Logo

Privacy Policy

Last Updated: 21/10/2025

Introduction

Welcome to Urobank. This Privacy Policy explains how UroPrep Limited (Company No. 16833894) ("we", "us", "our") collects, uses, stores, and protects your personal information when you use our website and services at www.urobank.co.uk (the "Service").

We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Information We Collect

We collect and process the following categories of personal information:

1.1 Information You Provide Directly

Registration Information:

  • Email address
  • Full name
  • Password (stored in encrypted form)

Payment Information:

  • Payment details are collected and processed by our payment provider, Stripe
  • We do not store your complete credit/debit card details on our servers
  • We receive confirmation of successful payments and billing information from Stripe

Communications:

  • Any messages, feedback, or support queries you send to us
  • Your communication preferences regarding marketing emails

1.2 Information We Collect Automatically

Usage Data:

  • Questions you have answered and your responses
  • Your progress through the question bank
  • Performance statistics and results
  • Login history (date, time, and IP address)

Technical Data:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Referring website/source
  • Pages viewed and features used

Analytics Data:

  • We use Cloudflare Web Analytics on our marketing pages, which collects anonymous usage statistics without using cookies or tracking individual users
  • This service is privacy-preserving and does not require your consent

1.3 Information We Do Not Collect

Privacy Protection:
  • We do not track your browsing activity outside of our website
  • We do not use advertising cookies or third-party tracking technologies
  • We do not collect sensitive personal data (health data, biometric data, etc.)

2. How We Use Your Information

We use your personal information for the following purposes:

2.1 To Provide Our Service (Legal basis: Contract Performance)

  • Create and manage your account
  • Process your subscription payments
  • Provide access to the question bank and educational content
  • Track your progress and performance to personalise your learning experience
  • Remember your preferences and settings

2.2 To Communicate With You (Legal basis: Contract Performance & Legitimate Interests)

Service Communications (you cannot opt out):

  • Send welcome emails and account setup information
  • Send subscription confirmation and payment receipts
  • Send password reset requests and security notifications
  • Send important service updates or changes to our Terms and Conditions
  • Respond to your support queries and feedback

Marketing Communications (opt-in required):

  • Send study tips, new question updates, and special offers (only if you have opted in)
  • You can opt out of marketing emails at any time using the unsubscribe link in any marketing email

2.3 To Improve Our Service (Legal basis: Legitimate Interests)

  • Analyse usage patterns to understand which questions are most useful or difficult
  • Identify technical issues and improve website performance
  • Develop new features and content based on user needs
  • Conduct internal research and statistical analysis

2.4 To Ensure Security and Prevent Fraud (Legal basis: Legitimate Interests)

  • Detect and prevent fraudulent activity or unauthorised access
  • Monitor for suspicious account behaviour or password sharing
  • Comply with legal obligations and respond to lawful requests from authorities
  • Enforce our Terms and Conditions

2.5 To Comply With Legal Obligations (Legal basis: Legal Obligation)

  • Maintain financial records as required by HMRC and UK tax law
  • Respond to valid legal requests from law enforcement or regulatory bodies
  • Comply with data protection laws and regulations

3. How We Share Your Information

We do not sell your personal information to third parties. We only share your information in the following limited circumstances:

3.1 Service Providers

We share information with trusted third-party service providers who help us operate our business:

Payment Processing:

  • Stripe processes all payments on our behalf
  • Stripe's privacy policy: https://stripe.com/privacy
  • Stripe handles all card details securely and we never see your complete card information

Hosting Services:

  • Railway hosts our application on servers located in the European Union
  • Railway's privacy policy: https://railway.app/legal/privacy

Analytics:

  • Cloudflare Web Analytics collects anonymous, aggregated traffic data on our marketing pages
  • No personal data or cookies are used by this service
  • Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/

3.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (court orders, subpoenas, warrants)
  • Requests from law enforcement or regulatory authorities
  • Protection of our rights, property, or safety, or that of our users

3.3 Business Transfers

If UroPrep Limited is involved in a merger, acquisition, or sale of assets, your personal information may be transferred to the new owner. We will notify you via email and/or a prominent notice on our website before your information is transferred.

4. International Data Transfers

Your personal data is primarily stored and processed within the European Union (via Railway's EU servers). However, some of our service providers may process data outside the UK/EU:

  • Stripe may process payment data in multiple jurisdictions
  • Email service providers may have servers in various locations

When we transfer data outside the UK/EU, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO)
  • Adequacy decisions recognizing equivalent data protection standards
  • Other legally approved transfer mechanisms

5. Data Security

We take the security of your personal information seriously and implement appropriate technical and organisational measures to protect it:

Security Measures:

  • All data transmitted between your device and our servers is encrypted using SSL/TLS
  • Passwords are stored using industry-standard encryption (hashing and salting)
  • Our servers are hosted in secure, access-controlled data centers
  • We implement access controls to limit who can access your data internally
  • Regular security updates and monitoring

6. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy:

6.1 Active Accounts

We retain all your data while your subscription is active and for 30 days after it expires. This allows you to easily reactivate your account if you wish to renew.

6.2 Closed/Expired Accounts

If you do not renew your subscription, we will retain your data for 12 months after your subscription ends. This allows us to handle support queries and enables you to return to your account if you change your mind. After 12 months, all personal data (except payment records) is permanently deleted.

6.3 Payment Records

We are legally required to retain payment records for 7 years under UK tax law (HMRC requirements). Payment records include: transaction dates, amounts, payment confirmations. These records are kept separately and securely even after other account data is deleted.

6.4 Anonymized Data

We may retain anonymized, aggregated data (which cannot identify you) indefinitely for statistical and research purposes.

6.5 Marketing Consent

If you opt in to marketing emails but do not engage with them for 2 years, we will delete your marketing preferences and stop sending promotional content.

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

7.1 Right to Access

You have the right to request a copy of the personal information we hold about you.

7.2 Right to Rectification

If any information we hold about you is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your account settings, or contact us for assistance.

7.3 Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data. We will comply with your request within 30 days, except for:

  • Payment records, which we must retain for 7 years by law
  • Information we need to retain for legal claims or compliance

7.4 Right to Restrict Processing

You can ask us to temporarily restrict how we use your data in certain circumstances, such as when you contest the accuracy of the data.

7.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) and to transfer it to another service provider.

7.6 Right to Object

You have the right to object to processing of your personal data where we rely on legitimate interests as the legal basis (such as for marketing or analytics).

7.7 Right to Withdraw Consent

Where we process your data based on your consent (such as for marketing emails), you can withdraw consent at any time by:

  • Clicking "unsubscribe" in any marketing email
  • Updating your preferences in your account settings

7.8 Right to Lodge a Complaint

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

  • Website: https://ico.org.uk
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

8. Exercising Your Rights

To exercise any of your rights, please contact us.

Verification:

To protect your privacy and security, we may need to verify your identity before responding to your request. We may ask you to:

  • Confirm your email address
  • Provide information from your account
  • Answer security questions

Response Time:

We will respond to your request within 30 days. If your request is complex or we receive multiple requests, we may extend this period by an additional 60 days and will inform you of the delay.

No Charge:

We will not charge you for exercising your rights unless your request is manifestly unfounded, excessive, or repetitive.

9. Cookies and Tracking

9.1 Essential Cookies

We use essential cookies that are necessary for the website to function properly:

  • Session cookies to keep you logged in
  • Security cookies to protect against fraud and unauthorized access

These cookies are strictly necessary and do not require your consent.

9.2 Analytics

We use Cloudflare Web Analytics on our marketing/splash pages, which:

  • Does not use cookies
  • Does not track individuals
  • Collects only anonymous, aggregated data
  • Complies with all privacy regulations without requiring consent

9.3 No Third-Party Tracking

Privacy First: We do not use:

  • Advertising cookies
  • Social media tracking pixels
  • Third-party behavioral tracking
  • Cross-site tracking technologies

10. Children's Privacy

Our Service is intended for healthcare professionals and medical students who are at least 18 years of age. We do not knowingly collect personal information from anyone under the age of 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at and we will take steps to delete such information promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

Notification of Changes:

  • We will update the "Last updated" date at the top of this policy
  • For significant changes, we will notify you by email at least 30 days before the changes take effect
  • Continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

12. Third-Party Links

Our website may contain links to external websites, resources, or services that are not operated by us (such as medical journals, formularies, or educational resources).

Please Note:

  • This Privacy Policy does not apply to third-party websites
  • We are not responsible for the privacy practices or content of external sites
  • We encourage you to review the privacy policies of any third-party sites you visit
  • The inclusion of links does not imply endorsement of these sites by UroPrep Limited

Last Updated: 21/10/2025

Urobank is a service provided by UroPrep Limited (Company No. 16833894).

© 2025 UroPrep Limited. All rights reserved.

View Terms and Conditions

← Back to Home

Report Question Issue