Skip to content
ZenOptix

Security & GDPR

Designed for sensitive optical practice data

ZenOptix is built around controlled access, auditability and secure handling of patient, clinical and practice information.

Principles

Security principles built into the product

These principles shape how every ZenOptix module is designed, not added afterwards.

Least-privilege access

Users should only access what their role and context allow.

Organisation and branch context

Access is shaped by the organisation and location the user is working in.

Audit-focused design

Sensitive activity should be recorded and reviewable.

Controlled support

Support access should be deliberate, limited and auditable.

Privacy-aware workflows

Exports, files and patient data require careful handling.

Access Control

Role-based access for real practice teams

ZenOptix supports different team roles across platform, organisation and branch contexts, helping practices control who can access operational, financial and clinical areas.
Platform admins Organisation admins Location managers Receptionists Optometrists Locums Dispensing users Stock users Finance users Auditors

Menus are not the security boundary. Route and action permissions must still be enforced by the application. ZenOptix is designed so that hiding a screen is never the only protection.

User Access · Example

Auditability

Auditability for sensitive actions

ZenOptix is designed to record important activity across patient records, clinical visits, appointment changes, reports, exports, till activity, staff changes and support access.
  • Patient viewed or updated
  • Clinical visit signed or amended
  • Appointment booked, moved or reassigned
  • Report viewed or exported
  • Till payment or refund recorded
  • Staff roles or permissions changed
  • Support session started or ended

Patient Data

Careful handling of patient records, documents and images

Optical practices handle sensitive patient and clinical information. ZenOptix is designed to organise records, documents and images with controlled access and clear activity history.

Patient timeline

Activity organised around a clear history.

Clinical visit separation

Clinical records kept distinct and structured.

Documents and images

Structured, access-controlled storage.

Controlled exports

Exports are deliberate and visible.

Signed records and amendments

Changes are controlled and traceable.

Support Access

Support access should be controlled, not assumed

ZenOptix is designed so support activity can be handled through controlled sessions with clear visibility, rather than unrestricted background access.

Practice approval required

A support session starts with a request the practice approves, not standing access.

Time-limited and scoped

Approved sessions are scoped and time-limited rather than open-ended.

Audited actions

Support activity is designed to be recorded.

Reviewable support activity

Practices should be able to see what support did, and when.

GDPR

GDPR-aware by design

ZenOptix is designed to support privacy-aware practice workflows, including controlled access, data exports, retention decisions and audit trails.

Access control

Role and context shape what each user can reach.

Audit trails

Sensitive activity is designed to be reviewable.

Export visibility

Data leaving the system should be deliberate and visible.

Retention support

Designed to support considered retention decisions.

Opt-out preferences

Patient communication preferences are respected.

Data protection workflows

Privacy-aware handling built into daily tasks.

Subject access requests

SAR and data protection requests handled as a tracked workflow.

Patient portal visibility

Records reach the portal only when the practice shares them.

UK data residency

Practice and patient data is hosted in the United Kingdom.

Hosting & Transparency

Hosted in the UK, with nothing hidden from the practice

Where your data lives, who can reach it and what it costs to run should all be answerable without asking us. ZenOptix is built so a practice manager can check each of those things in the product.

UK-based hosting

ZenOptix runs on UK-based infrastructure. Practice and patient data stays in the United Kingdom.

Per-branch data isolation

Multi-branch practices switch context between branches, with data kept separated by branch.

Data protection requests

Subject access and data protection requests are handled as a built-in workflow rather than an ad hoc scramble.

Support access you approve

Support access requires practice approval, is time-limited and is fully audited.

Billing you can see

Invoices, payments and your plan are visible in the practice billing portal, with accounting exports for your bookkeeper.

SMS allowance transparency

Message usage, bundles and thresholds are visible in the app, so messaging costs are never a surprise.

Evidence-based communication

Clear, evidence-based security communication

ZenOptix communicates security and assurance capabilities according to their implemented and verified scope. Review the principles behind the workflows:

  • Role-based access shaped around team responsibilities
  • Branch context and least-privilege access principles
  • Controlled support access with reviewable activity
  • Audit-focused design and privacy-aware workflows

Request the security and data-processing documentation relevant to your practice before onboarding.

See it in your practice

Want to understand how ZenOptix controls access?

Book a demo and we'll show how roles, branch context and audit-focused workflows are designed into ZenOptix.