Quzek

Privacy Policy

Last updated: July 2026.

This Privacy Policy explains how Quzek ("Quzek", "we", "us", "our") collects, uses, discloses and protects personal information when you use our booking and practice management software, our websites, and related services (together, the "Service"). We take privacy seriously because our customers — health and wellness practices — trust us with information about themselves and about the people in their care.

Please read this policy alongside our Terms of Service, our Security overview, and, where applicable, our Data Processing Agreement.

1. Who we are, and how we act

Quzek plays two different roles depending on the information involved:

As a data controller — for information about the practitioners and practices that are our direct customers: the account and billing details you give us, and how you use our websites and the Service.

As a data processor — for the information a practice enters into the Service about its own clients or patients (appointments, contact details, clinical notes, intake answers, invoices and so on). For that information, the practice is the controller and decides how it is used; Quzek processes it only on the practice's instructions. If you are a client of a practice that uses Quzek, that practice — not Quzek — is responsible for your information, and you should direct privacy requests to them. We will support them in responding.

2. Information we collect

Information you give us
• Account and profile data — your name, email address, phone number, practice or business name, role, and password.
• Billing data — plan, billing contact and, where you pay by card, payment details handled by our payment processor (we do not store full card numbers).
• Content you enter — the data your practice records in the Service, which may include client contact details, appointments, clinical and treatment notes, intake and consent answers, uploaded files, and invoices. Some of this may be sensitive or "special category" data, including health information.
• Support and communications — messages you send us and records of our correspondence.

Information we collect automatically
• Usage and log data — actions taken in the Service, timestamps, and diagnostic data used to keep the Service secure and reliable.
• Device and connection data — IP address, browser type, operating system and similar technical information.
• Cookies and similar technologies — see the Cookies section below.

3. How we use information

We use information to:
• provide, operate, maintain and secure the Service;
• authenticate users and enforce role-based access;
• process bookings, reminders, invoices and payments;
• send transactional messages such as appointment confirmations, reminders and receipts;
• provide customer support and respond to your requests;
• monitor, troubleshoot, and improve the Service, and develop new features;
• detect, prevent and respond to fraud, abuse and security incidents;
• send you service and, where permitted, marketing communications (which you can opt out of at any time); and
• comply with our legal obligations and enforce our terms.

We do not sell personal information, and we do not use it for advertising.

4. Legal bases for processing (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies and we act as a controller, we rely on the following legal bases: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, support and improve the Service, balanced against your rights); consent (for optional marketing, which you may withdraw at any time); and legal obligation (to meet accounting, tax and other legal duties). Where we process client information as a processor, the practice (as controller) is responsible for establishing the legal basis.

5. Per-practice isolation

Each practice operates in its own separate, isolated database. Information entered by one practice is never accessible to another practice. Within a practice, access is controlled by role-based permissions that the practice administers, and access to sensitive records is recorded in an audit trail.

6. Sharing and disclosure

We share personal information only in these limited circumstances:
Sub-processors — trusted service providers who help us run the Service, under contract and only as needed (see below).
At your direction — for example, sending an email or SMS on a practice's behalf, or processing a payment.
Legal and safety — where required by law, to respond to lawful requests, or to protect the rights, property or safety of Quzek, our customers or the public.
Business transfers — if Quzek is involved in a merger, acquisition or asset sale, information may transfer as part of that transaction, subject to this policy.

We never sell your personal information.

7. Sub-processors

We engage a limited set of sub-processors to provide the Service, each bound by data-protection obligations consistent with this policy and our Data Processing Agreement. They fall into these categories:

A current list of sub-processors is available on request at [email protected], and we will make reasonable efforts to notify practices of material changes.

8. International data transfers

We may process and store information in countries other than your own. Where we transfer personal information across borders, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (and the UK Addendum) — to ensure it remains protected. Practices requiring a signed Data Processing Agreement, or US healthcare providers requiring a Business Associate Agreement (BAA), can request one — see our Data Processing Agreement or contact us.

9. Data retention

We retain personal information for as long as your practice uses the Service, and afterwards only as needed to comply with legal, accounting or reporting obligations, resolve disputes and enforce our agreements. Practices can configure retention periods within the Service, export their data at any time, and request deletion of their practice's data when they stop using Quzek. Where we anonymise data so it can no longer identify anyone, we may retain and use it without further notice.

10. Security

We protect information with encryption in transit (TLS) and at rest, including field-level encryption of sensitive clinical notes; optional two-factor authentication; automatic session logoff after inactivity; a password policy; role-based access on a need-to-know basis; per-practice database isolation; private file storage served only to authorised users; and an audit trail of access to sensitive records. No system is perfectly secure, but security is designed into the platform. See our Security page for detail.

11. Consent

Where processing relies on consent — such as a client agreeing to a practice's privacy policy or opting in to direct marketing — the Service records that consent with a timestamped, versioned history and allows it to be withdrawn at any time. Withdrawing consent does not affect processing that already took place.

12. Your privacy rights

Depending on where you live, you may have some or all of the following rights over your personal information: to access it, correct it, delete it, export it (data portability), object to or restrict its processing, withdraw consent, and not be discriminated against for exercising your rights. These rights are recognised under regimes including:

Where Quzek is the controller, contact us to exercise these rights (see below). Where a practice is the controller of client information, the Service provides built-in tools — a complete data export and a right-to-erasure (anonymisation) action per client — so the practice can fulfil requests; clients should contact the practice directly, and we will assist that practice. You also have the right to lodge a complaint with your local data-protection authority.

13. Marketing communications

With your consent or where otherwise permitted, we may send you news, offers and product updates. Every marketing email includes an unsubscribe link, and you can opt out at any time. We will still send you essential service messages (for example, security or billing notices) that are necessary to operate your account.

14. Cookies and similar technologies

We use strictly necessary cookies to keep you signed in and to keep the Service secure, and a limited set of functional and analytics cookies to remember preferences and understand usage so we can improve. We do not use advertising or cross-site tracking cookies. You can control cookies through your browser settings, though disabling essential cookies may stop parts of the Service from working.

15. Children’s privacy

The Service is intended for use by health and wellness practices, not by children directly. A practice may record information about a minor client as part of delivering care; that information is handled under the practice's instructions and its own privacy notices and consents. We do not knowingly collect personal information directly from children.

16. Automated decision-making

We do not use your personal information to make decisions that produce legal or similarly significant effects about you based solely on automated processing.

17. Data breach notification

We maintain an incident-response process. If we become aware of a personal-data breach affecting a practice's data, we will notify the affected practice without undue delay and provide the information reasonably needed for it to meet its own notification obligations — for example the GDPR 72-hour authority-notification rule, the Australian Notifiable Data Breaches scheme, or the HIPAA Breach Notification Rule.

18. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology or the law. When we make material changes we will update the date at the top and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.

19. Contact us

If you have questions about this policy, want to exercise your rights, or wish to reach our privacy team (including any data-protection contact), email [email protected]. If you are a client of a practice that uses Quzek, please contact that practice directly, as they control your information.

Privacy questions, answered

Does Quzek sell my data?
No. We never sell personal information and we do not use it for advertising. We use it only to provide, secure and improve the Service.
Who owns the data my practice enters?
Your practice does. Quzek is the processor and custodian; you can export your data at any time and request deletion when you leave.
I’m a patient of a clinic that uses Quzek. Who do I contact about my data?
Contact the practice you booked with — they are the controller of your information. Quzek supports the practice in responding to your request.
Can I get a Data Processing Agreement or a BAA?
Yes. Practices can request a DPA (for GDPR and similar regimes) or a Business Associate Agreement (for US HIPAA) at [email protected].