Skip to main content

Legal

Privacy notice

Last updated: 18 April 2026 · This is a Phase 0 notice covering the PPG Toolkit marketing site only. Separate notices will cover each tool when it launches.

Who we are

The PPG Toolkit is operated by My Practice Manager Ltd (the data controller), a company registered in England & Wales (company number 16021943) with its registered office in Manchester, England. You can reach us at contact@mypracticemanager.co.uk for any privacy question, including to exercise your rights under UK GDPR.

What this notice covers

This notice describes how we handle personal data collected through the ppgtoolkit.co.uk marketing site. It does not cover the forthcoming PPG Toolkit tools themselves; each will have its own privacy notice when it launches.

What we collect and why

We keep the data we hold to a minimum. The only categories of personal data we collect on this site are:

  • Your email address when you submit the signup form to join the first cohort. We currently accept NHS email addresses only (.nhs.net and .nhs.uk) as a quality filter.
  • Technical signup metadata: the IP address and user-agent string at the moment you submit the form. We use these only for spam prevention and fraud audit, and we retain them for a maximum of 90 days.
  • Anti-bot verification: when you complete the Cloudflare Turnstile challenge on the signup form, your IP and a short-lived token are shared with Cloudflare for verification. Cloudflare is our processor for this check.
  • Analytics events: Google Analytics 4 (via Firebase Analytics) records aggregate page views and funnel events so we can see which parts of the site are working. By default we run in cookieless mode: no _ga or _gid cookies are set unless you accept the cookie banner.

Lawful basis

Our lawful basis for processing your email address is consent (UK GDPR Article 6(1)(a)): you submit it to ask us to contact you when the toolkit opens. You can withdraw that consent at any time by emailing us or using the unsubscribe link in any email we send you.

Our lawful basis for the technical signup metadata (IP, user-agent) is legitimate interest (UK GDPR Article 6(1)(f)), specifically our interest in preventing spam and abuse of the signup form.

How long we keep it

  • Email address: kept on our signup list until you unsubscribe, or until 24 months of inactivity after the toolkit launches (whichever is sooner). After that it is deleted.
  • Technical signup metadata: deleted within 90 days of the signup.
  • Analytics events: retained within Google Analytics 4 according to GA4 retention settings (currently 14 months).

Who we share it with

We do not sell your personal data and we do not share it for advertising. We use a small set of processors to operate the site:

  • Google Cloud / Firebase: hosting, email queue, analytics (Google Ireland Ltd).
  • Amazon SES: sending transactional emails (Amazon Web Services EMEA SARL).
  • Cloudflare Turnstile: bot-protection on the signup form.

All of these are bound by written data-processing terms. We may add processors as the product grows; this page will be updated accordingly.

International transfers

Some of our processors are located outside the UK. Where that is the case we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to its processing. To exercise any of these rights, email contact@mypracticemanager.co.uk. We will respond within one calendar month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to resolve things first, if you can bear with us.

Changes to this notice

We will update this notice as the PPG Toolkit site evolves. Material changes will be signalled at the top of the page; the “last updated” date will always reflect the current version.

← Back to PPG Toolkit