Security & data protection
Your care data. Clear responsibilities.
Support your UK GDPR responsibilities with authorised access, traceable care-note history and clear data-processing terms. Understand how ServPatch handles care information, and what remains your organisation’s responsibility.
Updated 3 October 2026
Everyday safeguards
The essentials, in plain English.
Authorised, role-based access
Your organisation issues staff accounts. Each person’s role determines what they can see.
Encrypted in transit
Information is encrypted as it travels between the ServPatch app and the service.
Hosted on AWS in London
Application servers run in AWS’s London Region. AWS holds ISO/IEC 27001:2022 certification for its in-scope services.
Traceable care-note history
See who created, reviewed or amended a care note, and when.
Your records, clear responsibilities
Your organisation controls its care records. ServPatch processes them on your behalf under agreed terms.
People stay in charge
Patch works with authorised information. Staff check its answers against the records and remain responsible for care decisions.
Who does what
A clearer picture of how data is handled.
Care records, website enquiries and AI-assisted features have different purposes. Knowing the difference helps your organisation ask the right questions.
Your organisation’s care records
Read the Privacy PolicyFor care-record data entered into the platform, your care organisation is the data controller. It determines why the data is used and is responsible for its lawful use. ServPatch acts as a processor, handling that data on the organisation’s behalf under the agreed terms.
For our own website enquiries and business records, ServPatch is the controller. Our Privacy Policy explains these uses separately.
UK GDPR and sensitive information
ICO special category data guidance ↗ (opens in a new tab)Care records can contain health information, which is special category data. The controller needs an appropriate lawful basis under Article 6 of UK GDPR and a separate condition under Article 9, together with any applicable Data Protection Act 2018 requirements.
Software does not select that basis for you or establish compliance on its own.
Processing terms and service providers
AWS ISO/IEC 27001 information ↗ (opens in a new tab)The applicable processor terms and security information are agreed before ServPatch processes care-record data for a customer. Ask us for the documents available for your proposed arrangement, including relevant providers, processing locations and international-transfer safeguards.
ServPatch’s application servers are hosted in the AWS Europe (London) Region, eu-west-2. This does not mean every connected service, backup, AI process or website service uses the same provider or location.
AWS holds ISO/IEC 27001:2022 certification for its in-scope services and regions. This is AWS’s certification, not a certification of ServPatch. Our application, configuration and data-handling responsibilities remain separate.
Access requests, retention and deletion
Account and data deletionRequests about a person’s care records should normally go to the care provider as controller. ServPatch assists in accordance with the customer agreement and applicable law. Access, correction, restriction, portability and deletion rights depend on the circumstances.
Record-retention requirements and agreed service terms affect what can be deleted and when. Closing an account should not be treated as a promise to erase every record immediately.
Reporting a data concern
For a suspected data-protection incident involving ServPatch, contact [email protected] and follow your organisation’s incident procedure. Personal-data incidents are handled in line with applicable law and the customer agreement, including notification where required.
Describe the issue without emailing care records, passwords or other sensitive details. Ask for a suitable way to share further information.
Using Patch responsibly
Helpful answers. People stay in charge.
Patch helps staff find and understand information available to their role. An AI answer is not a substitute for the underlying record or a professional decision.
Only what your role can see
Patch works within each person’s permissions. No back door to records.
Check the record
Answers come from recorded information. Staff check them against the records before relying on them.
People review AI output
Carers review voice-note text before saving. Calorie figures are estimates, not a nutrition plan.
No diagnosis, no decisions
Patch is not a clinician. Care decisions, escalation and professional advice stay with people.
Before you get started
Bring your security questions.
A short website summary is only a starting point. Contact us to discuss the scope of your service and request the technical and contractual information needed for your review.
Hosting, encryption and recovery
Ask about the locations used for your service, database and file encryption at rest, backup arrangements and recovery procedures. Our public summary describes encryption in transit; specific storage and recovery safeguards should be confirmed for the proposed arrangement.
Access and audit scope
Review how accounts are issued and removed, which information each role can access and what changes are recorded. Care-note history should not be read as a claim that every action across the platform is logged.
AI providers and data handling
Before using AI with care data, ask which provider and service are involved, what information is sent, where it is processed, how long it is retained and whether it is used for model training.
Contracts, retention and leaving
Review the Data Processing Agreement, service providers and transfer safeguards, retention arrangements, export options and the process for ending the service. Agree these before care-record processing begins.
Ask us anything about your data.
We’ll walk through hosting, access, AI processing and contracts for your proposed arrangement.
Prefer to talk now? Call 020 3764 2332 or email [email protected]
