Skip to main content

Legal

Privacy policy

What personal data this website collects, why, where it goes and how to exercise your rights — written to describe what the site actually does, not a template.

Last reviewed 10 July 2026

Who we are

This website is operated by Jayex Limited (“Jayex”, “we”), the data controller for the personal data it collects. We build patient check-in, calling and waiting-room management systems for the NHS.

  • Registered company: Jayex Limited (England & Wales), company no. 15843905
  • Registered office: 2 Claridge Court, Lower Kings Road, Berkhamsted HP4 2AF
  • ICO registration: ZB745364
  • Data protection officer: dpo@jayex.com

You can reach us using the phone number or email address in the footer of every page, or through the contact page. For anything specifically about your personal data, our data protection officer is at dpo@jayex.com.

This policy covers this website. Our products handle patient data inside NHS organisations under separate agreements with those organisations — clinical data never leaves the practice network, and none of it flows through this site.

What we collect when you enquire

The only place this site asks you for personal data is the enquiry form. Step one asks for your name, work email address, organisation, the kind of organisation it is and what you’re interested in. An optional second step asks who currently provides your patient-flow system, when that contract ends and a phone number — so we can time our reply usefully instead of chasing you.

We use these details for one purpose: responding to the enquiry you chose to send, and the sales conversation that follows if you want one. The lawful basis is our legitimate interest in answering a business enquiry you initiated. We don’t sell your data and we don’t add you to third-party marketing lists.

Submissions are screened for spam: a hidden field only bots fill in, a check that the form wasn’t submitted faster than a person can type, rate limits per network address, and Cloudflare Turnstile — which loads and runs only once you begin filling in the form. Suspected spam is set aside and never contacted.

Turnstile checks a few technical signals from your browser — such as your IP address and user-agent — to tell people from bots, without setting advertising cookies or asking you to solve a puzzle. Cloudflare’s handling of that data is described in its Turnstile Privacy Addendum.

Data we collect from public sources

Separately from this website, our sales team sometimes contacts practices, groups and hospitals we believe our systems could help. For that we may collect the name and work contact details of relevant staff from public listings — for example NHS.UK — where those details are published precisely so the organisation can be reached.

We use those details for one purpose: introducing services relevant to the organisation’s role. The lawful basis is our legitimate interest in reaching the organisations our products are built for. If we contact you this way and you’d rather we didn’t, say so — or email dpo@jayex.com — and we’ll stop and remove your details.

How you found us

When you first arrive, the site stores how you got here — campaign tags in the link you followed, the referring site and the page you landed on — in a first-party cookie named jx_attrib. If you later send an enquiry, that first-visit source is attached to it, so we know which of our channels actually produce conversations.

It records how you arrived, once — not your browsing, not your identity, and nothing readable by any other site. The details are in the cookie policy.

Where enquiry data goes

An enquiry is stored in this site’s own database, emailed to our sales team, and recorded in our customer-relationship system — which we built ourselves and host in the UK, so your details don’t leave the country to be processed. Those are the only routine destinations; the flow exists so a person answers you, not to build profiles.

Beyond that, we would disclose personal data only where the law requires it or where it’s genuinely necessary to establish or defend a legal claim (which can involve our professional advisers).

Measurement on this site

We measure how the enquiry form is used — viewed, started, submitted — under a random per-visit identifier that is hashed before storage and tied to your browsing session, not to you. It tells us where the form loses people; it cannot tell us who you are.

Aggregate page analytics run on Matomo, which we host ourselves and configure to work without cookies. Your visits are counted, not tracked: no analytics cookie is set and no analytics data is shared with a third-party analytics company.

How long we keep it

We keep enquiry and customer records for up to six years after our last contact with you, then delete them. If you’d like an enquiry you sent to be deleted sooner, ask us — see your rights below.

Your rights

Under UK data protection law you can ask us to:

  • show you the personal data we hold about you (access)
  • correct it (rectification)
  • delete it (erasure)
  • stop or limit what we do with it (objection and restriction)
  • give it to you in a portable form (portability)

Contact us using the details above and we’ll respond within one calendar month. If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk.

Changes to this policy

If what the site does changes, this page changes with it — the policy describes actual behaviour, so it is updated whenever that behaviour is.