PractisBase Privacy Policy
1. Introduction and Who We Are
1.1. This Privacy Policy explains how Cerulean Labs Limited (“we,” “us,” or “our”) handles personal data in connection with the PractisBase platform.
1.2. We are a Maltese company registered as a Limited Liability Company. Our details are:
- Full Legal Name: Cerulean Labs Limited
- Company Registration Number: C 116764
- Privacy Contact Email: privacy@labscerulean.com
2. Our Roles: Controller vs. Processor
2.1. Under the General Data Protection Regulation (GDPR) and the Data Protection Act (Cap. 586 of the Laws of Malta), data roles dictate our legal responsibilities and liabilities. It is strictly understood that PractisBase operates under a dual-role structure depending on the data category.
2.2. Data Controller: We act exclusively as a Data Controller for your platform registration, billing details, usage data, and direct support communications. This means we decide how and why this specific subset of administrative data is processed.
2.3. Data Processor: We act strictly as a Data Processor for all client, patient, and project content, as well as all financial ledgers, invoices, and practice data you upload or generate within PractisBase. You (the professional User) are the sole Data Controller for this information. We process this data solely on your instructions to provide the platform’s functionality. We accept no controllership, ownership, or liability over the accuracy, legality, or regulatory compliance of your practice’s data.
3. Personal Data We Collect as a Controller
3.1. We collect the following categories of data where we act as a Controller for our own administrative purposes:
- Identity & Contact Data: Name, email address, profession / professional title, warrant details (where provided), and VAT number (where provided) for account creation and service configuration.
- Financial Data: Billing information and subscription history (processed securely via our payment sub-processors when billing is active).
- Technical & Usage Data: IP address, browser type, device information, login times, terms-acceptance records, and platform interaction telemetry to ensure security and performance.
- Feedback & Support Data: Content of support requests and community feedback / feature suggestions.
4. Purposes and Legal Bases for Processing
4.1. We process your Controller data (the administrative data outlined in Section 3) on the following legal bases:
- Performance of a Contract: To register your account, provide access to the Service, and process your subscription payments in accordance with our Master Service Agreement.
- Our Own Legal Obligations: To comply strictly with Cerulean Labs Limited’s own corporate tax, statutory accounting, and anti-money laundering (AML) requirements under Maltese law. This includes retaining your billing information and subscription invoices to satisfy our own corporate audits.
- Legitimate Interests: To analyse platform usage, improve our product features, maintain network security, and handle community feedback.
- Consent: Where legally required (e.g., for non-essential cookies or direct marketing). You may withdraw consent at any time.
4.2. Explicit Clarification on User Tax & Financial Data: For the avoidance of doubt, the “Legal Obligation” basis cited in Section 4.1 refers exclusively to Cerulean Labs Limited’s corporate obligations. We do not process, analyse, or audit the financial data, ledgers, or tax figures you input into the platform under any legal obligation to verify your practice’s tax compliance. You remain the sole Data Controller and assume absolute liability for your own professional tax declarations, VAT returns, and financial submissions to the Malta Tax and Customs Administration (MTCA) or any other authority.
5. Medical Vault, Professional Desks, and Special Category Data
5.1. The PractisBase Medical Vault allows medical professionals to store special category personal data (e.g., patient health records).
5.2. Your Controllership: You are strictly the Data Controller for this data. You must ensure you have a lawful basis to process your patients’ health data.
5.3. Vault Encryption: The Medical Vault uses client-side cryptography. We do not hold the decryption keys and cannot read plaintext clinical content. If you lose your recovery codes, your vault data is irreversibly lost.
5.4. Architect/Engineer documents: Files uploaded to the Studio and Technical desks remain your intellectual property. We process them solely to provide document library and stamping features.
6. Accountant Pack and Third-Party Access
6.1. PractisBase provides an accountant export pack that you may download and share with your warranted accountant or tax advisor. You choose what to share; there is currently no separate accountant login seat on the platform.
6.2. By downloading and sending that pack (or otherwise sharing practice data), you remain the Data Controller of that information. Your accountant acts as an independent Data Controller or authorised processor for their own professional obligations.
7. Sharing Data and Sub-processors
7.1. We do not sell your personal data.
7.2. We share data with trusted sub-processors only as needed to host the platform, store files, send transactional email, and process payments.
7.3. A current list of our sub-processors:
- Railway — application hosting and database
- Cloudflare — CDN/security and R2 file storage
- Google Workspace / Google LLC — transactional email
- Stripe — billing and payments (when live)
8. International Transfers
8.1. We prioritise hosting your data within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses (SCCs) or equivalent adequacy decisions.
9. Security & Retention
9.1. We implement appropriate technical measures to protect data. You are responsible for safeguarding your credentials.
9.2. Account Data is retained while active. Customer Content is deleted upon account closure, subject to short-term automated backup cycles.
10. Your Rights
10.1. You have the right to access, rectify, erase, restrict, or object to the processing of your personal data. Email privacy@labscerulean.com to exercise these rights.
10.2. You may lodge a complaint with the Maltese supervisory authority: the Office of the Information and Data Protection Commissioner (IDPC).
11. Cookies, Local Storage, and Biometrics
11.1. We use cookies and local storage to keep you logged in and ensure platform security.
11.2. Any biometric unlock feature for the Medical Vault (e.g., fingerprint or facial recognition) operates entirely on your local device. We do not collect, transmit, or store your biometric data on our servers.
12. Children’s Data
12.1. PractisBase is a B2B service for adult professionals. We do not knowingly collect personal data from individuals under 18 years of age.
13. Changes to this Policy
13.1. We may update this Privacy Policy. We will notify you of material changes via email or an in-app notice. Continued use of the platform after the effective date constitutes acknowledgement of the updated policy.
14. Data Processing Summary (Processor Schedule)
14.1. When we act as a Data Processor for your Customer Content, we strictly agree to:
- Process the data only on your documented instructions (which includes providing the PractisBase service).
- Ensure our personnel are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures.
- Only engage sub-processors under a written contract offering equivalent protection, and notify you of changes to our sub-processors.
- Delete or return the data upon termination of your account, subject to backup cycles.
- Cooperate reasonably with audits and inspections mandated by your GDPR obligations.
Related document
Use of PractisBase is also governed by the Master Service Agreement.