SmartSphere Visibility Intelligence ← Back to site
Legal

Privacy & Data Protection Notice

Version 1.0 · Last updated 18 July 2026

1. Who we are and how to contact us

This notice explains how SMARTSPHERE GLOBAL LIMITED ("SmartSphere", "we", "us" or "our") collects and uses personal information when you visit our website, contact us, receive our services, work with us, or appear in public-source research undertaken for a client project.

SMARTSPHERE GLOBAL LIMITED is a private limited company registered in England and Wales under company number 16719729. We trade as SmartSphere Global and SmartSphere AI. Our registered office is Flat 20 Mynterne Court, Swanton Gardens, London, England, SW19 6BW.

For our own website, business administration, marketing and client relationships, we normally act as the data controller. This means we decide why and how personal information is used.

2. Scope of this notice

This notice applies to:

  • visitors to our website and landing pages;
  • people who make an enquiry, book a call, download a resource, attend a webinar or communicate with us;
  • clinic owners, directors, practitioners, employees and contractors of prospective or current clients;
  • suppliers, professional advisers and business partners;
  • people whose professional information appears in public sources reviewed during AEO visibility, authority, competitor or market research; and
  • authorised users of AI content systems, Custom GPTs or other tools that we configure for a client.

A clinic remains responsible for its own patient privacy notice, clinical records, consent processes, confidentiality duties and lawful use of patient information. This notice does not replace a clinic's patient privacy notice.

3. When we act as controller or processor

When SmartSphere is a controller

We act as controller for personal information used for our own business purposes, including enquiries, contracts, billing, website operation, security, marketing, public-source business research, supplier management and legal compliance.

When SmartSphere is a processor

We may act as a processor when a clinic asks us to handle personal information strictly on its documented instructions, for example when we are given limited access to a website, analytics account, CRM, content-approval workflow or staff knowledge base. In that situation, the clinic is normally the controller and our processing must be governed by a written data-processing agreement.

Role depends on the facts

The same project may involve both roles. For example, we are controller for our contract and invoicing records, while we may be processor for client-controlled information used to configure a content system. We define the roles in the proposal, statement of work and data-processing terms before processing begins.

4. Personal information we collect

4.1 Website, enquiry and event information

  • name, work email address, telephone number, job title, clinic or company name, location and website;
  • information entered into forms, booking pages, chat tools, questionnaires or webinar registrations;
  • your enquiry, project interests, preferred contact method, budget or timescale information you choose to provide;
  • IP address, browser/device information, approximate location, referral source, pages viewed and cookie preferences; and
  • communications, call notes and meeting recordings where recording has been clearly notified.

4.2 Client and supplier information

  • identity and business contact details of authorised contacts and team members;
  • contracts, proposals, instructions, approvals, account information and project correspondence;
  • billing details, invoices, payment status and transaction references (we do not normally store full payment-card details);
  • website, analytics, search, social or workflow access information provided through role-based invitations;
  • support requests, feedback, testimonials and complaint records; and
  • security and audit logs connected with access to our systems or client tools.

4.3 AEO, authority and competitor research information

  • public clinic and business information, such as services, locations, contact details and website content;
  • practitioner names, professional roles, published qualifications, registrations and biographies;
  • public search results, AI-assisted search outputs, business listings, social profiles, directories and press coverage;
  • public reviews and ratings. We minimise the collection of reviewer identities and avoid reproducing sensitive patient details; and
  • test prompts, platform/date/location context, screenshots, observations and benchmark results used in an audit.

4.4 AI content systems and Custom GPT information

  • approved brand voice, values, treatment menu, target audience and business positioning;
  • approved treatment information, FAQs, aftercare information, contraindication wording and compliance guidance supplied by the clinic;
  • content drafts, prompts, outputs, team feedback and approval decisions;
  • authorised staff names, work emails, roles and access permissions; and
  • usage and technical logs needed for support, security and quality control.

Use anonymised or synthetic patient personas

Patient personas, FAQs and examples should be fictional, aggregated or irreversibly anonymised. They must not be copied from identifiable patient records, consultation notes, treatment photographs or medical histories.

4.5 Special-category and criminal-offence information

Health information is special-category personal data and requires additional legal protection. Our standard services do not require identifiable patient health information. We do not intentionally collect criminal-offence information for standard services.

We may incidentally receive limited health information if a person includes it in an enquiry or complaint. We will use only what is necessary to respond, restrict access, and delete or retain it in line with law and our retention rules.

5. Where information comes from

We obtain information:

  • directly from you or your clinic, including forms, calls, contracts, onboarding and support;
  • from publicly available sources, such as websites, professional registers, Companies House, business directories, social media, public reviews, search engines and AI-assisted search results;
  • from referrals, event partners or professional networks, where they are permitted to share the information;
  • from service providers that support website analytics, booking, payment, security or communications; and
  • from a client acting as controller when it instructs us to provide services.

Where we obtain an individual's business contact information from a public or third-party source for direct outreach, we provide privacy information at or before the first communication, or within the applicable statutory period, unless a lawful exception applies.

6. Why we use information and our lawful bases

We use personal information only where we have a valid legal basis. The table below describes our main purposes. The appropriate basis can depend on the circumstances.

PurposeTypical informationLawful basisNotes / safeguards
Respond to enquiries and prepare proposalsContact details, enquiry, clinic informationSteps requested before entering a contract; legitimate interestsWe use only what is needed to respond and assess fit.
Deliver contracted servicesClient contacts, instructions, project content and access dataContract; legitimate interestsProcessor data is handled under documented instructions and a DPA.
AEO and public-source auditsPublic clinic/practitioner information, search results and audit evidenceLegitimate interestsWe assess necessity, proportionality and reasonable expectations; named patient/reviewer data is minimised.
Build AI content systems and Custom GPTsApproved brand, treatment and staff-user informationContract; legitimate interestsNo identifiable patient data by default; human review and access control.
Billing, accounting and taxInvoices, payments, company and contact detailsContract; legal obligationFinancial records are retained for statutory and legal purposes.
Operate and secure our website and systemsDevice, log, authentication and security dataLegitimate interests; legal obligation where applicableUsed for fraud prevention, access control, troubleshooting and incident response.
Direct marketing and business developmentBusiness contact details, interests, interactions and suppression recordsConsent or legitimate interests, subject to PECREvery electronic message includes an opt-out; objections are respected.
Record calls or meetingsAudio/video, attendee names and chatLegitimate interests or consent, depending on contextRecording is notified in advance; participants can request an unrecorded alternative where feasible.
Handle rights requests and complaintsIdentity, correspondence, case evidenceLegal obligation; legitimate interestsWe verify identity proportionately and keep an audit trail.
Establish, exercise or defend legal claimsContracts, communications, project and complaint evidenceLegitimate interests; legal obligation; legal claims condition where special-category data is involvedAccess is restricted and retention is limited to the relevant period.

7. AEO visibility audits and public-source research

Our visibility and authority services may test how a clinic appears across a defined set of patient-style searches on search engines and AI-assisted platforms. The audit may record whether the clinic appears, which treatments are associated with it, what public information is referenced, and where information is unclear or inconsistent.

We apply the following safeguards:

  • testing is based on a documented prompt set, platform, date, location context and assessment criteria;
  • we collect information about businesses and professional roles rather than creating profiles about patients;
  • we use public information lawfully and do not bypass authentication, technical restrictions or private patient systems;
  • we minimise reviewer names and do not intentionally reproduce patient stories or health details from reviews;
  • audit outputs are observational and can vary by platform, model, personalisation, location and time; and
  • public practitioner details used for outreach are handled under our direct-marketing and transparency rules.

No guarantee of AI visibility

AI-assisted search outputs are variable. We do not promise that a clinic will appear, be recommended or remain visible on any platform. Audit scores are internal project benchmarks, not official metrics supplied or endorsed by an AI or search provider.

8. AI tools, Custom GPTs and human review

We may use artificial intelligence tools to support research, summarisation, content drafting, structuring, quality checking and workflow automation. We remain responsible for selecting appropriate tools and applying proportionate human review.

Our AI commitments

  • We do not use AI to make solely automated decisions about individuals that produce legal or similarly significant effects.
  • We do not configure a clinic AI assistant to diagnose, recommend an individual treatment, provide personalised medical advice or replace a professional consultation.
  • Clinical and patient-facing content must be reviewed and approved by the clinic's appropriately qualified healthcare professional before publication.
  • Custom GPTs are configured with approved business and treatment content. We do not use identifiable patient records as knowledge-base material or prompt examples under the standard service.
  • We use role-based access, confidentiality settings and provider controls appropriate to the project. Link-accessible tools must contain only information approved for that access model.
  • Where feasible, we use business-grade settings that limit provider use of customer content for model improvement, but the exact provider terms and transfer arrangements are assessed for each project.
  • We maintain a record of approved AI providers and subprocessors and update clients when required by contract.

A separate DPIA and enhanced governance are required before deploying a patient-facing AI assistant that collects personal information, processes health information, profiles individuals, connects to clinical systems or could materially influence patient decisions.

9. Patient data and special-category health data

Do not send patient records under the standard service

Clients must not send or upload identifiable medical histories, consultation notes, symptoms, diagnoses, prescriptions, laboratory results, treatment photographs, before-and-after images, appointment details that reveal health information, or patient communications unless SmartSphere has expressly agreed the processing in writing.

Before we intentionally process identifiable patient or special-category health data, all of the following must be completed:

  1. a written scope defining the purpose, necessity and data fields;
  2. a controller/processor role assessment and Article 28-compliant data-processing agreement;
  3. the clinic's documented Article 6 lawful basis and Article 9 condition, plus any required Schedule 1 condition or appropriate policy document;
  4. a DPIA and, where relevant, clinical safety, confidentiality and medical-device/regulatory assessment;
  5. approved systems, access controls, encryption, retention/deletion instructions and incident-response contacts;
  6. an approved subprocessor and international-transfer assessment; and
  7. appropriate privacy information and, where required, consent or other patient-facing notices.

If identifiable patient information is sent to us outside an agreed process, we may stop work, restrict access, return or securely delete the information, and notify the clinic so that it can assess any confidentiality or data-breach obligations.

10. Sharing information and service providers

We do not sell personal information. We share it only where necessary for the purposes in this notice, where required by law, or where you have asked us to do so.

Recipients may include:

  • website, hosting, form, booking and content-management providers;
  • email, cloud storage, document collaboration and video-meeting providers;
  • approved AI, search, analytics and automation providers;
  • accounting, banking, payment and professional-services providers;
  • specialist contractors who are bound by confidentiality and data-protection obligations;
  • the client clinic and its authorised users where information is produced for that client;
  • insurers, legal advisers, auditors, regulators, courts, law-enforcement bodies or public authorities where necessary; and
  • a buyer, investor or successor in connection with a genuine business transaction, subject to appropriate safeguards.

Depending on the final system configuration, providers may include our website hosting platform, Google and OpenAI or alternative approved providers. A current subprocessor list will be maintained and made available on request.

11. International transfers

Some service providers may process personal information outside the United Kingdom. Before making a restricted transfer, we use an available lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another permitted safeguard. Where required, we assess whether the protection in the destination is not materially lower and apply supplementary measures.

For client-controlled data, transfer arrangements are documented in the data-processing agreement or subprocessor terms. Clients may ask for information about the relevant safeguard.

12. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose collected, including legal, tax, accounting, security and dispute-resolution needs. We consider the amount, sensitivity, risk and applicable limitation or statutory periods.

Record typeTypical periodReason / deletion approach
Unsuccessful enquiries and discovery-call notesUp to 24 months after last meaningful contactBusiness follow-up and evidence of communications; earlier deletion on justified request unless needed for legal reasons.
Marketing contactsUntil opt-out, objection or inactivity review; suppression record retainedSuppression data is kept to ensure we do not contact the person again.
Client contracts, core correspondence and final deliverablesNormally 6 years after the relationship endsContract, tax, accountability and legal-claims evidence.
Invoices and accounting recordsNormally 6 years from the relevant financial periodTax and accounting obligations.
AI prompts, working drafts and temporary project filesNormally deleted or anonymised within 90 days after acceptance, unless part of the agreed project recordMinimisation; final approved content and necessary audit evidence may be retained with the contract record.
Meeting recordingsNormally 90 days, unless a longer period is agreed or needed for a disputeTranscription, quality and action tracking.
Website/security logsTypically 12 months, subject to provider settings and incident needsSecurity, diagnostics and abuse prevention.
Rights requests and data-protection complaintsNormally 6 years after closureEvidence of compliance and handling of disputes.
BackupsRotating cycle, normally up to 90 daysResilience; deleted data may persist temporarily in protected backups and is not restored except for recovery.

These are target periods and may be shortened or extended where justified. Client processor data is returned or deleted at the end of services in accordance with the client's instructions and contract, unless UK law requires retention.

13. Security

We use proportionate technical and organisational measures designed to protect personal information against unauthorised access, alteration, loss, misuse or disclosure. Measures may include:

  • multi-factor authentication and strong account controls;
  • role-based access, least privilege and access reviews;
  • encryption in transit and provider-supported encryption at rest;
  • secure sharing links, approved storage locations and password-manager use;
  • device security, software updates, anti-malware and backups;
  • confidentiality obligations, training and documented operating procedures;
  • supplier due diligence, processor terms and subprocessor controls;
  • incident detection, breach assessment, notification and remediation; and
  • data minimisation, anonymisation and deletion controls.

No internet or storage system is completely secure. If you believe information connected with SmartSphere has been compromised, contact us immediately at infos.smartsphere@gmail.com.

14. Direct marketing and outreach

We may contact clinic owners, directors and relevant business contacts about services that we reasonably believe may be relevant to their professional role. We comply with UK GDPR and the Privacy and Electronic Communications Regulations (PECR).

  • For corporate subscribers, PECR may permit business-to-business electronic mail without prior consent, but UK GDPR still applies. We assess legitimate interests, identify ourselves and provide a clear opt-out.
  • Sole traders and certain partnerships are treated like individuals under PECR, so consent is generally required for unsolicited electronic mail unless a valid soft opt-in or other rule applies.
  • We screen telephone marketing against applicable preference services and respect prior objections.
  • We do not use special-category data to target marketing.
  • You may object to direct marketing at any time. We will stop and retain only a minimal suppression record.

To opt out, use the unsubscribe link in an email or contact infos.smartsphere@gmail.com.

15. Cookies and storage/access technologies

Our website may use cookies, pixels, local storage, scripts or similar storage and access technologies. We provide clear information and, where required, obtain valid consent before using non-essential technologies.

Typical categories are:

CategoryPurposeConsent positionCurrent status
Strictly necessary / securityOperate the site, remember privacy choices, prevent abuse and maintain sessionsMay be used without consent where a PECR exception appliesHosting platform and security technologies only.
FunctionalRemember preferences or enable requested featuresConsent unless a specific exception appliesNone currently used.
AnalyticsMeasure visits and improve site performanceConsent unless configured to meet a specific low-risk exceptionNone currently used.
Advertising / trackingMeasure campaigns, retarget or build audiencesPrior consent required in normal circumstancesNone currently used.

Our website loads fonts from Google Fonts, which means your browser connects to Google's servers and shares your IP address with Google. We will update this table before introducing any new storage or access technology. Where we use non-essential technologies, you will be able to reject them as easily as you accept them and change your choices later.

16. Your data-protection rights

Depending on the circumstances and applicable exemptions, you may have the right to:

  • be informed about how your personal information is used;
  • request access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information in certain circumstances;
  • ask us to restrict processing in certain circumstances;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests and object absolutely to direct marketing;
  • withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing; and
  • request safeguards and human review in relation to applicable solely automated decisions.

To exercise a right, email infos.smartsphere@gmail.com. We may request proportionate information to verify identity and clarify the request. We normally respond within one month, subject to lawful extensions or exceptions. There is normally no fee, but the law permits a fee or refusal in limited circumstances.

Where we act only as processor, we will forward or assist with the request as required by our agreement with the relevant clinic, which remains responsible for responding.

17. Data-protection complaints

You may complain if you believe we have infringed data-protection law in the way we have handled personal information. You do not need to use legal language.

How to complain to SmartSphere

  • Email infos.smartsphere@gmail.com with the subject "Data Protection Complaint"; or
  • write to the registered office shown in section 1.

We will acknowledge a data-protection complaint within 30 days. Without undue delay, we will make appropriate enquiries, keep you informed where necessary, and tell you the outcome of our investigation. We may ask for additional information where reasonably needed.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator. The ICO will usually expect you to raise the matter with us first. Visit the ICO website or telephone 0303 123 1113.

19. Contact details

Detail
ControllerSMARTSPHERE GLOBAL LIMITED
Company number16719729
Registered officeFlat 20 Mynterne Court, Swanton Gardens, London, England, SW19 6BW
Email / telephoneinfos.smartsphere@gmail.com · 07938 502621

End of privacy notice