This policy is written for UK clinics using Seviko and for accounting-app assessments (including Intuit QuickBooks and Xero). It covers the marketing website, the Seviko product, and optional accounting connections such as QuickBooks Online and Xero.
1. Who we are
Seviko (“we”, “us”, “our”) provides cloud practice-management software for independent UK ear care and audiology clinics, at www.sevikouk.com.
Seviko is a trading name of SEVIKO LTD, a company registered in England and Wales (company number 17322349), registered office 14 Norcot Road, Tilehurst, Reading, England, RG30 6BU. We are registered with the UK Information Commissioner’s Office (registration number [ICO REGISTRATION NUMBER]).
For privacy questions, email [email protected]. We have not appointed a statutory Data Protection Officer; privacy matters are handled by the contact above.
2. Who is responsible for your data
UK data protection law distinguishes the controller (who decides why and how personal data is used) from the processor (who acts on the controller’s instructions).
- Clinic and patient records in Seviko. The clinic that holds the Seviko account is the controller. We are the processor. We only process that data to provide the Service, on the clinic’s instructions, and as described in this policy and our end-user licence agreement.
- Website visitors, trial enquiries and account holders. Seviko is the controller of names, emails and similar details you give us directly (for example via the contact form).
- QuickBooks Online. If a clinic connects QuickBooks, the clinic is the controller of the accounting data in its QuickBooks company. Intuit is a separate organisation that provides QuickBooks. We process QuickBooks data solely to provide the integration the clinic has authorised. We do not become the controller of the clinic’s QuickBooks company.
- Xero. If a clinic connects Xero, the clinic is the controller of the accounting data in its Xero organisation. Xero Limited is a separate organisation. We process Xero data solely to provide the integration the clinic has authorised. We do not become the controller of the clinic’s Xero organisation.
3. Data we collect
Account and clinic data
When a clinic starts a trial or uses Seviko we collect account-holder name, email, clinic name, role, login credentials (stored hashed), billing details where relevant, and settings the clinic configures.
Patient and clinical data (on the clinic’s behalf)
Clinics enter patient records, appointments, consent, clinical notes, audiograms, tympanometry, hearing-aid orders, invoices, reminders and related documents. That data may include special-category health data. We process it only as the clinic’s processor.
Website and support
If you contact us or register interest we collect the details you submit, plus basic technical data such as IP address, browser type and pages visited, used to run and secure the site.
Accounting data
If the clinic connects an accounting platform, we collect the data described in the QuickBooks and Xero sections below.
We do not sell personal data. We do not use patient, QuickBooks or Xero data for advertising.
4. QuickBooks Online and Intuit data
Seviko can optionally connect to QuickBooks Online so a clinic can sync bookkeeping data (for example invoices, payments and customer records used for accounts) instead of re-keying it. The connection is authorised by the clinic through Intuit’s OAuth consent screen. It is not required to use Seviko.
What we access
Depending on the permissions the clinic grants, we may read and/or write:
- company information for the connected QuickBooks organisation;
- customers / contacts used for invoicing;
- items or services, tax codes and chart of accounts needed to post invoices correctly;
- invoices, credit notes, payments and related accounting transactions the clinic chooses to sync.
We do not send patient clinical records, audiograms, consent forms or clinical notes to Intuit. Only accounting information the clinic elects to sync is exchanged with QuickBooks.
How we use it
We use QuickBooks data only to:
- create, update or match invoices, payments and customer records between Seviko and the clinic’s QuickBooks company;
- show sync status and resolve mapping or error messages in the clinic’s Seviko account;
- maintain an audit of what was synced, so the clinic can see what happened.
We do not use Intuit or QuickBooks data to market to anyone, to train general-purpose AI models, or to build products for other clinics. One clinic’s QuickBooks data is never visible to another clinic.
How we share it
QuickBooks data stays in the clinic’s Seviko tenant and is transmitted to Intuit only as needed to perform the sync the clinic requested. We do not sell it, rent it, or share it with third parties for their own purposes. Sub-processors we use to host or operate Seviko may process it solely to run the Service, under written contracts.
Disconnecting and deletion
A clinic can disconnect QuickBooks at any time from Seviko’s accounting settings, and can also revoke Seviko’s access from the clinic’s Intuit account. After disconnect:
- we stop accessing the clinic’s QuickBooks company;
- we do not make further API calls with that connection;
- copies of accounting data already stored in Seviko (for example an invoice that originated in the clinic) remain as part of the clinic’s Seviko records until the clinic deletes them or the account is closed, subject to the retention rules below;
- OAuth tokens are revoked and discarded.
Data that has already been written into the clinic’s QuickBooks company remains under the clinic’s QuickBooks subscription and Intuit’s terms. We cannot delete data from Intuit’s systems on the clinic’s behalf; the clinic manages that in QuickBooks.
Intuit’s role
Intuit is not affiliated with Seviko. Use of QuickBooks is governed by Intuit’s own terms and Intuit Privacy Statement. Intuit is not responsible for Seviko, and we are not responsible for QuickBooks.
5. Xero data
Seviko can optionally connect to Xero so a clinic can sync bookkeeping data (for example invoices, payments and contacts used for accounts) instead of re-keying it. The connection is authorised by the clinic through Xero’s OAuth consent screen. It is not required to use Seviko.
What we access
Depending on the permissions the clinic grants, we may read and/or write:
- organisation information for the connected Xero organisation;
- contacts used for invoicing;
- items or services, tax rates and chart of accounts needed to post invoices correctly;
- invoices, credit notes, payments and related accounting transactions the clinic chooses to sync.
We do not send patient clinical records, audiograms, consent forms or clinical notes to Xero. Only accounting information the clinic elects to sync is exchanged with Xero.
How we use it
We use Xero data only to:
- create, update or match invoices, payments and contacts between Seviko and the clinic’s Xero organisation;
- show sync status and resolve mapping or error messages in the clinic’s Seviko account;
- maintain an audit of what was synced, so the clinic can see what happened.
We do not use Xero data to market to anyone, to train general-purpose AI models, or to build products for other clinics. One clinic’s Xero data is never visible to another clinic.
How we share it
Xero data stays in the clinic’s Seviko tenant and is transmitted to Xero only as needed to perform the sync the clinic requested. We do not sell it, rent it, or share it with third parties for their own purposes. Sub-processors we use to host or operate Seviko may process it solely to run the Service, under written contracts.
Disconnecting and deletion
A clinic can disconnect Xero at any time from Seviko’s accounting settings, and can also revoke Seviko’s access from Xero (connected apps). After disconnect:
- we stop accessing the clinic’s Xero organisation;
- we do not make further API calls with that connection;
- copies of accounting data already stored in Seviko (for example an invoice that originated in the clinic) remain as part of the clinic’s Seviko records until the clinic deletes them or the account is closed, subject to the retention rules below;
- OAuth tokens are revoked and discarded.
Data that has already been written into the clinic’s Xero organisation remains under the clinic’s Xero subscription and Xero’s terms. We cannot delete data from Xero’s systems on the clinic’s behalf; the clinic manages that in Xero.
Xero’s role
Xero is not affiliated with Seviko. Use of Xero is governed by Xero’s own terms and Xero Privacy Notice. Xero is not responsible for Seviko, and we are not responsible for Xero.
6. How we use personal data
- to provide, maintain and support the Service;
- to set up trials, accounts and clinic configuration;
- to send service messages (for example security, billing and product changes) — not marketing, unless you have asked us to;
- to reply to enquiries and provide support;
- to keep an audit trail, manage consent records and help clinics meet UK GDPR, DPA 2018 and clinical-record duties;
- to run optional integrations the clinic connects, including QuickBooks Online and Xero;
- to protect the Service against abuse, and to comply with law.
Arli, our optional AI assistant on the Supreme plan, is designed so that it does not receive patient-identifiable data. It is not used to analyse QuickBooks or Xero data for any purpose other than helping the clinic operate its own account, where that feature is enabled.
7. Lawful bases
Where Seviko is the controller, we rely on:
- Contract — to provide the Service you have asked for;
- Legitimate interests — to secure the Service, improve it in aggregate, and reply to enquiries, where those interests are not overridden by your rights;
- Consent — where we ask for it (for example optional marketing email);
- Legal obligation — where we must keep or disclose information by law.
Where we are the clinic’s processor, the clinic is responsible for its own lawful basis, including for special-category health data (typically healthcare provision and associated legal duties).
8. Who we share data with
We share personal data only as needed to run the Service:
- Hosting and infrastructure in the United Kingdom, to store and operate Seviko;
- Email, SMS and similar providers the clinic uses for reminders, where the clinic has enabled them;
- Intuit / QuickBooks Online, if the clinic connects that integration;
- Xero, if the clinic connects that integration;
- Other integrations the clinic enables (for example payment providers), under that provider’s terms;
- Professional advisers or authorities where required by law or to protect rights.
Staff access is role-based and limited to what is needed for support and operations. We do not share one clinic’s data with another clinic.
We keep a current list of the sub-processors we use to host and operate Seviko, with each provider’s purpose and processing location, on our sub-processors page. We put a written data-processing contract in place with each of them and notify account holders before adding or replacing one that processes clinic data.
9. International transfers
Patient and clinic records in Seviko — including the main database and backups — are stored in UK data centres (London). Uploaded files and documents are held in object storage located in the European Economic Area (EU). Seviko records are kept within the UK/EEA and are not stored outside it.
Some optional features transmit limited personal data outside the UK when the clinic enables them. In particular, if a clinic uses SMS or messaging reminders, the recipient’s name, contact number and appointment details are passed to the messaging provider, which may process them outside the UK under its own terms. This is transmission to deliver a message the clinic requested, not storage of clinical records abroad. Where such a provider processes personal data from outside the UK, we rely on a lawful transfer mechanism (see below).
If a clinic connects QuickBooks Online, accounting data the clinic chooses to sync is sent to Intuit. Intuit may process that data outside the UK in line with its own privacy statement and the terms the clinic accepted with Intuit. That transfer happens because the clinic chose to connect QuickBooks, not because we host clinical records abroad.
If a clinic connects Xero, accounting data the clinic chooses to sync is sent to Xero. Xero may process that data outside the UK in line with its own privacy notice and the terms the clinic accepted with Xero. That transfer happens because the clinic chose to connect Xero, not because we host clinical records abroad.
Where a sub-processor must see personal data from outside the UK, we use a lawful transfer mechanism (such as the UK International Data Transfer Addendum) and limit what they can access.
10. How long we keep data
- Website enquiries — as long as needed to respond and for a short follow-up period, unless you become a customer.
- Clinic accounts — for the life of the account. After closure we retain data only as needed to wind down the account, resolve disputes, and meet legal obligations, then delete or irreversibly anonymise it.
- Clinical records — retained according to the clinic’s settings and UK professional norms (Seviko’s default tooling supports 8 years for adults and until age 25 for children). Records are archived rather than hard-deleted while those duties apply.
- QuickBooks and Xero tokens — until the clinic disconnects the relevant integration or the account is closed.
- Synced accounting copies in Seviko — as part of the clinic’s records, on the same basis as other clinic data, unless the clinic deletes them sooner.
11. Security
We use encryption in transit and at rest, access controls, audit logging, and UK hosting for Seviko records. No method of transmission or storage is perfectly secure; we work to protect data to a standard appropriate to health and accounting information.
Intuit and Xero credentials, OAuth tokens, and app secrets are stored securely and are not exposed in the product interface. A clinic should also protect its own QuickBooks, Xero and Seviko user roles.
If we become aware of a personal-data breach we will notify the affected clinic without undue delay, and — where we are the controller — notify the ICO within 72 hours and affected individuals where required, in line with UK GDPR.
12. Your rights
Under UK GDPR you can ask for access, correction, deletion, restriction, objection, or portability of personal data, and you can withdraw consent where we rely on it. Those rights are not always absolute.
- If you are a clinic user or website visitor, email [email protected].
- If you are a patient of a clinic that uses Seviko, contact that clinic. They are the controller. We will help the clinic fulfil subject-access and similar requests (Seviko includes SAR export tooling for this).
You can also complain to the Information Commissioner’s Office at ico.org.uk.
13. Cookies
The public website uses only cookies (or similar) that are needed to operate the site, remember essential preferences, and submit forms. We do not use advertising cookies. The Seviko application uses session and security cookies required to keep you signed in and protect the account.
14. Children
Seviko is a professional tool for clinics, not a consumer app aimed at children. Clinics may hold records about child patients. That data is processed on the clinic’s instructions as described above. The public website is not directed at children.
15. Changes
We may update this policy as the product or the law changes. The “last updated” date at the top will change. Material changes will be notified to account holders by email or in-product notice where appropriate.
16. Contact and complaints
Privacy and data-protection requests: [email protected].
If we cannot resolve a concern, you may contact the ICO. If your concern is about data inside QuickBooks, you may also need to contact Intuit or use QuickBooks’ own account tools. If it is about data inside Xero, you may need to contact Xero or use Xero’s own account tools.
Related: End-user licence agreement.