Trust · United Kingdom

UK GDPR: programme in progress.

Health data is special category data under UK GDPR. You, the clinic, are the controller; MedAppz would be your processor. Our server is in the United States, so using MedAppz is a restricted transfer out of the UK. The transfer safeguards and processor contracts are not in place yet. Here is what is.

Status as of 24 September 2026MedAppz United Kingdom
An illustration of a clinic team reviewing a shared, secured workspace

Where we stand, as of 24 September 2026

This covers UK GDPR and the Data Protection Act 2018. MedAppz does not claim compliance with it or any certification under it. This is a programme in progress, and this table is where it stands. Records are stored on one server: Boston, United States · Hostinger VPS. For a UK clinic that is a restricted transfer.

ItemStatusNote
Processor contract (Art. 28) between you and MedAppzIn progressA processing addendum exists in the legal centre, written for India. A UK version is not yet published.
Transfer safeguards for US hosting (IDTA or UK Addendum)Not startedNeeded because the server is in the US. Not in place.
UK hosting regionNot startedThere is one server, in the US. No UK region is set up.
Sub-processor agreementsNot startedWe hold no signed agreement with any sub-processor yet: not the host, not the AI or speech vendors, not the SMS, email or WhatsApp providers.
Breach notification to the ICO within 72 hoursNot startedThe breach register tracks Indian deadlines only. The ICO clock is not built.
Data subject request deskIn progressThe Security Centre logs access, correction and erasure requests on a 30-day clock. It was built for India’s DPDP Act and is not yet tailored to UK GDPR.
Audit trail, emergency access, access reviews, backupsIn placeListed below, each with the module that does it.
GDPRDesk and NHSLinkIn progressIn development; see their catalog pages.

In place in the product today

Each of these runs in the product now. The line under each one names the part of the law it relates to. That is a pointer for your own review, not a claim that the clause is met.

An audit trail that cannot be editedRecord opens, searches and exports are written once: who, when, from where, under which permission. The log is append-only by database trigger and hash-chained day by day; the chain is re-verified nightly.Audit schema and AuditLens · Security of processing — Art. 32
One clinic cannot read another’s rowsRow-level security on every tenant table, bound to the transaction. The account the application runs as cannot switch it off.Database row-level security · Security of processing — Art. 32
Emergency access that expires and is reviewedBreak-glass access needs a written reason, lasts at most four hours (a database constraint), and lands on a review queue.BreakGlass · Integrity and confidentiality — Art. 5(1)(f)
Consent records, by notice versionMessages are gated on the consent notice the patient accepted, by version, at the moment of sending. Withdrawal cancels what is queued.ConsentVault and the consent service · Conditions for consent — Art. 7
Access reviews with two-person revocationThe Security Centre runs dated access-review campaigns over privileged grants (full patient data, money, platform, emergency access). A challenge raises a two-person approval; a campaign cannot close with unread items.Security Centre · Regular testing of measures — Art. 32(1)(d)
Strong sign-in and short sessionsArgon2id password hashing, lockout after five failures, optional or organisation-required app-based two-factor, 15-minute access tokens with rotating refresh tokens, and a five-minute idle-out on shared devices.Identity
Encryption in transit, and sealed credentialsTLS on every connection, with certificates renewed automatically. Keys and passwords a clinic gives us are sealed with AES-256-GCM, bound to the organisation, and never shown back.TLS and the secrets envelope
Nightly verified backups, with a rehearsed restoreThe database and files are dumped every night and each dump is checked before the run counts as a success. A full restore was rehearsed on 3 September 2026.ops/backup.sh · Ability to restore availability — Art. 32(1)(c)
Exports are whitelisted and recordedOnly listed views can be exported, each needs its permission, and each export is recorded with its row count and data classes.Exports · Records of processing — Art. 30
AI you can switch off, or send redactedOne setting per organisation: off, redacted (the default) or full. Redacted strips the name, date of birth, hospital number, phone and email before the request leaves our server. A named person accepts every draft.AI governance

What you would need to do

  • Hold a lawful basis under Art. 6 and a condition under Art. 9 for the health data you keep.
  • Carry out a DPIA before adopting a new system for patient records, and a transfer risk assessment for US hosting.
  • Keep your own records of processing and pay the ICO data protection fee if it applies to you.
  • Do not move real patient records in until the processor contract and transfer safeguards are signed.
  • Turn AI and transcription off, or keep them on redacted, until the vendors’ terms suit you.
This page describes our product. It is not legal advice; take your own advice on how the law applies to your practice.

Sub-processors and where they are

Every outside service the product can send data to, where it processes it, and whether an agreement is signed. The list is generated from the register the product itself reads, the same one the Trust Centre shows.

ServiceLocationAgreement
HostingerThe rented server the database, the application and the uploaded files run onOne rented regionNone signed yet
S3-compatible object storageWhere uploaded files and documents live when object storage is switched onThe bucket region the deployment configuredNone signed yet
AnthropicAI drafting and answeringUnited StatesNone signed yet
OpenAIAI drafting and answeringUnited StatesNone signed yet
Google (Gemini)AI drafting and answeringUnited StatesNone signed yet
NVIDIA NIMAI drafting and answeringUnited StatesNone signed yet
The configured speech-to-text serviceTurning a consultation recording into a transcriptWherever SPEECH_API_BASE_URL points — api.openai.com (United States) unless changedNone signed yet
The clinic’s own Jitsi serverCarrying the live audio and video of a video visitWherever the clinic hosts itNone signed yet
ResendSending emailUnited States / European UnionNone signed yet
MSG91Sending SMSIndiaNone signed yet
Meta (WhatsApp Business)Sending WhatsApp messages through the official APIMeta’s global networkNone signed yet
The clinic’s paired WhatsApp numberSending WhatsApp messages from the clinic’s own handset sessionMeta’s global network, through the clinic’s own numberNone signed yet
Google (Firebase Cloud Messaging)Delivering push notifications to a phoneGoogle’s global networkNone signed yet
RazorpayTaking a payment online, and holding a standing UPI Autopay or e-mandate authorisationIndiaNone signed yet
PhonePeTaking a payment onlineIndiaNone signed yet
StripeTaking a payment onlineUnited StatesNone signed yet
Pine LabsTaking a card payment on the counter terminalIndiaNone signed yet
Google SheetsReceiving a scheduled exportGoogle’s global networkNone signed yet
Google Business Profile and MetaReading reviews and publishing the clinic’s repliesGoogle and Meta’s global networksNone signed yet
The clinic’s own mail serverThe mailbox MedAppz proxies rather than copiesWherever the clinic’s mail is hostedNone signed yet
The hospital’s own GST Suvidha ProviderRegistering the hospital’s own patient invoices with the Invoice Registration PortalIndiaNone signed yet
The clinic’s own Tally serverReceiving the accounting export, and answering which vouchers it tookWherever the clinic runs TallyNone signed yet
A database the clinic bringsA destination the clinic asked the product to write toWherever the clinic hosts itNone signed yet

Send us your UK GDPR questions

Your security questionnaire is longer than this page. Leave a number and we will answer it line by line, including where the answer is “not yet”.

We use your name, phone number and clinic name for one thing: to answer this enquiry about MedAppz. It is stored on our own server, in the single region our trust centre names, and it is not sold or passed to anyone else.

Email us

You can withdraw either at any time: write to hello@medappz.com, or tell whoever calls you, and we will delete what you gave us.