Consentz

Consentz — Privacy Policy

SMARTMATTER LLC (trading as Consentz)

Last updated: 15 August 2026

Previous versions of this policy are available on request — please email privacy@consentz.com.

What this policy covers

This policy covers (1) the Consentz clinical CRM, EHR and consent-management platform, (2) the Consentz patient-facing clinic directory and enquiry service, and (3) professional profiles listed in that directory. It explains when Consentz acts as a controller (including for clinic and practitioner account, business-contact and payment information) and when it acts as a processor for a clinic.

SMARTMATTER LLC ("Consentz", "we", "us" or "our") is registered at 30 N Gould St, Suite R, Sheridan, Wyoming 82801, USA. We are registered with the UK Information Commissioner's Office under registration number ZB678435.

Because Consentz is based in the United States, personal data may be transferred to the US and other countries under the safeguards described in Part D2.

Data protection contact: privacy@consentz.com

UK representative: Under Article 27 UK GDPR we have appointed Data Protection Representative Limited (trading as DataRep) as our UK representative for data-protection matters. If you are in the UK, you may contact DataRep, quoting Consentz / SmartMatter LLC, at:

DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom.

This representative appointment applies to all processing described in this policy.

How this policy is organised

  • Part A applies to clinics, practitioners and staff who use the Consentz Application.

  • Part B applies to patients and visitors who use the Directory or submit an enquiry.

  • Part C applies to clinics and practitioners whose professional details are listed in the Directory. Because we build these listings from public sources, Part C is also our notice to those practitioners under Article 14 UK GDPR. Parts B and C together form the Consentz Directory notice.

  • Part D contains general terms that apply to everyone this policy covers.

  • Part E is a supplementary notice for people in the United States.

Our roles at a glance

Processing activity Consentz role Other controller
Clinic account, billing, support, security and service administration Controller Not applicable
Patient information entered into the Application by a clinic Processor, on the clinic's documented instructions The relevant clinic
Directory enquiry collection, validation, routing and lead administration Controller Each recipient clinic becomes a separate controller for its own use after receipt
Professional profiles and visibility scores in the Directory Controller Not applicable

Important

Consentz and each clinic act as separate controllers, each for their own purposes, and are not joint controllers. Where the law requires consent — including explicit consent for health-related Directory enquiries — we ask for it separately at the relevant point. For how a clinic may process your personal data, please read their own privacy policy.

PART A — Clinics, practitioners and staff using the Consentz Application

A1. Scope and roles

This Part applies when you are a clinic, practitioner or staff member and register for, administer or use the Consentz clinical CRM, EHR, consent-management and related workflow services (the "Application").

A2. Information we collect

We may collect the following categories of information about clinic users, practitioners, staff and business contacts:

  • identity, professional and contact details — name, role, job title, qualifications, skills, experience, professional registrations and memberships, practice name, business address, email address and telephone number;

  • account, subscription and commercial information — plan, billing status, invoices and transaction references; our payment providers process full payment-card details unless we expressly state otherwise;

  • communications, support requests, training records, feedback and survey responses;

  • marketing preferences and records of engagement with our communications; and

  • technical, usage and security information — IP address, device and browser details, log-in records, audit logs, features used, referral source and cookie identifiers where permitted.

A3. How we use clinic-user information

We use this information to: provide, administer, secure and support the Application and accounts; process subscriptions and keep financial records; communicate about service changes, incidents, support and training; prevent fraud and unauthorised access; analyse and improve the service; manage relationships, complaints and legal claims; and send relevant B2B marketing where permitted, subject to opt-out.

Purpose Data used Lawful basis
Provide, administer and support the Application Account, contact, configuration and usage data Performance of a contract (Art 6(1)(b))
Take payment and keep financial records Billing and payment data Legal obligation (Art 6(1)(c)) / contract
Secure the service, prevent fraud and improve the product Usage, device and security-log data Legitimate interests (Art 6(1)(f))
B2B marketing to clinic users Business-contact data Legitimate interests (with opt-out); consent where required
Non-essential cookies and consent-based marketing Device and marketing data Consent (Art 6(1)(a)); PECR
Comply with law and handle claims/regulators Relevant records as needed Legal obligation / legitimate interests

We collect this information directly from you, automatically from your use of the Application, and from clinics, payment providers and public professional sources.

A4. How we process Clinic Patient Data

When Consentz processes Clinic Patient Data, it does so only as the clinic's processor, under the clinic's instructions and the data processing agreement in the Terms; this policy does not govern that processing. Consentz does not use Clinic Patient Data to advertise to patients.

A5. Anonymous and aggregated statistics

Where permitted by the clinic agreement, we may create aggregated statistics intended not to identify a patient, practitioner or clinic, and use them to operate, secure, benchmark and improve the services. We do not attempt to re-identify these outputs; where data is only pseudonymised we continue to protect it as personal information.

A6. Marketing

We may send clinic users relevant service and business communications. You can opt out of promotional communications at any time via the unsubscribe link or by emailing support@consentz.com. Operational messages are not marketing. We do not market to patients merely because a clinic has uploaded their details. Where the law requires consent for marketing, we obtain a clear opt-in and you can withdraw it as easily as you gave it.

A7. Retention

  • Account and service records: normally the account term plus up to six years (or longer where the law requires).

  • Invoices, payment and tax records: up to seven years or longer where law requires.

  • Security, access and audit logs: periods appropriate to their purpose and sensitivity.

Full detail is in our Data Retention Policy.

A8. Clinic-user rights

Clinic users may have rights to access, correct, erase, restrict or object to certain processing, and to portability. Requests concerning Clinic Patient Data should be made to the clinic that controls the record. The general information in Part D also applies.

PART B — Patients and visitors using the Directory or submitting an enquiry

B1. Scope and our role

This Part applies when patients and website visitors browse the Consentz clinic directory (the "Directory"), create an account, or submit a request for information, pricing, a consultation or another clinic service (an "Enquiry"). Consentz is the controller of the information it collects for the Directory and Enquiry service. The clinic or practitioner you contact is the separate controller of the information it holds once we pass on your Enquiry (please read their own privacy policy).

Consentz operates a paid introduction service: where you ask to be contacted by a clinic you have chosen, we make your enquiry available to that clinic for a fee. We do not sell your information to multiple clinics or to other third parties. Where a clinic instead receives an enquiry directly through its own Consentz account, that clinic is the controller and Consentz only processes the enquiry on its behalf.

B2. Information we may collect

The exact fields are shown on the relevant form and may include: identity and contact information (name, email, telephone); demographic information (age range, date of birth, sex/gender where clearly requested); location (postcode, town, region, preferred treatment location); Enquiry information (clinic selected, treatment of interest, pricing/consultation request, preferred timing, message content); consent and routing records (choices shown, notice version, time of submission, clinic sent to); communications and records used to administer the Enquiry; and technical/usage information (IP, device, referral source, cookie identifiers where permitted).

We do not currently carry out background or criminal-record checks; if we introduce them we will update this policy first. We do not seek special-category data for our own purposes — please provide only what is relevant to the Enquiry. The Directory is not an emergency service.

B3. How we use Enquiry information

We use it to: collect, validate, administer and transmit the Enquiry; share it with the selected clinic so they can respond; share it with alternative clinics only where you make a separate, clear choice permitting that; communicate about status and outcome; detect fraud and abuse; administer clinic billing and lead disputes; respond to rights requests, complaints and legal obligations; and produce aggregated statistics — never using your health-related Enquiry for unrelated advertising.

An Enquiry may reveal or allow inference of information about your health. For collecting and routing such Enquiries in the UK we rely on your consent under Article 6(1)(a) and, for special-category health data, your explicit consent under Article 9(2)(a). We rely on legitimate interests for limited supporting activities (security, fraud prevention, administration, legal claims, non-intrusive analytics).

We ask for this consent by a clear affirmative action at the point you submit the Enquiry, after telling you who will receive it and why. It is separate from accepting this policy, and you can withdraw it at any time without affecting earlier processing.

B4. Selected clinic and alternative clinics

The form identifies the selected clinic. Your consent to send the Enquiry to that recipient is separate from any optional choice to share it with alternative clinics; refusing alternative sharing will not prevent the selected clinic responding. Where alternative sharing is offered, the form will name the specific additional clinics and let you select them at the point you consent, and we keep a record of the consent wording, time and actual recipients. You may withdraw consent for future sharing at any time.

B5. What happens after a clinic receives the Enquiry

Each recipient clinic becomes a separate controller for its own use of the Enquiry after receipt; its privacy notice applies to its contact with you. Clinics are contractually required to use a lead only for the relevant Enquiry, provide appropriate privacy information, avoid unrelated marketing, protect the information and avoid onward sale. Consentz remains a controller for the copy and records it retains for routing, billing, consent evidence, security and legal purposes.

B6. Commercial arrangements and rankings

A clinic may pay Consentz a subscription, listing fee, introduction fee or lead fee; we do not sell your personal data — the fee is for the introductory service. We disclose paid or sponsored placement where required and do not present payment as evidence of clinical quality. The Directory visibility score is not a clinical-quality, safety or outcomes rating.

B7. Retention

  • Enquiry content and routing records: normally up to 12 months after submission, unless a shorter or longer period is reasonably required for a complaint, security issue or legal claim.

  • Consent, recipient and suppression records: up to six years where reasonably necessary to demonstrate compliance.

  • Financial and lead-billing records: up to seven years.

See our Data Retention Policy for detail.

B8. Your choices and rights

You may withdraw consent for future consent-based processing, ask us not to send the Enquiry to additional clinics, and exercise the rights in Part D and Part E. Where we rely on consent, you can withdraw it as easily as you gave it.

PART C — Clinics and practitioners listed in the Directory (Article 14 notice)

Because we build directory listings from public and published sources rather than from you directly, this Part is also the notice we are required to give you under Article 14 UK GDPR.

C1. Information we hold

Depending on what is available, a listing may include: clinic or trading name; business address; telephone number; email address; social-media handles; professional registrations and accreditations; the services and treatments offered; and a location map where relevant. We also hold profile-completeness and public-web-presence signals used to calculate the visibility score, and any corrections, claims and communications about the listing.

We do not hold photographs, and we do not publish pricing. We do not intentionally publish a practitioner's private home address unless they have used it as a public professional address.

C2. Where we got your information (sources)

We build listings from information that is already publicly available. Our sources fall into these categories:

  • UK regulatory and accreditation registers, including the CQC, JCCP, GMC, Save Face, Healthcare Improvement Scotland (HIS), Healthcare Inspectorate Wales (HIW) and RQIA;

  • practitioners' and clinics' own websites;

  • publicly available business listings, including Google Business listings; and

  • published industry and awards lists, including the Tatler aesthetics list, the Aesthetics Awards and the CCR Awards.

We compile this using a combination of automated tools and manual research. Where a listing is built from more than one source we may hold it as a single combined profile. Using a public source does not remove our transparency or accuracy obligations.

C3. What we use it for, and our lawful basis

We use listing information only to:

  1. create and publish a directory listing so the public can find practitioners and clinics;

  2. generate a visibility score for the listing;

  3. contact you to invite you to claim, correct or update your profile; and

  4. offer and pass patient enquiries ("leads") to you about your own listing.

Our lawful basis for 1–3 is legitimate interests — our interest in operating a directory that helps patients find and contact qualified practitioners, which cannot be achieved without identifying and listing them. We have carried out a legitimate interests assessment balancing this against your rights. Where you have claimed your profile and we provide lead services, we rely on our contract with you and, where relevant, your consent.

We do not sell or share your profile data with any third party. The only enquiries we pass on are to the practitioner or clinic the enquiry is about.

Purpose Data used Lawful basis
Create and publish listings from public sources Name/clinic, address, contact details, registrations, services Legitimate interests
Generate the visibility score Public profile signals (accreditations, website, completeness) Legitimate interests
Contact you to claim or correct a profile Name, business contact details Legitimate interests
Provide lead services to a claimed practitioner Account data; enquiry data Contract; consent

C4. Visibility scores and profiling

The visibility score is our assessment of objective, factual signals — such as whether you hold recognised accreditations, whether you have a website and business listing, the quality of your online discoverability, whether pricing and location are shown, and how complete your public information is. It is not an assessment of medical competence, patient safety, treatment suitability, clinical outcomes or regulatory endorsement. Scores fall within a banded range and are not a negative ranking of individuals.

The score is not made solely by automated means — a member of our team reviews scoring before it is relied upon, so it does not produce legal or similarly significant effects on you. If you believe your score is wrong or unfair, you can ask us to review it at privacy@consentz.com and we will genuinely look into it. You may also object to this processing.

C5. Claiming your profile

If we contact you, you can claim your profile by following the link we send, verifying your identity and that you are the owner, and creating an account. Once claimed, you can edit or remove your listing content and access patient enquiries about your listing (pay-per-lead or by subscription). When you claim, we become the controller of the account information you give us; we remain a controller of the directory listing and score while your listing appears.

C6. Your control, objection and removal

You control whether you appear in the Directory:

  • You can remove your listing entirely at any time — yourself once you have claimed it, or by emailing privacy@consentz.com.

  • To protect against misuse, where you ask us to remove or change a listing you have not claimed, we may first take a light step to confirm you are the person the listing is about, so a competitor or third party cannot make a request about your data without authority.

  • When a listing is removed, we retain only a minimal suppression record needed to ensure we do not list you again, unless the law requires us to keep more.

We will action reasonable objection, correction and erasure requests promptly.

C7. Disclosure and retention

Listings are displayed publicly and may be indexed by search engines. We disclose data to service providers supporting hosting, communications, security and analytics (see Part D1). We keep listings while they remain relevant, and after removal keep only the minimal suppression record described above. See our Data Retention Policy.

PART D — General terms applying across the services

D1. Service providers and other recipients

We use vetted providers, each bound by written confidentiality and data-protection terms and permitted to process information only for the contracted service. These include Amazon Web Services and DigitalOcean for cloud hosting (UK regions), and Twilio and Plevo for email/SMS communications, together with providers for analytics, error monitoring, payment processing and support. A current list naming each processor is available on request. We remain responsible for our processors.

We may also disclose information where reasonably necessary to comply with law, protect people, investigate fraud, enforce agreements, defend legal claims, or support a corporate transaction.

D2. International transfers

SmartMatter LLC is based in the United States, and some access to personal data takes place from outside the UK by our own personnel. Our primary hosting is in the UK, so personal data is not routinely stored outside the UK. Where a restricted transfer to the US does occur, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. SmartMatter LLC is also in the process of self-certifying under the UK Extension to the EU–US Data Privacy Framework; we will update this policy to rely on that framework once certification is finalised. We carry out transfer assessments where required and apply supplementary measures appropriate to the risk.

D3. Security

We use technical and organisational measures maintained under our information security policy (we are ISO 27001 certified and independently audited each year), including role-based access, authentication, encryption in transit, logging, backups, vulnerability management, staff controls and incident-response procedures. No system can eliminate all risk, but we review and improve our safeguards as the services develop.

D4. Cookies and similar technologies

We use strictly-necessary technologies for security, authentication, session management and requested functions. We use analytics, advertising or other non-essential cookies only after obtaining consent. Continuing to browse is not treated as consent; non-essential cookies are off by default and set only if you opt in, and you can reject or withdraw them as easily as you accept them. Full detail — cookie names, providers, purposes and durations — is in the Cookie Notice at Annex A.

D5. Direct marketing

We do not use personal data for direct marketing you have not opted in to receive, and you may opt out at any time. We may keep a limited record to respect your opt-out.

D6. Children

The Directory and Enquiry services are for adults aged 18 or over, and Consentz does not knowingly create Directory accounts or profiles for children. Before submitting an Enquiry you must confirm you are 18 or over, or that you are the parent or legal guardian of the person named and are authorised to provide the information. This is not clinical consent on behalf of a minor.

D7. Your data-protection rights

Depending on the law and circumstances, you may have rights to: be informed and access your information; correct it; request erasure or restriction; object to legitimate-interests processing or to direct marketing; receive certain information in a portable format; withdraw consent where processing relies on it; and complain to a regulator.

To exercise a right or make a data-protection complaint, email privacy@consentz.com. We may need information to verify your identity. We respond to a data-subject request without undue delay and within one month (extendable for complex requests, which we will tell you about). We handle complaints under our Data Protection Complaints Policy at Annex B.

UK individuals may also complain to the Information Commissioner's Office (ico.org.uk; helpline 0303 123 1113; Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF). We ask that you contact us first so we can try to put things right.

D8. Changes to this policy

We may update this policy to reflect service, legal or operational changes. We will post the updated version and change the date above. Where a change materially affects an existing use or consent choice, we will provide additional notice and seek consent only where the law requires it.

D9. Contact

SmartMatter LLC (Consentz)

30 N Gould St, Suite R, Sheridan, Wyoming 82801, United States

Email: privacy@consentz.com

ICO registration: ZB678435 — ico.org.uk

UK representative: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom

PART E — United States supplementary notice

*This Part concerns US state privacy laws and has not been reviewed by UK counsel. Have it checked by qualified US privacy counsel before relying on it.*

E1. Scope

This Part supplements the policy for people in the United States and applies in addition to Parts A–D where US state law applies.

E2. Categories, sources and purposes

The categories of personal information we collect, the sources, and the purposes are described in Parts A–D. We collect identifiers, contact and demographic data, commercial and payment data, internet/usage data, and, for Directory enquiries, health-related information you provide.

E3. US Consumer Health Data Notice

Where US consumer-health-data laws apply, we collect health-related enquiry data directly from the consumer and use it to provide, route and administer the requested Enquiry, communicate about it, prevent fraud, maintain consent and disclosure records, secure the service and comply with law. We share it with the selected clinic and processors that support the service. Where applicable law requires affirmative consent to collect or a separate consent to share consumer health data, we obtain it first. We do not use geofencing around healthcare facilities.

E4. Compensated introductions, sale and advertising

We do not sell Clinic Patient Data or Directory Enquiry information to data brokers or use it for unrelated cross-context behavioural advertising. A recipient clinic may pay Consentz for an introduction, subscription or lead. Some state laws may classify a compensated disclosure as a "sale" even where the consumer requested it; where such a law applies we provide the required notice, consent, authorisation or opt-out before the disclosure.

E5. US privacy rights

Subject to applicable law, US residents may have rights to confirm, access, correct, delete, obtain a portable copy, withdraw consent, opt out of sale/targeted advertising/certain profiling, and appeal a refusal. Submit a request to privacy@consentz.com stating "US Privacy Request" and your state of residence. We recognise valid universal opt-out signals, including Global Privacy Control, where required.

E6. HIPAA and California medical-information law

HIPAA applies based on the parties, relationship and context. Directory Enquiries collected by Consentz independently may fall outside HIPAA. Where Consentz processes protected health information on behalf of a HIPAA-covered clinic as its Business Associate, the applicable Business Associate Agreement and HIPAA govern that processing.

E7. Security and breach notification

We maintain safeguards and incident-response procedures for sensitive information and provide breach notices where required by applicable law.

E8. California notice at collection

For California residents, the categories collected, sources, purposes, retention approach and categories of recipients are described in Parts A–E. Where the CCPA applies, California residents may exercise the rights in E5.

Annex A — Cookie Notice

This Notice forms part of this policy (Part D4). Strictly-necessary cookies are always on. Non-essential cookies are off by default and set only if you opt in; you can change your choices at any time using our cookie controls.

Cookie / technology Provider Purpose Type Duration
Session / sign-in Consentz Keep you signed in; security Strictly necessary Session
Security token (CSRF) Consentz Prevent cross-site request forgery Strictly necessary Session
Load balancing AWS / DigitalOcean Route requests; availability Strictly necessary Session
[analytics — to confirm] [provider — to confirm] Understand usage Non-essential (opt-in) [to confirm]
[error monitoring — to confirm] [provider — to confirm] Diagnose faults Non-essential (opt-in) [to confirm]
[chat/support — to confirm] [provider — to confirm] Enquiry chat Functional (opt-in) [to confirm]

*Entries marked [to confirm] to be completed from the live cookie scan / your Complianz export.*

Annex B — Data Protection Complaints Policy

1. Purpose. This policy explains how to make a complaint about how Consentz handles personal data, and how we deal with it. It applies to anyone whose personal data we hold — practitioners and clinics listed in our directory, practitioners and staff who use our software, and members of the public who make enquiries.

2. What it covers. It covers our handling of personal data — how we collected it, use it, share it, or a request to correct, object to, or delete it. It does not cover: the medical treatment, advice or care provided by any clinic or practitioner (Consentz is a technology platform, not a healthcare provider, gives no medical advice, and is not responsible for the treatment, conduct or outcomes of any clinic or practitioner); a clinic's own handling of a patient's data once we have passed an enquiry to them (from that point they are the independent controller); or general service or billing complaints, which go to care@consentz.com.

3. How to complain. Email privacy@consentz.com with your name and contact details, what your complaint is about, and what you would like us to do. No special form or wording is needed.

4. Verifying identity. To protect people's data, we may ask you to confirm your identity before we act — particularly for correction or deletion — so that no one can make a request about another person's data without authority. We keep this as light as possible.

5. How we handle it. We aim to acknowledge within 5 working days and respond fully within 30 calendar days; if a complaint is complex and we need longer, we will tell you why. Data requests (access, correction, objection, deletion) are handled within the timescales required by law, normally within one month.

6. If you are not satisfied. We ask that you contact us first so we can put things right. You may complain to the UK Information Commissioner's Office at any time: ico.org.uk/make-a-complaint/; helpline 0303 123 1113.

7. Records. We keep a record of complaints and outcomes to meet our accountability obligations and improve how we handle personal data, kept only as long as necessary.

Annex C — Data Retention Policy

We keep personal data only for as long as we need it for the purpose we collected it, or as long as the law requires.

Type of data How long we keep it Why
Directory listings While the listing is active To run the directory
Suppression record (after a listing is deleted) Ongoing (identifier only) To ensure we do not re-list someone who asked to be removed
Claimed account data (name, email, phone, clinic, credentials) Account duration + 6 years Manage the account; defend legal claims; limitation period
Billing / payment records Up to 7 years Legal / accounting obligations
Patient enquiry content and routing records Up to 12 months Deal with the enquiry, complaints, security
Consent, recipient and suppression records Up to 6 years Demonstrate choices, disclosures and compliance
Support and communications 2 years Handle and review support issues
Security and access logs 12 months Security and fraud prevention
Complaints records As long as necessary (guide: 6 years) Accountability
Cookies / analytics Per the durations in Annex A Per each cookie's stated duration
Marketing consents Until withdrawn + a short record thereafter Prove consent; honour withdrawal

Where a patient enquiry is passed to a clinic, the clinic becomes the independent controller of its copy and sets its own retention. When a period ends, we securely delete or anonymise the data, unless the law requires us to keep it or we need it to establish, exercise or defend legal claims. We review this approach at least annually.

Scroll to Top
Schedule a Demo

Schedule a Demo and we'll onboard and set up your clinic for FREE