Data processing addendum

Article 28 UK GDPR terms for clinicians and practices using NeuroScribe. This page sets out the processing we carry out; a countersigned copy for your records is available on request.

Version 2.0 · In force from 20 August 2026 · Forms part of the terms of service and prevails over them on data protection matters

1. Roles and instructions

You are the controller of the clinical records entered into the platform. NeuroScribe is the processor and processes those records only on your documented instructions, which are the instructions given by using the platform’s features and these terms.

We will not process the records for our own purposes, will not use them to train or improve any machine learning model, and will not disclose them to a third party except to a sub-processor under section 6 or where required by law. Where the law requires disclosure, we will tell you first unless legally prohibited. If we believe an instruction infringes data protection law, we will tell you without undue delay and may pause that processing until it is resolved.

2. Subject matter and duration

Processing lasts for the term of your subscription plus the wind-down period in section 9. The purpose is to provide clinical documentation, AI-assisted drafting where you have enabled it, audit logging, and subscription administration. Processing operations include collection, storage, structuring, retrieval, de-identification, transmission to the AI provider for drafting, export and erasure.

3. Categories of data and data subjects

  • Data subjects: patients undergoing assessment and their parents/guardians or other informants; clinicians and practice staff who hold accounts.
  • Personal data: account and contact details; pseudonymised patient identifiers (practice reference, initials, date of birth, gender, referral route, and an optional NHS number).
  • Special category data: health data in clinical free text, developmental history, standardised measure scores, consent records and reports.

4. Our obligations

  • Process personal data only on your instructions and for the purposes above.
  • Limit access to personnel who need it for a defined task, under written confidentiality obligations that survive the end of their engagement, with data protection and clinical confidentiality training before access is granted.
  • Implement the technical and organisational measures in section 5.
  • Not engage a sub-processor without the terms in section 6.
  • Assist you with data subject requests, DPIAs, and consultations with the ICO, using the platform’s export, erasure and audit features, and respond to a written request for that assistance within 5 working days.
  • Notify you of a personal data breach affecting your records without undue delay and in any event within 48 hours of becoming aware, with the nature of the breach, the categories and approximate number of records affected, the likely consequences, the containment and remedial steps taken, and a contact point — so you can meet your own 72-hour obligation to the ICO.
  • Keep a record of processing carried out on your behalf and make available the information needed to demonstrate compliance with this addendum.

5. Security measures

  • Pseudonymised patient records by design, with no requirement to store full names.
  • De-identification of free text before any AI drafting request, with a second check that refuses the request if an identifier appears to have survived.
  • Row-level access rules scoping every record to the responsible clinician.
  • Mandatory multi-factor authentication for clinical access, enforced in the database as well as the interface, so a single-factor session can read no clinical data.
  • Least-privilege service roles, with privileged database routines restricted and never callable by unauthenticated or anonymous access.
  • Database triggers preventing cross-clinician linkage, blocking assessments without consent, and locking reports once approved.
  • Atomic audit logging of clinical writes, exports, approvals and dispatches.
  • Export integrity: every patient export is recorded with requester, format, timestamp and SHA-256 checksum, and is refused if that record cannot be written.
  • Encryption in transit and at rest as provided by our hosting provider.
  • Managed backups by the hosting provider, subject to the same access controls and deletion timescales as live data.

These measures are reviewed when the platform changes materially. We will not reduce the overall level of protection during the term.

6. Sub-processors

We use sub-processors for cloud hosting and database services, AI drafting, and subscription payments. Each is bound by written terms no less protective than this DPA, and we remain liable to you for their processing. You give general authorisation for their use; we will give at least 30 days’ notice of any intended addition or replacement so you can object on reasonable data protection grounds, and if the objection cannot be resolved you may terminate the affected service without penalty and export your records. The current list, with each sub-processor’s role and location, is available on request.

7. International transfers

Where a sub-processor processes data outside the UK, that transfer relies on UK adequacy regulations or the ICO International Data Transfer Agreement / UK Addendum to the EU standard contractual clauses, with a transfer risk assessment. Ask us for the current transfer position for your configuration before entering live patient data; we will confirm it in writing and tell you if it changes.

8. Data subject rights

Requests should be directed to you as controller. The platform provides a full machine-readable export of a single patient record in JSON or CSV with an integrity checksum, a permanent erasure action, and a request log that tracks the one-month statutory deadline. Where a request reaches us directly, we will refer it to you within 5 working days rather than respond on your behalf, and will not disclose data to the requester ourselves.

9. Return and deletion

You control retention in Settings; records past the retention period are flagged for clinician review rather than deleted automatically, because deciding what must be kept is a clinical and legal judgement. On termination you may export your records for 30 days. On your written instruction, or at the end of that wind-down period, we delete remaining personal data from live systems within 30 days and from backups within the hosting provider’s backup cycle, except a non-clinical audit entry recording that erasure took place and anything we must keep by law. We will confirm deletion in writing on request.

10. Audits and demonstrating compliance

We will respond to reasonable written information requests about our processing and security within 20 working days. On-site or third-party audits may be arranged no more than once a year, or after a breach affecting your records or where a regulator requires it, subject to reasonable notice, confidentiality, agreed scope, and no access to other customers’ data.

11. Liability, precedence and law

This addendum forms part of the terms of service and prevails over them on any data protection matter. Liability under it is subject to the limits in the terms of service, except where data protection law does not permit limitation. Each party remains liable for its own compliance as controller or processor. This addendum is governed by the law of England and Wales.

We make no compliance certification, accreditation or assurance claim in this document. It describes the measures implemented in the platform so that you can assess them in your own DPIA and governance process.

Related documents