Legal
Data Protection
This is a draft template and should be reviewed by a qualified adviser before publication.
Our approach
ScopeTrail is built around a simple principle: we process the minimum information necessary to recover a missed enquiry, and nothing more. We do not collect or store clinical or medical information.
UK GDPR
We process personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. Where ScopeTrail processes patient contact details on behalf of a practice, the practice remains the data controller and ScopeTrail acts as a data processor under a data processing agreement.
Security
Access to practice and patient information is restricted to what is required to operate the service, and is reviewed as part of our onboarding process with each practice.
Sub-processors
We rely on a small number of specialist providers for telephony and messaging delivery. Details of current sub-processors are available on request.
Data processing agreement
A data processing agreement is put in place with every client practice as part of onboarding, setting out roles, responsibilities and retention periods in full.
Contact
Questions about data protection can be sent to [email protected].
← Back to homepage