Last updated: 29 July 2026
Medipay UK ("Medipay", "we", "us") provides a payments platform for healthcare practices in the United Kingdom. This policy explains what personal data we handle, why, and the rights you have. It covers our merchant portal at portal.medipayuk.co.uk, our payment pages, and messages we send on behalf of practices.
For practice staff accounts and platform operations, Medipay is the data controller. For patient details that a practice stores or sends through Medipay (such as a name, email address, phone number or payment reference), the practice is the controller and Medipay processes that data on the practice's instructions.
We never see or store full card numbers. Card details are entered directly into secure fields hosted by our PCI DSS certified payment gateway; they do not pass through or rest on Medipay systems.
Legal bases under UK GDPR: performance of a contract, legitimate interests in running a secure payments service, and legal obligation for financial records. We do not sell personal data and we do not use it for advertising.
Only with providers needed to run the service: our payment gateway and the practice's acquiring bank to process payments; a hosting provider and a database provider (data held in the UK and EU); an email delivery provider and an SMS provider for messages; and, where a practice connects its own accounting software such as Xero, Sage or QuickBooks, that provider on the practice's instruction. Each processes data under contract and only for these purposes.
The optional support chat in the portal is powered by an AI assistant provider (Anthropic). Support conversations are processed only to answer your query and route it to our team; they are not used to train AI models, and the assistant has no access to payment card data or to any connected accounting software.
Financial transaction records are kept for the retention period UK law requires (typically six to seven years). When a practice erases a patient, contact details are anonymised immediately and only the anonymised financial record remains.
You can ask for access to your data, correction, erasure, restriction or portability. Patients can ask their practice, which can export or erase patient data directly in Medipay; you can also contact us and we will help. You can complain to the Information Commissioner's Office (ico.org.uk) at any time.
All connections are encrypted in transit. Access to data is limited by role and workspace, every table is protected by row level security, and administrative actions are recorded in an audit log.
Medipay UK, email: engineering@medipayuk.co.uk. If this policy changes, the date above changes with it.