Skip to content

Security & data protection

Your care data. Clear responsibilities.

Support your UK GDPR responsibilities with authorised access, traceable care-note history and clear data-processing terms. Understand how ServPatch handles care information, and what remains your organisation’s responsibility.

Updated 3 October 2026

Everyday safeguards

The essentials, in plain English.

  • Authorised, role-based access

    Your organisation issues staff accounts. Each person’s role determines what they can see.

  • Encrypted in transit

    Information is encrypted as it travels between the ServPatch app and the service.

  • Hosted on AWS in London

    Application servers run in AWS’s London Region. AWS holds ISO/IEC 27001:2022 certification for its in-scope services.

  • Traceable care-note history

    See who created, reviewed or amended a care note, and when.

  • Your records, clear responsibilities

    Your organisation controls its care records. ServPatch processes them on your behalf under agreed terms.

  • People stay in charge

    Patch works with authorised information. Staff check its answers against the records and remain responsible for care decisions.

Who does what

A clearer picture of how data is handled.

Care records, website enquiries and AI-assisted features have different purposes. Knowing the difference helps your organisation ask the right questions.

  • Your organisation’s care records

    For care-record data entered into the platform, your care organisation is the data controller. It determines why the data is used and is responsible for its lawful use. ServPatch acts as a processor, handling that data on the organisation’s behalf under the agreed terms.

    For our own website enquiries and business records, ServPatch is the controller. Our Privacy Policy explains these uses separately.

    Read the Privacy Policy
  • UK GDPR and sensitive information

    Care records can contain health information, which is special category data. The controller needs an appropriate lawful basis under Article 6 of UK GDPR and a separate condition under Article 9, together with any applicable Data Protection Act 2018 requirements.

    Software does not select that basis for you or establish compliance on its own.

    ICO special category data guidance ↗ (opens in a new tab)
  • Processing terms and service providers

    The applicable processor terms and security information are agreed before ServPatch processes care-record data for a customer. Ask us for the documents available for your proposed arrangement, including relevant providers, processing locations and international-transfer safeguards.

    ServPatch’s application servers are hosted in the AWS Europe (London) Region, eu-west-2. This does not mean every connected service, backup, AI process or website service uses the same provider or location.

    AWS holds ISO/IEC 27001:2022 certification for its in-scope services and regions. This is AWS’s certification, not a certification of ServPatch. Our application, configuration and data-handling responsibilities remain separate.

    AWS ISO/IEC 27001 information ↗ (opens in a new tab)
  • Access requests, retention and deletion

    Requests about a person’s care records should normally go to the care provider as controller. ServPatch assists in accordance with the customer agreement and applicable law. Access, correction, restriction, portability and deletion rights depend on the circumstances.

    Record-retention requirements and agreed service terms affect what can be deleted and when. Closing an account should not be treated as a promise to erase every record immediately.

    Account and data deletion
  • Reporting a data concern

    For a suspected data-protection incident involving ServPatch, contact [email protected] and follow your organisation’s incident procedure. Personal-data incidents are handled in line with applicable law and the customer agreement, including notification where required.

    Describe the issue without emailing care records, passwords or other sensitive details. Ask for a suitable way to share further information.

Using Patch responsibly

Helpful answers. People stay in charge.

Patch helps staff find and understand information available to their role. An AI answer is not a substitute for the underlying record or a professional decision.

  • Only what your role can see

    Patch works within each person’s permissions. No back door to records.

  • Check the record

    Answers come from recorded information. Staff check them against the records before relying on them.

  • People review AI output

    Carers review voice-note text before saving. Calorie figures are estimates, not a nutrition plan.

  • No diagnosis, no decisions

    Patch is not a clinician. Care decisions, escalation and professional advice stay with people.

Before you get started

Bring your security questions.

A short website summary is only a starting point. Contact us to discuss the scope of your service and request the technical and contractual information needed for your review.

  • Hosting, encryption and recovery

    Ask about the locations used for your service, database and file encryption at rest, backup arrangements and recovery procedures. Our public summary describes encryption in transit; specific storage and recovery safeguards should be confirmed for the proposed arrangement.

  • Access and audit scope

    Review how accounts are issued and removed, which information each role can access and what changes are recorded. Care-note history should not be read as a claim that every action across the platform is logged.

  • AI providers and data handling

    Before using AI with care data, ask which provider and service are involved, what information is sent, where it is processed, how long it is retained and whether it is used for model training.

  • Contracts, retention and leaving

    Review the Data Processing Agreement, service providers and transfer safeguards, retention arrangements, export options and the process for ending the service. Agree these before care-record processing begins.

Ask us anything about your data.

We’ll walk through hosting, access, AI processing and contracts for your proposed arrangement.

Prefer to talk now? Call 020 3764 2332 or email [email protected]