VisionSuite logo VisionSuite
Home About Portals Contact us

GDPR

Last updated: 16 June 2026

1. Overview

This page explains how Maia Vision Ltd approaches UK GDPR and data protection responsibilities in connection with VisionSuite, the web-based platform available at https://visionsuite.maiavision.co.uk.

This page applies to VisionSuite only. It does not necessarily apply to the general Maia Vision Ltd website at https://maiavision.co.uk, which may have separate privacy notices, policies, or terms.

VisionSuite is designed to support research, clinical data management, participant engagement, collaboration, and related workflows within vision science, optometry, ophthalmology, healthcare research, and associated fields.

Depending on the relevant project configuration, VisionSuite may process personal data, confidential research data, health-related information, clinical images, visual field data, Optical Coherence Tomography data, questionnaire responses, study documentation, uploaded files, and operational system records.

Identifiable health-related information is likely to be special category personal data under UK data protection law. Such information should only be processed through VisionSuite where the relevant organisation has appropriate governance, a lawful basis, a special category condition, ethical approval where required, participant information, consent arrangements where applicable, contractual coverage, and data protection documentation.

This page provides a general overview of VisionSuite's GDPR approach. It does not replace the VisionSuite Privacy Policy, Cookie Policy, Terms and Conditions, any project-specific privacy notice, participant information sheet, consent form, research protocol, contract, or Data Processing Agreement.

2. Data Controller and Processor Roles

Maia Vision Ltd's role depends on the context in which personal data is processed and the decisions made by the organisation responsible for the relevant project.

Project, participant, research, and health-related data

Where a university, research organisation, healthcare organisation, sponsor, study team, clinical service, or other customer uses VisionSuite to manage project, participant, research, or health-related data, that organisation will usually act as the data controller.

The data controller is responsible for deciding why and how personal data is processed. This normally includes deciding what data is collected, the lawful basis for processing, any special category condition, participant information and consent arrangements, user access requirements, retention periods, data subject rights handling, and research governance requirements.

In these circumstances, Maia Vision Ltd will usually act as a data processor. Maia Vision Ltd processes personal data on behalf of the data controller and in accordance with the controller's documented instructions, the relevant contract, and any applicable Data Processing Agreement.

Maia Vision Ltd controller activities

Maia Vision Ltd may act as a data controller for limited business and platform administration purposes. This may include managing VisionSuite user accounts, responding to support requests, maintaining platform security, keeping operational records, managing customer relationships, complying with legal obligations, and protecting the rights, security, and integrity of Maia Vision Ltd and VisionSuite.

Sub-processors and supporting services

Maia Vision Ltd may use supporting services to host, secure, maintain, back up, monitor, and support VisionSuite. These may include hosting providers, backup storage providers, certificate providers, source code management services, communication services, professional advisers, and technical support providers.

Where a supporting service processes personal data on behalf of Maia Vision Ltd or a customer organisation, appropriate contractual, technical, organisational, and data protection safeguards should be in place.

Supporting services relevant to VisionSuite operations may include the production VPS hosting provider, Let's Encrypt and Certbot for SSL/TLS certificate management, GitHub for source code version control only, and controlled secondary backup storage used by Maia Vision Ltd.

Production databases, uploaded files, secrets, private keys, environment variables, and runtime data are not intended to be stored in the GitHub source code repository.

3. Lawful Basis for Processing

Personal data must only be processed where there is a valid lawful basis under UK GDPR. The applicable lawful basis depends on the purpose of the processing, the type of information involved, and the relationship between the individual, Maia Vision Ltd, and the relevant project or organisation.

Where Maia Vision Ltd acts as a data controller, we may rely on one or more lawful bases depending on the activity.

We may rely on contract where processing is necessary to provide VisionSuite, manage accounts, support users, administer customer relationships, or take steps before entering into a contract.

We may rely on legitimate interests where processing is necessary for appropriate business, operational, technical, or security purposes, provided those interests are not overridden by an individual's rights and freedoms. This may include maintaining platform security, preventing misuse, responding to support requests, improving reliability, keeping appropriate records, and communicating with users or customer organisations about VisionSuite.

We may rely on legal obligation where processing is necessary to comply with legal, regulatory, accounting, tax, corporate, security, or data protection obligations.

We may rely on consent where consent is appropriate, such as for optional communications, non-essential cookies, or specific features where consent is required. Where processing is based on consent, consent can be withdrawn at any time.

For research, healthcare, university, public-sector, or clinical research projects, the relevant data controller may rely on other lawful bases, including public task, legal obligation, legitimate interests, contract, or consent, depending on the project and legal context.

Where special category data is processed, such as identifiable health-related data, the relevant data controller must also identify an appropriate special category condition under UK GDPR and the Data Protection Act 2018.

Maia Vision Ltd does not decide the lawful basis for project, participant, research, or health-related data where it acts as a data processor. That responsibility remains with the relevant data controller.

4. Data Subject Rights

Individuals may have rights under UK data protection law in relation to their personal data. These rights may include the right to be informed, the right of access, rectification, erasure, restriction of processing, objection, data portability, and rights relating to automated decision-making.

Individuals may also have the right to withdraw consent where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

These rights are not always absolute. Their availability may depend on the lawful basis for processing, the type of data involved, research exemptions, legal obligations, clinical or health-related requirements, contractual obligations, security needs, and other applicable rules.

Where Maia Vision Ltd is the data controller for the relevant information, requests can be made using the contact details at the end of this page.

Where a request relates to project, participant, research, clinical, or health-related data controlled by a university, research organisation, healthcare organisation, sponsor, investigator, study team, or other project owner, Maia Vision Ltd may need to refer the request to the relevant data controller.

Where Maia Vision Ltd acts as a data processor, Maia Vision Ltd will support the relevant data controller in responding to data subject rights requests where required by applicable law, contract, or Data Processing Agreement.

VisionSuite may support rights handling through functionality such as access to relevant records, correction of inaccurate information, export of data, deletion where appropriate, restriction of access, and project-level review by authorised users. The availability and use of these functions may depend on the relevant project configuration and governance requirements.

5. Security Measures

Maia Vision Ltd uses technical and organisational measures designed to protect personal data processed through VisionSuite.

VisionSuite requires authenticated user access. Users must log in before accessing protected areas of the platform, and unauthorised users are not permitted to access restricted research, participant, or project information.

VisionSuite implements role-based permissions and project-level access controls. Access to data and functionality is restricted according to the user's assigned role, project responsibilities, and authorised access scope. This supports the principle of least privilege and helps reduce unnecessary exposure of sensitive information.

Communications between users and VisionSuite are protected using HTTPS/TLS encryption. SSL/TLS certificates are issued through Let's Encrypt and managed using Certbot on the production server.

Passwords are not stored in plain text. User passwords are securely hashed before storage.

Administrative access to the production server is restricted to authorised Maia Vision Ltd personnel responsible for system administration, maintenance, and support. Server administration is performed through secure SSH access.

VisionSuite may use web security headers and browser-side protections such as Content Security Policy, frame protection, content type sniffing protection, referrer policy controls, and permissions policy restrictions.

VisionSuite records system activity information to support accountability, troubleshooting, operational monitoring, governance, and incident investigation. Further enhancement of audit logging is included in the security roadmap.

Data at rest is currently protected through server-level access controls, application-level access controls, role-based permissions, project-level restrictions, and restricted administrative access. Further encryption-at-rest options may be reviewed as part of customer security assessment, contractual requirements, or the VisionSuite security roadmap.

VisionSuite uses backup processes to support operational recovery and disaster recovery. Full-system backups are currently performed weekly, with a secondary backup copy retained separately by Maia Vision Ltd using controlled cloud storage.

6. International Transfers

VisionSuite production data is intended to be hosted in the United Kingdom. Current production hosting is located in Birmingham, United Kingdom, data centre region gb/bhx.

Where project, participant, research, or health-related data is processed in VisionSuite, the relevant data controller is responsible for determining whether any international transfer takes place and whether appropriate safeguards are required.

Maia Vision Ltd does not intend to transfer VisionSuite production databases, uploaded files, or participant data outside the United Kingdom unless the transfer is necessary, lawful, documented, and protected by appropriate safeguards.

If a restricted international transfer is required, appropriate safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules, or another lawful transfer mechanism recognised under UK data protection law.

Where required, a transfer risk assessment or equivalent data protection test should be completed before transferring personal data outside the United Kingdom.

Use of third-party services, remote support, cloud storage, or customer-directed exports may require separate assessment depending on the relevant project, service provider, jurisdiction, and data categories involved.

7. Data Retention and Deletion

Personal data should only be kept for as long as necessary for the purposes for which it is processed.

Where Maia Vision Ltd acts as a data controller, retention periods will depend on the relevant purpose. Account, support, customer, technical, security, and operational records may be retained for as long as needed to provide VisionSuite, maintain security, comply with legal obligations, resolve disputes, support audits, and meet operational requirements.

Where Maia Vision Ltd acts as a data processor, retention of project, participant, research, and health-related data is normally determined by the relevant data controller. This may include retention requirements set out in the research protocol, ethics approval, participant information, study documentation, institutional policy, contract, Data Processing Agreement, sponsor requirements, or applicable law.

VisionSuite may support deletion, export, archiving, or restriction of data where appropriate and where permitted by the relevant project configuration and governance arrangements.

Backup copies may retain deleted or amended information for a limited period until backups are overwritten or deleted according to the applicable backup cycle. Backup retention requirements may be reviewed and formalised as part of customer security assessment, contractual requirements, or the VisionSuite security roadmap.

At the end of a project, contract, or processing arrangement, return, deletion, archiving, or continued retention of data will be handled according to the relevant data controller's documented instructions, the applicable contract, Data Processing Agreement, research governance requirements, and legal obligations.

8. Breach Notification

Maia Vision Ltd maintains procedures to assess and respond to suspected security incidents and personal data breaches affecting VisionSuite.

In the event of a suspected incident, Maia Vision Ltd will take reasonable steps to investigate what has happened, assess affected systems and data, contain and mitigate identified risks, preserve relevant evidence where appropriate, notify relevant parties where required, support assessment of notification obligations, and implement corrective and preventative actions.

Where Maia Vision Ltd acts as a data processor and becomes aware of a personal data breach affecting controller data, Maia Vision Ltd will notify the relevant data controller without undue delay and provide information reasonably required to support the controller's assessment and response.

The relevant data controller is usually responsible for deciding whether a personal data breach must be reported to the Information Commissioner's Office and whether affected individuals must be notified.

Under UK GDPR, where a breach is likely to result in a risk to people's rights and freedoms, the relevant controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the risk to individuals is high, affected individuals must also be notified without undue delay.

Where Maia Vision Ltd acts as a data controller for the affected data, Maia Vision Ltd will assess and manage any applicable ICO or individual notification obligations directly.

Users should report suspected security issues, unauthorised access, data incidents, or vulnerabilities affecting VisionSuite as soon as possible using the contact details at the end of this page.

9. Contact and Requests

For GDPR enquiries, privacy questions, security concerns, data subject rights requests, or suspected data incidents relating to VisionSuite, please contact Maia Vision Ltd using the details below.

When contacting us, please include enough information for us to identify your account, project, organisation, request, or concern. Please do not send unnecessary health, clinical, participant, or special category data by email unless we specifically request it through an appropriate secure channel.

If your request relates to a research study, healthcare project, university project, clinical workflow, or participant record, you may also need to contact the relevant university, research organisation, healthcare organisation, sponsor, investigator, study team, project administrator, or data protection officer.

Where Maia Vision Ltd is not the data controller for the relevant data, we may refer your request to the appropriate controller or assist that controller in responding to your request.

You also have the right to complain to the UK Information Commissioner's Office, the UK supervisory authority for data protection. The ICO can be contacted at https://ico.org.uk.

Contact

Maia Vision Ltd
Company number: 17251920
167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom

Email: azwan.ismail@maiavision.co.uk

VisionSuite

Developed and maintained by MAIA Vision Ltd.

Where to find us

MAIA Vision Ltd

Company number: 17251920

167-169 Great Portland Street
5th Floor
London
W1W 5PF
United Kingdom

Overview

Home About Us Portals Contact

Questions?

Portal Login Contact Us
Privacy Policy Terms & Conditions Cookie Policy GDPR

© 2025-2026 VisionSuite

Developed by MAIA Vision Ltd