Last updated: May 2026 · ClarityQ Ltd · Company No. 17072041 · Document Ref: CQ-PN-001
ClarityQ Ltd is a clinical analytics platform registered in England and Wales (Company No. 17072041), with its registered address at 71-75 Shelton Street, London, WC2H 9JQ. ODS Code: O3E4P.
For data protection enquiries, contact: info@clarityq.co.uk
ClarityQ Ltd is the Data Processor. The GP practice or NHS organisation that commissions ClarityQ is the Data Controller.
As Data Processor, ClarityQ:
The Data Controller (GP practice) determines the purposes and means of processing personal data, ensures a lawful basis exists under UK GDPR, and is responsible for providing fair processing information to data subjects (patients).
ClarityQ processes data under the following lawful bases:
The Data Controller (GP practice) relies on their own lawful basis for collecting and sharing data with ClarityQ, typically under Article 6(1)(e) — Public task, or Article 9(2)(h) — Health care provision.
Clinical analytics data (pseudonymised): Aggregated, population-level health indicators extracted from EMIS Web or SystmOne. No direct patient identifiers are processed.
User account data: Name, email address, role, organisation, login timestamps, and audit trail of platform actions.
Clinical Scribe transcriptions: Voice-to-text output only. Audio is processed ephemerally and never stored. Only the transcribed text is retained for the clinician to review and copy.
Triage Co-pilot input: Symptom descriptions entered by clinicians. Automated PII detection strips any patient-identifiable information (NHS numbers, names, postcodes, dates of birth, email addresses, phone numbers) before processing.
ClarityQ implements automated PII detection and stripping on all free-text input fields. The following identifiers are automatically detected and blocked:
This operates at both the client-side (immediate user feedback) and server-side (API-level blocking) to ensure defence in depth.
ClarityQ shares data only with the following sub-processors, all under Data Processing Agreements. AWS stores pseudonymised NHS patient data; AccuRx and Docman Connect transiently transfer patient messages/clinical letters (not stored by ClarityQ); all other sub-processors handle no NHS patient data:
All NHS patient data is processed and stored within the UK (AWS eu-west-2, London region). No international transfers of NHS patient data take place. The only sub-processor located outside the UK is GitHub (USA, source code only), covered by Standard Contractual Clauses.
ClarityQ will not share personal data with any third party for marketing purposes.
ClarityQ retains data for 7 years in accordance with the NHS Records Management Code of Practice 2021. This applies consistently across:
Clinical Scribe audio: Never stored. Processed ephemerally and discarded immediately after transcription.
On subscription termination: Data may be exported or returned within 30 days. All patient, clinical, audit and records data is then retained for the full 7-year period required by NHS records management before secure deletion.
ClarityQ implements comprehensive security measures:
As a data subject, you have the following rights:
For patient data, rights requests should be directed to the Data Controller (your GP practice), as ClarityQ processes this data on their behalf.
For platform user data, contact info@clarityq.co.uk. We will respond within 30 days.
If you are dissatisfied with how your data is handled, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
We encourage you to contact us first at info@clarityq.co.uk so we can try to resolve any concerns directly.
For privacy or data protection queries:
ClarityQ Ltd
71-75 Shelton Street, London, WC2H 9JQ
Email: info@clarityq.co.uk
Company No. 17072041 · ODS Code: O3E4P