Security & data protection

Your care data.
Clear responsibilities.

Support your UK GDPR responsibilities with authorised access, traceable care-note history and clear data-processing terms. Understand how ServPatch handles care information and what remains your organisation’s responsibility.

Updated

Authorised access

Your organisation issues carer accounts, with access limited to authorised team members.

Encrypted connections

Information is encrypted as it travels between the ServPatch app and the service.

Hosted on AWS in London

Our application servers run in AWS’s London Region. AWS holds ISO/IEC 27001:2022 certification for its in-scope services.

Supporting UK GDPR compliance

Clear controller and processor responsibilities, agreed processing terms and support for care-record requests. Your organisation remains in control of its care data.

Care-note history

See who created, reviewed or amended a care note, and when. This supports accountability when reviewing a record.

People stay in charge

Patch works with authorised information. Staff check its answers against the records and remain responsible for care decisions.

Who does what

A clearer picture of how data is handled.

Care records, website enquiries and AI-assisted features have different purposes. Knowing the difference helps your organisation ask the right questions.

Read the Privacy Policy

Your organisation’s care records

For care-record data entered into the platform, your care organisation is the data controller. It determines why the data is used and is responsible for its lawful use. ServPatch acts as a processor, handling that data on the organisation’s behalf under the agreed terms.

For our own website enquiries and business records, ServPatch is the controller. Our Privacy Policy explains these uses separately.

UK GDPR and sensitive information

Care records can contain health information, which is special category data. The controller needs an appropriate lawful basis under Article 6 of UK GDPR and a separate condition under Article 9, together with any applicable Data Protection Act 2018 requirements.

Software does not select that basis for you or establish compliance on its own. See the ICO’s special category data guidance.

Processing terms and service providers

The applicable processor terms and security information are agreed before ServPatch processes care-record data for a customer. Ask us for the documents currently available for your proposed arrangement, including relevant providers, processing locations and international-transfer safeguards.

ServPatch’s application servers are hosted in the AWS Europe (London) Region, eu-west-2. This does not mean every connected service, backup, AI process or website service uses the same provider or location.

AWS holds ISO/IEC 27001:2022 certification for its in-scope services and regions. This is AWS’s certification, not a certification of ServPatch. Our application, configuration and data-handling responsibilities remain separate.

Access requests, retention and deletion

Requests about a person’s care records should normally go to the care provider as controller. ServPatch assists in accordance with the customer agreement and applicable law. Access, correction, restriction, portability and deletion rights depend on the circumstances.

Record-retention requirements and agreed service terms affect what can be deleted and when. Account deletion and care-record retention are explained separately; closing an account should not be treated as a promise to erase every record immediately.

Reporting a data concern

For a suspected data-protection incident involving ServPatch, contact [email protected] and follow your organisation’s incident procedure. Personal-data incidents are handled in line with applicable law and the customer agreement, including notification where required.

Describe the issue without emailing care records, passwords or other sensitive details. Ask for a suitable way to share further information.

Using Patch responsibly

Helpful answers.
People stay in charge.

Patch helps staff find and understand information available to their role. It can support a handover or help bring recorded details together, but an AI answer is not a substitute for the underlying record or a professional decision.

See what Patch does
  • Stay within authorised access

    Use Patch for information your role allows you to access, following your organisation’s policies.

  • Check before relying on an answer

    AI can make mistakes. Check the relevant record, dates and context before using a response in care work.

  • Keep care decisions with people

    Patch is not a clinician and does not replace medical advice or your escalation procedures.

Before you get started

Bring your security questions.

A short website summary is only a starting point. Contact us to discuss the scope of your service and request the technical and contractual information needed for your review.

Hosting, encryption and recovery

Ask about the locations used for your service, database and file encryption at rest, backup arrangements and recovery procedures. Our public summary describes encryption in transit; specific storage and recovery safeguards should be confirmed for the proposed arrangement.

Access and audit scope

Review how accounts are issued and removed, which information each role can access and what changes are recorded. Care-note history should not be read as a claim that every action across the platform is logged.

AI providers and data handling

Before using AI with care data, ask which provider and service are involved, what information is sent, where it is processed, how long it is retained and whether it is used for model training. Review the applicable processing terms as part of your organisation’s assessment.

Contracts, retention and leaving the service

Review the Data Processing Agreement, relevant service providers and transfer safeguards, retention arrangements, export options and the process for ending the service. Agree these details before care-record processing begins.