Privacy Policy

Last updated: March 2026 ยท PAfolio ยท pafolio.co.uk

Summary: PAfolio collects only the data needed to run your GMC portfolio. We never sell your data. We never share it with third parties for marketing. Your clinical information belongs to you.

1. Who we are

PAfolio ("we", "us", "our") is a UK-based digital portfolio platform for Physician Associates and Anaesthesia Associates. PAfolio is operated as a sole trader business in the United Kingdom.

For data protection purposes, we are the Data Controller of your personal information.

Contact: hello@pafolio.co.uk ยท pafolio.co.uk

2. What data we collect

Account information

Portfolio data

Payment information

Payment is processed by Stripe. We do not store your card details. We only receive confirmation that payment was made and your subscription status.

Technical data

3. How we use your data

We never use your data for advertising. We never sell your data. We never share your data with third parties for marketing purposes.

4. Legal basis for processing

Under UK GDPR, we process your data on the following legal bases:

5. Data storage and security

All data is hosted exclusively in the Supabase Ireland (West) region (eu-west-1), providing full EEA/GDPR compliance. Data is encrypted at rest using AES-256 and in transit over HTTPS/TLS.

Passwords are hashed and never stored in plain text. We implement row-level security (RLS) so users can only access their own data. No data is stored outside the EEA.

PAfolio is designed to align with NHS Data Security and Protection Toolkit (DSPT) standards and is registered with the Information Commissioner's Office (ICO).

We retain your data for as long as your account is active. If you close your account, we delete your personal data within 30 days.

6. Third parties we use

Each of these providers is bound by their own GDPR-compliant privacy policies and data processing agreements.

7. Cookies

PAfolio uses only essential cookies required for the service to function:

We do not use advertising cookies, tracking cookies, or any third-party analytics cookies. We do not use Google Analytics or Facebook Pixel.

8. Your rights under UK GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, email us at hello@pafolio.co.uk. We will respond within 30 days.

9. Clinical data โ€” important note

PAfolio stores portfolio evidence including CPD logs, significant event reflections and assessment records. Please ensure:

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. Continued use of PAfolio after changes constitutes acceptance of the updated policy.

11. Complaints

If you have concerns about how we handle your data, please contact us first at hello@pafolio.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Contact us about your data Email: hello@pafolio.co.uk ยท Website: pafolio.co.uk
We aim to respond to all data requests within 30 days.