Operated by: Nicholas Mohammed trading as H.E.Rv3 ("we", "us", "our")
Address: 2 Goodall Street, Walsall WS1 1QL, United Kingdom
Contact: qnicktech@gmail.com
Effective date: 11 June 2026

1. Who This Notice Is For

This notice applies to:

Your clinic or GP practice is the Data Controller. H.E.Rv3 provides the software as a Data Processor acting on the Controller's instructions. For questions about how your specific clinic uses your data, contact your clinic directly.

2. What Personal Data We Process

For Patients

CategoryExamples
Identity dataFull name, date of birth, NHS number, address, telephone, email
Health data (Special Category)Medical history, diagnoses, medications, allergies, lab results, clinical notes, referrals
Appointment dataAppointment dates, times, clinician, attendance records
Financial dataBilling records, insurance details (where applicable)
System dataLog-in timestamps, device type (for access audit purposes)

For Staff Users

CategoryExamples
Identity dataFull name, professional registration number, role, work email
Access dataLog-in timestamps, actions taken within the system (audit log)
Authentication dataUsername, MFA device registration (passwords never stored in plain text)

3. Legal Basis for Processing

PurposeLegal basis (UK GDPR)
Electronic health records and clinical workflowArt. 6(1)(c) — legal obligation; Art. 9(2)(h) — healthcare provision
Scheduling and appointmentsArt. 6(1)(b) — contract; Art. 9(2)(h)
Prescribing and medication managementArt. 6(1)(c) — legal obligation; Art. 9(2)(h)
Clinical decision support (AI suggestions)Art. 9(2)(h). AI outputs are informational only; clinician approval required before recording
Billing and invoicingArt. 6(1)(b) — contract
Audit loggingArt. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interests
FHIR data exportArt. 6(1)(c) — legal obligation; Art. 20 — data portability
System securityArt. 6(1)(f) — legitimate interests

4. Retention Periods

Record typeRetention period
Adult patient health recordsMinimum 8 years from last clinical contact (NHS Records Management Code 2021)
Paediatric recordsUntil the patient turns 25, or 8 years from last contact — whichever is longer
Audit logs7 years
Billing records7 years (HMRC requirement)
Staff access data3 years after end of employment or contract

5. Who We Share Your Data With

We do not sell your personal data.

RecipientPurposeSafeguards
AWS (cloud infrastructure)Hosting and storageAWS BAA / DPA in place
Sentry (error monitoring)Application error detectionNo PHI transmitted
AI/CDS provider (where enabled)Clinical decision supportDe-identified prompts only; provider DPA in place
Lemon Squeezy (payment processor)Billing only — name, email, payment details. No PHI transmitted.Standard Contractual Clauses
Clinical teamProviding your careRole-based access control (RBAC)
Regulatory bodiesWhere required by lawOnly when legally required

6. International Transfers

We process your data within the United Kingdom. Where third-party providers process data outside the UK, we ensure a UK adequacy regulation is in force or a UK IDTA is in place. AI provider prompts contain de-identified data only.

7. Your Rights

RightWhat it meansHow to exercise
Access (Art. 15)Request a copy of your personal dataContact your clinic or qnicktech@gmail.com
Rectification (Art. 16)Correct inaccurate dataContact your clinic
Erasure (Art. 17)Delete your data — subject to legal retention requirementsContact your clinic; clinical records must be retained per Section 4
Restriction (Art. 18)Restrict processing in certain circumstancesContact your clinic
Portability (Art. 20)Receive your data in FHIR R4 formatContact your clinic
Object (Art. 21)Object to legitimate-interests processingContact your clinic
Automated decisions (Art. 22)Not subject to purely automated clinical decisionsH.E.Rv3 never makes automated clinical decisions — all AI outputs require clinician approval

We will respond within one calendar month.

8. Security Measures

9. Changes to This Notice

We will update this notice when our processing changes or when the law requires. Previous versions are available on request.

10. Complaints

You have the right to complain to the Information Commissioner's Office (ICO):