Privacy notice

How personal data is handled in NeuroScribe under the UK GDPR and the Data Protection Act 2018.

Version 2.0 · In force from 20 August 2026 · Consent records store the notice version that applied when consent was given

Who is responsible for the data

The clinician or practice using NeuroScribe is the controller of the clinical records they enter. NeuroScribe operates as the processor, handling that data only on the controller’s instructions and only to provide the documentation service described here.

Practices must publish their own patient-facing notice with their organisation name, data protection contact and, where applicable, their Data Protection Officer and ICO registration. This notice covers the platform’s own processing only.

What data the platform holds

  • Clinician account data: email address, name, professional role, registration number and organisation.
  • Patient records — pseudonymised by design: a practice reference and initials rather than a full name, date of birth, gender, referral source and referring clinician. An NHS number is optional.
  • Clinical free text: observations, developmental history, standardised measure scores and multi-informant notes entered by the clinician.
  • Consent records: which purposes the patient or their guardian agreed to, and the notice version in force at the time.
  • Reports: drafts, approved versions and dispatch status.
  • Audit trail: which account performed which clinical action and when.
  • Billing: subscription status held with our payment provider. Card details never reach NeuroScribe.

Clinical free text is entered by the clinician, so it may contain names or other details typed into a note. Treat all record content as special category health data.

Lawful basis

Clinical records are special category data. Practices normally rely on Article 6(1)(e) or (f) together with an Article 9(2)(h) condition for the provision of health care, with the corresponding DPA 2018 Schedule 1 condition. Consent recorded in the platform documents the patient’s clinical agreement and controls optional processing such as AI-assisted drafting, sharing with the referrer and service analytics; the controller must confirm the lawful basis that applies in their own setting.

AI-assisted drafting

Drafting is optional and blocked at database level unless AI consent has been recorded for that patient.

Before any text is sent for drafting it passes through de-identification: names, dates, addresses, postcodes, phone numbers, email addresses, NHS and National Insurance numbers, record references and named organisations are replaced with labelled placeholders. The request is then re-checked and refused if an identifier appears to have survived. Structured identifiers such as the patient reference and NHS number are never included.

The model returns draft text only. It is instructed never to state a diagnosis and never to invent history, scores or dates. No report can be approved or dispatched without an explicit clinician action, and approved reports are locked against further edits.

De-identified text remains personal data in law. It is sent to our AI provider solely to generate that draft.

Who the data is shared with

Data is shared only with the sub-processors needed to run the service: our cloud hosting and database provider, our AI drafting provider, and our payment provider for subscription billing. Records are never sold, and are never used for advertising. Controllers should ask us for the current sub-processor list, including any transfers outside the UK and the safeguards applied, before deploying the platform clinically.

Retention

Each practice sets its own retention period in Settings, defaulting to eight years since a record was last updated. Records that pass that period are flagged for review so a clinician can decide whether to erase them. Clinical records are never deleted automatically, because deciding what must be kept is a clinical and legal judgement, not a technical one.

When a record is erased, the patient details, consent record, assessments and reports are permanently removed. A single audit entry is kept recording that an erasure took place, with no clinical content — this is our record of compliance.

Security

  • Every record is scoped to the responsible clinician by database access rules.
  • Multi-factor authentication is mandatory for clinical access and is checked in the database, not only in the interface: a session that has not completed a second factor cannot read or write any clinical record.
  • Database triggers prevent records being linked across clinicians, prevent assessments being saved without consent, and lock reports once approved.
  • Clinical writes and their audit entries are saved in a single transaction.
  • Every patient export is recorded in the audit trail with the requester, format, timestamp and a SHA-256 checksum, and the download is refused if that record cannot be written.
  • Data is encrypted in transit and at rest by our hosting provider.

International transfers

Where a provider processes data outside the United Kingdom, the transfer relies either on UK adequacy regulations or on the ICO International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. Controllers should request the current transfer position for their configuration before entering live patient data, and we will confirm it in writing.

Automated decision-making

There is no automated decision-making or profiling with legal or similarly significant effects. AI output is draft text that a named clinician must read, correct and approve; the model is instructed never to state a diagnosis, and nothing can be dispatched without an explicit clinician action recorded in the audit trail.

Children and young people

Assessments frequently concern children. Records are pseudonymised by design, consent is normally given by a person with parental responsibility, and a young person able to decide for themselves may give or withdraw consent for optional processing such as AI drafting. Withdrawing AI consent blocks further drafting for that record immediately.

Personal data breaches

We keep an internal record of any personal data breach. Where a breach affects records a practice controls, we notify that practice without undue delay and in any event within 48 hours of becoming aware, with the nature of the breach, the categories and approximate number of records involved, the likely consequences and the measures taken. The practice, as controller, decides on notification to the ICO within 72 hours and to affected individuals.

Your rights

Patients and their guardians have the right of access, rectification, erasure, restriction, objection and portability, and the right to withdraw optional consent at any time. Requests are answered within one month, extendable by two further months for complex requests where we tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.

Requests should go to the treating practice as controller. The platform gives clinicians a full machine-readable export of a single patient record in JSON or CSV with an integrity checksum, a permanent erasure action, and a request log that tracks the statutory deadline. If a request reaches us directly we refer it to the responsible practice rather than answering on their behalf.

Anyone unhappy with how their data has been handled may complain to the Information Commissioner’s Office at ico.org.uk, without prejudice to any other remedy.

Changes to this notice

Material changes are published here with a new version number and effective date before they take effect. Because each consent record stores the notice version in force when it was captured, a change that widens the purposes of processing requires fresh consent rather than a silent update.

Cookies

The platform sets only the cookies and local storage needed to keep you signed in and to process payment. There is no advertising or third-party tracking, so no consent banner is required. Details are in the cookie policy.

Related documents