Security & GDPR
Is my clients' data safe with The Practitioner Portal?
Yes — and here is exactly how, in plain language. Clinical notes are encrypted, every access to a record is logged, staff see only what their role allows, GDPR subject-access and erasure workflows are built into the product, and no generative AI reads your notes inside the platform.
Last updated 10 July 2026
How are clinical notes protected?
Notes are encrypted in the database — not just hidden behind a login. When a note is opened, that access is recorded: who, when, and which record. The audit trail exists so that "who saw this?" always has an answer.
Who in my practice can see what?
Access follows roles. Practitioners see their own caseload. Reception staff can run the diary, assign homework and manage bookings without any route into clinical notes — the interface doesn't merely hide them, the server refuses to serve them.
How does the portal handle GDPR?
Two GDPR rights need real machinery, not policy documents: the right of access and the right to erasure. The portal ships both as workflows — a subject-access request produces a structured export of a client's data, and erasure runs as a supervised cascade across every table a client touches.
Does AI read my notes?
No. There is no generative AI inside the platform — nothing summarises, rewrites or "learns from" your clinical notes. Some practices choose to connect optional external services (like the independent TheraScript documentation assistant); anything sent to such a service is de-identified first, and the connection is opt-in per practice.
What about client consent?
Consent is recorded per client and checked where it matters — surveys, shared resources and any optional data connections respect what the client has actually agreed to.
What we don't claim
You'll notice this page has no wall of certification badges. We'd rather tell you precisely what the product does than decorate. If your professional body or insurer needs specific answers for a data-protection assessment, ask us — you'll get direct answers from the people who built it.
Common questions
Can I get all of a client's data out for a subject-access request?
Yes — the DSAR export workflow produces a structured export of everything held about that client.
Can receptionists read session notes?
No. Reception roles have no access to clinical notes — enforced on the server, not just hidden in the interface.
Is my data used to train AI?
No. There is no generative AI in the platform, and your clinical data is not used to train anything.
Privacy that's built in, not bolted on.
Free for your first thirty days when we open. Your data stays yours, always.