Privacy policy

Last updated: 23 September 2026 · Draft pending legal review

Who we are

InvoicingPortal is operated by [Company legal name], [registered address], company number [number] ("we", "us"). We are the data controller for the personal data described here. ICO registration number: [ICO number].

Questions or requests: [privacy contact email].

What we collect

Please don't store patient or service-user identifiable information in the portal. It is designed for your own business records.

Why we use it, and our lawful basis

We don't sell your data, and we don't use it for advertising.

Who can see it

Your workspace is private to your account. Other users can't see it. We use these service providers to run InvoicingPortal:

Cookies

We use one strictly necessary cookie, lpp_session, to keep you signed in. It lasts up to 30 days or until you sign out. We don't use analytics or advertising cookies, so we don't ask for cookie consent.

How long we keep it

We keep your account and workspace while your account is open, including after your free period or plan ends, so you can come back to it. If you ask us to delete your account, we delete your data within 30 days, and it is removed from our backups within a further 7 days. Server logs are kept only as long as needed for security and troubleshooting.

Your rights

Under UK data protection law you can ask to access, correct, delete or receive a copy of your data, and to object to or restrict how we use it. Contact [privacy contact email]. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk.

Security

Passwords are hashed, sign-in sessions use secure cookies, repeated sign-in attempts are limited, and data is backed up daily. No system is perfectly secure, so please use a strong password that you don't use elsewhere.

Changes

If we change this policy in a meaningful way, we'll tell you by email or in the portal before the change takes effect.