Document version 1.0 · Last updated 18 September 2026 · Next review 18 September 2027
1. INTRODUCTION
1.1 This Privacy Notice explains how the Federation of Independent Practitioner Organisations (“we”, “us”, “our”, or the “Federation”) collects, uses, stores, and protects your personal information when you use our litigation funding and registration platform at fipo.uk (the “Website”).
1.2 We are committed to protecting your privacy and complying with data protection laws, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
1.3 Please read this Privacy Notice carefully before providing any personal information through our Website. By using our Website and providing your information, you acknowledge that you have read and understood this Privacy Notice.
2. WHO WE ARE
2.1 Data Controller:
Federation of Independent Practitioner Organisations
Company Number: 4148752
Registered Office: 2 St Marys Road, Tonbridge, Kent TN9 2LB
Email: office@fipo.uk
Telephone: 020 7205 4166
2.2 We are the data controller for the personal information you provide through this Website. This means we are responsible for deciding how we hold and use your personal information.
2.3 Data Protection Officer:
Data Protection Officer
Email: office@fipo.uk
Address: 2 St Marys Road, Tonbridge, Kent TN9 2LB
2.4 You can contact our Data Protection Officer if you have any questions about this Privacy Notice or how we handle your personal information.
3. WHAT PERSONAL INFORMATION WE COLLECT
We collect and process the following categories of personal information:
3.1 Registration and Account Information
When you register for an account on our Website, we collect:
- Full name
- Email address
- Telephone number (mobile and/or landline)
- Practice address(es)
- GMC (General Medical Council) registration number
- Professional qualification details
- Specialty and sub-specialty
- Professional organisation membership details
- Username and password (password stored in encrypted form only)
3.2 Professional Practice Information
To assess eligibility and calculate potential damages, we collect:
- Years qualified and in practice
- Current employment status (NHS/private/mixed)
- Private Medical Insurance (PMI) provider relationships
- Approximate percentage of income from PMI work
- Practice size and patient volume (approximate)
- Geographic location of practice
- Specialisation and service types offered
- Estimated annual income ranges (optional)
- Estimated financial losses from PMI restrictions
3.3 Financial Information
For litigation funding contributions, we collect:
- Payment method selection (PayPal, BACS Direct Debit)
- Payment confirmation details
- Contribution amount
- Payment date and status
Important: We do NOT store complete credit card or bank account numbers. Payment processing is handled by secure third-party payment processors (PayPal, Stripe) who maintain their own secure systems. We receive only transaction confirmation details.
3.4 Uploaded Documents
You may upload the following documents to our Website:
- Proof of identity (passport, driving licence, other photo ID)
- GMC registration certificate
- Signed Deed of Assignment with witness details
- Witness identification documents
- Professional organisation membership certificates
- PMI provider agreements and contracts
- Fee schedules and payment records
- Correspondence with PMI providers
- Practice income evidence (tax returns, accounts – optional)
- Other supporting documentation
Legal Professional Privilege: Some documents you upload may be legally privileged communications with solicitors. We treat all uploaded documents as potentially privileged and maintain appropriate confidentiality safeguards.
3.5 Identity Verification Information
To verify your identity and professional credentials:
- GMC Register verification results
- Professional registration status checks
- Referral code information (linked to affiliated organisation)
- IP address at time of registration
- Device information (browser type, operating system)
3.6 Legal Documents and Consents
- Executed Deed of Assignment (with electronic signature)
- Witness details for Deed execution
- Consent records (to assignment, data processing, participation)
- Acknowledgments of terms and conditions
- Tax implications acknowledgments
- Litigation participation agreements
3.7 Communication Records
- Email correspondence with you
- Support queries and responses
- Telephone call records (if you contact us)
- Messages sent through the Website
- Notification preferences
3.8 Website Usage Information
3.9 We automatically collect certain information when you visit our Website:
- IP address
- Browser type and version
- Operating system
- Pages visited and time spent
- Date and time of access
- Device type (desktop, mobile, tablet)
- Clickstream data
3.10 Cookies and Similar Technologies
We use cookies and similar tracking technologies. See Section 12 for detailed information about our cookie practices.
4. HOW WE COLLECT YOUR INFORMATION
We collect personal information through:
4.1 Direct Provision
Information you provide directly when you:
- Register for an account
- Complete registration forms
- Upload documents
- Execute the Deed of Assignment electronically
- Make payment contributions
- Contact us via email, phone, or contact forms
- Update your account or preferences
4.2 Automated Collection
Information collected automatically when you:
- Visit our Website (usage data, cookies)
- Navigate through pages
- Download documents or forms
4.3 Third-Party Sources
Information we receive from:
- GMC Register: Professional registration verification
- Payment processors: Payment confirmation (PayPal, Stripe)
- Professional organisations: Membership verification (with your consent)
- Our legal advisors: Case-related information
- Referral organisations: Confirmation of legitimate referral codes
4.4 Public Sources
- GMC Register (publicly available professional registration data)
- Professional directory listings (where applicable)
5. LEGAL BASIS FOR PROCESSING YOUR INFORMATION
Under UK GDPR, we must have a lawful basis to process your personal information. We rely on the following legal bases:
5.1 Contract (Article 6(1)(b))
- Processing necessary for the performance of a contract with you, specifically:
- Managing your registration and account
- Processing your assignment of legal claims to the Federation
- Managing your participation in collective litigation
- Processing your contribution payments
- Providing access to your account dashboard
5.2 Legal Obligation (Article 6(1)(c))
Processing necessary to comply with legal obligations, including:
- Financial record-keeping requirements
- Tax reporting obligations
- Anti-money laundering checks
- Court orders or regulatory requirements
- Disclosure obligations in litigation
5.3 Legitimate Interests (Article 6(1)(f))
Processing necessary for our legitimate interests or those of a third party, including:
- Fraud prevention and detection
- Network and information security
- Enforcing our legal rights
- Managing and administering the litigation effectively
- Improving our Website and services
- Communicating about the litigation progress
Balancing Test: We have carefully balanced our legitimate interests against your rights and freedoms. We only rely on legitimate interests where your rights do not override our interests.
5.4 Consent (Article 6(1)(a))
Where we rely on your consent, you have the right to withdraw consent at any time. We rely on consent for:
- Non-essential cookies and analytics
- Marketing communications (if any – we do not currently send marketing)
- Sharing information beyond litigation requirements
- Optional data processing activities
5.5 Legal Claims (Article 9(2)(f) for Special Category Data)
For special category data (if any is inadvertently collected), we may rely on:
- Establishment, exercise, or defence of legal claims
- Substantial public interest (Article 9(2)(g))
Special Category Data: We do not intentionally collect special category data (health data, racial/ethnic origin, political opinions, religious beliefs, etc.). If such data is inadvertently included in documents you upload, we process it only to the extent necessary for the litigation.
6. HOW WE USE YOUR INFORMATION
6.1 Litigation Purposes
We use your information to:
- Assess your eligibility to participate in the litigation
- Verify your professional credentials and identity
- Process your assignment of claims via Deed of Assignment
- Calculate your potential individual damages
- Prepare evidence for court proceedings
- Instruct expert witnesses
- Communicate with defendants
- Distribute damages if litigation is successful
- Manage settlement negotiations
6.2 Financial Management
We use your information to:
- Process contribution payments
- Track funding threshold progress
- Manage trust accounting obligations
- Process refunds if minimum threshold not reached
- Calculate cost recovery and distribution ratios
- Provide financial reports to solicitors and auditors
- Comply with tax reporting requirements
6.3 Website and Account Management
We use your information to:
- Create and manage your user account
- Provide access to secure member areas
- Authenticate your identity when you log in
- Send account-related notifications
- Respond to your queries and support requests
- Improve Website functionality and user experience
6.4 Communication
We use your information to:
- Send important updates about the litigation
- Notify you of required actions or documents
- Respond to your inquiries
- Provide litigation progress reports
- Send confirmation emails (registration, payment, document uploads)
- Notify you of changes to terms or policies
Marketing: We do NOT use your information for marketing purposes. All communications relate to the litigation or your account.
6.5 Verification and Fraud Prevention
We use your information to:
- Verify your GMC registration and professional status
- Validate referral codes
- Detect duplicate or fraudulent registrations
- Prevent unauthorised access to the Website
- Protect against cyber attacks and security breaches
- Monitor for suspicious activity
6.6 Legal and Regulatory Compliance
We use your information to:
- Comply with court orders and legal obligations
- Respond to regulatory inquiries
- Maintain audit trails
- Respond to Solicitors Regulation (“SRA”) inquiries and requirements (in consultation with our legal advisors)
- Meet data protection obligations
- Defend legal claims
6.7 Analysis and Improvement
We use aggregated or anonymised information to:
Analyse registration trends and patterns
- Improve Website functionality
- Identify technical issues
- Optimise user experience
- Assess litigation participation demographics
8. INTERNATIONAL TRANSFERS
8.1 UK-Based Processing: We process your personal information primarily within the United Kingdom.
8.2 Limited International Transfers: Some service providers may process data outside the UK/EEA, including:
- Cloud storage providers (e.g., AWS, Google Cloud) – may have servers globally
- Payment processors (PayPal, Stripe) – US-based companies with global operations
- Email services – may route through international servers.
8.3 Safeguards for International Transfers: Where we transfer personal information outside the UK, we ensure appropriate safeguards including:
- Adequacy Decisions: Transfers to countries with UK adequacy decisions (e.g., EEA countries, specific approved countries)
- Standard Contractual Clauses: EU Commission approved contracts between us and the recipient
- UK International Data Transfer Agreement: ICO-approved transfer agreements
- Service Provider Certifications: Processors certified under recognised frameworks.
8.4 You can obtain information about specific safeguards by contacting our Data Protection Officer.
9. HOW LONG WE KEEP YOUR INFORMATION
We retain your personal information for different periods depending on the purpose:
9.1 During Active Litigation
Retention Period: Throughout the litigation and until final resolution (including appeals)
Reason: Necessary for legal claims and litigation management
9.2 Post-Litigation
Retention Period: 7 years after final resolution of litigation
Reason:
- Limitation periods for potential claims
- Regulatory and tax requirements
- Professional indemnity insurance requirements
- Audit and compliance needs
9.3 Financial Records
Retention Period: Minimum 7 years from end of financial year
Reason: Tax law requirements, trust accounting obligations
9.4 Legal Documents
Retention Period: Deed of Assignment and related legal documents retained permanently or for limitation period (12 years for deeds)
Reason: Legal enforceability, proof of assignment
9.5 If Litigation Not Commenced
Retention Period: 3 years if litigation does not commence
Reason: Administrative purposes, potential future litigation, regulatory
9.6 Website Account Data
Retention Period: Deleted 1 year after litigation conclusion (subject to legal document retention requirements above)
Reason: No ongoing need for account access
9.7 Communications
Retention Period: 7 years from date of communication
Reason: Evidence of notifications, compliance records
9.8 Cookies and Analytics
Retention Period: Up to 26 months for analytics data
Reason: Statistical analysis, Website improvement
9.9 Secure Deletion: When retention periods expire, we securely delete or anonymise your information using industry-standard deletion methods.
Exceptions: We may retain information beyond these periods if:
- Required by law or court order
- Necessary to defend legal claims
- You have consented to longer retention
- Anonymised for statistical purposes (no longer personal data)
10. YOUR RIGHTS UNDER DATA PROTECTION LAW
You have the following rights regarding your personal information:
10.1 Right of Access (Article 15)
You have the right to:
- Obtain confirmation whether we process your personal information
- Access your personal information
- Receive information about how we use your data
How to exercise: Submit a Subject Access Request to our Data Protection Officer. We will respond within one month (extendable by two months for complex requests).
What we provide: Copy of your personal information in commonly used electronic format (usually PDF).
10.2 Right to Rectification (Article 16)
You have the right to:
- Correct inaccurate personal information
- Complete incomplete personal information
How to exercise: Log into your account and update information directly, or contact us with corrections.
Timeframe: We will correct errors within one month.
10.3 Right to Erasure / “Right to be Forgotten” (Article 17)
You have the right to request deletion of your personal information in certain circumstances.
IMPORTANT LIMITATION – Litigation Context:
Your right to erasure is significantly limited because we process your information for legal claims. Under Article 17(3)(e), we can refuse erasure where processing is necessary for:
Establishment, exercise, or defence of legal claims
This means we cannot delete your information while:
- Litigation is active or contemplated
- Limitation periods are running
- We have legal/regulatory retention obligations
Limited Erasure Available:
- If you withdraw before litigation commences AND minimum threshold not reached
- After all retention periods have expired
- For information not necessary for legal claims (e.g., marketing preferences if we ever collect them)
10.4 Right to Restriction of Processing (Article 18)
You have the right to request we restrict processing of your personal information in certain circumstances:
- You contest the accuracy of data (restriction while we verify)
- Processing is unlawful but you don’t want erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (restriction while we verify grounds)
Effect: We store the data but don’t actively process it (except with your consent or for legal claims).
10.5 Right to Data Portability (Article 20)
You have the right to:
- Receive personal information you provided in structured, commonly used format
- Transmit that data to another controller
Limitations:
- Only applies to information YOU provided (not information we generated)
- Only where processing is based on consent or contract
- Only for automated processing
Practical application: Limited in litigation context as most processing is for legal claims, not based on consent.
10.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests.
IMPORTANT LIMITATION:
You cannot object to processing that is:
- Necessary for legal claims (litigation)
- Required by legal obligation
- Necessary for contract performance
Where you CAN object:
- Marketing (though we don’t do marketing)
- Some analytics and profiling (limited application here)
10.7 Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal effects.
Our Position: We do NOT use automated decision-making or profiling that produces legal effects. All significant decisions involve human review.
10.8 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time.
- Effect: We will stop processing for that purpose (but can continue for other lawful purposes).
- Limitations: Cannot withdraw consent for processing necessary for legal claims or legal obligations.
10.9 Right to Complain
You have the right to lodge a complaint with the supervisory authority:
Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
Our Preference: We encourage you to contact us first so we can try to resolve your concern.
11. HOW TO EXERCISE YOUR RIGHTS
11.1 Contact Methods:
Email: office@fipo.uk
Post: Data Protection Officer, Federation of Independent Practitioner Organisations, 2 St Marys Road, Tonbridge, Kent TN9 2LB
Online Form: Contact page
11.2 What to Include:
- Your full name and contact details
- Description of your request
- Proof of identity (to protect your information)
- Account username (if applicable)
11.3 Our Response:
- Timeframe: One month (extendable to three months for complex requests)
- Free of charge: Generally no fee (we may charge for manifestly unfounded or excessive requests)
- Verification: We may request additional information to verify your identity.
13. SECURITY MEASURES
We take the security of your personal information seriously and implement appropriate technical and organisational measures:
13.1 Technical Measures
- Encryption: All data transmission uses HTTPS/SSL encryption
- Secure Storage: Encrypted storage for sensitive documents and data
- Access Controls: Role-based access limiting who can view data
- Firewalls: Web application firewall protection
- Security Monitoring: 24/7 monitoring for threats and intrusions
- Regular Updates: Security patches and software updates
- Backup Systems: Regular encrypted backups stored securely
- Authentication: Strong password requirements, optional two-factor authentication
- Antivirus/Malware: Protection against malicious software
13.2 Organisational Measures
- Staff Training: Data protection training for all personnel with data access
- Confidentiality Agreements: All staff and contractors bound by confidentiality
- Access Logs: Audit trails of who accesses personal information
- Data Minimisation: We collect only information necessary for purposes
- Need-to-Know: Access granted only to those who require it
- Incident Response Plan: Procedures for handling security breaches
- Vendor Management: Security assessment of third-party processors
- Physical Security: Secure facilities for any physical records
13.3 Security Limitations
- No Absolute Security: Despite our measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security.
- Your Responsibility:
- Keep your login credentials confidential
- Use a strong, unique password
- Log out after using shared devices
- Report suspicious activity immediately
- Keep your email account secure (password reset emails)
13.4 Data Breach Notification:
If a personal data breach occurs that is likely to result in high risk to your rights:
- We will notify you without undue delay
- We will notify the ICO within 72 hours of becoming aware
- We will provide information about the breach and steps taken
- We will advise on measures you can take to protect yourself.
14. CHILDREN’S PRIVACY
14.1 Our Website is not intended for children under 18 years of age.
14.2 We do not knowingly collect personal information from anyone under 18. Registration for participation in the Litigation is only for qualified medical professionals.
14.3 If we become aware we have inadvertently collected information from someone under 18, we will delete it promptly.
15. LINKS TO OTHER WEBSITES
15.1 Our Website may contain links to third-party websites (e.g., GMC Register, payment processors, legal resources).
15.2 Important: We are not responsible for the privacy practices of other websites. This Privacy Notice applies only to our Website.
15.3 Recommendation: Read the privacy policy of any website you visit after leaving ours.
16. CHANGES TO THIS PRIVACY NOTICE
16.1 We may update this Privacy Notice from time to time to reflect:
- Changes in law or regulation
- Changes to our practices
- New features or services
- Feedback or complaints.
16.2 Notification of Changes:
- Material Changes: We will notify you by email or prominent Website notice
- Minor Changes: Updated version posted on Website with new “Last Updated” date
- Your Responsibility: Review this Privacy Notice periodically
- Continued Use: Your continued use of the Website after changes constitutes acceptance of the updated Privacy Notice.
16.3 Archives: Previous versions available on request from our Data Protection Officer.
17. CONTACT INFORMATION
17.1 Data Protection Queries
Data Protection Officer:
Data Protection Officer
Federation of Independent Practitioner Organisations
2 St Marys Road, Tonbridge, Kent TN9 2LB
Email: office@fipo.uk
Tel: 020 7205 4166
17.2 General Website Queries
Email: office@fipo.uk
Tel: 020 7205 4166
Website: fipo.uk
17.3 Litigation Queries
17.4 For questions about the litigation itself (not data protection):
Email: fipo@harcusparker.co.uk
Tel: 020 7205 4166
17.5 Complaints
First Step: Contact our Data Protection Officer
Supervisory Authority:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk
18. YOUR ACCEPTANCE OF THIS PRIVACY NOTICE
18.1 By using our Website, registering for an account, and providing personal information, you acknowledge that:
- ✓ You have read and understood this Privacy Notice
- ✓ You consent to the collection, use, and disclosure of your information as described
- ✓ You understand your rights and how to exercise them
- ✓ You understand the limitations on your rights in the litigation context
- ✓ You understand information may be disclosed in court proceedings
If you do not agree with this Privacy Notice, please do not use our Website or provide personal information.
Document Version: 1.0
Last Updated: 18 September 2026
Next Review Date: 18 September 2027
This Privacy Notice has been prepared in accordance with UK GDPR, the Data Protection Act 2018, and guidance from the Information Commissioner’s Office. It has been reviewed by Harcus Parker as legal advisers to the litigation.
