Data protection & compliance
Last updated 18 August 2026
This page summarises how mzpay is governed, for practice owners, information governance leads and clinical safety officers. Supporting documents are available to customer practices on request from info@praxisdental.co.uk.
The legal entity
mzpay is operated by Praxis Health Technologies Ltd, England & Wales company no. 17294974, registered office 128 City Road, London, EC1V 2NX. The company is registered with the Information Commissioner's Office, registration ZC180094.
Data processing agreement
Each customer practice signs a UK GDPR Article 28 data processing agreement with us before live data is processed. It names the practice as controller and Praxis Health Technologies Ltd as processor, defines exactly what patient data mzpay handles (patient names and treatment references from billing records - never contact details, dates of birth or clinical records), lists sub-processors, and sets out breach notification, audit and deletion terms.
Clinical safety (DCB0129)
mzpay is a financial administration system: it is not used in the delivery of care and no clinical decision is made in it. We nonetheless maintain a clinical risk management file under DCB0129 - a clinical risk management plan, a hazard log scored on the NHS England 5x5 matrix, and a clinical safety case report - so a deploying practice can complete its own DCB0160 assessment from our documentation.
The named Clinical Safety Officer is Dr Syed Ali (GDC 289983), who meets the competence DCB0129 describes for the role, evidenced by current GDC registration and completed clinical risk management training (NHS Digital Clinical Safety programme and a CPD-accredited Clinical Safety Officer practitioner course, 2026).
Where data lives
All data is hosted in the European Union: database and encrypted document storage with Supabase, application hosting with Vercel. Data in transit is protected by TLS. Scanned invoices live in a private storage bucket that is never publicly readable. Access to data is role-based within the application, and every material action is recorded in an audit log.
Sub-processors
- Supabase - database and document storage (EU)
- Vercel - application hosting (EU region)
- Anthropic - AI invoice reading and aggregate insights; no model training on customer data
- Resend - staff email delivery, where enabled
- Google - optional sign-in, authentication only, where enabled
Practices are notified before any sub-processor is added or replaced.
What mzpay never holds
No patient contact details, no dates of birth, no NHS numbers, no medical histories, no clinical notes, no radiographs. The patient data surface is limited to what billing records already contain: a name, a treatment description, a tooth reference and an amount.
Incidents and breaches
Suspected security incidents are reported to info@praxisdental.co.uk and handled under our breach response procedure: containment, assessment, notification of the controller practice without undue delay, and ICO notification where required by law.