Privacy Policy
1. What data we collect
[Placeholder] Describe the categories of data processed: account details for clinic staff (name, email, role); operational data entered into the platform, which may include patient and carer identifiers and clinical scheduling information; and technical data such as logs. Specify what is and isn't collected.
2. How we use it
[Placeholder] Explain the purposes and lawful bases for processing: providing the service, coordinating theatre activity, generating operational analytics, and support. Clarify that Bramwell augments a clinic's own systems and acts as a processor and/or controller as appropriate (to be determined with legal review).
3. Storage & security
[Placeholder] Describe where data is hosted, encryption in transit and at rest, access controls, tenant isolation, and organisational safeguards. State the hosting regions.
4. Third parties
[Placeholder] List sub-processors (hosting, infrastructure, email, analytics) and the safeguards governing them, including any cross-border transfer mechanisms.
5. Data retention & erasure
[Placeholder] Set out retention periods and the erasure process. Note that the platform supports anonymising a patient's identifying details on request while retaining de-identified operational data; describe how retention aligns with clinic obligations.
6. Your rights
[Placeholder] Describe the rights available to data subjects under the applicable regime(s), such as access, rectification, erasure, restriction, portability and objection, and how to exercise them.
7. Contact
Bramwell is built and run by Elliot Kneba, MRCVS, who is the individual responsible for data handled by the platform. Data requests and privacy enquiries, including requests for access, correction or erasure, can be sent to hello@bramwell.vet.
[Placeholder] The formal controller and processor designations, and any registration details, are to be confirmed with legal review before launch.