Patientcentre Privacy Policy

Modified on Wed, 8 Apr at 11:13 AM

PRIVACY POLICY: PATIENTCENTRE APP

Last Updated: March 2026

1. INTRODUCTION

Nervecentre Software Ltd ("we", "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and look after your personal data when you use the Patientcentre mobile application (the "App").

This policy should be read alongside our general Nervecentre Privacy Policy and the Terms of Use for the App.


2. WHO IS RESPONSIBLE FOR YOUR DATA? (IMPORTANT)

Under data protection law, there are different "Controllers" responsible for your information depending on the type of data:

  • The Healthcare Organisation (e.g., your NHS Trust): They are the Data Controller for your official medical records (e.g., test results, letters, appointments). Nervecentre acts as their Data Processor to show this information to you in the App.

  • NHS England: They are the Data Controller for your NHS login. We do not see or store your NHS login password. For this personal information, the role of Nervecentre Software Ltd is the “Data Processor” only and we must act under the instructions provided by NHS England (as the “Data Controller”) when verifying your identity.


3. DATA WE COLLECT ABOUT YOU

We collect and process the following types of data:

  • Identity Data: Provided via NHS login, including your name, NHS number, date of birth, and email address.

  • Clinical Data (Viewed): Information pulled from your Healthcare Organisation, including investigation results, medications, and clinical letters.

  • Clinical Data (Entered by You): Information you input, such as clinical observations (e.g., blood pressure), completed forms, questionnaires, and messages sent to your clinical team.

  • Administrative Data: Information regarding your appointments and waiting list status.

  • Usage Data: Your IP address, device type, operating system and usage statistics. This is used for security and app performance monitoring.

  • Proxy Data: If you use the data sharing feature, we process the name and account details of the person you have authorised to view your data and act on your behalf in the App.


4. HOW WE USE YOUR DATA

We use your information for the following purposes:

  • To provide the Service: Authenticating you via NHS login and displaying your health records.

  • Clinical Communication: To allow you to send messages and forms to your healthcare providers.

  • Account Management: To manage your preferences and data sharing (proxy) settings.

  • Clinical Safety: To ensure that observations and forms are accurately mapped to your patient record (in compliance with DCB0129 standards).

  • Legal Compliance: To comply with our obligations to the NHS and healthcare regulators.


5. OUR LAWFUL BASIS FOR PROCESSING

Under UK GDPR, we rely on the following legal bases:

  1. Contract: To provide the App services you requested by accepting our Terms of Use.

  2. Public Task: When we process data on behalf of an NHS Trust to help them deliver your healthcare.

  3. Legal Obligation: Where we must retain records for clinical safety or regulatory reasons.

  4. Health & Social Care (Special Category Data): We process your health data under Article 9(2)(h) of the UK GDPR (provision of health or social care).


6. DATA SHARING AND DISCLOSURE

We do not sell your data. We only share your information with:

  • Your Healthcare Organisation: To ensure the data you enter in the App (like forms or observations) reaches your clinicians.

  • NHS login: To verify your identity.

  • Your Chosen Proxies: Only if you explicitly use the App's "share my data" feature to grant a friend, family member, or other trusted person access.

  • Service Providers: Secure cloud hosting providers (based in the UK) who help us run the Patient Platform.


7. DATA SECURITY

Consistent with Nervecentre’s high security standards:

  • All data is encrypted both in transit and at rest.

  • We use NHS login, which meets the highest standard of identity verification in the UK.

  • We recommend you use your device’s biometric security (FaceID/Fingerprint) to add an extra layer of protection to the App.


8. DATA RETENTION

  • Official Medical Records: These are retained by your NHS Trust in accordance with the national NHS Records Management Code of Practice.

  • App Account Data: We keep your account information for as long as you use the App. If you delete your account, we will remove your personal identifiers from our platform, unless we are required to keep specific data for clinical safety auditing.


9. YOUR RIGHTS

You have the right to access, correct, or erase your personal data. However, there are specific rules for health data:

  • To correct your medical record: You must contact the Healthcare Organisation (Trust) that provided the data. Nervecentre cannot change your official medical records.

  • To delete App data: You can stop sharing data by deleting the App or revoking permissions within the App settings.

  • To exercise other rights: You can contact our Data Protection Officer at privacy@nervecentresoftware.com.


10. CHILDREN’S PRIVACY

The App is not intended for use by anyone under the age of 16. We do not knowingly collect data from children under this age.


11. CONTACT US AND COMPLAINTS

If you have any questions about this notice, please contact our DPO at: Email: privacy@nervecentresoftware.com Address: Nervecentre Software Ltd, Denmark Court, 18 Market Place, Wokingham, Berkshire, RG40 1AL.

You also have the right to make a complaint at any time to the Information Commissioner’s Office (ICO) (www.ico.org.uk).

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article