Privacy policy
Last updated 7 October 2026
This policy explains how Nova Ray Limited (“we”, “us”) handles personal data when you visit this website or use EasyWDA, our compliance and stock-management software for wholesale dealers of medicines.
1. Who we are
EasyWDA is provided by Nova Ray Limited, a company registered in England and Wales with company number 13451272. Our registered office is 4th Floor, Silverstream House 45 Fitzroy Street, Fitzrovia, London, England, W1T 6EB. We are registered with the Information Commissioner’s Office (ICO) under registration number ZB799211.
For anything about this policy or your personal data, email privacy@spark.clinic.
2. Controller or processor
Under UK data protection law (UK GDPR and the Data Protection Act 2018) we act in two different roles:
- We are the controller for data about the organisations that subscribe to EasyWDA and their users’ accounts: login details, security information and how the service is used. We are also the controller for visitors to this website.
- We are a processor for the records each subscribing organisation (“tenant”) keeps in EasyWDA: their customers, suppliers, staff, training records, due-diligence documents and so on. The tenant is the controller of that data and decides what is recorded and why. We process it only to provide the service, on their instructions.
3. What we collect
Account and security data
- Name, email address, job title and role within the organisation.
- A securely hashed password (we never store or see your password itself).
- A mobile number, if you choose text-message codes for two-factor authentication.
- Sign-in history, IP address and browser details, used for security.
- An audit trail of changes you make to records: who, when, what changed and the reason given.
Organisation data
- Your organisation’s name, address, licence numbers and the contact details of its Responsible Person and licence holder.
- Billing and invoice details.
Data tenants record in the service (we process this for them)
- Customer and supplier contacts, licence details and due-diligence records, including identity documents of persons of significant control where the tenant chooses to collect them.
- Partner-portal accounts for those customers and suppliers.
- Staff training records, quiz results, certificates and electronic signatures (time and IP address of signing).
- Operational records such as orders, deliveries, returns, complaints, deviations and controlled-drug entries, which may include names of the people involved.
Website visitors
Our public pages don’t use analytics, advertising or tracking. Our web server keeps standard access logs (IP address, page requested, time) for security.
4. How we use it and why
| Purpose | Lawful basis |
|---|---|
| Providing the service: accounts, sign-in, storing and showing records | Contract with the subscribing organisation; legitimate interests in respect of its individual users |
| Two-factor authentication, preventing fraud and investigating misuse | Legitimate interests (keeping the service and regulated records secure) |
| Keeping an audit trail and backups of GDP records | Legitimate interests, and helping tenants meet their legal obligations under the Human Medicines Regulations 2012 and the GDP guidelines |
| Service emails (password resets, reminders, alerts, invoices) | Contract / legitimate interests |
| Billing and accounting records | Contract and legal obligation |
| Responding to enquiries and support requests | Legitimate interests |
We do not sell personal data, use it for advertising, or make automated decisions about individuals that have legal or similarly significant effects.
5. Who we share it with
We use a small number of trusted service providers (sub-processors), each bound by contract to protect the data:
- Hosting: our servers are located in the United Kingdom.
- Email delivery (Google): to send service and notification emails.
- Twilio: to send text-message sign-in codes, only if you choose that option.
- Google: only if a tenant connects Google Drive for backups (see section 6).
Within the service, a tenant’s data is visible only to that tenant’s users, and to the tenant’s own customers and suppliers through the partner portal where the tenant shares it. Our support staff access tenant data only when needed to provide support or keep the service running. We may also disclose data where the law requires it, for example to a regulator or the police.
6. Google Drive backups
Tenants can optionally connect their own Google Drive account so that a copy of each nightly backup is stored off-site, under their control.
- We request only the
drive.filepermission. It lets EasyWDA create and manage the files it uploads. We cannot see, read or change any other file in the Drive. - We use this access only to create a backup folder and upload backup files to it.
- Access tokens are stored encrypted. Disconnecting Drive in EasyWDA, or removing access in your Google account settings, stops all further uploads.
- Backup files already in your Drive belong to you; we never delete them.
EasyWDA’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, sell it, or use it to train AI models, and no person reads it except where you ask us to for support, for security reasons, or where the law requires it.
7. International transfers
Our main data store is in the United Kingdom. Some providers, such as Twilio and Google, may process data outside the UK. Where they do, we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to keep the data protected.
8. How long we keep it
- Tenant records are kept while the organisation subscribes. GDP and controlled-drug records generally have to be kept for at least five years, and tenants are responsible for setting retention for their own records.
- Audit trail entries can’t be edited or deleted, because they are part of the regulated record.
- Backups on our servers are kept daily for 7 days, then one per week up to 60 days, and are deleted after that. Copies in a tenant’s own Google Drive are kept for as long as the tenant chooses.
- When an organisation leaves, we can provide a full export and then delete its data, apart from anything we must keep by law (for example our billing records, normally six years).
- Server access logs are kept for a short period for security, then deleted.
9. Security
Data is encrypted in transit (HTTPS). Two-factor authentication is required to sign in. Access depends on each user’s role, and sensitive tokens are encrypted at rest. Backups are made every night and checked weekly. No system is perfectly secure, but we review our measures regularly and will notify affected tenants, and the ICO where required, of any personal data breach.
10. Cookies
We use only strictly necessary cookies: a session cookie that keeps you signed in, a security token that protects forms, and, if you tick “Remember me”, a cookie that keeps you signed in on that device. We do not use analytics or advertising cookies, so no cookie banner is needed.
11. Your rights
Under UK data protection law you can ask to:
- get a copy of your personal data;
- have inaccurate data corrected;
- have data deleted or its use restricted, where the law allows (some regulated records must be kept);
- object to processing based on legitimate interests;
- receive data you provided in a portable format.
Email privacy@spark.clinic and we’ll reply within one month. For data a tenant holds about you, see the note in section 2. If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office (0303 123 1113).
12. Changes and contact
We’ll update this page when our practices change, and tell tenants by email or in the app about any significant change. Our terms of service include the data processing terms that apply between us and each tenant. Questions? Email privacy@spark.clinic.