Legal
Legal Release Statement
- Version:
- 1.0
- Effective:
- 15 September 2026
- Last updated:
- 15 September 2026
- Operator:
- MTX STUDIO Ltd trading as Plinical
- Company no.
- 15856187
- Registered office:
- Princess House The Square, 3rd Floor, Shrewsbury, Shropshire, England, SY1 1JZ
This statement explains how Plinical's legal documents apply to the website and software, how customer agreements take effect, and the responsibilities of MTX STUDIO Ltd and its clinic customers.
1. Operator and scope
Plinical is operated by MTX STUDIO Ltd, company number 15856187, whose registered office is Princess House The Square, 3rd Floor, Shrewsbury, Shropshire, England, SY1 1JZ. In this statement, we, us and our refer to MTX STUDIO Ltd.
Plinical provides clinic-management software to UK clinic businesses and self-employed professionals. This statement explains the legal framework for that service. The customer's Order and the applicable contractual terms determine its rights and obligations.
2. Governing documents
Document | What it covers
Website Terms | Access to and use of the public Plinical website.
SaaS Terms | The software subscription, trial, fees, renewal, cancellation and service obligations, together with the accepted Order.
Data Processing Agreement | Processing of clinic personal data on the clinic's behalf, including security, Sub-processors, transfers, assistance and deletion.
Privacy Notice | Personal information for which MTX acts as controller, including business enquiries, account administration and subscription billing.
Cookie Policy | Cookies and similar storage or access technologies and the choices available for their use.
Each document identifies its own version and relevant date. For a subscription, the accepted Order and incorporated SaaS Terms apply. The DPA takes precedence for the processing of clinic personal data where it conflicts with the service agreement; mandatory transfer clauses take precedence where required. This statement does not amend those documents or create additional subscription charges.
3. Customer acceptance and document versions
A customer agreement takes effect through the acceptance process specified in the Order and contractual terms. The accepting person must have authority to bind the identified clinic business. The legal customer identity, accepted documents and date of acceptance must be recorded, and the customer must be able to retain its accepted agreement.
The publication date of a document is separate from the date on which an individual customer accepts it.
Publishing a new version does not automatically replace an existing customer's accepted agreement.
Changes apply through the notice and variation provisions of that agreement and applicable law. A clinic trading name alone does not replace the identity of the contracting company, individual or partnership.
4. Clinic records and access
The clinic is controller of its patient and clinical records. It determines the purposes for which those records are used and remains responsible for clinical decisions, lawful instructions, required privacy information and retention requirements. MTX acts as processor when providing hosted and automated Plinical functions on the clinic's behalf.
Clinic staff use their own authorised accounts. Under Plinical's operating model, MTX staff do not access clinic patient records or sign in to clinic workspaces; support is provided by ticket and reply with guidance or a solution. Clinics must use synthetic or fully redacted information in support requests and must not send patient records, passwords or decryption keys.
5. Data protection safeguards
The DPA sets out the security measures and assistance MTX must provide, including confidentiality, access restrictions, incident notification, support for data rights, audit information, and return or deletion of clinic personal data. Clinics also have responsibilities for their users, devices, communications and downloaded records.
Before a service processes patient health data, the applicable security measures, supplier contracts, permissions for the data categories involved and international-transfer safeguards must be in place.
Encryption and a selected hosting region are safeguards within that assessment. They do not replace the required contractual permissions or transfer arrangements.
The DPA identifies the relevant Sub-processors and governs notice of additions or replacements and the clinic's right to object. Requests for supporting compliance information are handled through the DPA's information and audit provisions, with appropriate protection for confidential information and other customers' data.
6. Accountability and governance
MTX remains responsible for its own data-protection obligations. Company management makes operational and service-release decisions. The Data Protection Officer's role is to advise and monitor independently. Release decisions must take account of the relevant security evidence, supplier arrangements, data-protection impact assessment requirements and applicable law.
Operational approvals, supplier assessments and implementation evidence are recorded separately. This statement does not certify their completion or confer regulatory approval on the software.
7. Publication and changes
Version 1.0 is dated 15 September 2026. It applies when published and replaces the previous informational text at this page. It does not alter any customer's accepted contract.
Updates identify a new version and document date. Contractual changes remain subject to the applicable agreement and required notice or acceptance.
8. Contact details
Legal, privacy, security and support enquiries: support@mtxstudio.com.
Data Protection Officer: Theodoros Mentis, th.mentis@mtxstudio.com.
Patients seeking access to, correction of, or other action concerning their clinic records should contact their clinic. Information about MTX's processing and how to raise a privacy complaint is provided in our Privacy Notice.