Privacy notice

The privacy doctrine explains our architecture; this page is the formal notice: what personal data medrics itself holds, why, for how long, who else touches it, and your rights. Last updated 5 September 2026.

Who is responsible

The data controller is MEDRICS LTD, a company registered in England and Wales (company number 16046579), registered office 4 St. Martins Drive, Priorslee, Telford TF2 9WE. We are registered with the Information Commissioner's Office (registration ZB925290). We have not appointed a data protection officer, because we are a small company and the law does not require one. Contact for anything on this page: info@medrics.co.uk.

The app: we hold nothing

Locum Manager processes your documents on your own computer. We run no accounts, no analytics and no telemetry in the app, so we cannot see your data, so this notice has nothing to say about it. Delete the folder and it's gone. The same is true of the clinical documentation aid and the voice-reflection tool: they run on your own device and store nothing with us.

What we do hold, and why

DataWhy (lawful basis)Kept until
Session sign-ups & mailing list: name, email (when you join the mailing list, registering for the free shortcuts or a session, or email us; list signups are captured by a Google form, so Google processes the submission) To send you what you signed up for, automatically: the shortcut links and how to use them, news of the Portfolio system (career and money insights), and session announcements (consent) You unsubscribe. Every email has the option
Watching a recording on demand: the video is hosted on YouTube (unlisted) and embedded from youtube-nocookie.com — nothing is sent to Google until you press play; from then Google's own privacy policy applies to the player. To earn the certificate you complete the same feedback form as a live session (a Google form: name, email, your answers). A paid recording is bought through Stripe (your card details go to Stripe, never to medrics; we keep your email, what you bought and Stripe's payment id so we can send your link and issue your certificate) To issue your certificate and, if you use the portfolio, your CPD record (contract — you asked for the certificate) Certificates and attendance records: 6 years (appraisal evidence)
Attendance & certificates: that your email attended a session, hours, certificate issued. Where a session ran on Zoom or Microsoft Teams we import the participant list to mark attendance To issue your CPD certificate and power CPD auto-transfer if you use it (contract) 6 years (certificates are evidence you may need at appraisal)
Member service data: your member token (we store only a hash of it), the metadata you consented to send (counts, hours, gaps), claim lines you previewed and sent, and feedback you give us. Payments are taken by Stripe: we never see your card number; Stripe holds your email and invoice history To provide the service you asked for (contract) Membership ends + 12 months; feedback 24 months
Assessor sign-off: if you are a trainee: the single item you chose to share and the signed record. If you are a supervisor or assessor: your name, work email, GMC number, role, the statements you agreed or edited, and your signature Trainee: you asked a named doctor to review it (contract). Assessor: you are carrying out a supervision task you agreed to, and the record must show who signed it (legitimate interest). Your details are used only on that record and on the receipt we send you The signed record lives in the trainee's own portfolio. Our server copy is reduced to an audit stub (assessor name, role, dates) once the trainee has collected it; unsigned requests are cleared 60 days after the link expires
Usage counts: that a member used a service on a date (never content, and only a non-reversible member id) To know which services matter (legitimate interest) 24 months
Trust review portal: if you use a review link we sent your NHS trust: your name and work email if you give them, and the comments and answers you type To run the patient-information review with your team (legitimate interest; contract where your trust has one with us) The link expires after 180 days; comments are kept as business records while we work with your trust
Trust staff contact details from public sources: if your work name, role, email or phone number is published on your trust's website, we may hold it to contact the team responsible for the pages our reports describe. This notice is the fuller statement of that, and our first email links here Contacting the right team about its own published patient information (legitimate interest; you can object at any time and we will stop) While your trust is a prospect or customer; re-checked and removed when stale
Contributors, presenters and teachers: name, email, skills or bio, the materials you send, and your replies to our questions To run the teaching programme and the contributor programme you joined (contract / consent) While active + 12 months; presenter session records 6 years as CPD evidence
Testers: name and email for a test link, and the feedback you give To test tools with clinicians before release (legitimate interest) Link period + 12 months
Paid reviewers: if we engage you as a contractor to review our content: your name, email, GMC number (clinical roles), rate, the hours and findings you record on your private workspace link, and our payment records To run and pay for the engagement you agreed (contract), and to keep the company's accounting records (legal obligation). Your findings are read by a person, never by an AI service 6 years after the last payment (company records); the workspace link expires after 90 days unless renewed
Diagnostics reports: a technical report you chose to send from the app after previewing it byte-for-byte To fix the problem you reported (consent) 12 months
Clinician leaflet picker search telemetry (leaflets.medrics.co.uk): the text of a search that found nothing; no identifier, no address. The patient search on this site records nothing. To add the leaflets people look for (legitimate interest) 90 days
Leaflet picker sync: only if you are a member and choose to sign in on the clinician picker: your chosen hospital, specialty and the named leaflet sets you save, held against your membership id. Never your professional registration number, and never anything about a patient So your saved sets follow you between devices (contract) 12 months after last use

How we use AI

We use AI models to help draft and review our own work. Messages and documents written by people outside medrics (replies from trusts, contributors, presenters and supervisors) are processed only by models running on our own hardware and are never sent to a cloud AI provider. Where we do use cloud AI services (Anthropic, OpenAI) for our own drafting, personal identifiers are removed from the text first. No AI decision is made about you without a person; nothing an AI drafts is sent to you without a person at medrics reviewing it.

Where it lives, who else touches it

Member and service data is stored on medrics-controlled hardware in the UK, not in a third-party cloud database. The processors we use, each only for the purpose named: Google Workspace (email, forms and sheets), Brevo (mailing-list and event email; EU-hosted), Stripe (payments), Cloudflare (secure tunnel and proxy for our sign-off and portal links, standard connection logs), GoDaddy (this website's host, standard server logs), Apple iCloud (synchronised storage of our working files), GitHub (private code repository, no customer data), Zoom / Microsoft Teams (online sessions and participant lists), and Anthropic / OpenAI (AI drafting, as described above). Some of these companies are in the United States; where personal data reaches them we rely on the transfer safeguards in their terms, the UK Extension to the EU-US Data Privacy Framework where the provider is certified, otherwise the UK International Data Transfer Addendum. We never sell or share personal data, and community data (like rate cards) publishes only in anonymous, k-anonymity-protected form.

Cookies & page counts

This site sets no cookies and uses no cross-site trackers. Page counting is currently switched OFF: this site records nothing at all about your visit. If we turn it on we will say so here first, and it will stay the same anonymous count it is built to be: only the page path and, if you came from another site, that site's name, never your IP address, with no cookie or identifier of any kind, so views could not be linked to each other or to you. It would count views, not people. The patient leaflets and the Locum Manager app run no counting at all, switched on or off.

Your rights

You can ask for a copy of what we hold about you, ask us to correct or delete it, object to any processing based on legitimate interest, or withdraw consent at any time: email info@medrics.co.uk and we'll respond within a month. Where we must keep something (for example a certificate record) we will tell you why. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ico.org.uk).

If something goes wrong

If personal data we hold is lost or exposed and that is likely to put you at risk, we will tell the ICO within 72 hours and tell you directly if the risk to you is high.