GDPR

Data protection is part of how the platform works.

How Ostify meets UK GDPR, what that means for the agents you build, and what you can hand to your information governance team.

The principles

What the law asks for, and how we meet it.

UK GDPR sets out principles for handling personal data. The simplest way to meet them is to hold as little as possible, so that is how Ostify is designed.

  • Collect as little as possible

    Patients are not identified, and conversations are not stored. What we do and do not hold.

  • Use it only for its purpose

    A question is used to answer that question and nothing else. Your content and your patients’ questions are never used to train AI models.

  • Keep it no longer than needed

    Conversations are not kept at all. Website enquiries and analytics have fixed retention periods, set out in our privacy policy.

  • Keep it secure

    Encryption, controlled access and several layers of protection around every agent. How it is protected.

  • Be open about it

    An agent always says it is an automated assistant, not a person. What we collect on this website and why is in our privacy policy.

  • Be able to show it

    We are registered with the Information Commissioner’s Office, number ZC243397, and we keep the documents your own assurance process will ask for.

Who is responsible

Your agent, your decisions. Our platform, our safeguards.

Data protection law separates the organisation that decides why data is used from the one that handles it on their behalf.

You
Decide what your agent is forYou choose its purpose, its content and who it is offered to. Your organisation’s information governance team will usually want a data protection impact assessment (DPIA) before it reaches patients.
Ostify, for your agent
Handles data on your instructionsWe run your agent under data processing terms agreed with you, keep the platform secure, and can share our list of sub-processors on request.
Ostify, for this website
Responsible for what we collect hereFor enquiries and website analytics we are the controller, as our privacy policy explains.

Where data is processed

In the UK, and for testing, in the EU.

The full picture of where data goes is on the trust page. This is what it means for data protection.

Patient conversations
Processed in the UKNothing leaves the UK, so no international transfer is involved.
Evaluation and drafting
Processed in the EUThese work on your test questions and settings, not on patient conversations. UK law recognises the EU as giving an adequate level of protection.

People’s rights

Access, correction and deletion.

Everyone has the right to see, correct or delete the personal data held about them.

  • For patients

    Because conversations are not stored and patients are not identified, there is no record of a patient’s chat for us to hold, find or disclose.

  • For you

    You can ask us for the personal data we hold about you, or ask us to correct or delete it. Each request is logged and handled by a person.

  • How to ask

    Email info@ostify.co.uk. We reply within one month, and there is usually no charge. You can also complain to the ICO.