Iris ClinicalBack to home

Legal

Privacy Notice

Last updated: July 2026 · ICO Registration: C1962125

Who we are

Iris Clinical is an AI-powered clinical workspace for UK optometrists, developed by Iris Clinical Ltd (ICO Registration: C1962125). For any privacy enquiries, email privacy@irisclinical.co.uk.

What data we collect

Account information

Name, email address, optional practice name and GOC registration number. Password stored as a secure hash — we never see it.

Usage data

Features used and when, anonymised query data (questions asked, stripped of patient identifiers), referral letters generated, subscription status.

Technical data

Browser type, IP address (security only), essential cookies only.

We do not collect

Patient-identifiable information, special-category health data, or financial information beyond Stripe processing.

How we use your data

  • Contract: Providing the service to you.
  • Contract: Sending service emails (account, billing, security).
  • Legitimate interests: Improving AI responses and the quality of the product.
  • Legitimate interests: Keeping the service secure and preventing abuse.
  • Legal obligation: Meeting UK tax, accounting, and regulatory obligations.

We do not use your data for advertising. We do not sell data.

Who we share data with

SubprocessorRoleLocation
SupabaseDatabase and authenticationEU (Sweden)
StripePayment processingUSA — Standard Contractual Clauses (SCCs) apply
ResendTransactional email deliveryEU
Google GeminiAI inferenceUSA — Standard Contractual Clauses (SCCs) apply

Data retention

Account data
Until deletion + 30 days
Referral letters
Until deleted by user
Usage logs
24 months, then permanently anonymised
Billing records
7 years (legal requirement)

User-controlled chat retention. You can set your Iris chat history to auto-delete after 30 days, 90 days, or keep it forever, from Settings → Chat retention. When you shorten the window, older chats and their messages are permanently removed from our live systems within 24 hours by an automated daily job. Referral letters are explicitly excluded from this auto-deletion — they form your clinical audit trail and can only be removed by you, manually. Note that platform backups continue to expire on their own cycle independent of this setting.

Your rights

Under UK GDPR you have the right to access, correct, delete, restrict, object to, and port your personal data. To exercise any of these rights, email privacy@irisclinical.co.uk. We will respond within 30 days.

If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

We use strictly necessary cookies and local storage to keep you signed in and remember essential preferences. With your consent, we also use privacy-friendly product analytics (see below). We do not use advertising or third-party advertising cookies. You can decline analytics at any time via the "Necessary only" option on the cookie banner.

Analytics

With your consent, we use privacy-friendly, EU-hosted product analytics (PostHog, hosted in the EU) to understand how the app is used — for example, which features are opened, whether sign-up completed, and whether a referral letter was generated — so we can improve Iris Clinical.

We never send patient-identifiable data, clinical free-text, chat message content, or the contents of referral letters to our analytics provider. We do not run advertising and do not share analytics data with advertisers.

Analytics is off by default. It only turns on if you click "Accept analytics" on the cookie banner. Choosing "Necessary only" — or ignoring the banner — keeps analytics disabled. You can change your mind at any time by clearing your browser storage for this site and re-choosing on the banner.