1.0 About this Privacy Policy

This Privacy Policy explains how personal data is collected, used, shared and protected in connection with the relevant Medincle products and services, websites, support routes, orders, reseller arrangements and related communications.

In this operating model:

CareScribe Limited is the front-facing company, operator and service provider; and
Medincle Ltd. owns certain underlying Medincle intellectual property only.

Medincle is not intended to be in the routine operational flow for customer, reseller or website personal data in this model, but may retain or access limited personal data where lawfully required for historic contractual, finance, legal/compliance, security, legacy-system, IP-protection or transition/separation/exit purposes, subject to appropriate controls and lawful basis.

2.0 Who we are

CareScribe Limited (company number 11309937) is the relevant controller for the personal data described in this Privacy Policy where we process that data for our own front-facing business purposes.

CareScribe Limited is registered in England and Wales. Its registered office is Unit 2.3 Temple Studios, Temple Gate, Bristol, England, BS1 6QA.

Our Information Commissioner’s Office registration number is ZA775354.

If you have questions about this Privacy Policy or how we process personal data, you can contact us at:

3.0 How CareScribe and Medincle fit together

  • CareScribe is the controller for customer, prospect, reseller, website, order, billing, support, complaint, privacy-query and related commercial personal data in this operating model.
  • CareScribe also carries out the relevant day-to-day operational processing activities in the ordinary course.
  • Medincle is not intended to be in the routine operational flow for that personal data in this model, but may retain or access limited personal data where lawfully required for historic contractual, finance, legal/compliance, security, legacy-system, IP-protection or transition/separation/exit purposes, subject to appropriate controls and lawful basis.
  • Where CareScribe processes personal data on behalf of a customer or customer organisation as part of service delivery, the relevant contract, privacy notice and any applicable data processing agreement will govern that processing and CareScribe may act as processor rather than controller for that service data.

4.0 Personal data we may collect

Depending on the context, we may collect and process:

  • names and contact details;
  • organisation, account and user details;
  • order, billing, payment and subscription details;
  • support communications, service records and complaint records;
  • privacy-query, DSAR and compliance records;
  • reseller records;
  • website, form, cookie and analytics data;
  • security, access and audit logs; and
  • related operational, technical and commercial records.

If you use our services through an employer, educational institution, reseller or other organisation, we may receive your details from that organisation to provision access, administer the relevant service, or manage the relationship.

5.0 How we use personal data

We may use personal data to:

  • provide, operate and administer the relevant products/services;
  • create and manage accounts, licences, subscriptions and access;
  • manage orders, billing, payments and finance administration;
  • provide customer support, complaint handling and service communications;
  • manage reseller arrangements and customer communications;
  • protect security, investigate misuse and maintain service continuity;
  • comply with legal, regulatory, tax, audit and compliance obligations; and
  • respond to privacy requests, complaints and regulator enquiries.

6.0 Lawful bases

Where CareScribe acts as controller, we may rely on one or more of the following lawful bases, depending on the context:

  • Contract: where processing is necessary to provide products/services, administer orders, or take steps at your request before entering into a contract.
  • Legitimate interests: where processing is necessary to run, secure and improve our business, products/services, support processes, reseller relationships and customer communications, balanced against the rights and interests of affected individuals.
  • Legal obligation: where processing is necessary to comply with applicable law, regulatory requirements, tax obligations, audit duties or lawful requests from authorities.
  • Consent: where consent is required, for example for certain cookies or certain marketing communications.
  • Another lawful basis available under applicable data protection law where relevant.

Where CareScribe acts as processor for service-delivery personal data on behalf of a customer or customer organisation, we process that data on documented instructions and in accordance with the applicable contract and data processing terms.

Where we record outbound sales calls, reseller calls or other commercial calls for training, quality assurance, and to keep an accurate record of business discussions, we rely on Legitimate Interests where this is appropriate. We have conducted a Legitimate Interests Assessment (LIA) for this processing, which concludes that we can proceed because:

  • the context is B2B outreach or commercial relationship management, and individuals may reasonably expect business calls to be recorded for training, quality or recordkeeping purposes;
  • we seek to avoid capturing special category data and focus on professional contact and business discussion data only;
  • we provide notice that the call is recorded for training, quality or recordkeeping purposes;
  • if a person objects, we stop recording where practicable and delete the recording where required; and
  • access to recordings is restricted and recordings are retained only for a limited period unless required for an ongoing dispute, compliance matter or legal purpose.

7.0 Sharing personal data

We may share personal data with:

  • approved service providers and sub-processors who help us operate the relevant products/services or related business processes;
  • payment, billing, CRM, support, hosting, communications, analytics and security providers;
  • resellers, distributors or customer-appointed intermediaries where relevant to the applicable route or relationship;
  • professional advisers, insurers, auditors and regulators; and
  • competent authorities where required by law or where necessary to protect rights, safety or security.

Medincle is not intended to receive personal data in the routine operational flow in this model. If Medincle must receive or retain limited personal data, that sharing or retention must be limited, documented, need-to-know and subject to appropriate controls and lawful basis, including where required for historic contracts, finance, legal/compliance, security, legacy systems, IP protection, or a documented transition, separation, sale or exit scenario.

We do not sell personal data.

We maintain internal records of relevant processor/sub-processor categories and transfer safeguards used in this operating model and, where required, will reflect applicable provider or transfer information in customer-facing materials, contractual documents, DPA terms or other appropriate transparency materials.

Where limited historic, legal/compliance, finance, security, legacy-system or transition records remain with or are accessible to Medincle, that position should be documented, access-limited and reviewed against the relevant retention basis.

8.0 International transfers

Where personal data is transferred outside the UK/EEA or to a country that is not subject to an adequacy decision, we will use an appropriate lawful transfer mechanism and documented safeguards, which may include:

  • adequacy regulations or decisions;
  • the UK International Data Transfer Agreement (IDTA);
  • the UK Addendum to the EU Standard Contractual Clauses; and/or
  • supplementary contractual, organisational or technical measures where needed.

9.0 Retention

We keep personal data only for as long as reasonably necessary for the relevant purpose, including to:

  • provide the relevant service and support;
  • manage orders, billing and customer/reseller relationships;
  • maintain security, audit and compliance records;
  • respond to complaints, disputes and rights requests; and
  • comply with legal, tax, accounting and regulatory obligations.

Retention periods may vary depending on the nature of the data, the relevant service, the customer relationship, contractual commitments, legal requirements and whether ongoing investigation, dispute or compliance activity exists. When personal data is no longer required, it will be deleted, returned or anonymised where appropriate.

10.0 Security

We use appropriate technical and organisational measures to protect personal data, including:

  • access controls and least-privilege access;
  • secure support and administration controls;
  • incident escalation and response processes;
  • supplier review and contractual controls;
  • retention and deletion controls; and
  • other security measures appropriate to the risk.

11.0 Your rights

Depending on applicable law and the context of the processing, you may have rights to:

  • request access to personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing;
  • request portability of personal data;
  • withdraw consent where we rely on consent; and
  • complain to a supervisory authority, including the UK Information Commissioner’s Office where UK law applies.

To exercise rights or make a privacy request, contact us at [email protected]. We may need to verify identity before responding.

If CareScribe is processing personal data purely as processor on behalf of a customer or customer organisation, we may need to direct the request to the relevant controller or handle it in accordance with that controller’s instructions.

12.0 Complaints and privacy queries

Customer-facing privacy queries, complaints and requests for Medincle products and services should use CareScribe-facing privacy contact routes, not a Medincle-facing route, unless CareScribe expressly states otherwise.

You can contact us at:

If you are not satisfied with our response, you may complain to the UK Information Commissioner’s Office or another competent supervisory authority where applicable.

13.0 No AI training

Personal data handled in this operating model must not be used to train, fine-tune, benchmark or improve generative AI models unless expressly assessed, approved and disclosed where required.

Where approved third-party AI providers are used for inference in a relevant service, CareScribe will use appropriate contractual, security and privacy controls, including zero-retention or equivalent controls where applicable to the approved use case.

14.0 Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, regulatory, operational or service changes. Where appropriate, we will publish or otherwise make available the updated version through the relevant CareScribe route.