Trust Centre

Data protection

Last updated 10 July 2026

Your practice stays the data controller for everything in its workspace. AyrisIQ is your data processor, acting only on your instructions under a written data processing agreement.

What we hold, and what we refuse to hold

  • We hold: your policies, SOPs and governance documents; staff names, roles and training/competency evidence; de-identified incident, complaint and significant-event records; workspace account identities; and the audit trail of who did what.
  • Outside intended use: patient records and patient-identifiable information. Common identifier scans and database checks reduce accidental entry, but they cannot prove text is anonymous. Complaint and incident pilot entry therefore stores a short de-identified summary, not the source letter or narrative.
  • Special-category staff data (e.g. immunisation status or DBS outcomes uploaded as HR evidence) requires the controller to document its Article 6/9 and Schedule 1 conditions. External AI for staff evidence is disabled by default and evidence cannot affect compliance until a Full Admin approves it.

Where your data lives — current, honest position

  • Database, files and authentication: Supabase on AWS, London (eu-west-2).
  • AI processing: enabled general-governance analysis uses Amazon Bedrock, London (eu-west-2), direct in-region model. Inputs are minimised; sensitive staff, complaint and incident workflows are disabled unless both the platform and the named organisation are explicitly approved.
  • Error monitoring: Sentry error reporting, EU (Germany); no replay or tracing. Error telemetry is diagnostic metadata, not session recording; contractual and retention evidence remains a real-data launch gate.
  • Email notifications: sent via Resend in its EU region using fixed templates. Messages carry recipient/contact and notification data, not uploaded files.
  • The complete supplier list with locations is on the sub-processors page and is kept current.

Retention and deletion

Retention, export, backup expiry and deletion timing will be set in the signed customer DPA and retention schedule. Deletion is fail-closed in the app when file removal fails. A tested end-to-end deletion and restore drill remains required before a real-data pilot; no shorter technical deletion guarantee is claimed here.

Your rights machinery

  • DPA: Article 28 processor terms are being finalised and must be signed, together with the pilot scope, before real customer data is accepted.
  • DPIAs: internal and customer-support DPIA drafts exist but must be updated and approved against the released scope, suppliers and residual risks before real data.
  • Subject access / rights requests: routed through your practice as controller; we assist under the DPA.
  • Breach notification: we notify affected customer admins without undue delay — our target is within 24 hours of becoming aware.

See also the privacy policy (covering our website and account data) and the cookie policy (short version: no tracking cookies).