Last updated 10/07/2026
Effective date: 01.07.2026
Last updated: 01.07.2026
This Privacy Policy explains what happens with any personal data we gather from you in relation to:
This Privacy Policy should be read alongside any applicable CareScribe product terms, customer agreement, data processing agreement, website policy and cookie policy.
We recognise our obligations under data protection legislation and we are committed to keeping your personal data safe and secure. You should read this Privacy Policy so that you understand how we will handle your personal data. Our aim is to only use and hold your personal data in ways that you would reasonably expect us to.
We may amend this Privacy Policy from time to time. If we do so, we will make you aware via updates posted on our website.
CareScribe Ltd is the controller of your personal data for the purposes of this Privacy Policy.
CareScribe Ltd is registered in England and Wales with company number 11309937. Its registered office is Unit 2.3 Temple Studios, Temple Gate, Bristol, England, BS1 6QA.
Our registration number with the Information Commissioner’s Office is ZA775354.
If you have any questions about this Privacy Policy or how we process your personal data, please contact:
Privacy and security contact
[email protected]
CareScribe and Medincle are separate legal entities under common ownership/control. For Medincle-powered products and services, the intended operating model is that:
Medincle is not intended to be in the routine operational processing flow for CareScribe customer, reseller, website, order, support, billing, complaint or privacy-query personal data. If Medincle must access or retain limited personal data, this should be narrow, documented, need-to-know, proportionate and subject to an appropriate lawful basis or CareScribe instruction.
Medincle may retain or access limited records where lawfully required for historic contractual, finance, legal/compliance, security, legacy-system, IP-protection, transition, separation, sale or exit purposes.
“Personal data” is any information about an individual from which that individual can be identified. It does not include information from which an individual cannot be identified, for example anonymised data.
The types of personal data we may collect, use, store and transfer in relation to you may consist of the following:
If you are using our services through an organisation, we may receive your details from that organisation (e.g., your work email) to provision access.
We advise against uploading sensitive or special category personal data via any free-text website features (for example, a chatbot), unless you specifically need to.
We use personal data to:
For Medincle-powered products and services, CareScribe may also use personal data to administer the customer-facing and reseller-facing operating model, including website journeys, orders, billing/payment administration, support routing, privacy requests, complaints, reseller administration, operational compliance and internal records required under the CareScribe / Medincle MSA.
Where we act as controller, we rely on one or more of the following lawful bases:
Where we record outbound sales calls for training, quality assurance, and to keep an accurate record of business discussions, we rely on Legitimate Interests. We have conducted a Legitimate Interests Assessment (LIA) for this processing, which concludes that we can proceed because:
Our website uses cookies to distinguish you from other users. These cookies may process personal data. This helps us provide a good experience when you browse our website and allows us to improve it.
For detailed information on cookies we use and the purposes for which we use them, please see the CareScribe Cookie Policy.
We may share personal data with:
For Medincle-powered products and services, Medincle is not intended to receive personal data in the routine operational flow. If Medincle must receive, access or retain limited personal data, that access or retention should be limited, documented, need-to-know and subject to appropriate controls and lawful basis, including where required for historic contracts, finance, legal/compliance, security, legacy systems, IP protection, or a documented transition, separation, sale or exit scenario.
We do not sell personal data.
Where personal data is transferred outside the UK/EEA, we use appropriate safeguards, such as:
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit/at rest (where applicable), logging/monitoring, and staff confidentiality obligations.
We retain personal data only for as long as necessary for the purposes described in this policy, including:
Retention periods may vary by data type and context.
Depending on your location and how we process your personal data, you may have rights including:
To exercise rights, contact us using the details in this policy. We may need to verify identity before responding.
For Medincle-powered products and services, customer-facing privacy queries, complaints and rights requests should use CareScribe-facing privacy contact routes unless CareScribe expressly states otherwise.
If you are under the age of 16, you should not use our Software without appropriate adult supervision or without permission from the organisation, parent, guardian or responsible adult supporting your use of the service. We request that children do not provide us with personal information unless this is necessary for the relevant service and is provided through an appropriate authorised route.
Children who are under the age of 13 are not permitted to use our services unless this is expressly permitted through an approved organisational, parental, guardian or responsible-adult route. If we learn we have collected personal information from an individual under the age of 13 without an appropriate basis, we will delete that information as quickly as possible.
We may update this Privacy Policy from time to time. We will post the updated version and update the “Last updated” date.
Personal data handled under this operating model must not be used to train, fine-tune, benchmark or improve generative AI models unless expressly assessed, approved and disclosed where required.