Last updated 10/07/2026
This Privacy Policy explains how personal data is collected, used, shared and protected in connection with the relevant Medincle products and services, websites, support routes, orders, reseller arrangements and related communications.
In this operating model:
– CareScribe Limited is the front-facing company, operator and service provider; and
– Medincle Ltd. owns certain underlying Medincle intellectual property only.
Medincle is not intended to be in the routine operational flow for customer, reseller or website personal data in this model, but may retain or access limited personal data where lawfully required for historic contractual, finance, legal/compliance, security, legacy-system, IP-protection or transition/separation/exit purposes, subject to appropriate controls and lawful basis.
CareScribe Limited (company number 11309937) is the relevant controller for the personal data described in this Privacy Policy where we process that data for our own front-facing business purposes.
CareScribe Limited is registered in England and Wales. Its registered office is Unit 2.3 Temple Studios, Temple Gate, Bristol, England, BS1 6QA.
Our Information Commissioner’s Office registration number is ZA775354.
If you have questions about this Privacy Policy or how we process personal data, you can contact us at:
Depending on the context, we may collect and process:
If you use our services through an employer, educational institution, reseller or other organisation, we may receive your details from that organisation to provision access, administer the relevant service, or manage the relationship.
We may use personal data to:
Where CareScribe acts as controller, we may rely on one or more of the following lawful bases, depending on the context:
Where CareScribe acts as processor for service-delivery personal data on behalf of a customer or customer organisation, we process that data on documented instructions and in accordance with the applicable contract and data processing terms.
Where we record outbound sales calls, reseller calls or other commercial calls for training, quality assurance, and to keep an accurate record of business discussions, we rely on Legitimate Interests where this is appropriate. We have conducted a Legitimate Interests Assessment (LIA) for this processing, which concludes that we can proceed because:
We may share personal data with:
Medincle is not intended to receive personal data in the routine operational flow in this model. If Medincle must receive or retain limited personal data, that sharing or retention must be limited, documented, need-to-know and subject to appropriate controls and lawful basis, including where required for historic contracts, finance, legal/compliance, security, legacy systems, IP protection, or a documented transition, separation, sale or exit scenario.
We do not sell personal data.
We maintain internal records of relevant processor/sub-processor categories and transfer safeguards used in this operating model and, where required, will reflect applicable provider or transfer information in customer-facing materials, contractual documents, DPA terms or other appropriate transparency materials.
Where limited historic, legal/compliance, finance, security, legacy-system or transition records remain with or are accessible to Medincle, that position should be documented, access-limited and reviewed against the relevant retention basis.
Where personal data is transferred outside the UK/EEA or to a country that is not subject to an adequacy decision, we will use an appropriate lawful transfer mechanism and documented safeguards, which may include:
We keep personal data only for as long as reasonably necessary for the relevant purpose, including to:
Retention periods may vary depending on the nature of the data, the relevant service, the customer relationship, contractual commitments, legal requirements and whether ongoing investigation, dispute or compliance activity exists. When personal data is no longer required, it will be deleted, returned or anonymised where appropriate.
We use appropriate technical and organisational measures to protect personal data, including:
Depending on applicable law and the context of the processing, you may have rights to:
To exercise rights or make a privacy request, contact us at [email protected]. We may need to verify identity before responding.
If CareScribe is processing personal data purely as processor on behalf of a customer or customer organisation, we may need to direct the request to the relevant controller or handle it in accordance with that controller’s instructions.
Customer-facing privacy queries, complaints and requests for Medincle products and services should use CareScribe-facing privacy contact routes, not a Medincle-facing route, unless CareScribe expressly states otherwise.
You can contact us at:
If you are not satisfied with our response, you may complain to the UK Information Commissioner’s Office or another competent supervisory authority where applicable.
Personal data handled in this operating model must not be used to train, fine-tune, benchmark or improve generative AI models unless expressly assessed, approved and disclosed where required.
Where approved third-party AI providers are used for inference in a relevant service, CareScribe will use appropriate contractual, security and privacy controls, including zero-retention or equivalent controls where applicable to the approved use case.
We may update this Privacy Policy from time to time to reflect legal, regulatory, operational or service changes. Where appropriate, we will publish or otherwise make available the updated version through the relevant CareScribe route.