Skip to content
  • Product
  • How it works
  • Resources
  • Contact
Sign inGet started
  • Product
  • How it works
  • Resources
  • Contact
  • Sign in
Get started

Privacy policy

Last updated 8 October 2026.

Sections
  1. 1. Who is responsible for your information?
  2. 2. Information we process
  3. 3. How we use information
  4. 4. Our legal bases
  5. 5. Laboratory information
  6. 6. AI-assisted explanations
  7. 7. Automated decision-making
  8. 8. Who receives information?
  9. 9. International transfers
  10. 10. Where information is stored
  11. 11. How we protect information
  12. 12. Retention
  13. 13. Your rights
  14. 14. Access requests
  15. 15. Erasure
  16. 16. Backups and recovery
  17. 17. Closed clinics
  18. 18. Support communications
  19. 19. Marketing communications
  20. 20. Cookies and similar technologies
  21. 21. Complaints
  22. 22. Changes to this Privacy Policy
  23. 23. Contact us

Doxtor is a healthcare software platform operated by ASAI CAPITAL LTD.

ASAI CAPITAL LTD is a company registered in England and Wales under company number 15585773, with its registered office at:

13 Whitchurch Lane
Edgware
England
HA8 6JZ

For privacy and data protection enquiries, contact:

privacy@doxtor.health

This Privacy Policy explains how Doxtor handles personal information when you use the Doxtor website, application, patient portal or related services.

Because Doxtor is software used by clinics, an important distinction applies: the clinic that provides healthcare services to you is generally responsible for deciding why and how your clinical information is processed. Doxtor processes that information on the clinic’s behalf.

1. Who is responsible for your information?

The organisation responsible for your information depends on the processing activity.

Clinic patient information

Where a clinic uses Doxtor to manage your patient information, including:

  • your personal details;
  • orders;
  • laboratory results;
  • reports;
  • sample and testing information;
  • patient portal information;
  • communications sent on behalf of the clinic; and
  • related clinical records,

the clinic is generally the data controller.

Doxtor acts as the clinic’s data processor, processing that information according to the clinic’s instructions and the applicable Data Processing Agreement.

If you have a question about why your clinic collected your information, why a particular test was ordered, how your clinical information is used, or a clinical decision made about you, you should normally contact the clinic first.

Doxtor’s own processing

ASAI CAPITAL LTD may act as an independent data controller where it processes information for its own purposes, including:

  • operating and securing the Doxtor service;
  • security monitoring and audit logging;
  • fraud prevention;
  • managing clinic accounts;
  • billing and payments;
  • legal and regulatory compliance;
  • managing its own staff and authorised users;
  • handling support and service-management matters; and
  • maintaining records necessary to operate and protect the service.

2. Information we process

Depending on how you interact with Doxtor, we may process different categories of personal information.

Information relating to clinic users

This may include:

  • name;
  • email address;
  • telephone number;
  • account and authentication information;
  • organisation and role information;
  • login and session information;
  • communications with Doxtor;
  • billing and account information; and
  • security and audit information.

Patient information processed for clinics

Where a clinic uses Doxtor, information may include:

  • name;
  • date of birth;
  • sex at birth;
  • email address;
  • telephone number;
  • patient portal information;
  • orders and test information;
  • laboratory results;
  • reports and report versions;
  • sample and laboratory information;
  • appointment or booking information;
  • messages and communications;
  • information about access to the patient’s record; and
  • AI-generated explanations associated with reports.

Some of this information may constitute special category data, including health information.

Doxtor processes this information for the clinic and does not use it for unrelated purposes of its own.

3. How we use information

When Doxtor acts as a processor

For patient information processed on behalf of a clinic, Doxtor uses information to provide the services instructed by the clinic, including:

  • creating and managing orders;
  • managing patient records;
  • managing sample and laboratory workflows;
  • receiving and displaying laboratory results;
  • producing reports;
  • providing patient portal functionality;
  • sending communications on behalf of the clinic;
  • providing support to the clinic;
  • maintaining security and audit records;
  • carrying out authorised data exports and erasure requests; and
  • providing other functionality included in the clinic’s Doxtor service.

The clinic determines the purposes for which patient information is processed and the applicable lawful bases.

When Doxtor acts as a controller

Doxtor may process information for its own purposes where necessary to:

  • create and administer accounts;
  • provide and manage subscriptions;
  • process clinic billing;
  • maintain service security;
  • investigate suspected misuse or security incidents;
  • maintain audit and access records;
  • comply with legal obligations;
  • prevent fraud;
  • communicate with clinic customers about the service; and
  • operate and improve the reliability of the platform.

4. Our legal bases

Where Doxtor acts as a controller, we rely on appropriate legal bases under applicable data protection law.

Depending on the circumstances, these may include:

  • Performance of a contract: where processing is necessary to provide our services or manage our contractual relationship with a clinic or user.
  • Legal obligation: where we need to process information to comply with applicable law.
  • Legitimate interests: where processing is necessary for purposes such as service security, fraud prevention, service management, business administration and protecting our systems, provided those interests are not overridden by the individual’s rights.
  • Consent: where we rely on consent and applicable law requires it.

Where Doxtor acts as a processor for a clinic, the clinic is responsible for determining and documenting the appropriate lawful basis for its processing of patient information.

5. Laboratory information

Doxtor connects clinic workflows with laboratory services.

Where laboratory information is exchanged through Doxtor, the laboratory may be a separate controller or processor depending on the particular processing arrangement.

Doxtor may transmit information required for laboratory testing, including information such as:

  • patient name;
  • date of birth;
  • sex at birth;
  • tests ordered; and
  • information necessary to identify and process an order.

Laboratory results are returned to Doxtor and made available within the clinic’s workflow.

Doxtor does not itself perform laboratory testing.

6. AI-assisted explanations

Doxtor may provide AI-assisted explanations associated with laboratory results.

The information supplied for an AI explanation is limited to:

  • age;
  • sex at birth; and
  • laboratory results.

Names, dates of birth and direct identifiers are not included in the information sent for the AI explanation.

AI explanations are provided for informational and decision-support purposes only.

They are not a diagnosis, medical opinion or substitute for professional clinical judgement.

The clinic and its appropriately qualified healthcare professionals remain responsible for reviewing results, interpreting them in the appropriate clinical context and deciding what action should be taken.

AI explanations are stored with the relevant report and are included in applicable patient data exports.

7. Automated decision-making

Doxtor does not make decisions about patients that are intended to have legal or similarly significant effects on them solely through automated processing.

AI-assisted explanations are not intended to make clinical decisions automatically.

A healthcare professional remains responsible for reviewing information and making appropriate clinical decisions.

8. Who receives information?

Depending on the service being used, personal information may be shared with or processed by:

Your clinic

Your clinic receives and controls the patient information processed through its Doxtor account.

Laboratory providers

Information necessary to fulfil laboratory orders may be provided to the relevant laboratory.

Technology and service providers

Doxtor uses trusted third-party providers to help us operate the platform and deliver its services.

These providers may support:

  • cloud infrastructure and secure data storage;
  • application infrastructure;
  • email delivery;
  • text messaging;
  • payment processing;
  • laboratory integrations;
  • AI-assisted functionality;
  • security and monitoring; and
  • other essential technology services.

Where a third party processes personal information on our behalf, we put appropriate contractual and data protection arrangements in place.

We maintain records of relevant processors and sub-processors as part of our data protection arrangements and may provide further information to clinic customers where appropriate.

Professional advisers and authorities

We may disclose information where reasonably necessary to:

  • comply with a legal obligation;
  • respond to a lawful request from a competent authority;
  • establish, exercise or defend legal claims;
  • prevent fraud or serious misuse; or
  • protect the rights, safety and security of Doxtor, our customers or other individuals.

9. International transfers

Some of the third parties supporting Doxtor may process personal information outside the United Kingdom.

Where applicable data protection law treats this as a restricted international transfer, we use an appropriate lawful transfer mechanism and safeguards.

These may include:

  • a UK adequacy regulation;
  • appropriate contractual safeguards;
  • an applicable international data transfer agreement or addendum; or
  • another lawful mechanism recognised under applicable data protection law.

We assess relevant international transfers and the safeguards applicable to them.

10. Where information is stored

Doxtor is designed so that clinic and patient information is stored within appropriate UK or European infrastructure where applicable to the relevant service.

We use established cloud and technology providers to host, secure, store and deliver the Services.

We do not publish our detailed internal infrastructure architecture in this Privacy Policy. Information about relevant processors and sub-processors may be made available to clinic customers through our contractual and data protection documentation.

11. How we protect information

Doxtor uses technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.

These include controls around:

  • authentication and access management;
  • role-based permissions;
  • clinic-level data isolation;
  • encryption in transit;
  • audit logging;
  • access logging;
  • restricted access to sensitive laboratory information;
  • controlled data exports;
  • controlled erasure workflows;
  • backup and recovery procedures;
  • security monitoring; and
  • infrastructure-level security controls.

Access to sensitive information is restricted according to role and operational need.

Where particularly sensitive laboratory information needs to be accessed for an authorised operational purpose, additional controls may apply, including re-authentication and recording the reason for access.

No internet-based service can guarantee absolute security, but we continually review and improve our technical and organisational safeguards.

12. Retention

We retain information only for as long as necessary for the relevant purpose and according to applicable legal, contractual, clinical and regulatory requirements.

For patient information processed on behalf of a clinic, the clinic’s applicable retention period may be longer than Doxtor’s operational default. Where a clinic has established a longer retention period under its obligations, that longer period is applied.

Our principal operational retention periods include:

Information Retention
Patient clinical records, orders, results, reports, PDFs and AI explanations 8 years after last clinical activity, or the clinic’s longer period
Results links Expiry + 90 days
Patient portal account 12 months after access ends
Bookings that did not become an order 2 years after completion or cancellation
Support conversations and attachments 2 years after closure
Re-test reminders 12 months after being sent or cancelled
Records of emails and texts sent 12 months
Patient record access history 2 years
Audit logs 8 years, or the clinic’s longer clinical period
Information sent to the laboratory 90 days
Laboratory information received 90 days after processing or resolution, unless unresolved
Inbound webhook logs 90 days
Migration data from a previous system 30 days after formal migration sign-off, subject to any applicable hold

Some information may be retained for longer where a legal obligation, investigation, complaint, claim or other valid hold requires it.

The retention periods above are operational defaults and may be adjusted where a clinic’s documented requirements require a longer period.

13. Your rights

Depending on the circumstances and applicable law, you may have rights including:

  • the right to access your personal information;
  • the right to have inaccurate information corrected;
  • the right to request erasure;
  • the right to restrict processing;
  • the right to object to certain processing;
  • the right to data portability; and
  • rights relating to automated decision-making where applicable.

These rights are not absolute and may be subject to legal exemptions.

Patient information held for a clinic

Where Doxtor processes your information on behalf of a clinic, the clinic is generally responsible for deciding how your rights request should be handled.

Please contact the clinic first.

If a request is sent directly to Doxtor, we will promptly refer it to the relevant clinic and assist the clinic as required under our contractual arrangements.

Doxtor may need to verify the identity of the person making a request through the appropriate controller.

14. Access requests

Where a clinic receives a valid access request, Doxtor provides functionality allowing the clinic to generate a readable copy of the information held in the relevant patient record.

Depending on the circumstances, the export may include:

  • patient details;
  • orders and timelines;
  • laboratory results;
  • report versions;
  • AI explanations;
  • bookings;
  • messages;
  • portal access information;
  • communications;
  • access history; and
  • supplementary information about processing, retention and applicable rights.

Information relating to other individuals is excluded where appropriate.

The clinic remains responsible for reviewing the export and providing it to the patient through an appropriate secure method.

15. Erasure

The right to erasure is not absolute.

Where applicable, the clinic determines whether patient information should be erased, taking into account legal, clinical, regulatory and other applicable requirements.

Doxtor provides a controlled erasure process. Approved erasures are recorded and implemented through the Doxtor privacy workflow.

Some records may need to be retained, including certain audit records, access records, billing records and backup copies, where a lawful retention requirement applies.

Where information remains subject to a valid legal or regulatory requirement, it will not be erased merely because an individual has requested erasure.

16. Backups and recovery

Information removed from the live Doxtor environment is not manually altered inside historical backups.

Backups expire according to the applicable backup retention period.

Doxtor maintains an erasure record so that, following a restore, authorised erasures can be reapplied before the restored environment is returned to normal operation.

17. Closed clinics

When a clinic closes its Doxtor account, access to the active service is disabled.

Patient records are not necessarily deleted immediately because the clinic may have legal or clinical obligations requiring continued retention.

The appropriate outcome is determined through the clinic closure process and may include:

  • transfer to a successor;
  • return to the clinic;
  • continued retention under the applicable agreement; or
  • scheduled deletion.

Deletion requires appropriate privacy authorisation.

Doxtor may retain its own business records relating to the clinic, including account, billing and contractual records, where required.

18. Support communications

Doxtor may retain support conversations and attachments for operational, security and accountability purposes.

Where support communications contain patient information, they are handled according to the applicable clinic/controller arrangement.

A patient erasure request does not automatically require the deletion of correspondence between a clinic and Doxtor where that correspondence forms part of the clinic’s support or operational record.

19. Marketing communications

Doxtor may communicate with clinic customers and prospective customers about its services, products and updates where permitted by applicable law.

You can unsubscribe from marketing communications using the unsubscribe mechanism provided in the communication or by contacting us.

Service, security and legally required communications may still be sent where necessary.

20. Cookies and similar technologies

Our website and services may use cookies and similar technologies to:

  • operate essential functionality;
  • maintain security;
  • remember preferences;
  • understand how our services are used; and
  • provide other functionality where permitted.

Where consent is required for a particular technology, we will request it before using it.

Further information may be provided through our cookie settings or cookie notice.

21. Complaints

If you have concerns about how Doxtor has handled your personal information, please contact us first:

privacy@doxtor.health

We will investigate your concern and respond appropriately.

If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection supervisory authority.

Information about the ICO is available at ico.org.uk.

22. Changes to this Privacy Policy

We may update this Privacy Policy when our services, processing activities or legal obligations change.

Where appropriate, we will provide notice of material changes.

The latest version will always be published on the Doxtor website.

23. Contact us

ASAI CAPITAL LTD
Company number: 15585773

13 Whitchurch Lane
Edgware
England
HA8 6JZ

Privacy and data protection enquiries:
privacy@doxtor.health

Blood testing software for UK clinics: orders, samples, laboratory results and patient reports in one place.

contact@doxtor.health

Product

  • Overview
  • How it works
  • Branded reports
  • Patient portal

Resources

  • Guides
  • Clinical resources
  • FAQs
  • Articles

Company

  • Contact
  • Get started
  • Sign in

Legal

  • Privacy policy
  • Terms of service

© 2026 ASAI CAPITAL LTD