Legal
Privacy Policy
What personal data iPCN collects, why, how long it's kept, and who it's shared with.
Last updated: 26 August 2026. See also our Terms of Service and the Legal hub for our Data Processing and Data Sharing Agreements.
1. Who we are
Data controller / data processor
iPCN is operated by Alomco Ltd, registered in England and Wales (company number 11746274, registered office 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom).
For most data processed through iPCN, your organisation (the GP practice or PCN using iPCN) is the data controller, and Alomco Ltd acts as a data processoron your organisation's behalf — the same controller/processor relationship Alomco's sister product PCND (pcnd.info) uses. Where iPCN determines the purpose and means of processing itself (for example, account security, billing, and service-improvement analytics), Alomco Ltd acts as controller for that specific processing.
2. What we collect
Personal data processed through iPCN
Depending on which modules your organisation uses, iPCN may process:
- Staff records: name, work email, role, employment dates, contracted hours.
- Leave & rota data: annual leave, sickness/absence records, shift assignments.
- Compliance & training records: mandatory training completion, DBS/safeguarding check status and expiry dates, policy sign-off records.
- Appraisal records: self-reflection entries, 360°/multi-source feedback, meeting outcomes and tracked actions.
- Recruitment data: vacancy details and candidate applications (for organisations using iPCN Recruitment).
- eSign / document data: documents sent for signature, signatory name/email, signing IP address, timestamp, and audit trail.
- Account & usage data: login email, session activity, and (if you use Alom AI) your chat messages and the practice/user context needed to answer them.
- Billing data (paid modules only): handled directly by Stripe, our payment processor — iPCN does not store card numbers. We hold your Stripe customer reference and subscription status.
We do not knowingly process patient data through iPCN — iPCN is a staff/practice-operations platform, not a clinical system.
3. Why we process it
Our legal basis
- Contract performance (UK GDPR Art. 6(1)(b)) — to provide the service your organisation has signed up for: staff records, leave, rota, training, etc.
- Legitimate interests (Art. 6(1)(f)) — to keep the platform secure, maintain audit trails, and improve the product. Where we rely on this basis, we've considered that our interest doesn't override your rights.
- Legal obligation (Art. 6(1)(c)) — some records your organisation keeps in iPCN (e.g. mandatory training, DBS checks) exist because your organisation is itself under a separate legal/regulatory obligation to keep them; iPCN processes this data as your processor, on your instruction.
4. How long we keep it
Retention
Account and operational data is retained for the duration of your organisation's active subscription, plus a short grace period after cancellation to allow data export and account recovery.
If a free or discounted period lapses without action (see our Terms of Service, section 5, for the advance-notice schedule), your account is locked, not deleted: we retain your organisation's data for a grace period so you can pick up where you left off if you come back.
e-Signature audit trails (signatory name, email, IP address, timestamp) are kept for the lifetime of your organisation's subscription plus 7 years, in line with the evidential purpose they serve — the same retention period our sister product PCND applies to its own signature/audit data.
Some records your organisation keeps in iPCN (mandatory training evidence, DBS/safeguarding checks, appraisal history) may be subject to NHS records-management retention schedules that are longer than iPCN's own default. iPCN does not itself track or enforce these NHS-specific schedules — your organisation's own retention policy governs how long these records should be kept, and you can export or delete them accordingly.
On request, or on account deletion, we delete or anonymise personal data within a reasonable period, except where we're required to retain it (e.g. billing records for tax purposes, or signed-document audit trails as above).
5. Who we share it with
Sub-processors and third parties
We never sell personal data. We share data only with the processors needed to run the service:
| Processor | Purpose | Location |
|---|---|---|
| Neon (Neon Tech Inc.) | Database hosting | AWS eu-west-2 (London, UK) |
| Application server host | Hosts the iPCN application | Hostinger International Ltd, EU data centre |
| Stripe, Inc. | Payment processing for paid subscriptions | Global (US-based) — transfers safeguarded via the UK International Data Transfer Addendum, EU Standard Contractual Clauses, and the EU-U.S. Data Privacy Framework |
| Anthropic PBC | Alom AI assistant (chat-based help) | US — see section 6 below on what's sent |
| Microsoft 365 | Email delivery (e.g. notifications, admin@ipcn.info mailbox) | EU/UK Microsoft data centres |
6. International transfers
Where your data is processed
iPCN's primary infrastructure (database, application) is hosted in the UK/EU. Where a processor is based outside the UK/EEA (Anthropic, Stripe), we rely on the appropriate safeguard (standard contractual clauses or an adequacy decision) and, for Anthropic specifically, aim to limit what's sent to what's necessary to answer your question — your practice/user context and chat messages, not your organisation's full underlying records.
7. Multi-tenant isolation
How your organisation's data is kept separate
iPCN is a multi-tenant platform: every organisation's data is logically isolated. Application-level access controls scope every query to your organisation, and administrative access to cross-tenant data is restricted to platform administrators, with all such access logged.
8. Security
How we protect your data
- Encryption in transit (TLS) on all connections between your browser, the application, and the database.
- Encryption at rest for the database (AES-256, via our database host's infrastructure).
- Role-based access control — access to staff, compliance, and HR data is scoped to a member's role within their own organisation.
- Audit logging — sensitive actions (removing a team member, deleting a leave record, archiving an organisation) are logged with who did it and when, and are reviewable/reversible by a platform administrator.
- Daily encrypted database backups, retained on a rolling basis, stored off-site.
9. Cookies
What cookies we use
We use a small number of functional cookies — no third-party advertising or tracking cookies. Strictly necessary cookies are always on; everything else only runs if you accept the cookie banner shown on your first visit.
Strictly necessary (no consent required):
ipcn_session— keeps you signed in.ipcn_active_practice— remembers which organisation you're currently viewing, if you belong to more than one.ipcn_consent— remembers your cookie-banner choice, so we don't ask again on every visit.
Only set if you accept:
ipcn_attr— a first-touch record of how you found iPCN (e.g. which link or campaign), used only to understand what's working — never sold or shared with advertisers. You can withdraw consent at any time by clearing your cookies; we'll ask again on your next visit.
10. Your rights
Data subject rights under UK GDPR
You have the right to access, correct, or request erasure of your personal data, to object to or restrict certain processing, and to data portability. If your organisation is the data controller for your records (most cases — see section 1), please contact your organisation first; they can also ask us to act on your behalf. You can also contact us directly at admin@ipcn.info.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. Alomco Ltd's own ICO registration number is ZA571069.
11. Changes
Changes to this policy
We may update this policy from time to time. Material changes will be notified to organisation administrators by email or in-app notice before they take effect.
12. Contact
Questions about this policy
Email admin@ipcn.info for any question about how iPCN handles personal data.