Privacy policy
Last updated 8 October 2026.
Doxtor is a healthcare software platform operated by ASAI CAPITAL LTD.
ASAI CAPITAL LTD is a company registered in England and Wales under company number 15585773, with its registered office at:
13 Whitchurch Lane
Edgware
England
HA8 6JZ
For privacy and data protection enquiries, contact:
This Privacy Policy explains how Doxtor handles personal information when you use the Doxtor website, application, patient portal or related services.
Because Doxtor is software used by clinics, an important distinction applies: the clinic that provides healthcare services to you is generally responsible for deciding why and how your clinical information is processed. Doxtor processes that information on the clinic’s behalf.
1. Who is responsible for your information?
The organisation responsible for your information depends on the processing activity.
Clinic patient information
Where a clinic uses Doxtor to manage your patient information, including:
- your personal details;
- orders;
- laboratory results;
- reports;
- sample and testing information;
- patient portal information;
- communications sent on behalf of the clinic; and
- related clinical records,
the clinic is generally the data controller.
Doxtor acts as the clinic’s data processor, processing that information according to the clinic’s instructions and the applicable Data Processing Agreement.
If you have a question about why your clinic collected your information, why a particular test was ordered, how your clinical information is used, or a clinical decision made about you, you should normally contact the clinic first.
Doxtor’s own processing
ASAI CAPITAL LTD may act as an independent data controller where it processes information for its own purposes, including:
- operating and securing the Doxtor service;
- security monitoring and audit logging;
- fraud prevention;
- managing clinic accounts;
- billing and payments;
- legal and regulatory compliance;
- managing its own staff and authorised users;
- handling support and service-management matters; and
- maintaining records necessary to operate and protect the service.
2. Information we process
Depending on how you interact with Doxtor, we may process different categories of personal information.
Information relating to clinic users
This may include:
- name;
- email address;
- telephone number;
- account and authentication information;
- organisation and role information;
- login and session information;
- communications with Doxtor;
- billing and account information; and
- security and audit information.
Patient information processed for clinics
Where a clinic uses Doxtor, information may include:
- name;
- date of birth;
- sex at birth;
- email address;
- telephone number;
- patient portal information;
- orders and test information;
- laboratory results;
- reports and report versions;
- sample and laboratory information;
- appointment or booking information;
- messages and communications;
- information about access to the patient’s record; and
- AI-generated explanations associated with reports.
Some of this information may constitute special category data, including health information.
Doxtor processes this information for the clinic and does not use it for unrelated purposes of its own.
3. How we use information
When Doxtor acts as a processor
For patient information processed on behalf of a clinic, Doxtor uses information to provide the services instructed by the clinic, including:
- creating and managing orders;
- managing patient records;
- managing sample and laboratory workflows;
- receiving and displaying laboratory results;
- producing reports;
- providing patient portal functionality;
- sending communications on behalf of the clinic;
- providing support to the clinic;
- maintaining security and audit records;
- carrying out authorised data exports and erasure requests; and
- providing other functionality included in the clinic’s Doxtor service.
The clinic determines the purposes for which patient information is processed and the applicable lawful bases.
When Doxtor acts as a controller
Doxtor may process information for its own purposes where necessary to:
- create and administer accounts;
- provide and manage subscriptions;
- process clinic billing;
- maintain service security;
- investigate suspected misuse or security incidents;
- maintain audit and access records;
- comply with legal obligations;
- prevent fraud;
- communicate with clinic customers about the service; and
- operate and improve the reliability of the platform.
4. Our legal bases
Where Doxtor acts as a controller, we rely on appropriate legal bases under applicable data protection law.
Depending on the circumstances, these may include:
- Performance of a contract: where processing is necessary to provide our services or manage our contractual relationship with a clinic or user.
- Legal obligation: where we need to process information to comply with applicable law.
- Legitimate interests: where processing is necessary for purposes such as service security, fraud prevention, service management, business administration and protecting our systems, provided those interests are not overridden by the individual’s rights.
- Consent: where we rely on consent and applicable law requires it.
Where Doxtor acts as a processor for a clinic, the clinic is responsible for determining and documenting the appropriate lawful basis for its processing of patient information.
5. Laboratory information
Doxtor connects clinic workflows with laboratory services.
Where laboratory information is exchanged through Doxtor, the laboratory may be a separate controller or processor depending on the particular processing arrangement.
Doxtor may transmit information required for laboratory testing, including information such as:
- patient name;
- date of birth;
- sex at birth;
- tests ordered; and
- information necessary to identify and process an order.
Laboratory results are returned to Doxtor and made available within the clinic’s workflow.
Doxtor does not itself perform laboratory testing.
6. AI-assisted explanations
Doxtor may provide AI-assisted explanations associated with laboratory results.
The information supplied for an AI explanation is limited to:
- age;
- sex at birth; and
- laboratory results.
Names, dates of birth and direct identifiers are not included in the information sent for the AI explanation.
AI explanations are provided for informational and decision-support purposes only.
They are not a diagnosis, medical opinion or substitute for professional clinical judgement.
The clinic and its appropriately qualified healthcare professionals remain responsible for reviewing results, interpreting them in the appropriate clinical context and deciding what action should be taken.
AI explanations are stored with the relevant report and are included in applicable patient data exports.
7. Automated decision-making
Doxtor does not make decisions about patients that are intended to have legal or similarly significant effects on them solely through automated processing.
AI-assisted explanations are not intended to make clinical decisions automatically.
A healthcare professional remains responsible for reviewing information and making appropriate clinical decisions.
8. Who receives information?
Depending on the service being used, personal information may be shared with or processed by:
Your clinic
Your clinic receives and controls the patient information processed through its Doxtor account.
Laboratory providers
Information necessary to fulfil laboratory orders may be provided to the relevant laboratory.
Technology and service providers
Doxtor uses trusted third-party providers to help us operate the platform and deliver its services.
These providers may support:
- cloud infrastructure and secure data storage;
- application infrastructure;
- email delivery;
- text messaging;
- payment processing;
- laboratory integrations;
- AI-assisted functionality;
- security and monitoring; and
- other essential technology services.
Where a third party processes personal information on our behalf, we put appropriate contractual and data protection arrangements in place.
We maintain records of relevant processors and sub-processors as part of our data protection arrangements and may provide further information to clinic customers where appropriate.
Professional advisers and authorities
We may disclose information where reasonably necessary to:
- comply with a legal obligation;
- respond to a lawful request from a competent authority;
- establish, exercise or defend legal claims;
- prevent fraud or serious misuse; or
- protect the rights, safety and security of Doxtor, our customers or other individuals.
9. International transfers
Some of the third parties supporting Doxtor may process personal information outside the United Kingdom.
Where applicable data protection law treats this as a restricted international transfer, we use an appropriate lawful transfer mechanism and safeguards.
These may include:
- a UK adequacy regulation;
- appropriate contractual safeguards;
- an applicable international data transfer agreement or addendum; or
- another lawful mechanism recognised under applicable data protection law.
We assess relevant international transfers and the safeguards applicable to them.
10. Where information is stored
Doxtor is designed so that clinic and patient information is stored within appropriate UK or European infrastructure where applicable to the relevant service.
We use established cloud and technology providers to host, secure, store and deliver the Services.
We do not publish our detailed internal infrastructure architecture in this Privacy Policy. Information about relevant processors and sub-processors may be made available to clinic customers through our contractual and data protection documentation.
11. How we protect information
Doxtor uses technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.
These include controls around:
- authentication and access management;
- role-based permissions;
- clinic-level data isolation;
- encryption in transit;
- audit logging;
- access logging;
- restricted access to sensitive laboratory information;
- controlled data exports;
- controlled erasure workflows;
- backup and recovery procedures;
- security monitoring; and
- infrastructure-level security controls.
Access to sensitive information is restricted according to role and operational need.
Where particularly sensitive laboratory information needs to be accessed for an authorised operational purpose, additional controls may apply, including re-authentication and recording the reason for access.
No internet-based service can guarantee absolute security, but we continually review and improve our technical and organisational safeguards.
12. Retention
We retain information only for as long as necessary for the relevant purpose and according to applicable legal, contractual, clinical and regulatory requirements.
For patient information processed on behalf of a clinic, the clinic’s applicable retention period may be longer than Doxtor’s operational default. Where a clinic has established a longer retention period under its obligations, that longer period is applied.
Our principal operational retention periods include:
| Information | Retention |
|---|---|
| Patient clinical records, orders, results, reports, PDFs and AI explanations | 8 years after last clinical activity, or the clinic’s longer period |
| Results links | Expiry + 90 days |
| Patient portal account | 12 months after access ends |
| Bookings that did not become an order | 2 years after completion or cancellation |
| Support conversations and attachments | 2 years after closure |
| Re-test reminders | 12 months after being sent or cancelled |
| Records of emails and texts sent | 12 months |
| Patient record access history | 2 years |
| Audit logs | 8 years, or the clinic’s longer clinical period |
| Information sent to the laboratory | 90 days |
| Laboratory information received | 90 days after processing or resolution, unless unresolved |
| Inbound webhook logs | 90 days |
| Migration data from a previous system | 30 days after formal migration sign-off, subject to any applicable hold |
Some information may be retained for longer where a legal obligation, investigation, complaint, claim or other valid hold requires it.
The retention periods above are operational defaults and may be adjusted where a clinic’s documented requirements require a longer period.
13. Your rights
Depending on the circumstances and applicable law, you may have rights including:
- the right to access your personal information;
- the right to have inaccurate information corrected;
- the right to request erasure;
- the right to restrict processing;
- the right to object to certain processing;
- the right to data portability; and
- rights relating to automated decision-making where applicable.
These rights are not absolute and may be subject to legal exemptions.
Patient information held for a clinic
Where Doxtor processes your information on behalf of a clinic, the clinic is generally responsible for deciding how your rights request should be handled.
Please contact the clinic first.
If a request is sent directly to Doxtor, we will promptly refer it to the relevant clinic and assist the clinic as required under our contractual arrangements.
Doxtor may need to verify the identity of the person making a request through the appropriate controller.
14. Access requests
Where a clinic receives a valid access request, Doxtor provides functionality allowing the clinic to generate a readable copy of the information held in the relevant patient record.
Depending on the circumstances, the export may include:
- patient details;
- orders and timelines;
- laboratory results;
- report versions;
- AI explanations;
- bookings;
- messages;
- portal access information;
- communications;
- access history; and
- supplementary information about processing, retention and applicable rights.
Information relating to other individuals is excluded where appropriate.
The clinic remains responsible for reviewing the export and providing it to the patient through an appropriate secure method.
15. Erasure
The right to erasure is not absolute.
Where applicable, the clinic determines whether patient information should be erased, taking into account legal, clinical, regulatory and other applicable requirements.
Doxtor provides a controlled erasure process. Approved erasures are recorded and implemented through the Doxtor privacy workflow.
Some records may need to be retained, including certain audit records, access records, billing records and backup copies, where a lawful retention requirement applies.
Where information remains subject to a valid legal or regulatory requirement, it will not be erased merely because an individual has requested erasure.
16. Backups and recovery
Information removed from the live Doxtor environment is not manually altered inside historical backups.
Backups expire according to the applicable backup retention period.
Doxtor maintains an erasure record so that, following a restore, authorised erasures can be reapplied before the restored environment is returned to normal operation.
17. Closed clinics
When a clinic closes its Doxtor account, access to the active service is disabled.
Patient records are not necessarily deleted immediately because the clinic may have legal or clinical obligations requiring continued retention.
The appropriate outcome is determined through the clinic closure process and may include:
- transfer to a successor;
- return to the clinic;
- continued retention under the applicable agreement; or
- scheduled deletion.
Deletion requires appropriate privacy authorisation.
Doxtor may retain its own business records relating to the clinic, including account, billing and contractual records, where required.
18. Support communications
Doxtor may retain support conversations and attachments for operational, security and accountability purposes.
Where support communications contain patient information, they are handled according to the applicable clinic/controller arrangement.
A patient erasure request does not automatically require the deletion of correspondence between a clinic and Doxtor where that correspondence forms part of the clinic’s support or operational record.
19. Marketing communications
Doxtor may communicate with clinic customers and prospective customers about its services, products and updates where permitted by applicable law.
You can unsubscribe from marketing communications using the unsubscribe mechanism provided in the communication or by contacting us.
Service, security and legally required communications may still be sent where necessary.
20. Cookies and similar technologies
Our website and services may use cookies and similar technologies to:
- operate essential functionality;
- maintain security;
- remember preferences;
- understand how our services are used; and
- provide other functionality where permitted.
Where consent is required for a particular technology, we will request it before using it.
Further information may be provided through our cookie settings or cookie notice.
21. Complaints
If you have concerns about how Doxtor has handled your personal information, please contact us first:
We will investigate your concern and respond appropriately.
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection supervisory authority.
Information about the ICO is available at ico.org.uk.
22. Changes to this Privacy Policy
We may update this Privacy Policy when our services, processing activities or legal obligations change.
Where appropriate, we will provide notice of material changes.
The latest version will always be published on the Doxtor website.
23. Contact us
ASAI CAPITAL LTD
Company number: 15585773
13 Whitchurch Lane
Edgware
England
HA8 6JZ
Privacy and data protection enquiries:
privacy@doxtor.health