Privacy notice

The privacy doctrine explains our architecture; this page is the formal notice: what personal data medrics itself holds, why, for how long, who else touches it, and your rights. Last updated 5 September 2026.

Who is responsible

The data controller is MEDRICS LTD, a company registered in England and Wales (company number 16046579), registered office 4 St. Martins Drive, Priorslee, Telford TF2 9WE. We are registered with the Information Commissioner's Office (registration ZB925290). We have not appointed a data protection officer, because we are a small company and the law does not require one. Contact for anything on this page: info@medrics.co.uk.

The app: we hold nothing

Locum Manager processes your documents on your own computer. We run no accounts, no analytics and no telemetry in the app, so we cannot see your data, so this notice has nothing to say about it. Delete the folder and it's gone. The same is true of the clinical documentation aid and the voice-reflection tool: they run on your own device and store nothing with us.

What we do hold, and why

DataWhy (lawful basis)Kept until
Session sign-ups & mailing list: name, email (when you join the mailing list, registering for the free shortcuts or a session, or email us; list signups are captured by a Google form, so Google processes the submission) To send you what you signed up for, automatically: the shortcut links and how to use them, news of the Portfolio system (career and money insights), and session announcements (consent) You unsubscribe. Every email has the option
Watching a recording on demand: the video is hosted on YouTube (unlisted) and embedded from youtube-nocookie.com — nothing is sent to Google until you press play; from then Google's own privacy policy applies to the player. To earn the certificate you complete the same feedback form as a live session (a Google form: name, email, your answers). A paid recording is bought through Stripe (your card details go to Stripe, never to medrics; we keep your email, what you bought and Stripe's payment id so we can send your link and issue your certificate) To issue your certificate and, if you use the portfolio, your CPD record (contract — you asked for the certificate) Certificates and attendance records: 6 years (appraisal evidence)
Attendance & certificates: that your email attended a session, hours, certificate issued. Where a session ran on Zoom or Microsoft Teams we import the participant list to mark attendance To issue your CPD certificate and power CPD auto-transfer if you use it (contract) 6 years (certificates are evidence you may need at appraisal)
Member service data: your member token (we store only a hash of it), the metadata you consented to send (counts, hours, gaps), claim lines you previewed and sent, and feedback you give us. Payments are taken by Stripe: we never see your card number; Stripe holds your email and invoice history To provide the service you asked for (contract) Membership ends + 12 months; feedback 24 months
Assessor sign-off: if you are a trainee: the single item you chose to share and the signed record. If you are a supervisor or assessor: your name, work email, GMC number, role, the statements you agreed or edited, and your signature Trainee: you asked a named doctor to review it (contract). Assessor: you are carrying out a supervision task you agreed to, and the record must show who signed it (legitimate interest). Your details are used only on that record and on the receipt we send you The signed record lives in the trainee's own portfolio. Our server copy is reduced to an audit stub (assessor name, role, dates) once the trainee has collected it; unsigned requests are cleared 60 days after the link expires
Usage counts: that a member used a service on a date (never content, and only a non-reversible member id) To know which services matter (legitimate interest) 24 months
Trust review portal: if you use a review link we sent your NHS trust: your name and work email if you give them, and the comments and answers you type To run the patient-information review with your team (legitimate interest; contract where your trust has one with us) The link expires after 180 days; comments are kept as business records while we work with your trust
Trust staff contact details from public sources: if your work name, role, email or phone number is published on your trust's website, we may hold it to contact the team responsible for the pages our reports describe. This notice is the fuller statement of that, and our first email links here Contacting the right team about its own published patient information (legitimate interest; you can object at any time and we will stop) While your trust is a prospect or customer; re-checked and removed when stale
NHS service contact details on our patient find page (medrics.co.uk/patient-information/find/): when a patient searches, the page shows what their hospital trust's own service page says: the phone number, the hours, how to get in touch, and a link to that page. We copy these word for word from the trust's public website, including any work email address the page prints, and remove staff names from the quoted text Helping patients reach the right NHS team, which is why the trust published the details (legitimate interest). If your work details appear and you object, email info@medrics.co.uk and we will remove them Each page is re-read every 30 days; a page your trust takes down leaves ours at the next rebuild
Signing in to our private pages: if we invite you to a trust portal, a testing page, a work page, the clinician picker or to sign a trainee's forms, you sign in through Amazon Cognito, run for us by Amazon Web Services in its London region. It holds your email address, your password (scrambled) and your second sign-in step: a passkey (only its public half; the private half never leaves your device), a code it emails you, or an authenticator app link. Our own server keeps nothing about you once you close the page Keeping private pages for the people they were made for (contract, or legitimate interest for invited partner teams). Amazon Web Services acts for us under a data processing agreement Your sign-in account is deleted when your access ends; a sign-in on our server lasts at most 8 hours
Contributors, presenters and teachers: name, email, skills or bio, the materials you send, and your replies to our questions. If you present a session we record, the recording of your slides and voice, made only after you tick your agreement on the recording page To run the teaching programme and the contributor programme you joined (contract / consent) While active + 12 months; presenter session records 6 years as CPD evidence. The raw recording is deleted 30 days after it is made; the published video stays up until you ask us to take it down
Testers: name and email for a test link, and the feedback you give To test tools with clinicians before release (legitimate interest) Link period + 12 months
Paid reviewers: if we engage you as a contractor to review our content: your name, email, GMC number (clinical roles), rate, the hours and findings you record on your private workspace link, and our payment records To run and pay for the engagement you agreed (contract), and to keep the company's accounting records (legal obligation). Your findings are read by a person, never by an AI service 6 years after the last payment (company records); the workspace link expires after 90 days unless renewed
Diagnostics reports: a technical report you chose to send from the app after previewing it byte-for-byte To fix the problem you reported (consent) 12 months
Clinician leaflet picker search telemetry (leaflets.medrics.co.uk): the text of a search that found nothing; no identifier, no address. The patient search on this site records nothing. To add the leaflets people look for (legitimate interest) 90 days
Clinician picker sign-in (leaflets.medrics.co.uk): your regulator and professional registration number are sent once when you sign up or sign in, together with a PIN you choose. We keep only a keyed hash made from them (it cannot be turned back into the number), a scrambled form of the PIN, the day the account was made, a count of wrong PINs and your sign-in sessions. Nothing else is attached: not the regulator, no part of the number, no name, email or address, and nothing about any patient. The number is checked for format only; entering it is your professional declaration. The last three characters stay on your own device, so people sharing a computer can tell their sign-ins apart. If you were invited to sign in with a medrics account instead (see "Signing in to our private pages"), we keep no number, PIN or email for the picker: only a keyed hash of the account's own code and your sign-in, deleted when your sign-in ends. If you tick "This is my own device", we also keep an encrypted sign-in pass from Amazon Cognito for up to 30 days, so we can check once a day that your account is still active. We delete it when you sign out, when your 30 days end, or as soon as a check fails. Leave the box unticked and we keep nothing beyond your 12-hour sign-in To keep a clinician tool for registered professionals (legitimate interest) 12 months after your last sign-in ended; delete sooner from the tool or by asking us
Leaflet picker sync: only if you are a member and choose to sign in on the clinician picker: your chosen hospital, specialty and the named leaflet sets you save, held against your membership id. Never your professional registration number, and never anything about a patient So your saved sets follow you between devices (contract) 12 months after last use
Your Medrics account (when accounts open): your email address, a securely hashed password (never the password itself), your regulator with the last three characters of your registration number, your sign-in sessions (a device label and times — not your IP address) and a security log. We check new passwords against known breaches by sending only a short, anonymous fragment of a scrambled form of the password to Have I Been Pwned. Account emails are sent through Google Workspace. To provide the account you asked for and keep it secure (contract; legitimate interest for security logs) Until you delete the account (7 days to change your mind); security logs 12 months; sign-in codes 20 minutes
Follow-up scheduling on the clinician picker (test, leaflets.medrics.co.uk): if you hold a follow-up slot or request a scan for a patient, we keep an internal booking reference, the time, the kind of request and your picker account id. If the hospital unit has set up a sealing key, you may add the patient's hospital number: your browser encrypts it to the unit's key before it leaves, we store only the scrambled form and our server holds no key: it opens only on the unit's own diary page, with the key the unit keeps. Otherwise the patient's details go only in the email you send from your own NHS mail. Nothing readable about any patient is kept by us, and the patient's card shows only where and when To let a hospital unit line up a follow-up request with the patient's card without any patient data on our systems (legitimate interest) 90 days after the appointment or request
Hospital unit staff signing in to a follow-up diary (test): a unit's diary is reached by a link we replace each month. The link alone does not open it: you type your own NHS email address, and if it is on the list your unit gave us we send a six-digit code to it. We keep a keyed hash of the address, not the address itself, along with your sign-in times and which diary actions were taken. We keep no name and nothing about any patient. So that only named unit staff can see and manage that unit's own follow-up bookings (legitimate interest) Codes 10 minutes; a sign-in lasts at most 8 hours; the list entry until your unit or we remove it; security records 12 months

How we use AI

We use AI models to help draft and review our own work. Messages and documents written by people outside medrics (replies from trusts, contributors, presenters and supervisors) are processed only by models running on our own hardware and are never sent to a cloud AI provider. Where we do use cloud AI services (Anthropic, OpenAI) for our own drafting, personal identifiers are removed from the text first. No AI decision is made about you without a person; nothing an AI drafts is sent to you without a person at medrics reviewing it.

Where it lives, who else touches it

Member and service data is stored on medrics-controlled hardware in the UK, not in a third-party cloud database. The processors we use, each only for the purpose named: Google Workspace (email, forms and sheets), Brevo (mailing-list and event email; EU-hosted), Stripe (payments), Cloudflare (secure tunnel and proxy for our sign-off and portal links, standard connection logs), GoDaddy (this website's host, standard server logs), Apple iCloud (synchronised storage of our working files), GitHub (private code repository, no customer data), Zoom / Microsoft Teams (online sessions and participant lists), and Anthropic / OpenAI (AI drafting, as described above). Some of these companies are in the United States; where personal data reaches them we rely on the transfer safeguards in their terms, the UK Extension to the EU-US Data Privacy Framework where the provider is certified, otherwise the UK International Data Transfer Addendum. We never sell or share personal data, and community data (like rate cards) publishes only in anonymous, k-anonymity-protected form.

Cookies & page counts

This site sets no cookies and uses no cross-site trackers. Page counting is currently switched OFF: this site records nothing at all about your visit. If we turn it on we will say so here first, and it will stay the same anonymous count it is built to be: only the page path and, if you came from another site, that site's name, never your IP address, with no cookie or identifier of any kind, so views could not be linked to each other or to you. It would count views, not people. The patient leaflets and the Locum Manager app run no counting at all, switched on or off.

Your rights

You can ask for a copy of what we hold about you, ask us to correct or delete it, object to any processing based on legitimate interest, or withdraw consent at any time: email info@medrics.co.uk and we'll respond within a month. Where we must keep something (for example a certificate record) we will tell you why. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ico.org.uk).

If something goes wrong

If personal data we hold is lost or exposed and that is likely to put you at risk, we will tell the ICO within 72 hours and tell you directly if the risk to you is high.