Data minimisation
DoseRelay is built around minimal collection. Clinical records use opaque
patient tokens (e.g. Patient-DEMO01) rather than legal names or
NHS numbers as the product primary key. Patients log via
Telegram (primary) and/or WhatsApp Business Cloud API.
What we use data for
Logged self-report content is used to generate weekly review-prep PDFs for scheduled clinical reviews. We do not sell data. We do not train public foundation models on patient logs.
Where data is processed
Application infrastructure runs on Hetzner servers in the EU (Germany). Traffic to public endpoints uses TLS. Voice notes are transcribed with Google Gemini (paid API) solely to produce text for the log and PDF pipeline.
Messages leave the messenger app when our bot/webhook receives them — that is expected for Telegram bots and WhatsApp Business API integrations. After ingest, processing is under DoseRelay controls (tokenised store + PDF generation).
Retention
- Structured self-log events: until deletion request or operational retention (~12 months unless deleted sooner).
- Raw voice files: marked for deletion about 7 days after successful transcription/parse.
- Server-held weekly PDFs: short-lived operational copies (~90 days order of magnitude).
Roles & clinics
For pilot use with a clinic, the clinic is typically the data controller for care decisions and real identity; DoseRelay processes tokenised self-logs for review-prep. A data processing agreement (DPA) is available on request. DoseRelay is an early pilot and is not NHS DTAC-assessed.
This website
The marketing site is static. The sample report is fictional. Server access logs may retain standard technical metadata (IP, user-agent) for security and reliability.
Data deletion
To request deletion of your DoseRelay self-log data, see Data deletion instructions (or email [email protected] directly).
Contact
Privacy questions: [email protected]. Also see Terms of use.