FIPO – Federation of Independent Practitioner OrganisationsHarcus Parker

PRIVACY POLICY

Document version 1.0 · Last updated 18 September 2026 · Next review 18 September 2027

1. INTRODUCTION

1.1 This Privacy Notice explains how the Federation of Independent Practitioner Organisations (“we”, “us”, “our”, or the “Federation”) collects, uses, stores, and protects your personal information when you use our litigation funding and registration platform at fipo.uk (the “Website”).

1.2 We are committed to protecting your privacy and complying with data protection laws, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

1.3 Please read this Privacy Notice carefully before providing any personal information through our Website. By using our Website and providing your information, you acknowledge that you have read and understood this Privacy Notice.

2. WHO WE ARE

2.1 Data Controller:
Federation of Independent Practitioner Organisations
Company Number: 4148752
Registered Office: 2 St Marys Road, Tonbridge, Kent TN9 2LB
Email: office@fipo.uk
Telephone: 020 7205 4166

2.2 We are the data controller for the personal information you provide through this Website. This means we are responsible for deciding how we hold and use your personal information.

2.3 Data Protection Officer:
Data Protection Officer
Email: office@fipo.uk
Address: 2 St Marys Road, Tonbridge, Kent TN9 2LB

2.4 You can contact our Data Protection Officer if you have any questions about this Privacy Notice or how we handle your personal information.

3. WHAT PERSONAL INFORMATION WE COLLECT

We collect and process the following categories of personal information:

3.1 Registration and Account Information

When you register for an account on our Website, we collect:

  1. Full name
  2. Email address
  3. Telephone number (mobile and/or landline)
  4. Practice address(es)
  5. GMC (General Medical Council) registration number
  6. Professional qualification details
  7. Specialty and sub-specialty
  8. Professional organisation membership details
  9. Username and password (password stored in encrypted form only)

3.2 Professional Practice Information

To assess eligibility and calculate potential damages, we collect:

  1. Years qualified and in practice
  2. Current employment status (NHS/private/mixed)
  3. Private Medical Insurance (PMI) provider relationships
  4. Approximate percentage of income from PMI work
  5. Practice size and patient volume (approximate)
  6. Geographic location of practice
  7. Specialisation and service types offered
  8. Estimated annual income ranges (optional)
  9. Estimated financial losses from PMI restrictions

3.3 Financial Information

For litigation funding contributions, we collect:

  1. Payment method selection (PayPal, BACS Direct Debit)
  2. Payment confirmation details
  3. Contribution amount
  4. Payment date and status

Important: We do NOT store complete credit card or bank account numbers. Payment processing is handled by secure third-party payment processors (PayPal, Stripe) who maintain their own secure systems. We receive only transaction confirmation details.

3.4 Uploaded Documents

You may upload the following documents to our Website:

  1. Proof of identity (passport, driving licence, other photo ID)
  2. GMC registration certificate
  3. Signed Deed of Assignment with witness details
  4. Witness identification documents
  5. Professional organisation membership certificates
  6. PMI provider agreements and contracts
  7. Fee schedules and payment records
  8. Correspondence with PMI providers
  9. Practice income evidence (tax returns, accounts – optional)
  10. Other supporting documentation

Legal Professional Privilege: Some documents you upload may be legally privileged communications with solicitors. We treat all uploaded documents as potentially privileged and maintain appropriate confidentiality safeguards.

3.5 Identity Verification Information

To verify your identity and professional credentials:

  1. GMC Register verification results
  2. Professional registration status checks
  3. Referral code information (linked to affiliated organisation)
  4. IP address at time of registration
  5. Device information (browser type, operating system)

3.6 Legal Documents and Consents

  1. Executed Deed of Assignment (with electronic signature)
  2. Witness details for Deed execution
  3. Consent records (to assignment, data processing, participation)
  4. Acknowledgments of terms and conditions
  5. Tax implications acknowledgments
  6. Litigation participation agreements

3.7 Communication Records

  1. Email correspondence with you
  2. Support queries and responses
  3. Telephone call records (if you contact us)
  4. Messages sent through the Website
  5. Notification preferences

3.8 Website Usage Information

3.9 We automatically collect certain information when you visit our Website:

  1. IP address
  2. Browser type and version
  3. Operating system
  4. Pages visited and time spent
  5. Date and time of access
  6. Device type (desktop, mobile, tablet)
  7. Clickstream data

3.10 Cookies and Similar Technologies

We use cookies and similar tracking technologies. See Section 12 for detailed information about our cookie practices.

4. HOW WE COLLECT YOUR INFORMATION

We collect personal information through:

4.1 Direct Provision

Information you provide directly when you:

  1. Register for an account
  2. Complete registration forms
  3. Upload documents
  4. Execute the Deed of Assignment electronically
  5. Make payment contributions
  6. Contact us via email, phone, or contact forms
  7. Update your account or preferences

4.2 Automated Collection

Information collected automatically when you:

  1. Visit our Website (usage data, cookies)
  2. Navigate through pages
  3. Download documents or forms

4.3 Third-Party Sources

Information we receive from:

  1. GMC Register: Professional registration verification
  2. Payment processors: Payment confirmation (PayPal, Stripe)
  3. Professional organisations: Membership verification (with your consent)
  4. Our legal advisors: Case-related information
  5. Referral organisations: Confirmation of legitimate referral codes

4.4 Public Sources

  1. GMC Register (publicly available professional registration data)
  2. Professional directory listings (where applicable)

6. HOW WE USE YOUR INFORMATION

6.1 Litigation Purposes

We use your information to:

  1. Assess your eligibility to participate in the litigation
  2. Verify your professional credentials and identity
  3. Process your assignment of claims via Deed of Assignment
  4. Calculate your potential individual damages
  5. Prepare evidence for court proceedings
  6. Instruct expert witnesses
  7. Communicate with defendants
  8. Distribute damages if litigation is successful
  9. Manage settlement negotiations

6.2 Financial Management

We use your information to:

  1. Process contribution payments
  2. Track funding threshold progress
  3. Manage trust accounting obligations
  4. Process refunds if minimum threshold not reached
  5. Calculate cost recovery and distribution ratios
  6. Provide financial reports to solicitors and auditors
  7. Comply with tax reporting requirements

6.3 Website and Account Management

We use your information to:

  1. Create and manage your user account
  2. Provide access to secure member areas
  3. Authenticate your identity when you log in
  4. Send account-related notifications
  5. Respond to your queries and support requests
  6. Improve Website functionality and user experience

6.4 Communication

We use your information to:

  1. Send important updates about the litigation
  2. Notify you of required actions or documents
  3. Respond to your inquiries
  4. Provide litigation progress reports
  5. Send confirmation emails (registration, payment, document uploads)
  6. Notify you of changes to terms or policies

Marketing: We do NOT use your information for marketing purposes. All communications relate to the litigation or your account.

6.5 Verification and Fraud Prevention

We use your information to:

  1. Verify your GMC registration and professional status
  2. Validate referral codes
  3. Detect duplicate or fraudulent registrations
  4. Prevent unauthorised access to the Website
  5. Protect against cyber attacks and security breaches
  6. Monitor for suspicious activity

6.6 Legal and Regulatory Compliance

We use your information to:

  1. Comply with court orders and legal obligations
  2. Respond to regulatory inquiries
  3. Maintain audit trails
  4. Respond to Solicitors Regulation (“SRA”) inquiries and requirements (in consultation with our legal advisors)
  5. Meet data protection obligations
  6. Defend legal claims

6.7 Analysis and Improvement

We use aggregated or anonymised information to:

Analyse registration trends and patterns

  1. Improve Website functionality
  2. Identify technical issues
  3. Optimise user experience
  4. Assess litigation participation demographics

7. WHO WE SHARE YOUR INFORMATION WITH

We share your personal information only when necessary and with appropriate safeguards.

Information you provide through this portal will be shared with Harcus Parker, the solicitors acting in the claims, and with counsel and expert economists instructed in connection with those claims. All recipients are bound by legal professional privilege and applicable data protection obligations. Your information will be used solely for the purpose of pursuing the claims on your behalf.

7.1 Legal Advisors

Who: Harcus Parker and instructed barristers
Why: To prosecute the litigation on your behalf
What: All information necessary for legal representation including registration details, financial information, uploaded documents, and damages calculations
Safeguards: Professional legal privilege protects communications; solicitors bound by SRA rules and confidentiality obligations

7.2 Expert Witnesses

Who: Economic experts, industry experts, and other expert witnesses
Why: To prepare expert evidence for court proceedings
What: Professional practice information, financial data, market analysis data (typically anonymised or pseudonymised where possible)
Safeguards: Expert witness confidentiality obligations; non-disclosure agreements

7.3 The Court and Defendants

Who: High Court of Justice, defendant insurance companies, and their legal representatives
Why: Court disclosure obligations in litigation
What: Information relevant to the legal claims, as required by court rules and orders
Safeguards: Court rules govern disclosure; confidentiality orders may protect sensitive information; redaction of irrelevant personal data

Important: Once litigation commences, some of your information will become part of court proceedings and may be disclosed to defendants and potentially become public record. We will minimise disclosure to what is legally required and seek protective orders where appropriate.

7.4 Payment Processors

Who: PayPal, Stripe
Why: To process contribution payments
What: Payment transaction details (they collect payment card/bank details directly, not through us)
Safeguards: Payment processors are PCI DSS compliant and have their own privacy policies

7.5 IT Service Providers

Who: Website hosting provider, email service provider, backup services, security services
Why: To operate and secure the Website
What: Technical access to database and systems (minimal personal information access)
Safeguards: Data Processing Agreements, confidentiality obligations, security standards (ISO 27001 or equivalent)

7.6 Professional Verification Services

Who: GMC Register database provider, identity verification services (if used)
Why: To verify your professional credentials and identity
What: GMC number, name, date of birth (for identity checks)
Safeguards: Data Processing Agreements, limited purpose use

7.7 Accountants and Auditors

Who: Federation’s accountants and auditors
Why: Financial reporting, tax compliance, audit requirements
What: Financial contribution records, trust accounting data
Safeguards: Professional confidentiality obligations

7.8 Regulatory Authorities

Who: Information Commissioner’s Office (ICO), Solicitors Regulation Authority
Why: Compliance with legal and regulatory obligations
What: Information requested in formal inquiries or investigations
Safeguards: Legal obligations limit sharing to what is required

7.9 Law Enforcement

Who: Police, fraud investigators, court orders
Why: Legal obligation to comply with lawful requests
What: Information specified in warrant, court order, or statutory requirement
Safeguards: We verify legitimacy of requests and provide only what is legally required

7.10 Referral Organisations

Who: Professional organisations that issued referral codes
Why: To verify legitimate use of referral codes and provide participation statistics
What: Confirmation that member used their code (typically anonymised statistics)
Safeguards: Data Processing Agreements, limited information sharing

7.11 Other Participants (limited)

Who: Other litigation participants
Why: Collective action coordination (if necessary)
What: Minimal information (typically just number of participants, not individual identities)
Safeguards: Aggregated/anonymised data only; individual identities protected

We do NOT:

  1. Sell your personal information to third parties
  2. Share your information for marketing purposes
  3. Provide your information to data brokers
  4. Use your information for purposes unrelated to the litigation

8. INTERNATIONAL TRANSFERS

8.1 UK-Based Processing: We process your personal information primarily within the United Kingdom.

8.2 Limited International Transfers: Some service providers may process data outside the UK/EEA, including:

  1. Cloud storage providers (e.g., AWS, Google Cloud) – may have servers globally
  2. Payment processors (PayPal, Stripe) – US-based companies with global operations
  3. Email services – may route through international servers.

8.3 Safeguards for International Transfers: Where we transfer personal information outside the UK, we ensure appropriate safeguards including:

  1. Adequacy Decisions: Transfers to countries with UK adequacy decisions (e.g., EEA countries, specific approved countries)
  2. Standard Contractual Clauses: EU Commission approved contracts between us and the recipient
  3. UK International Data Transfer Agreement: ICO-approved transfer agreements
  4. Service Provider Certifications: Processors certified under recognised frameworks.

8.4 You can obtain information about specific safeguards by contacting our Data Protection Officer.

9. HOW LONG WE KEEP YOUR INFORMATION

We retain your personal information for different periods depending on the purpose:

9.1 During Active Litigation

Retention Period: Throughout the litigation and until final resolution (including appeals)
Reason: Necessary for legal claims and litigation management

9.2 Post-Litigation

Retention Period: 7 years after final resolution of litigation
Reason:

  1. Limitation periods for potential claims
  2. Regulatory and tax requirements
  3. Professional indemnity insurance requirements
  4. Audit and compliance needs

9.3 Financial Records

Retention Period: Minimum 7 years from end of financial year
Reason: Tax law requirements, trust accounting obligations

9.4 Legal Documents

Retention Period: Deed of Assignment and related legal documents retained permanently or for limitation period (12 years for deeds)
Reason: Legal enforceability, proof of assignment

9.5 If Litigation Not Commenced

Retention Period: 3 years if litigation does not commence
Reason: Administrative purposes, potential future litigation, regulatory

9.6 Website Account Data

Retention Period: Deleted 1 year after litigation conclusion (subject to legal document retention requirements above)
Reason: No ongoing need for account access

9.7 Communications

Retention Period: 7 years from date of communication
Reason: Evidence of notifications, compliance records

9.8 Cookies and Analytics

Retention Period: Up to 26 months for analytics data
Reason: Statistical analysis, Website improvement

9.9 Secure Deletion: When retention periods expire, we securely delete or anonymise your information using industry-standard deletion methods.

Exceptions: We may retain information beyond these periods if:

  1. Required by law or court order
  2. Necessary to defend legal claims
  3. You have consented to longer retention
  4. Anonymised for statistical purposes (no longer personal data)

10. YOUR RIGHTS UNDER DATA PROTECTION LAW

You have the following rights regarding your personal information:

10.1 Right of Access (Article 15)

You have the right to:

  1. Obtain confirmation whether we process your personal information
  2. Access your personal information
  3. Receive information about how we use your data

How to exercise: Submit a Subject Access Request to our Data Protection Officer. We will respond within one month (extendable by two months for complex requests).

What we provide: Copy of your personal information in commonly used electronic format (usually PDF).

10.2 Right to Rectification (Article 16)

You have the right to:

  1. Correct inaccurate personal information
  2. Complete incomplete personal information

How to exercise: Log into your account and update information directly, or contact us with corrections.

Timeframe: We will correct errors within one month.

10.3 Right to Erasure / “Right to be Forgotten” (Article 17)

You have the right to request deletion of your personal information in certain circumstances.

IMPORTANT LIMITATION – Litigation Context:

Your right to erasure is significantly limited because we process your information for legal claims. Under Article 17(3)(e), we can refuse erasure where processing is necessary for:

Establishment, exercise, or defence of legal claims

This means we cannot delete your information while:

  1. Litigation is active or contemplated
  2. Limitation periods are running
  3. We have legal/regulatory retention obligations

Limited Erasure Available:

  1. If you withdraw before litigation commences AND minimum threshold not reached
  2. After all retention periods have expired
  3. For information not necessary for legal claims (e.g., marketing preferences if we ever collect them)

10.4 Right to Restriction of Processing (Article 18)

You have the right to request we restrict processing of your personal information in certain circumstances:

  1. You contest the accuracy of data (restriction while we verify)
  2. Processing is unlawful but you don’t want erasure
  3. We no longer need the data but you need it for legal claims
  4. You have objected to processing (restriction while we verify grounds)

Effect: We store the data but don’t actively process it (except with your consent or for legal claims).

10.5 Right to Data Portability (Article 20)

You have the right to:

  1. Receive personal information you provided in structured, commonly used format
  2. Transmit that data to another controller

Limitations:

  1. Only applies to information YOU provided (not information we generated)
  2. Only where processing is based on consent or contract
  3. Only for automated processing

Practical application: Limited in litigation context as most processing is for legal claims, not based on consent.

10.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests.

IMPORTANT LIMITATION:

You cannot object to processing that is:

  1. Necessary for legal claims (litigation)
  2. Required by legal obligation
  3. Necessary for contract performance

Where you CAN object:

  1. Marketing (though we don’t do marketing)
  2. Some analytics and profiling (limited application here)

10.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal effects.

Our Position: We do NOT use automated decision-making or profiling that produces legal effects. All significant decisions involve human review.

10.8 Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time.

  1. Effect: We will stop processing for that purpose (but can continue for other lawful purposes).
  2. Limitations: Cannot withdraw consent for processing necessary for legal claims or legal obligations.

10.9 Right to Complain

You have the right to lodge a complaint with the supervisory authority:

Information Commissioner’s Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Telephone: 0303 123 1113
Website: www.ico.org.uk

Our Preference: We encourage you to contact us first so we can try to resolve your concern.

11. HOW TO EXERCISE YOUR RIGHTS

11.1 Contact Methods:

Email: office@fipo.uk
Post: Data Protection Officer, Federation of Independent Practitioner Organisations, 2 St Marys Road, Tonbridge, Kent TN9 2LB
Online Form: Contact page

11.2 What to Include:

  1. Your full name and contact details
  2. Description of your request
  3. Proof of identity (to protect your information)
  4. Account username (if applicable)

11.3 Our Response:

  1. Timeframe: One month (extendable to three months for complex requests)
  2. Free of charge: Generally no fee (we may charge for manifestly unfounded or excessive requests)
  3. Verification: We may request additional information to verify your identity.

12. COOKIES AND TRACKING TECHNOLOGIES

12.1 What Are Cookies? Cookies are small text files stored on your device when you visit our Website. They help the Website function properly and provide usage information.

12.2 Types of Cookies We Use

  1. Strictly Necessary Cookies (No consent required)
    • Session management and authentication
    • Security and fraud prevention
    • Essential Website functionality
    • Load balancing

Example: Login session cookie keeping you logged in

  1. Performance/Analytics Cookies (Consent required)
    • Website traffic analysis
    • Understanding how visitors use the Website
    • Identifying errors and issues

Example: Google Analytics (if used) – anonymised

  1. Functional Cookies (Consent required)
    • Remember your preferences
    • Enhance user experience
    • Remember language/region settings

12.3 We do NOT use:

  1. Marketing/advertising cookies
  2. Third-party advertising cookies
  3. Social media tracking cookies (except if you share content)

12.4 Third-Party Cookies We may use carefully selected third-party services that set cookies:

  1. Google Analytics (if used) – for Website statistics
  2. Payment processors (during payment process only)
  3. reCAPTCHA (for security)

12.5 Managing Cookies

  1. Browser Settings: You can control cookies through your browser settings. Most browsers allow you to:
    • See what cookies are stored
    • Delete cookies
    • Block all cookies
    • Block third-party cookies
  2. Browser Help Resources:

12.6 Impact of Blocking Cookies:

  1. Strictly necessary cookies: Website may not function properly
  2. Other cookies: Functionality may be limited but core features work

12.7 Our Cookie Banner: When you first visit, you’ll see a cookie banner allowing you to:

  1. Accept all cookies
  2. Reject non-essential cookies
  3. Manage cookie preferences

12.8 Cookie List

Cookie NameTypePurposeDuration
session_idStrictly NecessaryLogin session managementSession
csrf_tokenStrictly NecessarySecurity protectionSession
cookie_consentStrictly NecessaryRemember your cookie preferences1 year
_gaAnalytics (if used)Google Analytics visitor identification2 years
_gidAnalytics (if used)Google Analytics session identification24 hours

This list will be updated as cookies are implemented.

13. SECURITY MEASURES

We take the security of your personal information seriously and implement appropriate technical and organisational measures:

13.1 Technical Measures

  1. Encryption: All data transmission uses HTTPS/SSL encryption
  2. Secure Storage: Encrypted storage for sensitive documents and data
  3. Access Controls: Role-based access limiting who can view data
  4. Firewalls: Web application firewall protection
  5. Security Monitoring: 24/7 monitoring for threats and intrusions
  6. Regular Updates: Security patches and software updates
  7. Backup Systems: Regular encrypted backups stored securely
  8. Authentication: Strong password requirements, optional two-factor authentication
  9. Antivirus/Malware: Protection against malicious software

13.2 Organisational Measures

  1. Staff Training: Data protection training for all personnel with data access
  2. Confidentiality Agreements: All staff and contractors bound by confidentiality
  3. Access Logs: Audit trails of who accesses personal information
  4. Data Minimisation: We collect only information necessary for purposes
  5. Need-to-Know: Access granted only to those who require it
  6. Incident Response Plan: Procedures for handling security breaches
  7. Vendor Management: Security assessment of third-party processors
  8. Physical Security: Secure facilities for any physical records

13.3 Security Limitations

  1. No Absolute Security: Despite our measures, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security.
  2. Your Responsibility:
    • Keep your login credentials confidential
    • Use a strong, unique password
    • Log out after using shared devices
    • Report suspicious activity immediately
    • Keep your email account secure (password reset emails)

13.4 Data Breach Notification:

If a personal data breach occurs that is likely to result in high risk to your rights:

  1. We will notify you without undue delay
  2. We will notify the ICO within 72 hours of becoming aware
  3. We will provide information about the breach and steps taken
  4. We will advise on measures you can take to protect yourself.

14. CHILDREN’S PRIVACY

14.1 Our Website is not intended for children under 18 years of age.

14.2 We do not knowingly collect personal information from anyone under 18. Registration for participation in the Litigation is only for qualified medical professionals.

14.3 If we become aware we have inadvertently collected information from someone under 18, we will delete it promptly.

16. CHANGES TO THIS PRIVACY NOTICE

16.1 We may update this Privacy Notice from time to time to reflect:

  1. Changes in law or regulation
  2. Changes to our practices
  3. New features or services
  4. Feedback or complaints.

16.2 Notification of Changes:

  1. Material Changes: We will notify you by email or prominent Website notice
  2. Minor Changes: Updated version posted on Website with new “Last Updated” date
  3. Your Responsibility: Review this Privacy Notice periodically
  4. Continued Use: Your continued use of the Website after changes constitutes acceptance of the updated Privacy Notice.

16.3 Archives: Previous versions available on request from our Data Protection Officer.

17. CONTACT INFORMATION

17.1 Data Protection Queries

Data Protection Officer:
Data Protection Officer
Federation of Independent Practitioner Organisations
2 St Marys Road, Tonbridge, Kent TN9 2LB
Email: office@fipo.uk
Tel: 020 7205 4166

17.2 General Website Queries

Email: office@fipo.uk
Tel: 020 7205 4166
Website: fipo.uk

17.3 Litigation Queries

17.4 For questions about the litigation itself (not data protection):

Email: fipo@harcusparker.co.uk
Tel: 020 7205 4166

17.5 Complaints

First Step: Contact our Data Protection Officer

Supervisory Authority:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk

18. YOUR ACCEPTANCE OF THIS PRIVACY NOTICE

18.1 By using our Website, registering for an account, and providing personal information, you acknowledge that:

  • ✓ You have read and understood this Privacy Notice
  • ✓ You consent to the collection, use, and disclosure of your information as described
  • ✓ You understand your rights and how to exercise them
  • ✓ You understand the limitations on your rights in the litigation context
  • ✓ You understand information may be disclosed in court proceedings

If you do not agree with this Privacy Notice, please do not use our Website or provide personal information.

Document Version: 1.0
Last Updated: 18 September 2026
Next Review Date: 18 September 2027

This Privacy Notice has been prepared in accordance with UK GDPR, the Data Protection Act 2018, and guidance from the Information Commissioner’s Office. It has been reviewed by Harcus Parker as legal advisers to the litigation.