Skip to main content
Legal

Privacy Policy

How Flux Medical Limited collects, uses, protects and shares personal information through Lazomis QI.

At a glance

We collect only the information needed to provide, secure and improve Lazomis QI. We do not sell personal information. Healthcare organisations normally remain responsible for the project data they control, while Flux Medical Limited processes that data on their instructions.

Document control

Document control details
OrganisationFlux Medical Limited, trading as Lazomis QI
Company number16158150
Registered officeUnit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG
Privacy contactprivacy@lazomis.co.uk
Version2.0
Last updated15 August 2026
ReviewAt least annually and whenever processing materially changes

1. About this policy

Lazomis QI is operated by Flux Medical Limited (we, us or our). This policy explains how we collect, use, store, disclose and protect personal information when people use the Lazomis QI website, platform, audit and quality-improvement tools, organisational workspaces, demonstrations, resources, communications and associated services.

This policy is intended to provide the information required by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Personal data means information relating to an identified or identifiable living person. Special-category data includes particularly sensitive information such as health information and information revealing racial or ethnic origin, religious beliefs, genetic or biometric identity, sex life or sexual orientation.

This policy should be read with our Cookie Policy, Terms of Use, Data Protection & Information Governance statement, Artificial Intelligence Policy, organisational agreements and any just-in-time privacy notice displayed when information is collected. If those documents apply a stronger safeguard to a particular activity, the stronger safeguard applies.

2. Who we are and how to contact us

Flux Medical Limited is a company registered in England and Wales under company number 16158150. Its registered office is Unit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG.

Privacy questions, data-subject requests and concerns about confidentiality may be sent to privacy@lazomis.co.uk. We may ask for information reasonably necessary to verify identity before acting on a request. Please do not send patient-identifiable information through ordinary email unless a secure, authorised route has been agreed.

3. When we act as controller or processor

3.1 Flux Medical as controller

We normally act as controller when we decide why and how personal information is used. This generally includes website and individual-account administration, billing, enquiries, support, complaints, marketing preferences, security, fraud prevention, service analytics, product feedback, supplier management and our own legal and governance records.

3.2 Flux Medical as processor

When an organisation uses Lazomis QI for its own clinical audit, quality-improvement or service-evaluation activity, that organisation will usually decide the purpose, dataset, access and use of project information. It will normally be the controller and Flux Medical will normally act as processor under its documented instructions.

Organisational contracts and the facts of the processing determine the exact roles. If we receive a request relating to organisation-controlled project data, we may refer it to the relevant controller and assist that controller as required by law and contract.

Important

Lazomis QI does not become the controller of organisation-controlled project data merely because the platform hosts, analyses or exports it.

4. Who this policy covers

  • Website visitors and people using Lazomis resources.
  • Individual healthcare-professional account holders.
  • Organisational owners, administrators, members, contributors and invited collaborators.
  • People using demonstrations, trials or pilot programmes.
  • People submitting enquiries, support requests, complaints, feedback or surveys.
  • Newsletter recipients, event participants and professional contacts.
  • Suppliers, partners and representatives of prospective or existing customers.
  • People whose information is included in project data controlled by a Lazomis customer.

5. Information we collect

5.1 Account, identity and professional information

  • Name, email address, authentication identifiers and account status.
  • Professional role, grade, specialty, department and organisation.
  • Organisation type, NHS organisation information and ODS code where applicable.
  • Workspace membership, project role, permissions and invitations.
  • Professional interests or portfolio information that a user chooses to enter.

5.2 Project and workspace information

  • Project titles, descriptions, classifications and contributor details.
  • Standards, criteria, targets, exclusions, denominators, custom fields and data-collection forms.
  • Submitted records, notes, comments, improvement actions, cycle information and attachments.
  • Dashboards, analysis, reports, presentations, reflections and other generated outputs.
  • Workspace activity, change history, approvals, timestamps and audit trails.

5.3 Communications and support

We may collect contact-form messages, support correspondence, complaints, feedback, survey answers, demonstration requests, campaign interactions and attachments submitted through an authorised route.

5.4 Billing and transactions

We may process plan or product information, billing name and address, invoice details, transaction identifiers, payment status, refunds, chargebacks and dispute records. Complete card details are handled by the payment provider presented at checkout and are not intended to be stored by Lazomis QI.

5.5 Technical and usage information

We may collect IP address, device and browser information, operating system, login and session events, security logs, timestamps, page and feature usage, referral information, error and performance data, approximate location inferred from IP address, and cookie or consent choices.

5.6 Marketing and engagement

We may hold communication preferences, newsletter subscriptions, campaign engagement, event registration, referral source, suppression records and a history of communications with us.

6. Sources of personal information

We obtain information directly from the person, automatically through use of the service, or from another permitted source. Depending on the service, sources may include an employer or organisational administrator, a project owner who invites a collaborator, authentication and payment providers, authorised connected services, public NHS organisation and ODS datasets, professional contacts and publicly available organisational sources.

Where we obtain information from another source, we provide appropriate privacy information within the period required by law unless an exemption applies. Organisational customers are responsible for ensuring that they are entitled to provide project data and invitations to us.

7. Clinical audit, QI and service-evaluation data

Lazomis QI supports professional audit, quality-improvement and service-evaluation activity. It is not an electronic patient record and must not be treated as the authoritative clinical record.

Default data rule

Projects should use anonymous or appropriately pseudonymised information wherever the purpose can be achieved without direct identifiers. Names, NHS numbers, full addresses, photographs and unnecessary free-text clinical narratives should not be entered merely because a custom field allows free text.

  • The responsible user and organisation must confirm the project classification, permissions, data fields, lawful basis and local governance requirements.
  • Users must not upload information they are not authorised to disclose.
  • Custom fields must not be used to circumvent privacy, security or governance controls.
  • Identifiable or special-category patient data should be processed only where genuinely necessary, contractually supported, appropriately configured and approved by the responsible organisation.
  • Project exports and benchmarking must be assessed for small-number and re-identification risks before they are shared.
  • Pseudonymised information remains personal data and continues to require protection.

8. Special-category and confidential information

A project may contain health information or, depending on its subject, information revealing racial or ethnic origin, religious or philosophical beliefs, disability, genetic or biometric identity, sex life, sexual orientation or trade-union membership. Such information receives additional protection.

Where we act as processor, the customer must identify an appropriate UK GDPR Article 6 lawful basis, an Article 9 condition where required, and any common-law confidentiality or sector-specific requirement. We process the information only on documented instructions unless the law requires otherwise. Ordinary consent is not assumed to be the correct basis for every audit or organisational activity.

9. How and why we use personal information

Purposes, information used and lawful bases
PurposeTypical informationLawful basis
Create and administer accountsIdentity, contact, professional profile, permissionsContract; legitimate interests in operating the service
Provide individual services and outputsAccount, project configuration, user contentContract
Operate organisational workspacesMembers, permissions, project and audit-trail dataCustomer instructions as processor; contract with customer
Authenticate users and maintain securityCredentials, IP address, device, login and security eventsContract; legitimate interests; legal obligation where applicable
Provide support and handle enquiriesContact details, messages, account and diagnostic informationContract; legitimate interests
Process payments and refundsBilling, transaction status, invoice and dispute dataContract; legal obligation; legitimate interests
Send essential service communicationsContact and account informationContract; legitimate interests
Send optional marketingContact details, preferences and engagementConsent, or legitimate interests where permitted
Improve usability and performanceUsage, feedback, errors and aggregated analyticsLegitimate interests; consent for non-essential cookies where required
Prevent fraud, misuse and unlawful activitySecurity, account, transaction and usage informationLegitimate interests; legal obligation
Meet legal, regulatory and governance dutiesRelevant records and correspondenceLegal obligation; legitimate interests; legal claims
Establish or defend legal claimsAccount, project, transaction, complaint and security recordsLegitimate interests; legal claims conditions where applicable

Where we rely on legitimate interests, those interests include operating a safe and effective service, improving functionality, protecting users and the business, preventing misuse, administering customer relationships and establishing or defending claims. We assess whether those interests are overridden by the rights and freedoms of affected people.

10. Artificial intelligence

Some Lazomis QI features use artificial intelligence to help users draft, organise, map, analyse or summarise quality-improvement work. Examples may include project suggestions, aims and criteria, field suggestions, source-supported content, spreadsheet-column mapping, narrative summaries, reports and improvement ideas.

  • AI output may be incomplete, inaccurate or out of date and must be reviewed by a competent user.
  • AI does not replace clinical judgement, professional accountability or organisational governance.
  • Lazomis QI does not use AI to make autonomous diagnostic, treatment or other legally or similarly significant decisions about individuals.
  • We seek to send only the minimum information necessary to an AI service.
  • Sensitive project fields should be excluded from AI processing unless the use has been specifically assessed, approved and configured.
  • Customer project content is not used to train general-purpose AI models unless the use is separately assessed, transparently explained and supported by an appropriate agreement or genuinely optional permission.

Further information is provided in the Lazomis QI Artificial Intelligence Policy available through the website footer and governance pages.

11. Optional use of anonymised information

We may invite a user or organisation to permit the use of genuinely anonymised information for platform improvement, service evaluation, aggregated benchmarking, research-question development, properly governed research or publication. This is separate from the processing required to deliver the service.

  • Participation is optional and refusal does not reduce the core service.
  • Any permission request will be separate, specific and clear about the proposed use.
  • Anonymisation and re-identification risk must be assessed in context; pseudonymised information is not treated as anonymous.
  • Research classification, ethics, sponsorship, protocol, publication and other approvals must be obtained where applicable.
  • Permission to consider anonymised information does not itself authorise a new research study.

Unless and until an optional permission mechanism is presented and accepted, we do not treat ordinary account acceptance as permission to use customer project data for these wider purposes. Further detail is given in the Contributor Participation, Data Sharing and Consent Policy.

12. National data opt-out

The national data opt-out allows people in England to object to specified uses of confidential patient information for research and planning. It does not apply to genuinely anonymous information, individual care, uses based on the person's consent, legal requirements or certain approved exceptions.

Organisational customers acting as controllers are responsible for deciding whether the national data opt-out applies to their project or disclosure. Where Flux Medical acts as processor, we comply with documented controller instructions. We review new and materially changed processing to identify whether an in-scope use has been introduced. If our own processing becomes subject to the opt-out, the required checking and exclusion arrangements will be implemented before that processing begins.

People can learn about or change their choice at https://www.nhs.uk/your-nhs-data-matters/.

13. Payments

Payments are processed through the payment service shown at checkout. That provider may process payment details, fraud-prevention signals and transaction information under its own privacy terms and may act as an independent controller for parts of its service. Lazomis QI receives information needed to confirm payment, provide credits or subscriptions, issue invoices, administer refunds and handle disputes.

We do not intentionally store complete payment-card numbers or card security codes. Financial records are retained where required for accounting, taxation, fraud prevention and the resolution of disputes.

14. Cookies and analytics

We use cookies and similar technologies for strictly necessary functions such as authentication, session continuity, security and consent storage. With the user's choice where required, we may also use preference, analytics or marketing technologies to understand usage and improve the service.

Non-essential technologies should not be activated before the required consent is obtained. Users can review or change available choices through the cookie-settings control. Further information is provided in our Cookie Policy, including the current tools, purposes and durations.

15. Marketing, outreach and campaigns

We may send information about Lazomis QI tools, resources, events and services where the recipient has consented or where another lawful basis permits it. Recipients can unsubscribe through the communication or contact us. We may keep a minimal suppression record so that an opt-out continues to be respected. Necessary security, billing and service messages may still be sent while an account or contract remains active.

Where an organisational customer uses campaign or outreach features, the customer is responsible for having authority to upload recipient details and send the communication. Flux Medical normally acts as processor for that campaign data and follows the customer's documented instructions.

16. Sharing and recipients

We do not sell personal information. We disclose it only where necessary for the purposes described in this policy, under an appropriate agreement or where the law permits or requires disclosure.

  • Hosting, cloud-infrastructure, database and authentication providers.
  • Payment, billing and fraud-prevention providers.
  • Transactional email, communication and customer-support providers.
  • Analytics, error-monitoring and performance providers, subject to cookie choices where applicable.
  • AI service providers for approved AI-enabled features.
  • Professional advisers, insurers, auditors and security specialists.
  • Regulators, courts, law-enforcement or public bodies where disclosure is lawful and necessary.
  • A purchaser, investor or successor in a genuine corporate transaction, subject to confidentiality and appropriate safeguards.
  • Organisational customers, administrators and authorised collaborators where needed to operate the workspace.

Service providers acting on our behalf are subject to appropriate confidentiality, security and data-processing terms. A current subprocessor list may be made available through our contractual or governance documentation.

17. International transfers

Some service providers may process information outside the United Kingdom. Before making a restricted transfer, we use an applicable safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses or another lawful mechanism. Where required, we assess the destination, provider, access risks and supplementary measures.

Supplier locations and subprocessor arrangements may change. Material changes are assessed and contractual information is updated where necessary. People may contact us for further information about the safeguard applicable to their data, subject to lawful confidentiality restrictions.

18. Security

We use proportionate technical and organisational measures designed to protect confidentiality, integrity and availability. Measures may include encryption in transit, encryption at rest where supported, access controls, least privilege, role-based permissions, authentication safeguards, activity and security logging, environment separation, backups, recovery processes, vulnerability management, supplier assessment, incident response and confidentiality obligations.

No online service can guarantee absolute security. Users must protect their login credentials, use authorised devices and routes, configure workspace permissions carefully, and report suspected compromise promptly. Security events are investigated and affected controllers, individuals or regulators are notified where legally required.

19. Retention and deletion

We retain personal information only for as long as necessary for the relevant purpose, legal or contractual obligations, security, dispute resolution and the establishment or defence of claims. The precise period depends on the category, sensitivity, customer instructions and whether an account or contract remains active.

Retention categories and typical approach
CategoryTypical approach
Active account and profileRetained while the account is active and for a limited closure period needed for recovery, disputes and administration.
Organisation-controlled project dataRetained according to the customer agreement and instructions; export, return or deletion arrangements apply at contract end.
Individual project dataRetained while the account or purchased service remains active, then deleted or anonymised under the retention schedule.
Transactions and invoicesRetained for the period required by tax, accounting and company law, normally up to six years after the relevant financial period.
Support, complaints and legal correspondenceRetained for the time needed to resolve the matter and manage related legal, regulatory or contractual risk.
Security and authentication logsRetained for a proportionate security period based on risk, investigation needs and system design.
Marketing consent and suppressionConsent evidence is retained while relied upon; minimal suppression information may be retained to honour an opt-out.
BackupsRemoved through the normal backup-rotation cycle and protected from ordinary use while awaiting expiry.
Anonymous statisticsMay be retained because information that is genuinely anonymous is no longer personal data.

Deletion from the live service may not immediately remove information from protected backups. Backup copies are isolated, not restored for ordinary use, and expire through the established rotation process unless preservation is required for an incident or legal obligation.

20. Automated decision-making and profiling

Lazomis QI does not currently make solely automated decisions about people that produce legal or similarly significant effects. The service may use limited automation for authentication, security alerts, fraud detection, analytics, content organisation and non-binding recommendations. These functions support operation of the service and do not replace meaningful professional review.

If this position changes, we will assess the processing, introduce required safeguards, explain the logic and likely consequences where required, and update this policy before the new processing begins.

21. Your data-protection rights

Depending on the circumstances and lawful basis, a person may have the right to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, object, receive portable data, withdraw consent and obtain information about applicable automated decision-making. Rights are not absolute and lawful exemptions may apply.

Requests may be sent to privacy@lazomis.co.uk. We normally respond without undue delay and within one month, subject to any lawful extension. We may verify identity and ask for clarification where necessary. There is normally no fee, although the law permits a reasonable fee or refusal in limited circumstances involving manifestly unfounded or excessive requests.

Where Flux Medical acts only as processor, we may refer the request to the organisational controller and assist it in responding. Withdrawing consent does not affect processing already lawfully carried out before withdrawal.

22. Children

Lazomis QI is intended for healthcare professionals, organisational users and other authorised adults. It is not directed to children and children should not create accounts. A properly governed audit may concern paediatric or other services involving children; any related project information remains subject to the controller, clinical-data, confidentiality and safeguarding provisions in this policy.

24. Changes to this policy

We review this policy regularly and update it when our services, suppliers, processing or legal obligations materially change. The last-updated date identifies the current version. Significant changes may be communicated through the platform, by email or through another appropriate notice. Where practical, we retain earlier versions for governance and audit purposes.

25. Complaints and contact details

We encourage people to contact us first so that we can investigate and respond. This does not affect the right to complain directly to the Information Commissioner's Office (ICO).

Contact details
ContactDetails
Lazomis QI privacyprivacy@lazomis.co.uk
Flux Medical LimitedUnit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG
Information Commissioner's OfficeWycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ICO telephone0303 123 1113
ICO complaintshttps://ico.org.uk/make-a-complaint/data-protection-complaints/

Appendix A: Retention framework

The following operational principles should be applied alongside the detailed internal retention schedule and customer contracts.

  • Collect and retain only information needed for a defined purpose.
  • Assign an owner and review point to each information category.
  • Pause routine deletion only where a documented legal hold, incident or investigation requires preservation.
  • At contract end, follow the agreed export, return and deletion process for customer-controlled data.
  • Test deletion jobs and backup expiry rather than relying on policy statements alone.
  • Anonymise only where re-identification risk has been assessed in context.
  • Record material deletion failures and remedial action.

Appendix B: Authoritative references

This policy was prepared with reference to the following official UK sources. Guidance should be checked at each review because the Data (Use and Access) Act has prompted updates to some ICO material.