Cataract Glaucoma Lid Surgery About Fees Reviews Book a consultation

Privacy Notice

Sam Evans Ltd • Last updated: July 2026

This notice was updated in July 2026 to reflect the introduction of the Devon Eyes patient app, and the use of third-party processors Twilio, Supabase, and Semble.

1. Who we are

Sam Evans Ltd is the data controller for all personal data collected through the Devon Eyes website and patient app. We are registered with the Information Commissioner’s Office (ICO) as a Data Controller.

We adhere to the principles of UK GDPR and the Data Protection Act 2018, and to the GMC Code of Confidentiality.

2. What personal data we collect and why

2a. Marketing website (devoneyes.com)

When you submit an enquiry or booking request via the contact form on this website, we collect:

Purpose: to respond to your enquiry and, where relevant, arrange a consultation.
Lawful basis: legitimate interests (responding to a contact request).
Retention: enquiry data is retained for 12 months, after which it is deleted unless a clinical relationship has begun.

2b. Clinical care

Where you become a patient of Mr Sam Evans, we collect and process clinical information including medical history, examination findings, investigation results, treatment plans, and correspondence with other healthcare providers. This is necessary to provide safe and appropriate ophthalmic care.

Lawful basis: performance of a contract (provision of healthcare) and processing of special category data under Article 9(2)(h) UK GDPR (health data for medical purposes).
Retention: clinical records are retained for a minimum of 8 years from the date of last treatment, in line with NHS and medical defence guidance. Records relating to children are retained until the patient’s 25th birthday.

2c. Devon Eyes patient app

The Devon Eyes patient app is a progressive web application (PWA) provided to patients to support their care. Through the app we may collect:

Lawful basis: consent (for mobile number and SMS); performance of a contract / legitimate interests (for clinical app features).
Retention: app account data is retained for the duration of your care and deleted on request, subject to any overriding clinical record retention obligations.

2d. Website analytics

We use Google Analytics 4 (GA4) and Google Ads to understand how visitors use this website and to measure the effectiveness of our advertising. This involves the use of cookies and may involve the transfer of anonymised data to Google’s servers in the US under Standard Contractual Clauses.

Lawful basis: legitimate interests (understanding website usage to improve our service). You can opt out of analytics cookies via our cookie settings.

3. Third-party processors

We use the following third-party services to process personal data on our behalf. Each is engaged under a data processing agreement or equivalent contractual protection.

ProcessorPurposeData involvedSafeguards
Netlify Website hosting and form submission handling Enquiry form data (name, email, phone, message) Standard Contractual Clauses; DPA in place
Twilio SMS delivery — sending app access links to patients who have given explicit consent Mobile telephone number only Twilio Data Protection Addendum (automatically incorporated into Terms of Service since 2020); Standard Contractual Clauses; UK GDPR compliant
Supabase Patient app database — storing account data, clinical uploads, and app content Name, email, clinical information uploaded via the app Data Processing Agreement in place; data hosted on EU servers; SOC 2 Type II certified
Semble Practice management system — clinical records, appointments, invoicing Full clinical record, contact details, billing information UK-based healthcare data processor; DSPT-aligned; Data Processing Agreement in place
Google (Analytics & Ads) Website analytics and advertising measurement Anonymised usage data, cookies Standard Contractual Clauses; privacy-safe configuration
Notion Internal surgical logbook — aggregate outcomes data displayed on this website Surgical outcome data (no patient-identifiable information) No patient-identifiable data stored; Notion Business Terms apply

4. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, contact us at hello@devoneyes.com. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner’s Office at ico.org.uk or by calling 0303 123 1113.

5. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. Clinical data is stored and transmitted using encryption. App data is stored in Supabase with row-level security and access controls. We do not sell or share your personal data with third parties for marketing purposes.

6. International transfers

Some of our processors (including Google and Twilio) may transfer data outside the UK. Where this occurs, it is protected by Standard Contractual Clauses approved under UK GDPR or an equivalent adequacy mechanism.

7. Cookies

This website uses cookies for analytics and advertising measurement purposes. See our Cookie Policy for full details and opt-out options.

8. Changes to this notice

We may update this privacy notice from time to time. The date at the top of this page indicates when it was last revised. Where changes are material, we will take reasonable steps to bring them to your attention.

9. Contact

For any privacy-related queries, to exercise your rights, or to raise a concern:

This notice is provided for information purposes. It does not constitute legal advice. If you have concerns about how your data is handled, we encourage you to contact us directly in the first instance.

☎ Call Book a consultation