
UK individuals may also complain to the Information Commissioner's Office (ico.org.uk; helpline 0303 123 1113; Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF). We ask that you contact us first so we can try to put things right.
D8. Changes to this policy
We may update this policy to reflect service, legal or operational changes. We will post the updated version and change the date above. Where a change materially affects an existing use or consent choice, we will provide additional notice and seek consent only where the law requires it.
D9. Contact
SmartMatter LLC (Consentz)
30 N Gould St, Suite R, Sheridan, Wyoming 82801, United States
Email: privacy@consentz.com
ICO registration: ZB678435 — ico.org.uk
UK representative: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom
PART E — United States supplementary notice
*This Part concerns US state privacy laws and has not been reviewed by UK counsel. Have it checked by qualified US privacy counsel before relying on it.*
E1. Scope
This Part supplements the policy for people in the United States and applies in addition to Parts A–D where US state law applies.
E2. Categories, sources and purposes
The categories of personal information we collect, the sources, and the purposes are described in Parts A–D. We collect identifiers, contact and demographic data, commercial and payment data, internet/usage data, and, for Directory enquiries, health-related information you provide.
E3. US Consumer Health Data Notice
Where US consumer-health-data laws apply, we collect health-related enquiry data directly from the consumer and use it to provide, route and administer the requested Enquiry, communicate about it, prevent fraud, maintain consent and disclosure records, secure the service and comply with law. We share it with the selected clinic and processors that support the service. Where applicable law requires affirmative consent to collect or a separate consent to share consumer health data, we obtain it first. We do not use geofencing around healthcare facilities.
E4. Compensated introductions, sale and advertising
We do not sell Clinic Patient Data or Directory Enquiry information to data brokers or use it for unrelated cross-context behavioural advertising. A recipient clinic may pay Consentz for an introduction, subscription or lead. Some state laws may classify a compensated disclosure as a "sale" even where the consumer requested it; where such a law applies we provide the required notice, consent, authorisation or opt-out before the disclosure.
E5. US privacy rights
Subject to applicable law, US residents may have rights to confirm, access, correct, delete, obtain a portable copy, withdraw consent, opt out of sale/targeted advertising/certain profiling, and appeal a refusal. Submit a request to privacy@consentz.com stating "US Privacy Request" and your state of residence. We recognise valid universal opt-out signals, including Global Privacy Control, where required.
E6. HIPAA and California medical-information law
HIPAA applies based on the parties, relationship and context. Directory Enquiries collected by Consentz independently may fall outside HIPAA. Where Consentz processes protected health information on behalf of a HIPAA-covered clinic as its Business Associate, the applicable Business Associate Agreement and HIPAA govern that processing.
E7. Security and breach notification
We maintain safeguards and incident-response procedures for sensitive information and provide breach notices where required by applicable law.
E8. California notice at collection
For California residents, the categories collected, sources, purposes, retention approach and categories of recipients are described in Parts A–E. Where the CCPA applies, California residents may exercise the rights in E5.
Annex A — Cookie Notice
This Notice forms part of this policy (Part D4). Strictly-necessary cookies are always on. Non-essential cookies are off by default and set only if you opt in; you can change your choices at any time using our cookie controls.
| Cookie / technology | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| Session / sign-in | Consentz | Keep you signed in; security | Strictly necessary | Session |
| Security token (CSRF) | Consentz | Prevent cross-site request forgery | Strictly necessary | Session |
| Load balancing | AWS / DigitalOcean | Route requests; availability | Strictly necessary | Session |
| [analytics — to confirm] | [provider — to confirm] | Understand usage | Non-essential (opt-in) | [to confirm] |
| [error monitoring — to confirm] | [provider — to confirm] | Diagnose faults | Non-essential (opt-in) | [to confirm] |
| [chat/support — to confirm] | [provider — to confirm] | Enquiry chat | Functional (opt-in) | [to confirm] |
*Entries marked [to confirm] to be completed from the live cookie scan / your Complianz export.*
Annex B — Data Protection Complaints Policy
1. Purpose. This policy explains how to make a complaint about how Consentz handles personal data, and how we deal with it. It applies to anyone whose personal data we hold — practitioners and clinics listed in our directory, practitioners and staff who use our software, and members of the public who make enquiries.
2. What it covers. It covers our handling of personal data — how we collected it, use it, share it, or a request to correct, object to, or delete it. It does not cover: the medical treatment, advice or care provided by any clinic or practitioner (Consentz is a technology platform, not a healthcare provider, gives no medical advice, and is not responsible for the treatment, conduct or outcomes of any clinic or practitioner); a clinic's own handling of a patient's data once we have passed an enquiry to them (from that point they are the independent controller); or general service or billing complaints, which go to care@consentz.com.
3. How to complain. Email privacy@consentz.com with your name and contact details, what your complaint is about, and what you would like us to do. No special form or wording is needed.
4. Verifying identity. To protect people's data, we may ask you to confirm your identity before we act — particularly for correction or deletion — so that no one can make a request about another person's data without authority. We keep this as light as possible.
5. How we handle it. We aim to acknowledge within 5 working days and respond fully within 30 calendar days; if a complaint is complex and we need longer, we will tell you why. Data requests (access, correction, objection, deletion) are handled within the timescales required by law, normally within one month.
6. If you are not satisfied. We ask that you contact us first so we can put things right. You may complain to the UK Information Commissioner's Office at any time: ico.org.uk/make-a-complaint/; helpline 0303 123 1113.
7. Records. We keep a record of complaints and outcomes to meet our accountability obligations and improve how we handle personal data, kept only as long as necessary.
Annex C — Data Retention Policy
We keep personal data only for as long as we need it for the purpose we collected it, or as long as the law requires.
| Type of data | How long we keep it | Why |
|---|---|---|
| Directory listings | While the listing is active | To run the directory |
| Suppression record (after a listing is deleted) | Ongoing (identifier only) | To ensure we do not re-list someone who asked to be removed |
| Claimed account data (name, email, phone, clinic, credentials) | Account duration + 6 years | Manage the account; defend legal claims; limitation period |
| Billing / payment records | Up to 7 years | Legal / accounting obligations |
| Patient enquiry content and routing records | Up to 12 months | Deal with the enquiry, complaints, security |
| Consent, recipient and suppression records | Up to 6 years | Demonstrate choices, disclosures and compliance |
| Support and communications | 2 years | Handle and review support issues |
| Security and access logs | 12 months | Security and fraud prevention |
| Complaints records | As long as necessary (guide: 6 years) | Accountability |
| Cookies / analytics | Per the durations in Annex A | Per each cookie's stated duration |
| Marketing consents | Until withdrawn + a short record thereafter | Prove consent; honour withdrawal |
Where a patient enquiry is passed to a clinic, the clinic becomes the independent controller of its copy and sets its own retention. When a period ends, we securely delete or anonymise the data, unless the law requires us to keep it or we need it to establish, exercise or defend legal claims. We review this approach at least annually.
