Privacy Notice
Last updated 18 August 2026
We build software that helps hospitals recover outpatient appointment capacity that would otherwise go unused. This notice explains what we do with personal information, why, and what rights you have.
If anything here is unclear, write to us and we will explain it.
1. Who we are
Deep-Medical Ltd is registered in England and Wales under company number 13242918, at 1 Primrose Street, London, EC2A 2JN. We are registered with the Information Commissioner's Office under number ZB228006.
2. Our role, and what this notice covers
Data protection law separates the organisation that decides why personal information is used, the controller, from the organisation that handles it on the controller's instructions, the processor. We are both, in different situations, and the difference matters.
This notice covers the situations where we are the controller. That is the information we hold about people who visit our website, contact us, work for our customers or suppliers, or apply for jobs with us.
This notice does not govern how patient information is used. When a hospital or health system uses our software, that organisation decides why patient information is used and remains accountable for it. We handle it only on their documented instructions, under a written contract. Section 6 explains what we do in that role.
If you are a patient and you want to know how your information is used, the right place to look is your hospital's own privacy notice. Your hospital holds your record and is the organisation that can answer questions about it.
3. What we collect, why, and how long we keep it
We do not seek information about your health, race, religion, sexual orientation, political opinions or trade union membership. If you tell us something like an access requirement for a meeting, we use it only for that purpose.
Where a complaint or legal claim is in prospect, we may keep relevant information for longer.
4. Marketing
We may contact you about our work, our research and our events, where you have asked us to or where you work for an organisation we reasonably believe has a professional interest in it. Our lawful basis is our legitimate interest in promoting our services to relevant organisations, and we comply with the Privacy and Electronic Communications Regulations.
Every marketing email includes a way to unsubscribe. You can also tell us to stop at any time by writing to privacy@deep-medical.ai. We will act on that promptly, and keep a minimal record so that we do not contact you again by mistake.
We do not sell or rent your details.
5. Cookies
Cookies that are strictly necessary for this site to work are set automatically. Everything else is set only if you agree, and you can change your choices at any time using the Cookie preferences link in the footer. Our Cookie Notice lists every cookie we use.
6. When we work for a healthcare organisation
What we receive. Appointment and scheduling information from the organisation's systems. Depending on their instructions this can include appointment identifiers, dates and times, clinic and specialty information, appointment history, and demographic fields they select. We do not set out to handle health records, but the clinic attached to an appointment can indicate that a person has a health condition. We therefore treat everything we receive in this role as if it were health information.
What we do with it. Only what the organisation has contracted us to do, on their documented instructions. Not our own purposes.
Lawful basis. The organisation decides. In the NHS this is typically Article 6(1)(e) of the UK GDPR, processing necessary for a task carried out in the public interest, with Article 9(2)(h), processing necessary for the management of health and social care services.
Sub-processors. We use a small number of organisations to help deliver the service, each appointed under a written contract imposing the obligations we owe our customers. Customers receive the current list in their agreement with us and we notify them before it changes.
If you are a patient. Contact your hospital. They hold your record and are accountable for it. If a request reaches us directly we will pass it on and help them respond, but we cannot act on it ourselves.
7. Artificial intelligence and automated decisions
Our software predicts the likelihood that a scheduled appointment will not be attended, and recommends how unused capacity could be filled.
No patient's care, treatment, priority or place on a waiting list is decided by our software alone, and a person at the healthcare organisation remains responsible for the decisions that affect patients.
That means our software is not used to make decisions based solely on automated processing within the meaning of Article 22 of the UK GDPR.
8. Who we share information with
Service providers who help us run our business, including hosting, email, customer relationship management and security, acting on our instructions under written contracts. Professional advisers including lawyers, accountants, auditors and insurers. Investors and potential acquirers, under confidentiality obligations and using anonymised information where we can. Regulators, courts and law enforcement where the law requires it or where we need to establish or defend legal claims.
We do not sell or rent personal information.
9. Where information is held
Information held when delivering our software to NHS customers is stored in the United Kingdom.
10. How we protect information
We encrypt personal information in transit and at rest, restrict access to those who need it, log that access, train our staff and test our systems. We have a process for identifying, containing and reporting security incidents, including notifying the Information Commissioner's Office and affected people where we are required to.
No system is completely secure and we do not claim otherwise. Our current certifications and our security position are published at trust.
11. Your rights
You can ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it in certain circumstances, object to how we are using it, ask us to restrict how we use it, or ask for it in a portable format. Where we rely on your consent, you can withdraw it at any time. Where we rely on legitimate interests, you can object and we will stop unless we have compelling grounds not to.
Write to us using the details in section 14. We will respond within one month, and tell you if a complex request will take longer. There is no charge unless a request is clearly unfounded or excessive. We may need to confirm your identity first.
If you are a patient asking about appointment information, please see section 6.
If you are unhappy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put it right first.
12. Children
This website and our commercial services are intended for adults working in healthcare. We do not knowingly collect personal information from children through this site.
Our software is used by hospitals to schedule outpatient appointments, and some of those appointments are for children. Where that is the case the hospital remains the controller and section 6 applies in the same way.
13. Changes to this notice
We review this notice at least once a year and update it when our practices change. The date at the top shows when it last changed. Where a change materially affects how we use your information, we will tell you directly if we have your contact details.
14. Contact
Deep-Medical Ltd, 1 Primrose Street, London, EC2A 2JN
Please mark correspondence for the attention of the Data Protection Officer.