SendScript Privacy Policy
Sendscript Technologies Limited · Company No. 17307204
Table of Contents
1. About this Privacy Policy
This Privacy Policy explains how Sendscript Technologies Limited, a company registered in England and Wales under company number 17307204, trading as SendScript ("SendScript", "we", "us" or "our"), collects, uses, stores, discloses and otherwise processes personal information.
It applies when you:
- visit www.sendscript.com or another SendScript website that links to this Privacy Policy;
- use a SendScript mobile application, patient portal, professional portal or other digital service;
- create or use a patient, clinician, clinic, pharmacy, radiology, hospital, administrator or other professional account;
- use SendScript's telemedicine, electronic medical record, radiology, electronic prescription, pharmacy or marketplace services;
- book, request, receive or manage healthcare services through SendScript;
- communicate with SendScript, including through email, customer support, forms, demonstrations, events or sales enquiries; or
- work for, represent or provide services to a healthcare organisation that uses SendScript.
This Privacy Policy should be read together with:
- the applicable SendScript Terms and Conditions;
- any patient-facing privacy information provided by your doctor, clinic, hospital, pharmacy, radiology provider or other healthcare provider;
- any business customer data processing agreement;
- our Cookie Policy, available at www.sendscript.com/cookie-policy
- any consent, referral, prescription, consultation or booking information presented when a particular service is used; and
- any additional privacy notice provided for a specific SendScript product, country or service.
A healthcare provider using SendScript may have its own legal obligations and privacy notice. This Privacy Policy does not replace the privacy notice of your treating healthcare provider.
2. Who we are and how to contact us
Sendscript Technologies Limited
Registered in England and Wales, company number 17307204
116 Harley Street, 3rd Floor, London W1G 7JL, United Kingdom
Registered with the Information Commissioner's Office under registration reference ZC206663
Email: privacy@sendscript.com
Website: www.sendscript.com
Privacy and data-protection requests, and data protection complaints, may be sent to privacy@sendscript.com. Section 23 explains how to make a rights request and section 25 explains how to make a complaint.
2.1 Data Protection Officer
SendScript processes health information about patients on a significant scale as a core part of its services.
(a) SendScript has appointed a Data Protection Officer under Article 37 of the UK GDPR. The Data Protection Officer can be contacted at dpo@sendscript.com or by post at the address above, marked for the attention of the Data Protection Officer.
2.2 India contact and Grievance Officer
SendScript's team includes personnel based in India who are employed or engaged by Sendscript Technologies Limited and form part of its operational and technology function.
For individuals in India, the following email contact is published for privacy questions, rights requests and grievances:
Email: Grievanceofficer@sendscript.com
This email contact is published to meet the requirement under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 for a grievance officer whose contact details are published, and to meet the equivalent requirement under the Digital Personal Data Protection framework as its provisions come into force. Grievances are addressed within the period stated in section 24.
3. The laws covered by this Privacy Policy
For individuals in the United Kingdom, this Privacy Policy is intended to address applicable requirements under:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025, the principal data protection amendments in Part 5 of which came into force on 5 February 2026, with the complaints duty in section 103 coming into force on 19 June 2026;
- the Privacy and Electronic Communications (EC Directive) Regulations 2003;
- applicable health-record, professional-confidentiality, consumer and electronic-communications requirements; and
- any legislation replacing, amending or supplementing those laws.
UK law requires an organisation processing health information to identify both a lawful basis under Article 6 of the UK GDPR and an additional condition for processing special-category information under Article 9. Where the Article 9 condition relied on also requires a condition under Schedule 1 to the Data Protection Act 2018, that condition is identified and the associated appropriate policy document is maintained.
For individuals in India, this Privacy Policy is intended to address applicable requirements under:
- the Information Technology Act 2000;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, to the extent applicable;
- the Digital Personal Data Protection Act 2023 and the Digital Personal Data Protection Rules 2025 as their provisions come into force;
- applicable Indian healthcare, telemedicine, pharmacy, clinical-establishment and professional-confidentiality requirements; and
- any applicable regulations, directions or standards issued under those laws.
The Indian DPDP framework has a phased commencement timetable. The Digital Personal Data Protection Rules 2025 were notified in November 2025. Rules 1, 2 and 17 to 21 came into force on notification. Rule 4, concerning consent managers, comes into force twelve months after notification. Rules 3, 5 to 16 and 22 to 23, which contain the substantive notice, consent, security, breach-reporting, children's data, transfer and grievance obligations, come into force eighteen months after notification. SendScript applies privacy, security, transparency and individual-rights safeguards consistently. Statements in this Privacy Policy about statutory rights and duties reflect the provisions actually in force at the relevant time.
Where another country's privacy law applies to a particular service, SendScript provides a country-specific supplement.
4. SendScript's services
SendScript operates a connected healthcare technology platform that may include the following services.
4.1 Telemedicine
The telemedicine service may enable patients and healthcare professionals to arrange and attend remote consultations; participate in video or audio consultations; exchange secure messages; upload photographs, reports, referral documents or other files; complete pre-consultation forms; receive consultation-related communications; create or update clinical notes; issue referrals, prescriptions or investigation requests; and arrange follow-up care.
SendScript does not record or retain the audio or video content of ordinary telemedicine consultations by default. Clinical notes, messages, documents, appointment records and technical connection logs may be retained.
Where a recording function is enabled for a particular service, SendScript ensures that the user is clearly informed before recording begins, and the recording is only made where it is supported by an appropriate lawful basis and any necessary consent.
4.2 Electronic medical records
The electronic medical record or "EMR" service may allow authorised healthcare organisations and professionals to create and maintain patient records; document consultations, diagnoses and treatment plans; record allergies, medications and immunisations; request, receive and review laboratory or imaging results; create prescriptions and referrals; upload and manage documents; manage appointments, tasks and care workflows; communicate with patients and other authorised professionals; record consent, correspondence and administrative information; and maintain an audit history of access and changes.
The healthcare organisation using the EMR will normally determine why the patient record is created and how it is used for healthcare. SendScript will normally process that record on the organisation's behalf.
4.3 Radiology platform
The radiology service may facilitate imaging referrals and requests; appointment booking and management; clinical indications and safety questionnaires; communication between referring clinicians, patients and imaging providers; access to scan reports and, where enabled, images or secure image links; radiologist reporting workflows; status tracking; urgent-result or follow-up communications; billing and payment administration; and transfer of radiology information to the patient portal or relevant healthcare provider.
Depending on the service configuration, radiology information may include DICOM-related metadata, imaging identifiers, HL7 or FHIR messages, referral forms, scan reports, images, image links and related audit information.
4.4 Electronic prescriptions
The electronic prescription service may enable an authorised prescriber to create a prescription; select a medicine, dose, route, frequency, quantity and instructions; authorise a prescription using secure credentials or a PIN; issue a prescription token or notification to a patient; send a prescription to a participating pharmacy where requested or permitted; monitor whether the prescription has been sent, accessed or dispensed; receive dispensing-status information; and maintain an audit record showing relevant prescription activity.
Prescription information may include the identity and professional details of the prescriber, patient details, medication information, prescription dates, authorisation events, the selected pharmacy and dispensing information.
4.5 Healthcare marketplaces
SendScript may operate marketplaces through which users can search for, compare, contact or book specialist doctors; general practitioners or other healthcare professionals; clinics and hospitals; diagnostic or radiology providers; pharmacies; and other healthcare services.
Marketplace profiles may contain information intended to be publicly visible, such as professional or organisation name; profile photograph or logo; qualifications and experience; professional registration information; languages; clinical interests and services; clinic address and contact details; consultation formats; fees; availability; ratings or reviews; and regulatory, accreditation or verification information.
A participating healthcare professional, clinic or pharmacy is generally responsible for the healthcare or pharmacy services it provides. SendScript's role may be limited to providing the marketplace, booking, communication, payment or technology functionality.
4.6 Pharmacy platform
The pharmacy platform may allow authorised pharmacies and pharmacy personnel to receive and review prescriptions; verify patient and prescription details; record prescription acceptance, rejection or clarification; document dispensing; update dispensing status; communicate with a prescriber or patient; arrange collection or delivery; manage pharmacy staff access; manage transactions, invoices and related records; and maintain a dispensing and audit history.
The pharmacy remains responsible for its professional, legal, clinical, dispensing, record-keeping and patient-safety obligations.
4.7 Patient portal and mobile application
Where available, patients may use a SendScript account to view appointments; access records made available to them; receive prescriptions or prescription tokens; access reports and results; communicate with providers; upload documents; manage personal details; receive notifications; book services; and share selected records with an authorised person or healthcare provider.
The availability of particular information depends on the healthcare provider's configuration, applicable law and clinical considerations.
5. When SendScript is a controller and when it is a processor
The term controller refers to an organisation that decides why and how personal information is processed. The term processor refers to an organisation that processes personal information on a controller's documented instructions. Under Indian terminology, similar roles may be described as a Data Fiduciary and Data Processor.
SendScript's role depends on the service and the processing activity.
5.1 When SendScript is normally a controller
SendScript will normally act as a controller for information used to operate the SendScript website; manage SendScript's own business contacts and enquiries; create and administer professional or organisation accounts; manage SendScript subscriptions, contracts and invoices; verify healthcare professionals, clinics, pharmacies or organisations; publish and manage marketplace listings; manage SendScript's direct customer support; protect the platform, investigate misuse and maintain security logs; manage SendScript marketing preferences; administer corporate transactions and legal claims; conduct appropriately anonymised or aggregated service analysis; and comply with SendScript's own legal obligations.
SendScript may also be a controller for parts of a patient account, booking or payment process where SendScript independently determines why and how that information is required.
Annex 5 sets out the lawful basis SendScript relies on for each purpose for which it acts as a controller.
5.2 When SendScript is normally a processor
SendScript will normally act as a processor when a clinic, doctor, hospital, pharmacy, radiology provider or other healthcare organisation uses SendScript to process patient medical records; consultation notes; diagnoses and treatment information; prescriptions; dispensing information; radiology referrals, images or reports; laboratory information; patient communications; clinical documents; appointment information; care-related tasks and workflows; or other patient information entered or generated under that organisation's authority.
In these circumstances the healthcare organisation is normally the controller; the healthcare organisation determines the lawful basis and special-category condition; SendScript processes the information in accordance with the customer's instructions and the applicable agreement; requests concerning the clinical record may need to be referred to the relevant healthcare organisation; and the healthcare organisation determines the applicable clinical-record retention period, subject to law.
5.3 Independent and joint responsibilities
Some services involve more than one controller. For example, SendScript may be responsible for marketplace account administration while a doctor is separately responsible for the clinical consultation. A pharmacy may be responsible for dispensing while SendScript is responsible for operating the prescription-delivery infrastructure.
Where SendScript and another organisation jointly determine a particular processing activity, the parties enter a joint controller arrangement under Article 26 of the UK GDPR allocating their respective responsibilities, and the essence of that arrangement is made available to affected individuals on request.
6. Personal information we collect
The information collected depends on the person, product and service involved.
6.1 Identity information
This may include name; title; date of birth; age; gender or sex where clinically or legally relevant; patient or customer identifier; profile photograph; signature; identity-verification information; passport, driving-licence or other identification information where necessary; relationship to a patient; parental-responsibility or guardianship information; and insurance or membership identifiers.
6.2 Contact information
This may include email address; telephone number; residential, correspondence, billing or delivery address; emergency-contact information; communication preferences; and preferred language.
6.3 Account and authentication information
This may include username; encrypted or securely protected authentication credentials; account type; organisation; assigned role and permissions; multi-factor authentication information; secure PIN events; login dates and times; failed-login information; session information; password-reset activity; and account-status information.
We do not disclose passwords or secure PINs to other users. Credentials should not be shared.
6.4 Health and medical information
This may include symptoms and presenting complaints; medical, surgical, psychiatric, family and social history; diagnoses; allergies and sensitivities; medications; immunisations; clinical observations and measurements; consultation notes; care and treatment plans; laboratory requests and results; imaging requests, images and reports; referral information; prescription and dispensing information; pregnancy or reproductive information where clinically relevant; genetic or biometric information where a service requires it; photographs, recordings or documents supplied for clinical review; correspondence concerning care; consent and capacity information; information concerning disability or support requirements; and other information relevant to healthcare or patient safety.
Health information is special-category personal information under UK law and may constitute sensitive personal data or information under applicable Indian law.
6.5 Prescription and pharmacy information
This may include medication name; formulation and strength; dose; route; frequency; duration; quantity; prescribing instructions; prescription date; prescriber; prescription token or identifier; prescription status; selected pharmacy; dispensing date; quantity dispensed; collection or delivery status; pharmacy notes; and communications concerning clarification, substitution, availability or safety.
6.6 Radiology information
This may include referring provider; clinical indication; requested imaging modality and body area; appointment preferences; safety questionnaire responses; allergy or contrast information; implant, device or previous-procedure information; pregnancy information where relevant; prior imaging information; scan images; imaging metadata; scan reports; radiologist details; report status; urgent findings notifications; and follow-up information.
6.7 Professional and organisation information
For clinicians, pharmacies, radiology providers, clinics, hospitals and staff, this may include job title; professional qualifications; professional registration number; speciality; professional history; organisation and department; work address and contact details; licences, registrations or accreditations; insurance or indemnity information; identity-verification documents; staff role and permissions; signature; prescriber or dispenser identifiers; availability and pricing; contractual and billing information; and public profile information.
6.8 Appointment and communication information
This may include appointment date, time, type and location; booking status; cancellation and non-attendance information; waiting-list information; consultation type; reminders; secure messages; email or SMS delivery status; support correspondence; call records; feedback; survey responses; and complaints.
6.9 Financial and transaction information
This may include billing name and address; invoice information; payment amount; currency; payment status; transaction identifier; refund information; insurer or sponsor details; bank information for professional or organisation payments; and relevant accounting information.
Depending on the payment method, payment-card information may be collected directly by an authorised payment provider. SendScript may receive a payment token, transaction reference or confirmation rather than the full card number or security code.
6.10 Device, technical and usage information
This may include IP address; browser type and version; device type; operating system; application version; language; time zone; device identifiers; approximate location inferred from an IP address; login and session information; pages and features used; links selected; date, time and duration of activity; crash or error information; network and connectivity information; security events; and audit logs.
6.11 Marketplace and review information
This may include search and filter selections; saved providers; enquiries; booking requests; professional profile information; availability; prices; reviews; ratings; responses to reviews; moderation information; and evidence used to verify a profile or review.
6.12 Information about offences, safeguarding or risk
In limited circumstances, a healthcare provider may record information concerning safeguarding; violence or risk; fraud; prescription misuse; professional restrictions; criminal allegations or convictions; or legal proceedings.
Such information is only processed where there is an appropriate legal basis, an appropriate condition under Schedule 1 to the Data Protection Act 2018 where one is required, and a demonstrable operational need.
7. How we obtain personal information
7.1 Directly from you
For example, when you create an account; complete a form; book a service; attend a consultation; upload a document; send a message; make a payment; submit a review; contact customer support; register an organisation; create a professional profile; or provide information at an event or demonstration.
7.2 From healthcare and operational partners
This may include information from doctors and other healthcare professionals; clinics and hospitals; pharmacies; radiology and diagnostic providers; laboratories; insurers or assistance companies; referral organisations; employers where an occupational-health service is lawfully arranged; delivery providers; and payment providers.
7.3 From public and professional sources
For professional verification or marketplace administration, we may consult professional registers; regulator websites; healthcare-provider registers; public company registers; organisation websites; publicly available professional profiles; and other lawful public sources.
7.4 Automatically
Technical information may be collected through cookies; software development kits; server logs; authentication systems; application telemetry; security-monitoring systems; and similar technologies.
8. Why we process personal information
We may process information for the following purposes. Where SendScript acts as a controller, Annex 5 identifies the lawful basis and, for health information, the special-category condition relied on for each purpose.
8.1 Providing and administering the platform
This includes creating accounts; authenticating users; assigning roles and permissions; providing platform functionality; maintaining records; enabling uploads and downloads; delivering notifications; providing customer support; troubleshooting; maintaining availability; and managing subscriptions.
8.2 Facilitating healthcare
This includes arranging consultations; supporting clinical documentation; making patient information available to authorised professionals; facilitating prescriptions; facilitating dispensing; arranging diagnostic appointments; transmitting results and reports; managing referrals; supporting clinical communication; and maintaining a care-related audit trail.
SendScript does not replace the independent clinical judgement of a qualified healthcare professional.
8.3 Operating marketplaces
This includes creating and publishing profiles; verifying professional or organisation information; enabling search and comparison; processing enquiries and bookings; displaying availability and fees; administering reviews; preventing false listings; managing disputes; and analysing marketplace performance.
8.4 Payments and financial administration
This includes processing charges; issuing invoices; managing subscriptions; paying providers; administering refunds; detecting payment fraud; reconciling transactions; collecting amounts due; and meeting accounting and tax obligations.
8.5 Communicating with users
This includes appointment reminders; prescription notifications; report-availability notifications; service messages; security alerts; changes to terms or policies; support communications; complaint handling; operational updates; and marketing where permitted.
8.6 Security, audit and fraud prevention
This includes verifying identity and professional status; monitoring access; maintaining audit logs; detecting suspicious or unauthorised use; preventing fraud; investigating incidents; protecting patients, professionals and organisations; maintaining platform integrity; and establishing, exercising or defending legal claims.
8.7 Improving SendScript
This includes measuring platform performance; resolving errors; understanding feature use; conducting quality assurance; testing changes; developing new functionality; producing aggregated statistics; and improving accessibility and user experience.
Identifiable patient information is not used for unrelated product development merely because it is available. Production data is not copied into development or test environments unless there is a documented necessity, lawful authority and appropriate safeguards, and any such access is recorded in accordance with section 14.2.
8.8 Compliance and public safety
This includes meeting legal and regulatory requirements; responding to valid legal requests; cooperating with regulators; complying with professional and clinical-safety requirements; responding to safeguarding concerns; protecting vital interests in an emergency; and reporting incidents where legally required.
9. UK lawful bases
Where SendScript acts as a controller under UK law, one or more of the following lawful bases may apply. Annex 5 maps these bases to the specific purposes in section 8.
9.1 Contract
Processing may be necessary to provide a service requested by you; administer your account; process a booking or payment; provide a marketplace listing; perform a contract with a healthcare organisation; or take steps at your request before entering a contract.
9.2 Legal obligation
Processing may be necessary to comply with data-protection law; tax and accounting requirements; court orders; regulatory requirements; professional or healthcare requirements; fraud-prevention obligations; or other applicable law.
9.3 Legitimate interests
SendScript may rely on legitimate interests where necessary and proportionate, including to operate and improve the platform; administer business relationships; manage professional profiles; protect platform security; prevent misuse and fraud; maintain appropriate audit records; understand service performance; recover money owed; manage legal claims; and communicate with business contacts.
SendScript carries out and records a legitimate interests assessment before relying on this basis, balancing its interests against the rights, freedoms and interests of the individual. A summary of the relevant assessment is available on request to privacy@sendscript.com.
9.4 Recognised legitimate interests
Where the statutory conditions in Annex 9 to the UK GDPR are met, SendScript may rely on a recognised legitimate interest for an eligible purpose, such as preventing crime, safeguarding vulnerable individuals or responding to an emergency.
SendScript does not rely on this basis for routine commercial security monitoring or product analytics. Those activities are carried out under the ordinary legitimate interests basis in section 9.3, with a balancing assessment.
9.5 Vital interests
Information may be processed where necessary to protect someone's life or physical safety, particularly where the individual is unable to provide consent.
9.6 Public task
A healthcare customer may rely on public-task grounds where it is exercising an official function. SendScript does not rely on public task for its own processing.
9.7 Consent
Consent may be used for optional processing, such as certain marketing communications; optional cookies; an optional recording; an optional sharing function; publication of information not otherwise required; or another specific use for which genuine choice is available.
Consent may be withdrawn at any time, and withdrawing it is as easy as giving it. To withdraw consent, use the relevant control in your account, the unsubscribe link in a marketing message, or email privacy@sendscript.com. Withdrawal does not affect processing already carried out lawfully before withdrawal.
10. Health information and other sensitive information
10.1 UK special-category conditions
Where SendScript acts as a controller for health information, it must have both an Article 6 lawful basis and an Article 9 condition, together with any condition required under Schedule 1 to the Data Protection Act 2018.
Depending on the circumstances, the Article 9 condition may include health or social care, where processing is necessary for medical diagnosis, treatment, care or management of health services and the legal requirements concerning professional secrecy or confidentiality are met; explicit consent, for a specific optional use; vital interests, where the person is physically or legally incapable of giving consent; legal claims, where necessary to establish, exercise or defend a claim; substantial public interest, where an applicable statutory condition is satisfied; public health, where the legal requirements apply; or research or statistical purposes, where the applicable safeguards and legal conditions are satisfied.
SendScript does not assume that a health-data condition applies simply because the platform is used in healthcare. Where a condition in Part 1 or Part 2 of Schedule 1 to the Data Protection Act 2018 is relied on, SendScript maintains the appropriate policy document that legislation requires.
Where SendScript is a processor, the healthcare customer is responsible for identifying the relevant Article 6 basis and Article 9 condition. SendScript processes the information under the customer's instructions.
10.2 Professional confidentiality
Health information may be accessed by authorised healthcare professionals; authorised members of the relevant healthcare organisation; SendScript personnel with an operational need; approved service providers acting under confidentiality and data-processing obligations; and other recipients authorised by the patient, controller or law.
Access does not permit a person to use health information for personal, unrelated or unauthorised purposes. SendScript personnel are bound by contractual confidentiality obligations, access is role-based and logged, and misuse is treated as a disciplinary matter.
10.3 Indian sensitive information
While applicable Indian requirements remain in force, medical records, health information, financial information, passwords and certain biometric information may be treated as sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011.
SendScript applies reasonable security and confidentiality safeguards to such information and is implementing the DPDP framework as the relevant provisions commence, on the timetable described in section 3.
11. Product-specific processing
11.1 Telemedicine
For telemedicine, we may process identity and contact information; appointment information; clinical forms; live audio and video transmission; connection and device information; messages; clinical notes; uploaded documents; prescriptions; referrals; payment information; and follow-up communications.
Audio and video content is not routinely recorded by default. Technical information needed to connect, secure and troubleshoot the consultation may be logged.
The treating healthcare professional is responsible for the clinical consultation, diagnosis, advice, treatment and medical record.
11.2 EMR
For the EMR, SendScript processes information entered, uploaded, received or generated by the healthcare customer and its authorised users. SendScript does not independently decide what should be written in an individual patient's clinical record.
Access to an EMR is controlled through user accounts, roles and permissions configured by or for the healthcare organisation.
11.3 Radiology
For radiology, information may be shared between the patient; referring clinician; referring organisation; scan provider; radiologist; authorised administrative personnel; payment or insurance provider where applicable; and technical providers necessary to deliver reports or images.
The scan provider and reporting radiologist remain responsible for their clinical and regulatory duties.
11.4 Electronic prescriptions
Prescription information may be made available to the patient; the prescriber; authorised members of the prescriber's organisation; the pharmacy selected or authorised to dispense; authorised pharmacy staff; delivery providers where delivery is requested and permitted; and regulators or authorities where legally required.
A prescription token is confidential and should be treated in the same way as any other secure credential. SendScript applies verification and security controls before a prescription can be accessed and dispensed.
The patient receives the prescription token through the SendScript patient application and by email. When presenting the token to a pharmacy, the patient must also provide their date of birth as an additional verification detail. The pharmacy enters the prescription token, the patient’s date of birth and the pharmacy’s details into the SendScript system.
Once the information has been verified, the pharmacy can securely view and download the prescription for dispensing. When the prescription is dispensed, its status is updated within SendScript and the prescribing clinician is notified that the prescription has been dispensed.
Each prescription token is single-use and cannot be used again after the prescription has been dispensed. SendScript maintains an audit trail for each prescription, including the prescription ID, token activity, pharmacy details and dispensing status.
These controls reduce, but do not entirely eliminate, the risk of unauthorised access. Patients must not share, forward, publish or otherwise disclose their prescription token or verification information to anyone other than the pharmacy dispensing the prescription. If you believe that a prescription token has been disclosed to someone who should not have access to it, contact us immediately at privacy@sendscript.com so that the token can be reviewed and, where appropriate, cancelled.
11.5 Pharmacy
The pharmacy is responsible for verifying prescriptions; determining whether dispensing is lawful and clinically appropriate; counselling the patient; maintaining required dispensing records; fulfilling professional obligations; and managing medicine collection or delivery.
SendScript may maintain status and audit information showing which pharmacy accessed or dispensed a prescription.
11.6 Marketplace
When you contact or book a provider through a marketplace, SendScript may provide the provider with information necessary to respond or fulfil the booking; the provider will normally become an independent controller of information it receives; the provider's own privacy notice will apply to its healthcare service; SendScript may retain booking, transaction and communication information for administration, safety and dispute management; and public profile information may remain visible until the profile is removed or suspended.
12. Sharing personal information
We may share personal information with the following categories of recipient where necessary and lawful.
12.1 Healthcare providers
This may include doctors; nurses; pharmacists; radiologists; diagnostic professionals; clinics; hospitals; pharmacies; scan centres; laboratories; and other professionals involved in care.
12.2 Organisations using SendScript
Information may be accessible to authorised administrators and staff of the organisation responsible for the relevant account or patient record.
12.3 Service providers
We may use service providers for cloud hosting; data storage and backup; communications; video connectivity; email and SMS delivery; payment processing; customer support; identity and professional verification; cybersecurity; error monitoring; analytics; document processing; and professional advice.
Service providers are selected and managed in accordance with applicable data-protection requirements. Where they act as processors, they process information only for agreed purposes and under a written contract meeting the requirements of Article 28 of the UK GDPR.
12.4 Payment and financial organisations
Information may be shared with payment processors; acquiring banks; financial institutions; fraud-prevention services; insurers; and accounting providers.
12.5 Delivery providers
Where medicine, a test kit, a document or another item is delivered, necessary information may be shared with a delivery or logistics provider.
Delivery providers do not receive clinical information that is unnecessary for delivery.
12.6 Regulators, courts and public authorities
Information may be disclosed where required or permitted by law, including to courts; law-enforcement bodies; data-protection authorities; healthcare or pharmacy regulators; safeguarding bodies; tax authorities; and other competent authorities.
SendScript assesses the validity and scope of a request before disclosure unless prohibited from doing so.
12.7 Professional advisers
Information may be shared with legal advisers, auditors, insurers, consultants or other professional advisers where necessary and subject to confidentiality obligations.
12.8 Corporate transactions
Information may be disclosed in connection with an investment; financing; reorganisation; sale; merger; acquisition; transfer of assets; or insolvency process.
Only information reasonably necessary for the transaction is disclosed, and appropriate confidentiality and data-protection safeguards are applied.
12.9 With your direction or authorisation
Information may be shared where you ask us to send a record to a provider; share a prescription with a pharmacy; invite a family member or representative; generate a sharing link; provide information to an insurer; or otherwise make information available to a nominated person.
You should verify the recipient before sharing information.
SendScript does not sell personal information, and does not share personal information with third parties for their own independent marketing purposes.
13. Marketplace profiles, public information and reviews
Information placed in a public professional or organisation profile may be viewed by anyone.
Before publishing information, a professional or organisation must ensure that it is accurate; it is not misleading; it does not breach patient confidentiality; it does not include unnecessary personal information; and it complies with professional advertising requirements.
Reviews must not include another person's confidential medical information; prescription tokens; contact details; threatening or unlawful content; or information that the reviewer has no right to disclose.
Reviews must be genuine and must reflect the reviewer's own experience. SendScript does not publish, commission or incentivise fake reviews and does not permit providers to do so. Reviews are moderated against these requirements.
SendScript may review, restrict, redact or remove content where reasonably necessary to protect privacy, safety, platform integrity or legal rights.
SendScript may retain moderation information and previous versions where needed to investigate misuse or defend a legal claim.
14. International transfers and access from India
14.1 Regional data hosting
SendScript's data-hosting arrangements are designed around regional data residency.
Unless otherwise agreed in writing for a particular customer or service, UK production patient data is hosted in the United Kingdom, and India production patient data is hosted in India.
A specific customer agreement, integration or service may require a different arrangement. Where this occurs, the arrangement is assessed and documented before it is implemented.
14.2 India-based SendScript team
SendScript has team members in India who form part of Sendscript Technologies Limited.
India-based personnel do not have routine, unrestricted access to identifiable UK production patient information.
Their normal development and testing activities use synthetic data, anonymised information, or appropriately pseudonymised information.
Where exceptional access to identifiable production information is genuinely necessary for an authorised support, security or incident-management purpose, access is approved; limited to the minimum information required; role-based; time-limited where practicable; authenticated; logged and monitored; subject to confidentiality requirements; and covered by an appropriate international-transfer mechanism where required.
14.3 UK restricted transfers
Remote access from India to UK personal information may constitute an international restricted transfer even where the individual accessing the information works for the same company.
Where UK law requires a transfer safeguard, SendScript uses a UK adequacy regulation or data bridge; the UK International Data Transfer Agreement; the UK Addendum to the EU Standard Contractual Clauses; binding corporate rules, where applicable; or another legally recognised mechanism.
India is not currently the subject of UK adequacy regulations. Transfers to and access from India therefore rely on the International Data Transfer Agreement or the UK Addendum, supported by a transfer risk assessment.
SendScript carries out a transfer risk assessment to establish whether the protection for the information would be materially lower following the transfer, and applies supplementary safeguards where appropriate. A copy of the relevant assessment is available to business customers on request.
14.4 Transfers from India
Personal information processed in India may be transferred outside India subject to applicable law; the relevant customer agreement; patient or user notices; security requirements; sector-specific restrictions; and any general or special restriction issued by the Government of India.
Rule 15 of the Digital Personal Data Protection Rules 2025 permits transfers outside India subject to any restrictions the Central Government specifies. That rule is subject to the phased commencement described in section 3.
14.5 Other international providers
Some approved service providers may process information in another country.
Before using such a provider, SendScript assesses the country of processing; the type and sensitivity of the information; the provider's role; contractual protections; access controls; onward transfers; government-access risk; deletion arrangements; and applicable transfer requirements.
15. Data security
SendScript maintains technical and organisational measures designed to protect personal information against accidental loss; unauthorised access; unlawful use; alteration; destruction; unauthorised disclosure; and loss of availability.
Depending on the service, risk and configuration, these measures may include encryption in transit; encryption at rest where appropriate; role-based access controls; least-privilege permissions; multi-factor authentication; password and credential controls; secure PIN controls; audit logging; monitoring and alerting; development, test and production separation; use of synthetic or pseudonymised development data; backup and recovery arrangements; secure software-development practices; vulnerability assessment; security testing; patching and change management; supplier assessment; staff confidentiality obligations; privacy and security training; incident-response procedures; and business-continuity planning.
Security measures are reviewed according to risk and changes in the platform.
No internet, video, email, storage or electronic-communication system can be guaranteed to be completely secure. Users must also protect their devices, passwords, PINs, tokens and accounts.
15.1 User security responsibilities
You should use a strong and unique password; enable multi-factor authentication where available; keep prescription and sharing tokens confidential; sign out of shared devices; keep your contact details current; report suspicious activity promptly; not share professional accounts; not download patient information to unauthorised devices; and comply with your organisation's security requirements.
15.2 Personal-data incidents
Where SendScript becomes aware of a personal-data incident, it will, without undue delay, investigate; take proportionate containment and remediation measures; preserve relevant evidence; inform the relevant controller where SendScript is a processor; and notify a regulator or affected individual where SendScript is legally required to do so.
Where SendScript is a controller and a personal data breach is notifiable, it notifies the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, and notifies affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Where SendScript is a processor, it notifies the relevant controller without undue delay after becoming aware of the breach. Separate reporting obligations apply in India as the relevant provisions of the Digital Personal Data Protection Rules 2025 come into force.
16. Data retention
SendScript retains personal information only for as long as it is reasonably needed for the relevant purpose, subject to legal, regulatory, contractual and clinical-record requirements.
Retention is determined by considering the purpose of the processing; the nature and sensitivity of the information; patient-safety requirements; the healthcare provider's instructions; applicable record-management guidance; legal limitation periods; tax and accounting requirements; regulatory obligations; dispute or complaint requirements; security needs; and whether the information can be anonymised.
Annex 4 summarises the retention approach applied to each category of information.
16.1 Clinical records
Clinical records held in an EMR, pharmacy or radiology service will normally be retained according to the healthcare controller's documented retention schedule; applicable healthcare and professional requirements; relevant health-record guidance; patient-safety requirements; and the applicable contract.
Closing a SendScript account does not necessarily require deletion of the clinical record.
A right-to-erasure request may not apply where the information must be retained for healthcare, legal, regulatory, public-interest or legal-claims purposes. Health-record retention is governed by a documented schedule and periodic review.
16.2 Business and transaction records
Contracts, invoices, payment records and related business information may be retained for the applicable accounting, tax, audit and legal limitation periods.
16.3 Marketplace information
A professional or organisation profile may be retained while the account or listing is active.
After deactivation, information may be retained where necessary for transaction records; complaint handling; fraud prevention; professional verification; contractual enforcement; or legal claims.
Public visibility will normally cease before all underlying administrative records are deleted.
16.4 Support and communications
Support requests and communications may be retained for as long as necessary to resolve the request; improve support; evidence instructions; investigate a complaint; maintain safety; or defend a legal claim.
16.5 Security and audit information
Security logs, login records and audit histories may be retained according to a defined security and compliance schedule.
Clinical audit entries may need to remain linked to the clinical record to preserve record integrity.
16.6 Backups
Information may remain in secure backups for a limited period after deletion from the active system.
Backup information is protected and is not restored for ordinary operational use after a valid deletion unless required for recovery, security or law.
16.7 Deletion, return and anonymisation
At the end of a business customer contract, patient information will be returned; made available for export; retained for an agreed transition period; deleted; or handled in another agreed manner, in accordance with the contract and applicable law.
17. Accuracy and correction of clinical records
Users should keep their identity and contact information accurate.
A request to correct factual information in a clinical record does not necessarily permit the original entry to be erased or overwritten.
Healthcare records may need to preserve the original entry; the identity of the author; the date and time; the correction or addendum; the reason for the amendment; and an audit history.
Clinical opinions may not be inaccurate merely because a patient disagrees with them. A patient may be able to request that a note of disagreement or additional context be added.
Where SendScript is a processor, requests to amend clinical information will normally be referred to the healthcare controller.
18. Children and young people
SendScript's general professional and organisation services are intended for adults.
Healthcare services may be provided to children or young people where this is lawful and clinically appropriate.
Information concerning a child may be provided by a parent; a person with parental responsibility; a legal guardian; an authorised healthcare professional; or the child, where the child has sufficient legal capacity and understanding under applicable law.
18.1 UK children
In the United Kingdom, where SendScript relies on consent to offer an information society service directly to a child, section 9 of the Data Protection Act 2018 sets the minimum age for that consent at 13. A child below that age can only give consent through a person holding parental responsibility.
SendScript's minimum age for holding a patient portal account in the United Kingdom is 16 years of age. Below that age, a patient's information is accessed through an account held by a parent, a person with parental responsibility or a legal guardian, subject to the treating provider's configuration and clinical judgement.
The legal rules for a child's healthcare information are not determined solely by the age used for consent to online services.
A healthcare provider must consider parental responsibility; the child's maturity and understanding; capacity or competence; confidentiality; safeguarding; best interests; and applicable healthcare law and professional guidance.
18.2 India children
Under the Indian DPDP framework, a child is generally a person under 18.
Where the relevant provisions apply, verifiable parental consent may be required unless an applicable statutory exemption applies.
The DPDP Rules include limited healthcare-related exceptions for processing by clinical establishments and healthcare professionals where processing is restricted to health services necessary to protect the child's health.
18.3 Safeguards
When processing children's information, SendScript and the relevant provider will collect only necessary information; use age-appropriate privacy information where appropriate; restrict access; avoid unnecessary profiling or marketing; protect location and contact information; verify the authority of an adult where necessary; and prioritise the child's safety and interests.
SendScript takes account of the ICO's Age Appropriate Design Code where its services are likely to be accessed by children in the United Kingdom.
19. Automated processing, algorithms and artificial intelligence
SendScript may use automation to route notifications; identify incomplete fields; display results; mark values against supplied reference ranges; prioritise administrative tasks; detect suspicious access; generate summaries or drafts; support searching and workflow management; and help professionals review information.
A reference-range marker, generated summary, draft note, suggested workflow or similar output is a support tool; may be incomplete or inaccurate; does not replace the source record; does not itself constitute a diagnosis; must not replace professional judgement; and is required to be reviewed by an appropriately qualified person before it is used in clinical care.
SendScript does not make clinical decisions producing legal or similarly significant effects solely through automated processing without appropriate human involvement.
Where a materially significant solely automated decision is introduced, users will be given appropriate information; an applicable lawful basis will be identified; special-category restrictions will be considered; appropriate safeguards will be implemented; and rights to human review or challenge will be provided where required under Articles 22A to 22D of the UK GDPR.
Where SendScript uses a third-party artificial intelligence provider to deliver a feature, that provider acts as a processor under a written contract and is not permitted to use SendScript data to train its own general-purpose models.
20. Anonymised, aggregated and pseudonymised information
20.1 Anonymised information
Information is anonymised only where individuals are no longer identifiable by reasonably available means.
Genuinely anonymised information may be used for service statistics; capacity planning; performance analysis; security analysis; product improvement; business reporting; and research or innovation.
SendScript does not attempt to re-identify genuinely anonymised information.
20.2 Aggregated information
Aggregated information may include statistics such as appointment volumes; prescription-status totals; scan-booking trends; platform performance; usage by service type; or marketplace demand.
Outputs are structured to reduce re-identification risk.
20.3 Pseudonymised information
Pseudonymised information remains personal information where it can be linked back to an individual using additional information. It continues to receive data-protection safeguards.
20.4 Research
Identifiable health information is not used for an unrelated research project merely because it is stored on SendScript.
Research involving identifiable or pseudonymised information must have a defined purpose; an appropriate lawful basis and condition; necessary approvals; data-minimisation measures; appropriate transparency; access controls; and contractual and ethical safeguards where applicable.
21. Marketing and communications
21.1 Service communications
SendScript may send communications necessary to provide or administer a service, including account verification; security alerts; appointment reminders; prescription notifications; report notifications; support responses; payment information; operational updates; and changes to terms or policies.
These are not marketing communications, and you cannot opt out of them while you hold an account or are receiving a service.
21.2 Marketing
Where lawful, SendScript may send information about SendScript products; new features; professional services; events; educational material; or relevant offers.
Electronic marketing is sent in accordance with applicable data-protection and electronic-communications law, including the Privacy and Electronic Communications (EC Directive) Regulations 2003.
SendScript obtains consent where it is required. Where SendScript relies on the soft opt-in for existing customers, it does so only for its own similar products and services, and an opt-out is offered in every message.
21.3 Opting out
You may opt out by using the unsubscribe option in a marketing message; changing available communication preferences; or emailing privacy@sendscript.com.
Opting out of marketing does not stop essential service, safety, account, prescription or contractual communications.
21.4 Marketing involving health information
SendScript does not use identifiable health information to infer sensitive marketing interests or target advertising without a specific lawful basis and any required explicit consent.
SendScript does not sell patient health information to advertisers.
22. Cookies and similar technologies
SendScript may use cookies and similar technologies for secure login; authentication; session management; fraud prevention; remembering preferences; platform functionality; performance monitoring; analytics; and marketing where permitted.
A full list of the cookies used, their purpose and their duration is set out in our Cookie Policy at www.sendscript.com/cookie-policy. You can change your choices at any time using the cookie preferences control on our website.
22.1 Essential technologies
Essential technologies may be used where necessary to provide a service requested by the user; secure an account; maintain a session; remember privacy choices; process a payment; or protect the platform.
22.2 Analytics and functional technologies
SendScript may use analytics or functional technologies to understand and improve the service.
Consent is requested where it is legally required. The Data (Use and Access) Act 2025 introduced a limited exemption from the consent requirement for certain statistical and functionality purposes, provided clear information and an opt-out are given. Where SendScript relies on that exemption, it gives that information and that opt-out.
22.3 Advertising technologies
Advertising or cross-site tracking technologies are not placed without consent where consent is legally required.
Further detail is set out in the Cookie Policy and in the consent-management interface on our website.
23. Your rights in the United Kingdom
Depending on the circumstances and applicable exemptions, you may have the right to be informed about processing; request access to personal information; request correction; request erasure; request restriction; object to processing; request data portability; withdraw consent; object to direct marketing; request safeguards concerning significant automated decisions; complain to SendScript under section 25; and complain to the UK data-protection regulator.
These rights are not absolute.
For example, clinical information may need to be retained for patient safety; healthcare provision; professional obligations; legal claims; regulatory requirements; or public-interest reasons.
23.1 How to exercise a right
Email privacy@sendscript.com with your name; account email or other identifier; the organisation or healthcare provider involved; the right you wish to exercise; the information or period concerned; and any other detail that will help locate the information.
23.2 Identity verification
We may request proportionate information to verify your identity; your authority to act for another person; and the scope of the request.
This is intended to prevent information being disclosed to an unauthorised person.
Where we need further information to identify you or to clarify the scope of your request, the statutory response period is paused until you provide it.
23.3 Requests concerning healthcare-customer records
Where SendScript is a processor, we may refer the request to the healthcare controller; ask you to contact that organisation directly; or assist the healthcare controller in responding.
SendScript cannot independently delete or alter a controller's clinical record contrary to the controller's lawful instructions.
Where we refer your request to a healthcare controller, we tell you who that organisation is and how to contact it.
23.4 Response time and fees
Requests are handled without undue delay and in any event within one month of receipt.
That period may be extended by up to two further months where the request is complex or where we have received a number of requests from you. If we extend the period, we tell you within one month of receiving your request and explain why. Our searches in response to an access request are those that are reasonable and proportionate. We do not charge a fee for handling a request. Where a request is manifestly unfounded or excessive we may charge a reasonable fee to cover our administrative costs, or refuse to act on the request, and we will explain our reasons and your right to complain.
24. Rights and grievances in India
To the extent applicable under current Indian law and as relevant DPDP provisions come into force, individuals may be able to obtain information about the processing of their personal data; request correction, completion or updating; request erasure where retention is no longer lawful or necessary; withdraw consent; raise a grievance; nominate another person to exercise rights in the event of death or incapacity; and complain to the Data Protection Board of India where the statutory route is available.
A request may be sent to the Grievance Officer stated in section 2.2, or to privacy@sendscript.com.
The request should include enough information to identify the relevant account, service and organisation.
Where another healthcare organisation is the Data Fiduciary or controller, SendScript may refer the request to that organisation.
SendScript operates a grievance-redress process. While the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 apply, the Grievance Officer named in section 2.2 addresses a grievance within one month of receipt. When Rule 13 of the Digital Personal Data Protection Rules 2025 comes into force, SendScript will respond to grievances within the period it specifies, which may not exceed 90 days.
25. Privacy complaints
We take privacy complaints seriously.
If you consider that SendScript has infringed your data protection rights, you can complain to us directly. You do not need to use any particular form of words, and you do not need to refer to any legislation.
A complaint can be made:
- by email to privacy@sendscript.com, marked "Privacy Complaint"; or
- by post to Sendscript Technologies Limited, 116 Harley Street, 3rd Floor, London W1G 7JL, United Kingdom.
Please include your name and contact information; the account or organisation involved; a clear description of the concern; relevant dates; any supporting information; and the outcome you are seeking.
We will:
- acknowledge your complaint within 30 days of receiving it;
- investigate the complaint without undue delay, making enquiries that are reasonable and proportionate to the issues raised;
- request additional information where needed;
- keep you informed of progress and of any anticipated delay;
- respond with the outcome without undue delay; and
- explain any escalation route available.
These commitments reflect section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025, which came into force on 19 June 2026 and requires controllers to provide a route for data protection complaints, acknowledge them within 30 days of receipt, investigate them without undue delay and communicate the outcome.
25.1 UK regulator
You may complain to the UK data protection regulator at any time. You are encouraged, but not required, to contact SendScript first so that we have an opportunity to investigate.
The UK supervisory authority is the Information Commissioner's Office:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Under Part 6 of the Data (Use and Access) Act 2025 the Information Commissioner's Office is to be replaced by a new body, the Information Commission. At the date of this Privacy Policy the transfer of functions has not been commenced and the Information Commissioner's Office remains the supervisory authority. This Privacy Policy will be updated when the transfer takes effect.
25.2 India regulator
Where the relevant provisions and complaint routes are operational, an individual in India may be able to complain to the Data Protection Board of India after using the applicable grievance-redress process described in section 24.
26. Third-party websites and services
SendScript may link to websites, applications, payment pages, maps, professional registers, pharmacies, clinics or other third-party services.
SendScript is not responsible for a third party's independent privacy practices.
You should review the third party's privacy information before providing personal information.
The presence of a link does not mean that SendScript controls or endorses all of the third party's processing.
27. Business-customer responsibilities
A healthcare organisation using SendScript is responsible for identifying its lawful bases; issuing appropriate privacy information; determining who may access its records; maintaining accurate user accounts and permissions; configuring the platform appropriately; ensuring staff are authorised and trained; complying with clinical and professional requirements; responding to patient-rights requests; determining record-retention periods; reporting incidents to SendScript promptly; ensuring information entered into SendScript is lawful and relevant; managing integrations and data exports; entering an appropriate data-processing agreement; and ensuring it has authority to instruct SendScript.
Healthcare customers must not allow staff to share accounts; use production patient data for unauthorised testing; upload information unrelated to healthcare or the agreed service; access records without a professional or operational need; disclose prescription or sharing tokens improperly; or instruct SendScript to process information unlawfully.
28. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law; changes in the platform; new products; new data flows; changes in suppliers; changes in international arrangements; or improvements in privacy practices.
The updated version will display a revised version number and effective date.
Where a change materially affects how personal information is processed, we will provide an additional notice through the website; the application; email; the relevant healthcare organisation; or another appropriate communication method, in advance of the change taking effect where it is practicable to do so.
Historic versions may be requested by contacting privacy@sendscript.com.
29. Contacting SendScript
Questions, requests and complaints may be sent to:
Sendscript Technologies Limited, 116 Harley Street, 3rd Floor, London W1G 7JL, United Kingdom
Email: privacy@sendscript.com
Website: www.sendscript.com
General enquiries that are not about privacy may continue to be sent to support@sendscript.com.
Please use "Privacy Request" or "Privacy Complaint" in the subject line, as appropriate.
Annex 1 — Summary of role allocation
| Activity | SendScript's usual role | Other organisation's usual role |
|---|---|---|
| SendScript website and enquiries | Controller | Not applicable |
| SendScript business subscriptions and invoicing | Controller | Customer is controller of its own contact information |
| Professional account and marketplace profile | Controller | Professional or organisation is controller of the information it separately receives |
| Public provider listing | Controller for publication and marketplace administration | Provider responsible for accuracy and professional compliance |
| Patient clinical record in customer EMR | Processor | Clinic, doctor, hospital or other provider is controller |
| Telemedicine consultation | Processor for clinical content in most hosted arrangements; controller for limited platform and security data | Treating provider is controller for care |
| Radiology referral and report | Processor in most hosted arrangements | Referrer and imaging provider may each be controllers for their functions |
| Electronic prescription | Processor in most hosted arrangements; controller for limited platform and security administration | Prescriber and dispensing pharmacy are controllers for their professional functions |
| Pharmacy dispensing record | Processor where hosted for pharmacy | Pharmacy is controller |
| Patient portal | Role depends on data and configuration | Healthcare provider remains controller of its clinical record |
| Marketplace booking | Controller for booking administration where independently determined | Provider is controller for healthcare delivery |
| Platform security and fraud prevention | Controller for SendScript's own security obligations | Customer is controller for its own internal security and users |
| Customer support | Controller for SendScript account support; processor where support content relates to a customer-controlled patient record | Customer remains controller of patient information |
| Payment processing | Controller for transaction administration | Payment provider may be an independent controller or processor depending on the service |
The actual role is determined by the facts, contract and applicable law, rather than solely by this table.
Annex 2 — Product data summary
| Service | Main information processed | Typical recipients |
|---|---|---|
| Telemedicine | Identity, appointment, clinical forms, messages, live video and audio transmission, notes, uploads and connection data | Patient, clinician, clinic and technical communication providers |
| EMR | Demographics, history, notes, diagnoses, medication, allergies, results, documents, tasks and audit logs | Authorised healthcare-organisation users |
| Radiology | Referral, indication, safety information, appointment, images, reports, status and billing | Patient, referrer, scan provider, radiologist and authorised staff |
| Electronic prescription | Patient, prescriber, medicine, dose, directions, token, pharmacy and dispensing status | Patient, prescriber, selected pharmacy and authorised staff |
| Marketplace | Search, profile, availability, fees, booking, messages, reviews and transactions | User, provider, SendScript support and payment providers |
| Pharmacy platform | Prescription, patient, dispensing, collection or delivery and audit information | Pharmacy staff, prescriber, patient and authorised delivery provider |
| Patient portal | Account, appointments, reports, prescriptions, uploads, messages and sharing activity | Patient and authorised healthcare providers |
Annex 3 — Subprocessor and partner transparency
SendScript uses service providers in the following categories, each of which may process personal information on our behalf: cloud hosting; database and backup; communication and video connectivity; email and SMS delivery; payment processing; customer support; security monitoring; analytics; document processing; professional verification; and radiology or interoperability services.
A current list of the subprocessors used for each service is also available on request to privacy@sendscript.com.
For business customers, the applicable data processing agreement identifies the subprocessors used for that customer's services and sets out the notice period for any material change, together with the customer's right to object.
SendScript does not name an individual provider in this Privacy Policy. Naming providers here rather than in a separately maintained list would make the Privacy Policy inaccurate every time a supplier changed. The published list is the authoritative record.
Annex 4 — Retention framework
| Information type | General retention approach |
|---|---|
| Clinical and patient records | According to controller instructions, applicable healthcare requirements and patient-safety needs. Where SendScript is a processor, the healthcare controller sets the schedule. |
| Prescriptions and dispensing records | According to applicable prescriber, pharmacy and legal record-keeping requirements. |
| Radiology requests, images and reports | According to applicable healthcare-provider retention requirements and contract. |
| Account information | While the account is active and thereafter for legitimate administration, security or legal requirements. |
| Contracts, invoices and transactions | For applicable accounting, tax, audit and legal periods. |
| Marketplace profiles | While active, followed by limited retention for disputes, fraud prevention and legal claims. |
| Reviews and moderation records | While published and thereafter where necessary for moderation, complaints or legal claims. |
| Marketing information and preferences | Marketing preferences, including any objection or opt-out, are retained for as long as necessary to give effect to your choice. A record that you have opted out is kept indefinitely so that we do not contact you again in error. Other marketing information is reviewed periodically and deleted when it is no longer needed. |
| Support requests and communications | Retained for as long as necessary to resolve the request and thereafter for complaint handling, safety and legal claims, in accordance with section 16.4. |
| Consent and cookie preference records | Retained for as long as needed to evidence the choice made and to comply with the accountability principle. |
| Security logs, access logs and audit histories | Retained in accordance with SendScript's documented security and compliance schedule. Clinical audit entries remain linked to the clinical record for as long as that record is retained, to preserve its integrity. |
| Data protection rights requests and complaints | Retained for as long as necessary to handle the matter and thereafter for the applicable limitation period, so that SendScript can demonstrate compliance. |
| Backups | Retained for a limited period in accordance with section 16.6, after which deleted information is removed from backup media in the ordinary backup cycle. |
Where a category is not listed, retention is determined by applying the criteria in section 16.
Annex 5 — Purpose to lawful basis mapping
This Annex applies only where SendScript acts as a controller. Where SendScript acts as a processor, the healthcare organisation identifies the lawful basis and, for health information, the special-category condition. The Article 9 conditions listed below are the conditions SendScript expects to rely on; several also require a condition under Schedule 1 to the Data Protection Act 2018 and an appropriate policy document, which SendScript maintains.
| Purpose (section 8) | Article 6 basis | Article 9 condition where health information is involved | Notes |
|---|---|---|---|
| Creating and administering accounts, authentication, roles and permissions (8.1) | Contract; legal obligation for record-keeping | Not ordinarily applicable | Account data is not health data |
| Providing platform functionality and support (8.1) | Contract | Not ordinarily applicable, unless a support request contains health information | Where a support ticket contains health information, SendScript acts as a processor for that content |
| Facilitating healthcare where SendScript is a controller (8.2) | Legitimate interests | Health or social care purposes | In most hosted arrangements SendScript is a processor and this row does not apply |
| Operating marketplaces, publishing and verifying profiles (8.3) | Contract with the provider; legitimate interests in verification and integrity | Not ordinarily applicable | Professional data, not patient health data |
| Processing bookings and enquiries (8.3) | Contract; steps taken at your request before a contract | Explicit consent where a booking discloses a health condition | Only the minimum information needed to route the booking is used |
| Payments, invoicing and financial administration (8.4) | Contract; legal obligation under tax and accounting law | Not ordinarily applicable | Fraud checks rely on legitimate interests |
| Service and transactional communications (8.5) | Contract | Health or social care purposes where the message concerns care | Not marketing |
| Direct marketing (8.5, 21.2) | Consent, or legitimate interests where the soft opt-in applies | Not applicable. SendScript does not use health information for marketing | Opt-out in every message |
| Security, access monitoring, audit logging and fraud prevention (8.6) | Legitimate interests; legal obligation under Article 32 | Preventive or occupational medicine and health or social care purposes, where security logs relate to clinical systems | Recognised legitimate interests is relied on only for crime prevention, safeguarding and emergencies |
| Service improvement, quality assurance and testing (8.7) | Legitimate interests | Not applicable. Identifiable health information is not used for this purpose | Synthetic, anonymised or pseudonymised data is used |
| Compliance, regulatory cooperation and legal requests (8.8) | Legal obligation | Legal claims; substantial public interest where a Schedule 1 condition applies | Each request is assessed before disclosure |
| Safeguarding and emergency response (8.8) | Vital interests; recognised legitimate interests where the statutory conditions are met | Vital interests; substantial public interest for safeguarding, where the Schedule 1 condition applies | Used only where necessary to protect a person |
| Establishing, exercising or defending legal claims (8.6) | Legitimate interests | Legal claims | Includes retention beyond ordinary periods where a claim is anticipated |
| Corporate transactions (12.8) | Legitimate interests | Not applicable. Identifiable patient records are not disclosed for this purpose | Only information reasonably necessary is disclosed |
SendScript records a legitimate interests assessment for each purpose relying on legitimate interests, and a data protection impact assessment where processing is likely to result in a high risk to individuals.