Privacy policy
Last updated 18 Jul 2026 · version 0.3 (draft)
Draft — pending legal review. This wording is a working placeholder and must be approved by counsel for each corridor before launch.
1. What we process
Clinician account data: name, professional email, GMC (or equivalent) registration details, role, and organisation.
Patient referral data: the minimum clinical information a referring clinician includes in a case — identity details, clinical summaries, and medical records including imaging. Patients are never platform users; their data enters only through their clinician, with their consent.
Operational data: audit events (who accessed what, when, from where), security logs, and support correspondence.
2. Lawful basis
We process referral data on the basis of the patient’s explicit consent, captured item by item at referral creation and versioned with the exact wording shown. Clinician account data is processed for the performance of our contract with the clinician and our legitimate interest in verifying professional identity. UK GDPR and the Data Protection Act 2018 apply as the baseline to every case.
3. Corridors and international transfers
Each referral travels along a defined corridor with its own lawful transfer mechanism: Israel (UK adequacy), France (EU — direct transfer), Switzerland (adequacy), and Turkey (KVKK-approved standard contractual clauses, notified to the Turkish authority within 5 business days of signature).
For every transfer we apply the stricter of both countries’ rules on residency, retention, breach notification, and data-subject rights.
4. Data residency
A case’s storage region is set automatically from its corridor at intake. Cases involving France are stored on HDS-certified infrastructure physically located in the EEA; other corridors use UK or EEA regions. The residency region is visible on every case.
5. Retention
Clinical records are kept for the period required by the strictest jurisdiction involved in the referral — 20 years where French health-record law applies, and 10 years for our other corridors — measured from the last activity on the case.
Once that period expires the record is flagged for review rather than deleted automatically, because a case subject to a complaint or legal claim must be kept for longer. Audit records are retained as required for regulatory accountability.
6. Your rights and DSARs
Patients and clinicians can request access to, rectification of, or erasure of their personal data, and can ask for it in a portable form. We respond within one calendar month of receiving the request, as required by UK GDPR. Requests can be raised through the referring clinician or via the contact page; each one is logged with its deadline and tracked to completion.
Erasure removes your personal data from the referral record and deletes the associated documents. The tamper-evident audit trail is retained, because it is the evidence that the erasure was carried out and it protects every other case on the platform — but it no longer identifies you.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk
7. Security measures
AES-256 encryption at rest, TLS 1.3 in transit, role-based access on a least-privilege basis, mandatory multi-factor authentication, time-limited access for receiving clinicians, and an append-only tamper-evident audit log of every view, download, and export. See the security overview for detail.
8. Sub-processors
We use a small number of infrastructure sub-processors, each bound by data-processing agreements and listed — with purpose, location, and safeguard — on the sub-processors page. We will give notice before adding or changing sub-processors that touch patient data.
9. Contact and DPO
The data controller is Libamed Ltd, 58 Ael-Y-Bryn, Caerdydd (Cardiff) CF23 9LH, Wales, United Kingdom — company no. 17272473.
We are registered with the Information Commissioner’s Office under registration reference ZC220043, valid to 10 August 2027.
A Data Protection Officer appointment is in progress; until then the registered office is the contact point for all data-protection matters.
Questions about this document? Contact LibaMed Ltd, Cardiff, Wales — we aim to respond within two working days.