← Run Your Clinic
Security & GDPR
Run Your Clinic handles special category health data. Here is exactly how we protect it. Last updated 6 June 2026.
Key commitments
- Patient data never trains AI — Your clinical notes, transcripts, and patient data are never used to train or improve AI models — by us or any of our subprocessors.
- Audio is never stored — Consultation recordings are transmitted for transcription and immediately discarded. We do not retain audio files at any point.
- UK/EU primary storage — Primary data storage is in the UK/EU. Some subprocessors may process data outside the UK/EU under appropriate transfer safeguards, including Standard Contractual Clauses.
- DPA available on request — We provide a signed Data Processing Agreement for practitioners who require one for their own UK GDPR compliance obligations.
What data we hold
| Data type | Detail | Retention |
| Practitioner account data | Name, email, clinic name, profession | 8 years from account closure |
| Cliniko API key | Encrypted at rest, used solely to push notes to Cliniko on your behalf | Deleted on request or account closure |
| Consultation audio | Never stored — transcribed in transit and immediately discarded | Not retained |
| SOAP notes & transcripts | Linked to patient identifiers you provide; stored in your account | 8 years (healthcare records obligation) |
| Exercise programmes | Programme content and patient email address for delivery | 8 years from last activity |
| Call transcripts (Complete plan) | Transcript of AI Receptionist calls — no audio retained | Retained where clinically relevant or required for the patient record. Otherwise deleted within 30–90 days of the call. |
| Billing data | Direct Debit mandate reference only — actual bank details held by GoCardless | Duration of subscription |
Audio and recording policy
When you press Record in SCRPT Notes, audio is captured in your browser and transmitted directly to the transcription service over an encrypted connection. The audio file is never written to our servers.
Once transcribed, the transcript is sent to the AI model to produce your SOAP note. Only the final, practitioner-reviewed note is saved. You are responsible for obtaining appropriate patient consent for consultation recording, in line with your GOsC, GCC, or HCPC obligations and UK GDPR Article 9.
AI training policy
Your patient data is never used to train or improve any AI model — by us, OpenAI, Anthropic, or any other subprocessor.
We access AI APIs under agreements that explicitly prohibit using API inputs and outputs for model training. This applies to all content processed through Run Your Clinic — audio transcripts, SOAP notes, and patient details. We will never opt in to any data-sharing arrangement that would allow patient or clinical data to be used for training purposes.
Infrastructure and encryption
- Data at rest: AES-256 encryption via Supabase (hosted in Frankfurt, EU). SOC 2 Type II certified.
- Data in transit: TLS 1.2+ enforced for all connections — browser to API, API to database, and API to third-party processors.
- Access controls: Production database access is restricted to the application service account. No direct database access from development environments. Admin access is protected by a separate credential layer.
- Data location: Primary data storage is in the EU (Frankfurt). Some subprocessors may process data outside the UK/EU under appropriate transfer safeguards, including Standard Contractual Clauses — see the subprocessors table above.
Subprocessors
These are the third-party services that process data on our behalf:
| Subprocessor | Purpose | Location | Trains on data? |
| OpenAI | Audio transcription (Whisper) and SOAP note generation | USA (Standard Contractual Clauses) | No — API terms explicitly prohibit training on customer data |
| Supabase | Database hosting — stores practitioner accounts, clinical notes, exercise programmes | EU (Frankfurt) | N/A |
| GoCardless | Direct Debit payment processing — stores mandate details only | UK/EU | N/A |
| Vercel | Web application hosting (frontend only — no patient data) | EU | N/A |
| Telnyx | Telephone infrastructure for AI Receptionist (Complete plan only) | USA (Standard Contractual Clauses) | N/A |
Data Processing Agreement (DPA)
We act as your data processor for all patient data processed through Run Your Clinic. You are the data controller. A signed DPA is available on request — email hello@runyourclinic.com with "DPA Request" in the subject line and we will send it within 2 business days.
ICO registration
OsteoRise Limited is registered with the Information Commissioner's Office (ICO). Registration details are available on request. You have the right to lodge a complaint with the ICO at ico.org.uk.
Your rights under UK GDPR
- Access all personal data we hold about you
- Correct inaccurate or incomplete data
- Export your data in a portable format
- Request deletion of your account data (subject to 8-year clinical record retention where applicable)
- Object to or restrict processing
- Lodge a complaint with the ICO
To exercise any of these rights, email hello@runyourclinic.com. We will respond within 30 days.
Security disclosure
If you discover a security vulnerability, please email hello@runyourclinic.com with "Security disclosure" in the subject line. We will acknowledge within 24 hours and work to resolve confirmed vulnerabilities promptly.
Privacy Policy ·
Terms of Service ·
Request DPA ·
Subprocessor list
OsteoRise Limited · hello@runyourclinic.com · Last updated 6 June 2026