1.0 About this Privacy Policy

Effective date: 01.07.2026

Last updated: 01.07.2026

This Privacy Policy explains what happens with any personal data we gather from you in relation to:

  • your use of our website;
  • your use of and/or licensing of our software products (the “Software”); and
  • any customer service or other enquiries you submit to us.

This Privacy Policy should be read alongside any applicable CareScribe product terms, customer agreement, data processing agreement, website policy and cookie policy.

We recognise our obligations under data protection legislation and we are committed to keeping your personal data safe and secure. You should read this Privacy Policy so that you understand how we will handle your personal data. Our aim is to only use and hold your personal data in ways that you would reasonably expect us to.

We may amend this Privacy Policy from time to time. If we do so, we will make you aware via updates posted on our website.

2.0 Who we are

CareScribe Ltd is the controller of your personal data for the purposes of this Privacy Policy.

CareScribe Ltd is registered in England and Wales with company number 11309937. Its registered office is Unit 2.3 Temple Studios, Temple Gate, Bristol, England, BS1 6QA.

Our registration number with the Information Commissioner’s Office is ZA775354.
If you have any questions about this Privacy Policy or how we process your personal data, please contact:

Privacy and security contact
[email protected]

3.0 CareScribe and Medincle

CareScribe and Medincle are separate legal entities under common ownership/control. For Medincle-powered products and services, the intended operating model is that:

  • CareScribe is the default front-facing company for customer relationships, website journeys, orders, support, billing/payment administration, reseller relationships, privacy handling and commercial operations; and
  • Medincle retains ownership of Medincle intellectual property, technology, know-how, product assets and related proprietary rights.

Medincle is not intended to be in the routine operational processing flow for CareScribe customer, reseller, website, order, support, billing, complaint or privacy-query personal data. If Medincle must access or retain limited personal data, this should be narrow, documented, need-to-know, proportionate and subject to an appropriate lawful basis or CareScribe instruction.

Medincle may retain or access limited records where lawfully required for historic contractual, finance, legal/compliance, security, legacy-system, IP-protection, transition, separation, sale or exit purposes.

4.0 What personal data we collect

“Personal data” is any information about an individual from which that individual can be identified. It does not include information from which an individual cannot be identified, for example anonymised data.

The types of personal data we may collect, use, store and transfer in relation to you may consist of the following:

  • Identity and contact data: name, email address, job title, organisation, phone number.
  • Account and authentication data: login identifiers, user IDs, access logs.
  • Usage data: product usage events, feature interactions, device and browser information, IP address (where applicable), diagnostic information.
  • Communications data: emails and messages you send to us (e.g., support requests, sales enquiries).
  • Marketing preferences: opt-in/opt-out preferences.
  • Website data: pages visited and related analytics.

If you are using our services through an organisation, we may receive your details from that organisation (e.g., your work email) to provision access.

We advise against uploading sensitive or special category personal data via any free-text website features (for example, a chatbot), unless you specifically need to.

5.0 How we use personal data (purposes)

We use personal data to:

  • Provide and secure our services (including account creation, authentication, access control, troubleshooting).
  • Operate our business (billing, contract management, vendor management, recordkeeping).
  • Communicate with you (service messages, support replies, customer communications).
  • Improve our services (analytics, debugging, performance monitoring, product improvements).
  • Sales and marketing (where permitted, to respond to enquiries and share information about our services).
  • Comply with legal obligations and protect rights (e.g., fraud prevention, dispute resolution, regulatory compliance).

For Medincle-powered products and services, CareScribe may also use personal data to administer the customer-facing and reseller-facing operating model, including website journeys, orders, billing/payment administration, support routing, privacy requests, complaints, reseller administration, operational compliance and internal records required under the CareScribe / Medincle MSA.

6.0 Lawful bases (UK GDPR / EU GDPR)

Where we act as controller, we rely on one or more of the following lawful bases:

  • Contract: to provide services or take steps at your request before entering a contract.
  • Legitimate interests: to run and improve our business, keep our services secure, and communicate with business contacts (balanced against individual rights).
  • Legal obligation: to comply with laws and regulatory requirements.
  • Consent: for certain marketing activities and cookies/technologies where required.

Where we record outbound sales calls for training, quality assurance, and to keep an accurate record of business discussions, we rely on Legitimate Interests. We have conducted a Legitimate Interests Assessment (LIA) for this processing, which concludes that we can proceed because:

  • the context is B2B outreach, and individuals may reasonably expect business calls to be recorded for training/quality purposes;
  • we seek to avoid capturing special category data and focus on professional voice data only;
  • we provide immediate notice at the start of the call that it is recorded for training and quality purposes;
  • if a person objects, we stop recording and delete the recording; and
  • access to recordings is restricted and recordings are retained only for a limited period (unless required for an ongoing dispute).

7.0 Cookies and similar technologies

Our website uses cookies to distinguish you from other users. These cookies may process personal data. This helps us provide a good experience when you browse our website and allows us to improve it.

For detailed information on cookies we use and the purposes for which we use them, please see the CareScribe Cookie Policy.

8.0 How we share personal data

We may share personal data with:

  • Service providers (processors) that help us operate our business (e.g., cloud hosting, analytics, customer support tooling), under contractual obligations.
  • Professional advisers (legal, audit, accounting) where necessary.
  • Authorities where required by law or to protect rights and safety.
  • Business transferees in a merger, acquisition, or sale of assets (subject to appropriate safeguards).

For Medincle-powered products and services, Medincle is not intended to receive personal data in the routine operational flow. If Medincle must receive, access or retain limited personal data, that access or retention should be limited, documented, need-to-know and subject to appropriate controls and lawful basis, including where required for historic contracts, finance, legal/compliance, security, legacy systems, IP protection, or a documented transition, separation, sale or exit scenario.

We do not sell personal data.

9.0 International transfers

Where personal data is transferred outside the UK/EEA, we use appropriate safeguards, such as:

  • adequacy regulations/decisions (where available), and/or
  • Standard Contractual Clauses (SCCs) and the UK Addendum, plus supplementary measures where needed.

10.0 Security

We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit/at rest (where applicable), logging/monitoring, and staff confidentiality obligations.

11.0 Data retention

We retain personal data only for as long as necessary for the purposes described in this policy, including:

  • to provide services,
  • to meet legal, accounting, or reporting requirements, and
  • to establish, exercise, or defend legal claims.

Retention periods may vary by data type and context.

12.0 Your rights

Depending on your location and how we process your personal data, you may have rights including:

  • access,
  • rectification,
  • erasure,
  • restriction,
  • objection,
  • data portability, and
  • withdrawal of consent (where we rely on consent).

To exercise rights, contact us using the details in this policy. We may need to verify identity before responding.

For Medincle-powered products and services, customer-facing privacy queries, complaints and rights requests should use CareScribe-facing privacy contact routes unless CareScribe expressly states otherwise.

13.0 Children

If you are under the age of 16, you should not use our Software without appropriate adult supervision or without permission from the organisation, parent, guardian or responsible adult supporting your use of the service. We request that children do not provide us with personal information unless this is necessary for the relevant service and is provided through an appropriate authorised route.

Children who are under the age of 13 are not permitted to use our services unless this is expressly permitted through an approved organisational, parental, guardian or responsible-adult route. If we learn we have collected personal information from an individual under the age of 13 without an appropriate basis, we will delete that information as quickly as possible.

14.0 Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version and update the “Last updated” date.

15.0 How to contact us / complaints

  • Email: [email protected]
  • If you are in the UK, you can contact the Information Commissioner’s Office (ICO) on 0303 123 1113 or via their website.

16.0 No AI training

Personal data handled under this operating model must not be used to train, fine-tune, benchmark or improve generative AI models unless expressly assessed, approved and disclosed where required.