William Thomas Optical William Thomas Optical ← Back to portal

Privacy Policy

Last updated: 14 July 2026

This Privacy Policy explains how William Thomas Optical ("we", "us", "our") collects, uses, shares and protects personal data when you use our lens glazing laboratory services and the trade ordering portal at wtoptical.co.uk. We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

William Thomas Optical is a UK optical lens glazing laboratory supplying and glazing spectacle lenses, tints and coatings to opticians and optical practices ("customers"). For the personal data described here we are the data controller, except for prescription data, which we generally process on behalf of the ordering optician (see §3).

We are not required to appoint a Data Protection Officer; privacy questions and rights requests are handled by the contact above.

2. What personal data we collect

CategoryExamples
Account & contactYour name, work email, phone, job role, practice/company name and addresses, sign-in credentials.
Trade account & financialTrading-account application details, invoice addresses and emails, bank details you provide, credit terms, invoices and payment records.
Orders & job dataLens specifications, order/box references, tray reference photos, delivery details.
Prescription dataLens prescription values, sent by opticians against an order/box reference. We do not collect patient names or other direct patient identifiers. See §3.
CommunicationsMessages you send us through the portal and emails to and from our mailboxes.
Technical & securityIP address (recorded, for example, in the audit trail when a trading agreement is signed), the essential session cookie, and basic security/activity logs.

3. How and why we use personal data (legal bases)

PurposeLawful basis (UK GDPR Art 6)
Providing our services — processing and glazing orders, delivery, invoicing, running your trade account and portal login.Performance of a contract — Art 6(1)(b).
Verifying business identity and credit (e.g. Companies House checks) and managing credit limits.Contract, and our legitimate interests in safe trade credit — Art 6(1)(f).
Security, audit and fraud prevention (including recording the IP address when agreements are signed).Legitimate interests, and legal obligation where applicable — Art 6(1)(f)/(c).
Keeping accounting, tax and statutory records.Legal obligation — Art 6(1)(c).
Service messages and updates about the service.Contract / legitimate interests. Any marketing relies on consent or a soft opt-in, and you can opt out at any time.

Prescription data

Opticians send us prescriptions to fulfil orders. We do not receive or store patient names, dates of birth or other direct patient identifiers — a prescription reaches us as lens values against an order/box reference. On its own, a prescription with no identifier is not information from which we can identify a patient.

Where an order carries a reference that lets the optician link it back to a named patient (for example the optician's own patient reference), the prescription is pseudonymised rather than truly anonymous, and it still concerns health. In that case we process it on the optician's behalf as a processor — the optician is the controller for their patient's data and holds the patient-facing obligations — and only to fulfil the order. Given its sensitivity, we apply the safeguards in this notice to prescription data whether or not a reference is present.

4. AI-assisted features

To save time, the portal can use artificial-intelligence services to help read information from images you upload — for example extracting prescription values from a dispensing slip, or reading tray reference numbers from a photo. These features are assistive and human-reviewed: a member of staff checks the result before it is used, so there is no solely-automated decision-making that produces legal or similarly significant effects about you. Images and text submitted to these features may be processed by our AI providers (see §5).

5. Who we share data with

We do not sell personal data. We share it only with the service providers ("processors") who help us run the service, under contracts that require them to protect it and use it only on our instructions, and where we are legally required to. The categories are:

Category of recipientPurpose
Cloud hosting & infrastructureRunning the application and database.
File storage & backupsEncrypted storage of uploaded files and backups.
Email deliverySending and receiving service and invoice emails.
AI providersThe assistive image/text extraction described in §4.
Identity & credit verificationConfirming business identity (e.g. Companies House).
Couriers, payment processors & professional advisersDelivery, payments, and accounting/legal advice as needed.

A current list of our named sub-processors is available on request from the contact above.

6. International transfers

Some of our providers (in particular certain AI providers) may process personal data outside the UK. Where that happens, we rely on an appropriate safeguard recognised under UK data-protection law — such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses — so your data receives an equivalent level of protection. Details of the safeguard relied on for a particular provider are available on request.

7. How long we keep data

We keep personal data only for as long as necessary for the purposes above, then delete or anonymise it. Our indicative periods are:

DataRetention
Accounting & tax records6 years after the relevant accounting period (as required by law).
Trade account & order recordsFor the life of the account, and up to 6 years after it closes.
Prescription / order images & extractsOnly as long as needed to fulfil and evidence the order — as a default up to 12 months after completion, unless a longer period is agreed with the optician.
Signed agreement audit recordsFor the duration of the agreement and up to 6 years after it ends, to evidence the agreement.
Security & activity logsA short rolling period (typically up to 12 months).

8. Your rights

Under UK GDPR you have the right to: access your data; have it corrected or erased; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. To exercise any right, contact us at lab@wtoptical.co.uk.

If a request concerns a patient's prescription data that we hold on behalf of an optician, we will direct you to, or work with, that optician as the controller.

You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO): ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to resolve any concern first.

9. Cookies

The portal uses a single strictly-necessary cookie to keep you signed in. We do not use tracking, analytics or advertising cookies. Full detail is in our Cookie Notice.

10. Security

We protect personal data with measures including encryption in transit (HTTPS/TLS), an httpOnly secure session cookie, hashed passwords, role-based access controls and permission groups that limit which staff can see or change what, encrypted file storage and regular backups.

11. Children

The portal is a business-to-business service for opticians and is not directed at children. Any patient data we handle is provided by, and processed for, the optician placing the order.

12. Changes & contact

We may update this notice from time to time; the date at the top shows when it last changed. For any privacy question or to exercise your rights, contact lab@wtoptical.co.uk.