Security & Compliance

Built with UK clinic trust in mind

Enterprise-grade security, UK data residency, ICO registration, and full GDPR compliance. Your patients' data is protected at every layer.

UK data residencyAES-256 encryptionFull audit trailsICO registeredGDPR compliant

Where data is hosted

  • All patient data stored exclusively in UK-based data centres (Fly.io London, lhr region)
  • Zero cross-border data transfers — data sovereignty guaranteed
  • Multi-availability-zone deployment for high availability
  • Geographic redundancy within the UK region

Backups & disaster recovery

  • Automated daily backups with 30-day retention
  • Point-in-time recovery available within the retention window
  • Backup data encrypted at rest using AES-256
  • Regular disaster recovery testing and documented procedures

Access controls

  • Role-based access control (RBAC) — Admin, Practitioner, Receptionist, and custom roles
  • Per-user audit trails showing who accessed or modified what and when
  • Configurable security groups with granular permissions
  • Session management with automatic timeout for inactive sessions

Encryption at rest & in transit

  • AES-256 encryption for all stored data (database, files, backups)
  • TLS 1.3 enforced for all data in transit — no downgrade possible
  • Encrypted file storage for uploaded documents, scans, and attachments
  • API keys and secrets managed through environment-variable vaults, never in code

Audit logs

  • Every action is logged: logins, patient views, note edits, exports, deletions
  • Immutable audit trail — logs cannot be modified or deleted by any user
  • Filterable by user, action type, date range, and patient
  • Exportable for regulatory review or internal compliance audits

Retention & deletion policy

  • Clinic administrators control data retention settings
  • Right-to-erasure (GDPR Article 17) supported — patient data can be fully deleted on request
  • Automated data purge schedules available for expired records
  • Deleted data removed from backups within the retention window

AI data processing

  • AI Clinical Scribe uses OpenAI with strict data processing agreements
  • Audio recordings are processed and immediately discarded — never stored by the AI provider
  • No patient data is used for AI model training by any third party
  • AI features can be disabled per-clinic if not required
  • All AI processing logged in audit trail

DPA & privacy

  • Data Processing Agreement (DPA) available for all customers upon request
  • Registered with the UK Information Commissioner's Office (ICO)
  • Privacy Impact Assessments (PIAs) completed for all new features
  • GDPR-compliant consent management, data portability, and breach notification procedures
  • Subprocessor list available on request

Need more details?

Request our full DPA, security questionnaire response, or subprocessor list.