Privacy Policy
Last updated 2 August 2026 · Dr. Ordo
Dr. Ordo holds account data about practice staff, and processes patient records — including health data — on behalf of the practices that use it. The practice is the controller of its patients' data; Dr. Ordo acts only on its instructions and never uses patient data for anything else.
1. Who this covers, and who is responsible
This policy covers drordo.com and the Dr. Ordo application behind sign-in. Two roles matter. For the account data of practice staff and of visitors to the site, Dr. Ordo is the controller. For patient records entered by a practice — appointments, notes, billing — the practice is the controller and Dr. Ordo is its processor, acting only on its instructions.
2. What is collected
Staff account data. Email address, name, role within the practice, and the authentication records created at sign-in. Passwords are handled by the sign-in provider and are never stored by Dr. Ordo.
Billing data for the subscription. The payment processor handles payment and returns a subscription identifier and status; card numbers never reach Dr. Ordo.
Patient records, entered by the practice. These can include identity and contact details, appointment history, clinical notes and billing records — health data, which the law treats as a special category.
Access logs. Who in the practice viewed or changed which record, and when — kept because accountability over health data requires it.
3. How patient data is treated
Patient data is processed only to provide the service to the practice that entered it. It is not used to train models, not used for analytics across practices, not shared with advertisers, and not sold. Staff of one practice can never see another practice's records.
Access within Dr. Ordo's own operations is restricted to what is strictly needed to run and support the service, and is logged.
4. Legal bases
Staff account and billing data are processed to perform the contract with the practice and to meet accounting obligations. Patient data is processed on the practice's documented instructions; the practice is responsible for its own lawful basis, which for health data typically rests on the provision of care.
5. Retention
Patient records are retained for as long as the practice instructs, because medical record-keeping periods are set by the law and the professional rules that bind the practice, not by Dr. Ordo. When a practice ends its subscription it can export its records; after the stated export window they are deleted. Staff accounts are deleted when the practice removes them. Billing records are kept as long as tax law requires.
6. Processors and security
A sign-in provider handles authentication, a payment processor handles subscriptions, a transactional email provider delivers account email, and infrastructure providers host the service and its encrypted backups. Each processes data only on instruction. Data is encrypted in transit and at rest.
7. Your rights
Practice staff can ask Dr. Ordo for access to their own account data, for correction, for erasure, for restriction, and for a portable copy, under the UK GDPR and the EU GDPR. Requests are answered within one month, and you can complain to a supervisory authority.
Patients should address requests about their records to their practice, which is the controller; Dr. Ordo assists the practice in answering them, as a processor must.
8. Contact
Privacy questions and data requests go via the support page at /support.