Felgate Back to site

Legal

Privacy Policy

Version 0.2-draft · Effective 4 June 2026 · Operator: Andrei Trimbitas trading as Old Forge Technologies

Draft pending legal review. Felgate is finalising these terms with a solicitor. They are published for transparency; the binding version will carry a confirmed effective date.

This Privacy Policy explains how Andrei Trimbitas trading as Old Forge Technologies ("Felgate", "we", "us") handles personal data for which we are the controller: the data of practitioners who hold an account, their billing data, and visitors to our websites (felgate.co.uk, app.felgate.co.uk).

Scope note. When a practitioner uses Felgate to manage their clients, the practitioner is the data controller for their clients' data and we are the processor. That processing is governed by our Data Processing Agreement and the practitioner's own privacy notice - not by this policy. If you are a client of a practitioner, please refer to that practitioner's privacy information.

1. Who we are and how to contact us

Controller: Andrei Trimbitas trading as Old Forge Technologies, The Old Forge, Newmarket Road, Kennett, CB8 7PP, United Kingdom. Privacy contact: legal@felgate.co.uk.

2. The data we collect (as controller)

  • Account data - name, email, practice name, subdomain, password (hashed), MFA settings, role and preferences.
  • Billing data - plan, subscription status and payment metadata. Card details are handled by Stripe; we do not store full card numbers.
  • Usage and technical data - log data, IP address, device/browser information and actions taken in the control plane, used to run, secure and improve the Service.
  • Communications - emails and support messages you send us.

In our capacity as controller we do not seek to collect your clients' special-category health data for our own purposes; that data belongs to your tenant and is processed under the DPA.

3. Why we use it, and our lawful basis

PurposeLawful basis (UK GDPR)
Create and run your account, provide the ServiceContract (Art 6(1)(b))
Take payment, manage subscriptions, prevent fraudContract; Legal obligation; Legitimate interests
Secure the platform, prevent abuse, keep logsLegitimate interests (Art 6(1)(f))
Support and service communicationsContract; Legitimate interests
Sync an optional connected calendar you asked us to connect (§6)Contract; Consent (you choose to connect, and can disconnect)
Product analytics and improvementLegitimate interests
Marketing emails to practitioners (not clients)Consent or soft opt-in; unsubscribe anytime
Comply with law, respond to lawful requestsLegal obligation

4. Cookies and similar technologies

We use only strictly-necessary cookies to run the Service: a session cookie to keep you logged in; a "remember me" cookie (up to 30 days) if you choose it; and a CSRF token to protect forms. These are exempt from consent under PECR because they are essential to a service you have requested. We do not use advertising or third-party tracking cookies, and we do not currently use analytics cookies. If we introduce non-essential cookies we will ask for your consent first through a cookie banner and update this policy.

5. Who we share it with

RecipientPurposeLocation / safeguard
StripePayment processingSafeguarded under UK transfer mechanisms
IONOSDomain / DNS for tenant subdomainsUK / EU
Email providerTransactional & onboarding emailUK / EU preferred
Backup provider (if used)Encrypted off-site backupsUK / EU preferred
GoogleCalendar sync - only if the practitioner connects a Google account (see §6)Google LLC / Google Ireland Ltd, under its own safeguards
Professional advisers, authoritiesLegal, accounting, regulatoryAs required by law

Core hosting is self-managed by Andrei Trimbitas trading as Old Forge Technologies, which limits the number of third parties touching the data. We do not sell personal data. A current sub-processor list for client data is in the DPA.

6. Google Calendar and other connected accounts

Connecting a Google account is optional and entirely the practitioner's choice. Nothing in this section applies unless a practitioner connects one, and disconnecting stops all of it.

What we access

When a practitioner connects Google Calendar from their portal, they grant Felgate these Google OAuth scopes:

ScopeWhat we do with it
calendar.eventsCreate, update and delete the calendar events that correspond to appointments booked in Felgate, and read the events in the practitioner's chosen calendar so their Felgate agenda shows their whole day.
calendar.readonlyList the calendars on the account so the practitioner can pick which one to sync, and query free/busy so a slot the practitioner is already committed to cannot be booked by a client.
userinfo.emailDisplay which Google account is connected, so the practitioner can confirm they linked the right one.

What we send to Google

Only what an appointment needs: the client's first name only - never a surname, contact details, or any health information - plus the appointment's start and end time, the practice name, the meeting link if there is one, and any note the practitioner themselves added to the booking. A practitioner's calendar is often visible to a partner or on a shared screen, so the event is deliberately thin.

What we read back, and what we keep

Free/busy intervals, and - if the practitioner enables the agenda option - the title and time of events in the chosen calendar, read on demand at the moment they are needed. Google calendar content is not stored in our database, not written to logs, and never shown to clients. What we do store is the OAuth refresh token, the connected account's email address, and the chosen calendar id. These live in that practitioner's own tenant database, encrypted at rest with that tenant's own encryption key. Tokens are never pooled or exchanged centrally, and one practice's connection is not reachable from another's.

Limited use

Felgate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:

  • use Google user data for advertising, or sell or transfer it;
  • use it for any purpose other than providing and improving the calendar-sync features described above, which are user-facing and prominent in the product;
  • allow humans to read it, except with the practitioner's explicit permission for a support request they have raised, where required by law, or where necessary for security (for example, investigating abuse);
  • use it to develop, improve or train generalised AI or machine-learning models.

Turning it off

A practitioner can disconnect at any time from Calendar sync in their portal. We revoke the token with Google and delete our copy immediately. They can also revoke access directly from their Google Account at myaccount.google.com/permissions. Events Felgate has already created remain in the practitioner's calendar unless they delete them there.

7. International transfers

Where a recipient processes data outside the UK we rely on an approved transfer mechanism (UK adequacy regulations or the International Data Transfer Agreement / UK Addendum to the EU SCCs) and, following the Data (Use and Access) Act 2025, apply the "not materially lower" protection test. We prefer UK/EU regions for email and backups.

8. How long we keep it

We keep account and billing data while you have an account, then only as long as needed for legal, accounting and tax purposes (generally up to 6-7 years for financial records). Logs are kept for a limited period for security. Retention of your clients' data is governed by your tenant settings and the DPA.

9. Your rights

Under UK data protection law you can ask to access, rectify, erase or restrict your personal data, to object to certain processing, to portability, and to withdraw consent. Contact legal@felgate.co.uk; we respond within statutory timescales. You can also complain to the ICO (ico.org.uk), though we would appreciate the chance to help first. If your request concerns data held in your clients' records, you are the controller - use the in-product export and erasure tools.

10. Security

We protect personal data with encryption in transit (TLS) and at rest (special-category fields encrypted with per-tenant keys), access controls, multi-factor authentication, tenant isolation, monitoring and backups. No system is perfectly secure; we keep our measures under review. Our security commitments to practitioners as a processor are set out in the DPA.

11. Children

The Service is for practitioners (adults) and is not directed at children. Where a practitioner's client is a minor, the practitioner is the controller and is responsible for the appropriate consent and safeguards.

12. Changes

We may update this policy. The version and effective date are at the top. Material changes will be notified by email or in-product.


Questions about this document? Contact legal@felgate.co.uk.

© 2026 Felgate · An Old Forge Technologies venture Terms Privacy DPA Acceptable Use