Security and information governance
Last reviewed 01.09.26
We work with NHS trusts and health systems on outpatient scheduling. That means we handle information about appointments, and appointment information tells you something about a person's health.
This page exists so that the people who assess us can find what they need without asking us for it first. If something you need is not here, write to us and we will send it.
1. Our role in your data
When a healthcare organisation uses our software, that organisation is the data controller. It decides why patient information is used and it remains accountable for that decision. We are the processor, and we handle information only on its documented instructions under a written agreement.
We are a controller only for our own business information, such as our website visitors, commercial contacts, suppliers and job applicants. Our Privacy Notice covers that.
As a processor we cannot complete a data protection impact assessment for you, because the assessment is yours to make. What we can do is give you what you need to complete it quickly. See section 6.
If you are a patient, your hospital holds your record and is accountable for how your information is used. Questions about your appointment should go to your hospital. If you write to us we will pass your request on and help them respond, but we cannot act on it ourselves.
2. What we hold
Q1 2025-26 assessment, (valid until) Q2 = 29 November 2026
Each of these can be checked independently. We publish the reference numbers so that you can.
On DTAC. The Digital Technology Assessment Criteria is a framework that a supplier completes and the buying organisation assesses. NHS England does not endorse third party DTAC certification schemes, and there is no DTAC certificate to hold. Any supplier describing itself as DTAC certified is describing something that does not exist. We complete the DTAC question set and provide our response with supporting evidence on request.
On HIPAA. HIPAA has no certification scheme, and the US Department of Health and Human Services does not certify any product as compliant. What we can do, and do, is enter into a Business Associate Agreement.
On ISO 27001. We do not hold it. We hold Cyber Essentials Plus, which is independently assessed and covers our whole organisation.
3. Our AI, and what we do not do with your data
Our software does three things. It predicts the likelihood that a scheduled appointment will not be attended. It supports how patients are contacted about their appointments. And it identifies patients who could take a slot that has been released.
Where the decisions sit. These outputs support decisions taken by your staff. Your organisation sets the operating limits, decides which functions are switched on, and controls how far each one goes. Our software does not remove an appointment from a patient, does not change a booking a patient already holds, and is not used to deprioritise anyone or refuse anyone an appointment.
Accountability. Overall accountability for the design, operation and monitoring of our AI sits with Dave Hanbury, Chief Executive Officer. Roles and responsibilities for design, deployment, monitoring and escalation are defined internally, and performance and exceptions are monitored through live reporting.
Explainability. Your staff see the basis for each output, so that an intervention can be understood, questioned and overridden. We give you what you need to explain our part to a patient who asks.
Changes. If we want to use your information for anything beyond what your agreement covers, we ask you first, and the answer being no does not affect your service. Where a change to how our software operates would affect your own assessment, we tell you before we make it, not after.
4. Fairness and access
The purpose of our software is to remove barriers to attendance, not to sort patients by how likely they are to turn up. Our outputs are used to arrange support and to offer earlier appointments. They are not used to remove anyone from a list, to deprioritise anyone, or to refuse anyone an appointment.
What we do. We exclude directly identifiable and special category data from model training. We monitor outcomes by deprivation level through live reporting, so that you and we can see whether the service is improving access across groups rather than only in aggregate. Where we find a material difference between groups, we investigate it and review the configuration with you.
5. Where your data is held and how it is protected
Location. Information we process for NHS customers is held in the United Kingdom, in Amazon Web Services data centres in the London region.
In transit and at rest. Data is transferred by encrypted SFTP or secure API integration using HL7 and FHIR standards. It is encrypted in transit using TLS 1.2 or above, and at rest using AES-256.
Pseudonymisation. Historical appointment data is pseudonymised by the trust before transfer. Ongoing appointment data is pseudonymised within our systems after a defined period.
Retention. Retention is set by your agreement with us rather than by us. At the end of the retention period, appointment data is irreversibly anonymised.
6. What we will give you
Available on request:
– Our completed DTAC response with supporting evidence.
– Our customer agreement, including the data processing terms and security schedule.
– Our data protection policy.
– Information to support your DPIA, structured against the questions trusts actually ask, so that you are completing an assessment rather than gathering facts.
– A Business Associate Agreement, for organisations in the United States.
– Our clinical safety documentation
– Our most recent penetration test summary, under a non-disclosure agreement
Write to us and tell us which of these you need.
7. Contact and vulnerability reporting
Information governance and data protection: privacy@deep-medical.ai
Our Data Protection Officer is [Q14].
Security and vulnerability reports: security@deep-medical.ai
If you believe you have found a vulnerability in our systems or this website, tell us there. We will acknowledge your report within [X] working days and keep you updated. We will not pursue legal action against anyone who reports in good faith, does not access or modify data beyond what is needed to demonstrate the issue, and gives us reasonable time to fix it before disclosing publicly.
Deep-Medical Ltd, 1 Primrose Street, London, EC2A 2JN. Registered in England and Wales, company number 13242918. ICO registration ZB228006