1. Roles
For the documents you analyse, you are the data controller: you decide what to process and under what lawful basis. We provide the tooling and act as a processor only for the transient transmission required to generate an answer. For the operation of the website itself (security, delivery) we are the controller.
2. What we do not collect
- No account, name, e-mail address or password — there is no sign-up.
- No analytics, advertising identifiers or behavioural profiling.
- No copies of your documents, extracted text or conversations.
- No server-side chat history and no clinical database.
3. What is processed, and where
- Locally, in your browser: the uploaded file, the text extracted from it, your case titles and your conversation history (localStorage), and your consent record.
- Transiently, in transit: when you send a message, the extracted text you attached plus your messages travel over TLS to our server function and on to the AI model provider, solely to generate the reply. Nothing is written to disk by us.
- Infrastructure logs: our hosting provider may process technical request metadata (IP address, timestamp, user agent) for a short period for security and abuse prevention. Message content is not included.
4. Special category data
Health data is a special category under Article 9 GDPR. Virtual Clinic is designed so that such data stays on your device, and we ask you to pseudonymise before analysis. If you nonetheless attach identifiable health data, you must ensure an Article 9(2) condition applies — we do not and cannot assess that for you.
5. Lawful basis
- Consent (Art. 6(1)(a)): for the strictly necessary local storage you accept in the consent banner.
- Contract (Art. 6(1)(b)): for delivering the requested AI response.
- Legitimate interests (Art. 6(1)(f)): for the minimal technical logging required to keep the service secure and available.
6. Recipients and transfers
The only recipients are our hosting provider and the AI model provider that generates the completion. Model providers may process the request outside the EEA; such transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision. If your organisation cannot permit any extra-EEA transfer of clinical text, do not attach document text to a message.
7. Retention
- Documents and extracted text: kept in page memory for the session only.
- Case history and consent record: kept in your browser until you delete them.
- Message content on our servers: not retained.
- Technical infrastructure logs: short-term, provider-defined.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under Articles 15–22 GDPR. Because we hold no user data, you exercise most of these rights directly: your data is in this browser, and the workspace controls (delete a case, wipe all local data) or clearing site data give you immediate and complete erasure. You may also lodge a complaint with your national supervisory authority.
9. Security
Encrypted transport (TLS 1.2+), no persistent server-side store, no accounts to compromise, and client-side-only document parsing. See the full Security & Data Handling notice.
10. Children
The platform is not intended for anyone under 18 and we do not knowingly process data of minors as users.
11. Changes
Material changes to this notice will re-trigger the consent banner. The current version and date are shown at the top of this page.
