AboutPlatformModulesSolutionsFAQUpdates
Sign inBook a demo
Policies
Privacy PolicyPatient PrivacyYour Data RightsData ComplaintsAppropriate Policy DocCookiesWebsite TermsPlatform TermsAcceptable UseAccessibilityResponsible Disclosure
Cannexis Biopharma
ClinicalFlow Platform

Appropriate Policy Document (APD)

Applies to: Cannexis Biopharma Ltd's processing of special-category and criminal-offence data  |  Effective: 29 June 2026  |  FINAL v1.0 — approved for publication

Accountability document — Data Protection Act 2018, Schedule 1

1. Purpose of this document

This Appropriate Policy Document (APD) is maintained by Cannexis Biopharma Ltd ("Cannexis") under section 10 of, and Schedule 1 to, the Data Protection Act 2018 (DPA 2018). It documents how Cannexis complies with the principles in Article 5 of the UK GDPR when it processes special-category data (UK GDPR Article 9) and criminal-offence data (UK GDPR Article 10), and the policies it has in place for retention and erasure of that data.

It must be read with the Privacy & Data Protection Policy, the Record of Processing Activities (compliance/ropa.md), the Data Protection Impact Assessment (dpia.md), and the controller/processor analysis (compliance/controller-processor-joint-controller-analysis.md).

2. Roles — when Cannexis needs an APD

Cannexis's role varies by data flow (see the controller/processor analysis):

  • Patient clinical data on the ClinicalFlow platform — the treating clinic or pharmacy (tenant) is the controller and relies on its own Schedule 1 condition; that controller is responsible for its own APD. Cannexis is the processor and supports the controller, including by making this APD available as a baseline/template.
  • Cannexis's own controller processing that involves special-category or criminal-offence data — for example platform security and audit records that evidence access to health data, staff health/occupational data, and verification of prescriber fitness-to-practise/criminal-conviction status — Cannexis is the controller and this APD applies directly.
  • Any processing in which Cannexis is a joint controller with a tenant (per the Article 26 analysis) — this APD applies to Cannexis's part of that processing.

3. The Schedule 1 conditions relied upon

Special-category / criminal-offence processing Article 9/10 basis DPA 2018 Schedule 1 condition
Provision of health and social care via the platform (processor, on the controller's behalf) Art 9(2)(h) Sch 1, Part 1, para 2 (health or social care purposes)
Public-health and safety reporting (e.g. MHRA Yellow Card), where applicable Art 9(2)(i) Sch 1, Part 1, para 3 (public health)
Establishment, exercise or defence of legal claims Art 9(2)(f) (condition in the Article itself)
Preventing or detecting unlawful acts; safeguarding; regulatory requirements relating to fitness/suitability (e.g. prescriber verification, fraud prevention, audit) Art 9(2)(g) Sch 1, Part 2 (substantial public interest) — paras 10 (preventing/detecting unlawful acts), 11 (safeguarding), 12 (regulatory requirements/dishonesty/malpractice) as applicable
Criminal-offence data (e.g. prescriber regulatory/criminal-conviction checks) Art 10 Sch 1 condition as above (Part 2)

Where a Part 2 (substantial public interest) condition or the paragraph 1 condition is relied upon, this APD is a legal requirement. For the avoidance of doubt, Cannexis maintains it for all of the above.

4. Compliance with the Article 5 principles

(a) Lawfulness, fairness and transparency. Each processing activity has a documented Article 6 basis and Article 9/10 condition (see the ROPA and the privacy notices). Data subjects are informed through the Privacy & Data Protection Policy and the Patient Privacy Notice, including the source of any data not obtained directly from them.

(b) Purpose limitation. Special-category data is processed only for the care, safety, regulatory and security purposes described in the ROPA, and is not used for incompatible purposes. No marketing use is made of it.

(c) Data minimisation. Access is role-based and least-privilege; the BUSINESS_SUPER_ADMIN role is structurally blocked from clinical data; NHS numbers and other identifiers are encrypted and hash-referenced in logs; aggregate reporting suppresses small cells. (See the DPIA §4.4.)

(d) Accuracy. Identity is verified (NHS PDS verification once live; documented checks otherwise); records are corrected on rectification request; automated checks support but do not replace clinical judgement.

(e) Storage limitation. Special-category data is retained only for the periods in the ratified retention schedule (section 6) and then securely deleted or crypto-shredded after the statutory retention period (see the erasure policy, section 7).

(f) Integrity and confidentiality (security). Encryption at rest (including field-level encryption of health identifiers) and in transit; UK data residency for patient/clinical data; multi-factor authentication; tamper-evident, append-only audit logging; Cyber Essentials and DSPT alignment. (See the Privacy Policy §11 and the DPIA §8.)

Accountability. This APD, the ROPA, the DPIA, the sub-processor register, the retention schedule, staff training records and the DSPT submission together evidence accountability. An independent DPO (LHI Consulting) oversees compliance.

5. The Article 9(3) / professional-duty safeguard

Where Cannexis processes health data under the health/social care condition (Art 9(2)(h)), the processing is carried out by, or under the responsibility of, professionals subject to a duty of confidentiality (clinicians registered with the GMC/GPhC/NMC, and Cannexis staff bound by contractual confidentiality and the Acceptable Use Policy).

6. Retention

Special-category and criminal-offence data is retained in line with the DPO-ratified retention schedule:

Data class Retention
Clinical records (adult) 8 years after conclusion of treatment (children to 25th/26th birthday)
Audit logs (clinical-action subset) 10 years
Audit logs (operational) 7 years
FP10PCD prescription scans 8 years (part of the clinical record)
Controlled-drug register entries 7 years from last entry
DSAR / erasure case records 6 years from closure

The full schedule, including non-special-category classes, is in the Privacy & Data Protection Policy §10 and the ROPA.

7. Erasure

When the retention period for a class of special-category data ends, or where erasure is otherwise lawful and not overridden by a statutory retention duty, the data is securely deleted. On tenant decommissioning, records are first exported to the controlling clinic (so the clinic, as controller, can meet its own retention obligation) and Cannexis's residual copy is then rendered permanently unreadable by crypto-shredding (destruction of the encryption key). Crypto-shredding is not used to defeat a live statutory retention obligation — see the erasure wording in the Privacy Policy §12 and the tenant-offboarding runbook.

8. Review

This APD is reviewed at least annually and whenever a new special-category processing activity, a new Schedule 1 condition, or a material change to the law occurs. It will be retained for the duration of the processing and for 6 months after it ends, and earlier versions are kept for accountability.

Cannexis Biopharma Ltd · Company no. 16387680 · Registered office: 142-143 Parrock Street, Gravesend, Kent, DA12 1EY · ICO registration: ZC164947
Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY
Cannexis
ClinicalFlow Platform

Cannexis is the multi-tenant telemedicine and shared-care platform purpose-built for UK medical cannabis. We are a technology layer for CQC-registered clinics, specialist prescribers, pharmacist IPs, dispensing pharmacies and their patients — not a clinic.

UK GDPRDSPT-alignedCQC-readyUK-hosted

Platform

  • Modules
  • For clinics
  • For clinicians
  • For pharmacies
  • For patients

Company

  • About
  • Updates
  • Book a demo
  • hello@cannexis.org
  • Gravesend, Kent, United Kingdom
© 2026 Cannexis Biopharma Ltd · Company no. 16387680 · UK data residency
AboutFAQContactPoliciesPrivacyCookiesTermsAccessibility