Skip to main content
Back to dashboard

Privacy Notice

For staff at Wye Valley Surgery · Last updated: 7 August 2026

1. Who We Are

PracticeKit is operated by Aryash Health Limited (Companies House no. 17001109; ICO registration ZC086802). We are the data controller for the personal data processed through this service. Our Clinical Safety Officer is Dr Krishnan Pasupathi (GMC: 6050795), GP Partner at Wye Valley Surgery, High Wycombe.

The tools are supplied to the practice under an Information Governance Agreement (version 1.0), to be agreed and signed at a forthcoming partners' meeting. The agreement lists the tools in use and is re-agreed before any new tool is introduced.

2. This Notice Is About Staff Data

No tool currently in use processes patient-identifiable data. The tools available to you are staff and practice tools: guidance, reference material, scheduling, wellbeing and partnership business. This notice therefore explains how we handle information about you, as a member of practice staff.

Some tools that handle patient information have been built but are not in use and not available to staff. They are out of scope of the current agreement. None will be switched on until it has passed its own governance and clinical safety review, the agreement has been re-agreed, and this notice has been updated to describe it.

3. What Data We Handle

The tools in use handle three kinds of information only.

Practice documents and reference material

Policies, procedures, guidance and rotas. May contain staff names and internal contacts; access is restricted accordingly. Used by Safeguarding, the Learning hub, the Neighbourhood Health Guide and the patient safety (PSIRF) workspace.

Staff personal data

Information about you: leave and scheduling in the Rota, and the content of your own private reflective sessions in Practice Pulse. Session content is visible only to you — enforced in the database, not just on screen. See section 5.

Practice business information

The Practice Cockpit and the Partners' Corner hold the partnership's own business record: figures the partners enter by hand, the practice-year planner, the meeting record (agendas, notes, minutes and actions) and the partnership's decisions log. They name partners and may name staff in the ordinary course of partnership business. They hold no patient information by design. See section 8.

We do not collect:

  • NHS numbers
  • Patient names
  • Patient dates of birth, addresses or contact details
  • Any patient-identifiable clinical record

4. Lawful Basis for Processing

  • Article 6(1)(f) UK GDPR — Legitimate interests, for running the practice and supporting staff: scheduling, guidance, professional development, partnership business, and voluntary wellbeing tools.
  • Article 9(2)(a) UK GDPR — Explicit consent, for any health information you choose to share in a Practice Pulse or wellbeing conversation.

5. Your Private Tools

Three tools hold your own material and work differently from the rest. All are voluntary.

  • Staff Wellbeing (survey and check-in) — completely anonymous. No name, login details or user identifier is stored with any answer, survey responses carry no timestamp, and check-ins record only the week. The check-in chat itself is never stored anywhere — only the summary you approve is saved, anonymously. Statistics for small groups are hidden to protect anonymity. Nothing submitted here can be used in any HR process, and using the tool is not a way of formally reporting an issue.
  • Practice Pulse — your private reflective chat. Conversations are stored against your account and are visible only to you; you can delete them at any time. No coach, manager or administrator can read them.

6. Cloak (de-identification)

Cloak strips identifying details from text before you paste it into an AI tool, and restores them in the reply. The whole exercise runs in your own browser: the pasted text and the list of what was replaced never reach Aryash Health systems. The platform records only a metadata audit trail — who used the tool and when, with document length and identifier counts.

The optional second check sends the already de-identified text to Claude, the AI model our other tools use (see section 7), which returns advisory flags only and never rewrites your document. Cloak is for non-clinical and administrative documents only.

7. Where Data Is Processed

All AI processing and data storage take place within the United Kingdom or the European Economic Area. The UK's adequacy regulations treat the EEA as providing equivalent protection. No tool uses a US or global processing region.

  • Amazon Web Services (Bedrock) — every AI feature (Practice Pulse, the Staff Wellbeing check-in, the Cloak second check and the Practice Cockpit meeting wrap-up) uses Claude, Anthropic's AI model, served by AWS from Europe (London), eu-west-2. Requests use EU inference profiles, which may be processed in other AWS regions within the EU — never outside the UK/EEA. The Staff Wellbeing check-in uses the strongest available Claude model — a deliberate decision recorded in the wellbeing DPIA addendum. (Until 3 August 2026 these features used Google Vertex AI; Google no longer processes any PracticeKit data.)
  • Amazon Web Services (Transcribe) — the Practice Cockpit's Meeting mode can transcribe a partners' meeting live. When a partner presses “Start listening”, sound from the meeting-room microphone is streamed from the browser straight to Amazon Transcribe in Europe (London), eu-west-2, and comes back as text. No audio is stored by PracticeKit or by AWS; only the text is kept, with the meeting record, and it feeds the wrap-up above. The screen shows that transcription is on for as long as it runs, and everyone in the room should know before it starts.
  • Supabase — staff accounts and tool state, hosted in AWS Europe (London), eu-west-2.
  • Vercel — application hosting. Stores no tool content.

AWS does not use your inputs or outputs to train AI models; Claude models on Bedrock are served by AWS under AWS's terms, not by Anthropic directly. Data processing agreements with all providers are on file in Aryash Health governance records.

8. The Practice Cockpit and Partners' Corner

The Practice Cockpit is the partnership's business meeting platform. Access is closed by default and granted individually, by name: GP partners, plus any managers the partners invite. Invited managers see only what is recorded after 7 August 2026 — everything written before that date remains visible to partners only. A meeting summary reaches anyone else only when a partner chooses to email it — the tool sends nothing on its own.

The Partners' Corner is a separate, partner-only space for the partnership's own business, with its own record kept apart in the database. Its content is never shown to, or summarised for, anyone who is not a partner.

In Meeting mode an AI wrap-up drafts the minutes, decisions and actions. A partner reviews, edits and approves that draft; nothing becomes the record without that approval. Once approved, minutes are locked against further change at database level, and the record stamps who approved them and when.

9. Security and Access

  • Individual staff logins only — no shared accounts, no public access
  • Access is closed by default; tools are granted by role, and by exception per person
  • All data transmitted via HTTPS/TLS encryption
  • Encrypted at rest; both platforms certified to ISO 27001 among others
  • Row Level Security on all database tables
  • Audit logging of actions
  • Administrative access limited to Dr Krishnan Pasupathi, Director, Aryash Health Limited

10. Data Retention

Staff accounts remain active until deactivated by the practice. Practice Pulse content is retained until you delete it. Anonymous wellbeing submissions carry no identifier and are retained in aggregate. Partnership records in the Practice Cockpit and Partners' Corner are retained as the partnership's own business record.

11. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure (where applicable)
  • Restrict processing
  • Data portability
  • Object to processing
  • Lodge a complaint with the ICO

Anonymous wellbeing submissions cannot be linked back to you by design, so they cannot be retrieved or deleted on request. This is stated before you submit. Practice Pulse content is yours to read and delete at any time.

12. Clinical Safety

Aryash Health Limited assesses every tool for clinical safety before it is made available, under a clinical risk management process aligned with DCB0129, overseen by a named Clinical Safety Officer. None of the tools in use is clinical decision support; clinical judgement always remains with the clinician.

13. Cookies

PracticeKit uses essential cookies only for authentication and session management. We do not use tracking or advertising cookies.

14. Contact Us

For privacy queries or to exercise your rights:
Aryash Health Limited
Email: yadavakrishnan.pasupathi@nhs.net

You may also contact the Information Commissioner's Office (ICO) at ico.org.uk

© 2026 Aryash Health Limited. This notice is reviewed annually, or sooner if a tool's data handling changes or a new tool enters use. Full Data Protection Impact Assessment available on request.