Privacy notice

Last updated 24 September 2026

Introduction

This notice explains how we handle personal data for people who visit this site, subscribe to our newsletter, or hold a LeafletPlan account, and for the billing data of our customers. It sits alongside the customer agreement that governs how we handle the patient information a clinician sends through the app.

Who we are and how to contact us

LeafletPlan is a service of Meridian Health Systems Ltd, a company registered in England and Wales. We are the data controller for the marketing-site, account, and billing data described in this notice. You can reach our privacy team at privacy@leafletplan.com.

Our role: controller and processor

We are the controller for data about people who visit this site, subscribe to our newsletter, or hold a LeafletPlan account, and for our customers' billing data. For the patient information a clinician sends through the app, the clinician's organisation is the controller and we act only as their processor. See “Patient information” below.

Personal data we collect

  • Marketing site: if you subscribe to our newsletter, the email address you submit and the date you confirmed. We also use cookieless product analytics to count visits to named page categories and clicks on our main get-started link. It does not store a cookie, local-storage value, full URL, query, referrer, or Person profile.
  • Account: your name, work email, the organisation and teams you belong to, and your role, so you can sign in and use the service. Product analytics uses pseudonymous clinician and workspace keys created with a secret held by LeafletPlan. Analytics services do not receive direct identifiers.
  • Billing: your billing contact details, billing address, any company and VAT number you provide, and a record of your subscriptions and invoices. Card details are entered directly with our payment processor and are never stored on LeafletPlan's systems.
  • Customer support: the message you send, your account name and email, your account identifier, the page route you reported, and the application cell and release. We remove UUID record identifiers from the route before sending it to Slack. Do not include patient information in a support request.
  • Operational error monitoring: in production, our applications may send an exception class, a stripped stack trace, a release identifier, and a broad page category to Sentry. The browser request also exposes ordinary network data, such as an IP address, to Sentry in transit. We remove stored IP addresses and do not send error messages, form values, account identifiers, patient content, full URLs, queries, headers, cookies, or request bodies.

How we use your data

We use this data to operate the site and send our newsletter, to provide and administer your account, to take payments and keep the tax and accounting records the law requires, and to keep the service secure and prevent abuse. We use narrowly scoped product analytics to understand onboarding, core feature use, expected friction, and whether a sent leaflet was delivered, opened, or downloaded. We use operational error monitoring to find production faults and keep the service reliable. Our regional databases remain the authoritative record.

Legal basis for processing

  • Consent (UK GDPR Article 6(1)(a)): for newsletter emails, confirmed by double opt-in. You can withdraw at any time.
  • Contract (Article 6(1)(b)): to provide the service and manage your account and billing.
  • Legal obligation (Article 6(1)(c)): to keep tax and accounting records.
  • Legitimate interests (Article 6(1)(f)): to keep the service secure, prevent abuse, find production faults, and improve it using the limited product analytics described here.

Patient information

When a customer uses LeafletPlan, we process patient information on the customer's instructions to provide and support the service. Our Data Processing Agreement governs this processing.

Anonymous Information

We may use personal data on a customer's instructions to create Anonymous Information for insights. We remain the processor until it becomes Anonymous Information. The customer is responsible for ensuring that processing is lawful and transparent.

How we share your data

We do not sell or rent your personal data. We share it with the service providers that help us run LeafletPlan (secure hosting and infrastructure, email delivery, payment processing, product analytics, and operational error monitoring), each acting only on our instructions and under a contract that requires them to protect it. This includes Slack for customer-support messages. Card payments are handled by a PCI-DSS-compliant payment processor, not by us. We may also disclose data where the law requires it or to protect our rights.

Analytics services receive only the pseudonymous or cookieless data described in this notice.

International transfers

Some of our service providers are based outside the UK, including in the United States. Sentry stores our error-monitoring events in its Germany region, but its service may still involve international processing. Where personal data is transferred abroad, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the addendum to the EU Standard Contractual Clauses.

How long we keep your data

We keep newsletter data until you unsubscribe, and account data for as long as you have an account. We retain billing and invoice records for as long as the law requires, typically six years for UK financial records. Product-analytics events are kept for up to one year. We do not add a shorter application-side expiry, and we delete events earlier when an applicable data-rights request requires it or when the project is closed. Operational error-monitoring events are kept for 30 days. Patient information in our regional systems is retained in line with the customer agreement and the audit-trail requirements of the service. We do not store support requests in LeafletPlan. Support messages remain in our Slack support channel under the workspace's default retention policy.

Data security

We protect personal data with encryption in transit and encryption at rest for sensitive fields, strict separation between customers' data, and access controls that limit who can see it. No system can be guaranteed completely secure, but we work to protect your data and to meet our obligations if anything goes wrong.

Cookies

This marketing site sets no cookies or local-storage identifiers of its own. Its limited product analytics is cookieless, and Sentry error monitoring sets no cookies or local-storage identifiers. See our Cookie Notice for detail.

Your rights

You can request access to your data, or its correction, deletion, or portability, and object to or restrict certain processing, by emailing privacy@leafletplan.com. If a patient wants to exercise rights over information a clinician sent, we will pass the request to that organisation as controller. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Changes to this notice

We may update this notice from time to time. If a change is material we will give notice (for example, by email or on this site) before it takes effect.

Contact us

Questions about this notice or your data? Email privacy@leafletplan.com.