Trust Centre Document
Privacy Policy
How Cogent collects, uses and protects personal data under UK GDPR, including its roles: controller for clinicians, processor for client content.
1. Who we are
Cogent Clinic is a clinical practice environment and documentation assistant provided by Cogent Clinic Ltd, a company registered in the United Kingdom.
For the purposes of UK data protection law, Cogent Clinic Ltd is the data controller for the personal data described in this policy where we collect and use information about our clinician customers, website visitors, prospects, and business contacts.
In relation to content submitted by clinician customers for document generation, clinical workflow support (client folders, living formulation, supervision briefs), and reflective-thinking chat, our role is generally that of a data processor, acting on the clinician's instructions. The clinician remains the data controller for their patient data.
Controller name: Cogent Clinic Ltd
Product name: Cogent Clinic
Company number: SC887432
Registered address: Mearns Castle Golf Academy, Waterfoot Road, Glasgow, G77 5RR
Contact email for privacy matters: privacy@cogent.clinic
Website: www.cogent.clinic
Location: United Kingdom
2. What this policy covers
This policy explains how we collect, use, store, and protect personal data when:
- you visit our website,
- you contact us,
- you join a waitlist or request information,
- you become a clinician customer,
- you use the Cogent Clinic product, or
- you otherwise interact with us in a business capacity.
It also explains, at a high level, how data is handled when clinicians use the product to generate draft documentation.
3. The privacy approach
Cogent Clinic is designed around data minimisation. Patient-identifying details are tokenised client-side, and the clinician confirms the de-identification, before content is sent for processing, which means identifiable patient information does not reach the AI model or sub-processors in the normal course of operation, and the clinician reviews and controls what they submit. The placeholder mapping and saved transcripts, which can re-identify content, are stored encrypted at rest on UK infrastructure under a provider-held managed key, with access controlled and logged.
No technical system is perfect, so Cogent describes the residual risks honestly and maintains contractual, security, and incident-response controls on the basis that personal data could still be involved in edge cases, misuse, or failures.
4. The personal data we collect
A. Information about website visitors and prospects
We may collect:
- name,
- email address,
- organisation or practice name,
- phone number if voluntarily provided,
- enquiry details,
- marketing preferences,
- website usage data such as IP address, browser type, pages viewed, referral source, and basic analytics events.
B. Information about clinician customers
We may collect:
- name,
- work email address,
- billing details,
- account credentials and MFA-related information,
- subscription and transaction records,
- support correspondence,
- usage metadata, such as feature usage, timestamps, document type selected, and model route used,
- audit logs and security logs.
C. Content processed through the product
When a clinician uses Cogent Clinic, content is submitted for several connected workflows: drafting documents, managing client folders, maintaining a living formulation, preparing for supervision, live session transcription, running a folder-scoped reflective-thinking chat, and running a documentation-completeness check on a finished draft.
Our design is that:
- directly identifying patient details are detected and replaced with placeholders (tokenised) in the clinician's browser, and the clinician confirms the de-identification, before drafting text is sent for inference, so the inference model and its sub-processors do not receive real names in the normal drafting path (two paths are the disclosed exceptions: live session audio, which must be transcribed before it can be de-identified, and a clinician-uploaded handwritten note, which is sent as a file for text extraction before that tokenisation step runs on the extracted text),
- the mapping between placeholders and real names is stored encrypted at rest on our UK infrastructure under a provider-held managed key, with access scoped to least-privilege roles and logged,
- we process only the de-identified content for inference to generate drafts and to run the secondary surfaces (formulation sections drawn from the clinician's own content, reflective chat, completeness checks),
- session transcripts captured through the live-transcription feature are, at the clinician's choice, saved under the relevant client folder, stored encrypted at rest under a provider-held managed key. We can technically decrypt stored transcripts under those access controls, so we do not claim that nobody at Cogent could read them; access is least-privilege and logged. Retention is indefinite and deletion is controlled by the clinician,
- live transcription audio streams directly from the clinician's browser to an EU-hosted speech-to-text service. Audio does not pass through our infrastructure. The service processes audio at its European Union endpoint (AWS eu-west-1, Dublin). Because this processing takes place within the European Economic Area (EEA), it benefits from the UK's adequacy regulations for the EEA and no additional international transfer safeguards are required. Cogent Clinic Ltd has opted out of the sub-processor using customer audio or transcripts for model training or benchmarking via its documented opt-out process. Where a transcript is saved, it is stored by us in the UK encrypted at rest under a Provider-held managed key. The raw session audio transmitted for live transcription contains identifiable special category health data and cannot be de-identified before transcription. This is the only processing activity where the usual de-identification step does not apply before information reaches a sub-processor,
- the AI provider we use for inference operates on inference-only contractual terms. Customer content is not used to train or fine-tune any model.
Clinical content processed through the product is special category health data by design, not only in edge cases. A de-identified draft remains special category data, because replacing the name still leaves health information about a person who is re-identifiable through the placeholder mapping, and a saved session transcript contains identifiable health information. The de-identification step reduces what reaches the inference model and its sub-processors; it does not change the special category nature of the data we process on the clinician's behalf.
D. Payment and financial data
Payments are processed by Stripe, and Cogent does not store full payment card details directly.
Where we need personal data to enter into or perform a contract with a clinician customer (for example, account, billing, authentication, and security details), provision of that data is a contractual requirement. If it is not provided, we may be unable to create an account or provide the Cogent Clinic service.
5. How we use personal data
We use personal data to:
- operate and improve our website,
- respond to enquiries,
- manage waitlists, demos, and onboarding,
- create and manage customer accounts,
- provide the Cogent Clinic service,
- authenticate users and protect account security,
- process payments and maintain financial records,
- provide customer support,
- monitor service reliability, misuse, and security,
- maintain audit trails and accountability records,
- communicate service updates and important notices,
- send marketing communications where consent or another valid basis applies,
- comply with legal and regulatory obligations.
6. Our lawful bases
Depending on the context, we rely on one or more of the following lawful bases under UK GDPR:
Contract
Where processing is necessary to provide our service, manage an account, or respond to a request connected to entering into a contract.
Legitimate interests
Where processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and interests. This includes:
- securing the platform,
- preventing misuse,
- improving the product,
- handling support,
- maintaining appropriate records.
Consent
Where you opt in to receive marketing communications or where consent is otherwise required.
Legal obligation
Where we must retain or disclose information to comply with tax, accounting, legal, or regulatory obligations.
Special category data
The product routinely processes special category health data, and we do not treat this as a rare edge case. A de-identified draft remains special category data, because replacing the name still leaves health information about a person who is re-identifiable through the placeholder mapping, and a saved session transcript is identifiable health data by design, stored encrypted at rest under a provider-held key that we can technically decrypt. For this data the clinician customer is the controller and provides the applicable Article 9 condition, ordinarily Article 9(2)(h) (provision of health or social care), and Cogent acts as processor. We process it only to provide the service securely and under the clinician's documented instructions, never for our own purposes.
7. Processor role for clinician-submitted content
For clinician-submitted content used to generate draft documentation, we generally act as a processor on behalf of the clinician customer.
That means:
- the clinician decides the purpose and lawful basis for using the tool in their practice,
- the clinician is responsible for ensuring they have an appropriate legal basis for processing patient information,
- we process content on their behalf to provide the service,
- our Data Processing Agreement sets out the instructions, safeguards, and responsibilities between us and the clinician customer.
Automated decision-making and AI-generated outputs
Cogent Clinic produces draft documentation and related outputs that are always reviewed and controlled by the clinician. We do not use the product to make decisions about any individual based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 UK GDPR (as amended by the Data (Use and Access) Act 2025). The clinician remains responsible for reviewing, amending, and deciding whether to rely on any output.
8. Sharing personal data
We may share personal data with carefully selected service providers and sub-processors that help us run the service, including providers for:
- cloud hosting (including our UK-resident database and object storage),
- AI inference (on inference-only contractual terms; customer content is not used to train any model),
- live speech-to-text transcription (audio streams directly from the clinician's browser to a speech-to-text provider processing at its European Union endpoint (AWS eu-west-1, Dublin); audio does not transit our infrastructure; Cogent Clinic Ltd has opted out of model training and benchmarking on customer audio and transcripts via the provider's documented opt-out process; where a transcript is saved, it is stored by us in the UK encrypted at rest under a Provider-held managed key with access restricted to least-privilege roles and logged),
- authentication,
- payment processing,
- transactional email,
- error monitoring (metadata only, no clinical content),
- customer support,
- analytics (metadata only, no clinical content).
The live sub-processor list is published in the sub-processor register and kept up to date. It names our key sub-processors and their locations, including our AI inference provider Anthropic (accessed via Amazon Bedrock in the UK), our EU-hosted speech-to-text provider AssemblyAI, and our UK cloud hosting provider Amazon Web Services (AWS).
Personal data may also be disclosed where required by law, regulation, court order, or to establish, exercise, or defend legal claims.
Cogent does not sell personal data.
9. International transfers
Cogent Clinic is offered on a UK-only basis and is not offered to EU customers at this stage, with clinical-content processing kept inside the UK on UK-hosted infrastructure.
Some providers used for account administration, payment processing, customer support, email delivery, analytics or other business operations may process personal data outside the UK. Where this occurs, we ensure that an appropriate transfer mechanism is in place, including an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard. The arrangements for live speech-to-text processing are described separately in Sections 4 and 8. The transfer routes for our active providers are set out in the sub-processor register. You can request a copy of, or information about, the safeguards we rely on by contacting privacy@cogent.clinic.
10. Data retention
We keep personal data only for as long as necessary for the purposes we collected it for, including to satisfy legal, accounting, or regulatory requirements.
A fuller retention schedule is maintained separately. In summary:
- account data is retained during the customer relationship and for a short period after closure,
- financial records are retained for the legally required period,
- audit and usage metadata are retained only as long as needed for security and accountability,
- support correspondence is retained for a limited operational period,
- saved drafts are retained until the clinician deletes them or closes their account,
- saved session transcripts are retained indefinitely, stored encrypted at rest under a provider-held managed key with access least-privilege and logged, and are deleted manually by the clinician or automatically on client-folder or account deletion,
- folder-scoped chat conversations are retained until the clinician deletes the conversation or the folder.
11. Security
We use technical and organisational measures intended to protect personal data, including:
- encryption in transit,
- encryption at rest where appropriate,
- access controls and least-privilege permissions,
- MFA for accounts,
- logging and monitoring,
- vulnerability management,
- documented retention controls,
- incident response procedures.
No method of transmission or storage is completely secure, but we take data protection seriously and design the service to minimise exposure.
12. Personal data breach handling
We maintain an incident response plan for data breaches and security incidents. If a personal data breach occurs, we will assess it promptly and, where required, notify:
- the Information Commissioner's Office, and/or
- affected customers or other affected persons, within the timelines required by law.
Where we act as processor, we will notify the relevant clinician controller without undue delay in line with our contractual obligations.
13. Your rights
Depending on the context, you may have rights under UK data protection law, including the right to:
- access your personal data,
- rectify inaccurate data,
- erase your data,
- restrict processing,
- object to processing,
- data portability,
- withdraw consent where processing relies on consent,
- complain to the ICO.
These rights are not absolute and may depend on our role.
If you are a patient whose clinician has used Cogent Clinic, your rights will usually need to be exercised through your clinician as the controller of your clinical data.
Children's data. Cogent Clinic is provided to clinician customers acting in a professional capacity. Patients whose information is processed through the product may include children. Where this occurs, the clinician is the controller for that patient data and is responsible for any consent, safeguarding, and additional protections required when processing children's personal data.
14. Cookies and analytics
The website may use cookies or similar technologies for:
- essential site functionality,
- analytics,
- performance monitoring,
- marketing, if enabled.
Full details of the cookies and similar technologies used, and the controls available to you, are in our Cookie Policy.
15. Complaints
If you have concerns about how we handle your personal data, you have the right to make a data protection complaint directly to us as controller. You can use our electronic complaint form, or contact us at privacy@cogent.clinic, or by post at the registered address above. You can submit a complaint by any reasonable means, and you do not need to use any particular form of words. We will acknowledge your complaint within 30 days of receipt, take appropriate steps to investigate it, keep you informed of progress, and respond without undue delay. This right to complain to us is in addition to, and does not affect, your right to complain to the Information Commissioner's Office.
ICO registration: ZC132394
Data Protection Lead: Dr Aisha Tariq, Director, Cogent Clinic Ltd
Given that the product processes special category health data on behalf of clinicians, we keep under review whether a statutory Data Protection Officer is required under Article 37 UK GDPR. Our designated Data Protection Lead named above is responsible for data protection matters and is the point of contact for the supervisory authority and data subjects.
You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk
16. Changes to this policy
We may update this policy from time to time to reflect legal, technical, or operational changes. The latest version will be published on the website with the updated date.