⚕
MedicFlow
PrivacyTermsDisclaimer

Data Processing Information

Last updated: 20 April 2026 · UK GDPR Article 13/14 Information

Data controller

Haseeb Ullah trading as MedicFlow
Email: support@medicflow.uk
Website: medicflow.uk

Data we process and why

Data typePurposeLegal basisRetention
Name & emailAccount creation, login, service commsContractAccount life + 2 years
Clinical grade/specialityAI personalisationContractAccount life + 2 years
Usage logsBilling, rate limiting, fraud preventionLegitimate interests12 months
Payment statusSubscription managementContract7 years (HMRC)
IP addressSecurity, fraud preventionLegitimate interests90 days
AI query textProcessing via Anthropic API (not stored by us)ContractNot retained

Sub-processors

ProcessorPurposeLocationSafeguards
SupabaseAuth & databaseEU/USSCCs, SOC2
StripePayment processingUS/EUPCI DSS, SCCs
VercelWeb hostingUS/EUSCCs, ISO27001
AnthropicAI query processingUSSCCs

Your rights

Under UK GDPR you have rights of access, rectification, erasure, portability, restriction, and objection. Contact support@medicflow.uk to exercise these rights. Response time: 30 days. You may complain to the ICO at ico.org.uk.

Privacy PolicyTerms of ServiceClinical DisclaimerContact