Skip to main content

Privacy and governance

The privacy policy is the authoritative public statement. This page is the material an IG or DPIA review usually asks for.

Controller and processor roles

Swyftscale is the data controller for the personal data described here — clinician account data.

For clinical data, MedJot is not a processor at all in the ordinary case, because clinical data does not reach us. It is created and stored on the clinician's device, under the employing organisation's own governance, exactly as a paper notebook or a locally-saved document would be.

The exceptions are narrow, deliberate and user-triggered:

  • Running an AI feature transmits a redacted clinical summary.
  • A device transfer holds report content in memory for up to 10 minutes.
  • A saved template is stored against the account.

Each is described in Data flows.

Lawful bases

ProcessingBasis
Holding an account, providing the serviceArticle 6(1)(b) — performance of a contract
Knowing who our users are; protecting a clinical tool from abuseArticle 6(1)(f) — legitimate interests
Usage analyticsArticle 6(1)(a) — consent, plus PECR consent
Product update and marketing emailArticle 6(1)(a) — consent, plus PECR
Billing recordsContract, and legal obligation for retained financial records

Account-related email — security, billing, things a user must be told — is sent on the contract basis and is not affected by consent choices.

Three consents are asked as three separate questions: analytics, product updates, marketing.

  • Nothing is pre-ticked.
  • Answering is required; agreeing is not. "No" is recorded as a decision, and a missing record means "never asked" — a materially different fact.
  • Bundling them would mean consent that could not be given for one purpose without another, which is not freely given.
  • Withdrawal is as easy as giving, from the account profile, and withdrawing analytics consent purges that person's raw event log.

Consent records are written server-side and are not client-writable — a consent record its subject can silently rewrite is not a consent record.

Data minimisation

The profile is deliberately short, and the omissions are the design:

Not collectedReasoning
Day of birthA full DOB is a strong identifier and the one field that would meaningfully raise the cost of a breach. Month and year answers everything the product does with it.
Employer, trust, stationNot needed to provide or protect the service.
Professional registration numberNot verified, not needed.
Address, town, postcodeCounty is the finest granularity held. A postcode district plus a role plus a name can identify one person; a county cannot.

Region is derived from county rather than asked. Role, sector, country and county are closed vocabularies with no free-text option.

Special category data

MedJot is not designed to hold patient data and instructs users not to enter patient-identifiable information. Where clinicians follow that instruction, no special category personal data about patients is processed by us at any point.

Where a clinician enters identifiable detail against instruction, it remains on their device unless they run an AI feature — where redaction runs on both client and server as a safety net, though not as a guarantee.

The professional role recorded in a clinician's own profile is ordinary personal data, not special category.

Children

MedJot is a professional tool for clinicians and is neither directed at nor intended for use by children.

Data subject rights

Access, rectification, erasure, portability and objection are all supported. The privacy request form works whether or not the person can sign in, which matters for someone who has already left an organisation.

We may need to verify identity before completing a request. Complaints can be made to the ICO at ico.org.uk.

A DSAR to MedJot cannot return clinical records, because we hold none. A subject access request covering clinical documentation should be directed to the organisation whose devices hold it.

Automated decision-making

Registration and sign-in are assessed for fraud indicators. No account is suspended by automated decision alone — flagged accounts are queued for human review, most are unaffected, and a small number are asked to verify a mobile number.

The single exception is where a browser was previously used by an account a person had already suspended, where that earlier human decision carries across.

Users retain a session while suspended specifically so they can read the recorded reason and appeal to a person. See Suspension and appeals.

International transfers

Google (Firebase, Gemini) and Stripe may process data outside the UK and EEA under their own data protection commitments. See Subprocessors.

Retention

Summarised in Data flows.

Breach notification

We will notify affected users and the ICO in accordance with UK GDPR timescales. The blast radius of a breach of our systems does not include clinical records, because we hold none — a point worth recording explicitly in a DPIA, since it is unusual.

For your DPIA

Points reviewers most often want in writing:

  1. Clinical data is not transmitted to or stored by the supplier. Architectural, not configurable.
  2. The supplier cannot access patient data, and holds no mechanism to.
  3. AI processing is user-initiated, redacted twice, and neither prompt nor response is retained.
  4. Analytics is opt-in, has no free-text field by construction, and sends no account identifier to Google.
  5. Payment card data never reaches the supplier.
  6. No automated suspension without human review, with a working appeal route.
  7. The residual device-level risk is the organisation's to manage — see Deployment and devices.

Contact

hello@swyftscale.com. We are happy to complete your own IG or assurance templates and to speak to your DPO directly.