Privacy Policy
Last updated: July 2026
This Privacy Policy explains how Cognati Ltd (trading as Cubiq Cloud) (“Cubiq Cloud”, “we”, “us”) collects and uses personal data and the rights of individuals under UK data protection law.
We are committed to protecting personal data and complying with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
1. Who We Are
Company: Cognati Ltd (trading as Cubiq Cloud)
Registered number: 13081108
Registered office: 20 Egerton Close, London, HA5 2LP, United Kingdom
Email: info@cubiqcloud.com
We are a UK-based provider of healthcare customer relationship management and practice management software.
2. Our Role
We act in two capacities:
- As a Data Processor when we provide the Cubiq Cloud platform to healthcare practices and other organisations. In this context, our customers are the Data Controllers.
- As a Data Controller for our own business operations, including sales, marketing, billing, supplier management, and our website.
This Privacy Policy applies to personal data for which we act as Data Controller. Where we act as Data Processor, processing is governed by our Data Processing Agreement with the relevant customer.
3. Personal Data We Collect
Depending on your relationship with us, we may collect and process:
- Identity and contact details (name, job title, organisation, email, phone number)
- Account and login information
- Billing and payment details
- Communications with us (emails, support requests)
- Website usage data (IP address, device, pages visited)
- Marketing preferences
We do not determine the content of patient records or clinical data held in the Cubiq Cloud platform. That data is controlled by our customers.
4. Sources of Personal Data
We collect personal data directly from you (for example when you contact us or create an account) and from your organisation. We may also receive business contact details from publicly available sources and professional networks.
5. How We Use Personal Data
We use personal data to:
- Provide, administer, and support our services
- Manage customer and supplier relationships
- Respond to enquiries and provide customer support
- Send service communications (such as system notices and contractual updates)
- Carry out billing, payments, and accounting
- Improve and secure our products and services
- Manage our website and online presence
- Market our services where permitted by law
6. Lawful Bases for Processing
| Purpose | Lawful Basis |
|---|---|
| Providing and administering services | Performance of a contract |
| Customer and supplier management | Performance of a contract |
| Billing and accounting | Legal obligation |
| Responding to enquiries and support | Legitimate interests |
| Product improvement and security | Legitimate interests |
| Marketing communications | Consent or legitimate interests (where permitted) |
| Website analytics | Legitimate interests or consent (via cookies) |
Where we rely on legitimate interests, we have balanced those interests against individuals' rights and freedoms.
7. Marketing and Communications
We may send marketing communications to business contacts about our services where permitted by the Privacy and Electronic Communications Regulations (PECR). You can opt out at any time using the unsubscribe link or by contacting info@cubiqcloud.com. Service communications are not marketing and cannot be opted out of.
8. Who We Share Data With
We may share personal data with:
- Hosting and infrastructure providers
- Email and communications providers
- Analytics and monitoring services
- Professional advisers
- Regulators and authorities where required by law
All providers act under contract. We do not sell personal data.
9. International Transfers
We host data using Amazon Web Services. Personal data may be stored or accessed outside the UK or EEA. Authorised personnel in Indonesia may access systems for development and support. Where transfers occur, we use the UK IDTA and/or UK SCC Addendum and maintain Transfer Risk Assessments.
10. Data Retention
We retain personal data only as long as necessary:
- For the duration of a contractual relationship
- For up to 90 days after account closure
- Longer where required by law
Marketing data is retained until you opt out.
Where you make an explicit deletion request, we complete deletion within 30 days rather than waiting for these default periods. See our account deletion page for what is deleted and what we are required to keep.
11. Your Rights
You have the right to access, rectify, erase, restrict, object, port data, withdraw consent, and complain to the ICO.
Note: Where we act as Processor, requests should be directed to the relevant healthcare provider.
13. Mandatory Data
Where we require personal data to enter into a contract with you or your organisation, failure to provide that data may mean we are unable to provide our services.
14. Automated Decision-Making
We do not carry out solely automated decision-making or profiling that produces legal or similarly significant effects.
15. Children's Data
Our services are intended for use by professionals. We do not knowingly collect personal data directly from children.
16. Cookies and Tracking
Our website uses cookies for functionality, analytics, and marketing where permitted. You can manage preferences via your browser or site tools.
17. Complaints
You may contact us first or lodge a complaint with the Information Commissioner's Office:
Website: ico.org.uk
Telephone: 0303 123 1113
18. Mobile Application (Cubiqcloud CRM)
We publish a mobile application called Cubiqcloud CRM on Google Play and the Apple App Store. The app is for staff at practices that use Cubiqcloud. It is not a patient-facing app. This section describes what the app itself collects, in addition to the processing described above.
Data the app collects
- Account information — the name, email address, phone number and practice associated with the account you sign in with.
- Push notification tokens — an identifier issued by Apple or Google that lets us send notifications to your device about new enquiries and appointments. It is deleted when you sign out or delete your account.
- Images you choose to upload — if you attach a photo to a record, that image is uploaded and stored with the record.
Permissions the app requests
- Notifications — to alert you to new patient enquiries and appointment changes. The app works without this permission; you simply will not receive alerts.
- Camera and photo library — used only when you actively choose to attach an image to a record. We do not access your camera or photo library at any other time, and we do not scan your photo library.
What the app does not collect
The app contains no third-party analytics SDKs and no crash-reporting SDKs. We do not collect usage analytics, behavioural tracking data, advertising identifiers or location data from the app. We do not sell personal data, and the app contains no advertising.
Sharing and deletion
The app shares data only with the hosting, infrastructure and communications providers listed in Section 8. The analytics and monitoring services referenced there relate to our website, not the app. Apple and Google additionally process push notification tokens in order to deliver notifications to your device.
You can request deletion of your account and personal data at any time, without logging in, at our account deletion page. That page sets out exactly what is deleted, what we are legally required to keep, and how long it takes.
19. Changes
We may update this Policy from time to time. The latest version will be published on our website.