Legal

Data Protection

This is a draft template and should be reviewed by a qualified adviser before publication.

Our approach

ScopeTrail is built around a simple principle: we process the minimum information necessary to recover a missed enquiry, and nothing more. We do not collect or store clinical or medical information.

UK GDPR

We process personal data in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018. Where ScopeTrail processes patient contact details on behalf of a practice, the practice remains the data controller and ScopeTrail acts as a data processor under a data processing agreement.

Security

Access to practice and patient information is restricted to what is required to operate the service, and is reviewed as part of our onboarding process with each practice.

Sub-processors

We rely on a small number of specialist providers for telephony and messaging delivery. Details of current sub-processors are available on request.

Data processing agreement

A data processing agreement is put in place with every client practice as part of onboarding, setting out roles, responsibilities and retention periods in full.

Contact

Questions about data protection can be sent to [email protected].

← Back to homepage