Privacy & Data Protection Policy
Privacy policy (UK GDPR)
1. Introduction & scope
This policy explains how Cannexis Biopharma Ltd (“Cannexis”, “we”) handles personal data. It covers two distinct things, because our role is different for each: - The cannexis.org website — where we are the data controller for visitors, enquirers and business contacts; and - The ClinicalFlow platform (app.cannexis.org) — the technology layer that independent clinics and pharmacies use to deliver care. Here, the clinic or pharmacy is the controller of patient clinical data, and Cannexis is generally the processor acting on its instructions.
We comply with the UK GDPR and the Data Protection Act 2018, and we follow NHS data-security expectations including the Data Security and Protection Toolkit (DSPT).
2. Our roles — controller and processor
| Context | Cannexis's role | Who the controller is |
|---|---|---|
| Website visitors, enquiry forms, marketing contacts | Controller | Cannexis |
| Clinic / pharmacy (business) account & staff data | Controller | Cannexis |
| Our own platform telemetry, security logs, audit records | Controller | Cannexis |
| Patient clinical records on the platform | Processor | The treating clinic / pharmacy (our tenant) |
| Dispensing & controlled-drug records after handover to a pharmacy | Processor for routing; pharmacy is independent controller of its dispense record | The dispensing pharmacy |
What this means for patients. If you are a patient, your treating clinic or pharmacy is the controller of your clinical records and has its own privacy notice. You can exercise your rights through the platform or through that clinic, and Cannexis (as the technology provider) will support them. For clinical records, Cannexis acts only as the clinic's processor — on its instructions, under a written data-processing agreement — and cannot make decisions about your data on its own.
3. The personal data we process
3.1 Website visitors & enquirers (Cannexis as controller)
- Contact details you give us (name, email, phone, organisation, your message);
- Technical data (IP address, browser/device type, and cookie data — see section 14);
- Records of your correspondence with us.
3.2 Business / tenant contacts (Cannexis as controller)
- Account, contractual and billing-contact details for clinics, pharmacies and partners;
- Login, role and authentication data for staff users (including multi-factor authentication secrets, stored encrypted).
3.3 Platform — patient & clinical data (Cannexis as processor)
When a clinic or pharmacy uses ClinicalFlow to deliver care, the platform processes, on the clinic's behalf: - Identity & contact data — name, date of birth, address, contact details, NHS number; - Clinical data — medical history, conditions, symptoms, allergies, medications, consultation notes, eligibility and assessment information; - Prescribing & shared-care data — shared-care agreements, prescriptions, and controlled-drug register entries; - Dispensing & fulfilment data — dispense records and delivery details; - Payment metadata — references, amounts, status and timestamps. Cannexis does not hold full card details; card payments are handled by the pharmacy's own regulated payment provider.
4. Special category (health) data
Health and clinical data is “special category” data under Article 9 of the UK GDPR and is given extra protection. On the platform it is encrypted, access is tightly role-restricted, and every access to it is recorded in a tamper-evident audit log. Our lawful conditions for processing it are set out in section 6, and the additional safeguards required by the Data Protection Act 2018 (Schedule 1) are documented in our Appropriate Policy Document.
5. NHS data & integrations
To support safe care, the platform is being built to connect to NHS services. These NHS integrations are not yet live — they are introduced in phases as our NHS onboarding (ODS registration, Data Security and Protection Toolkit, and the NHS Connection Agreement) completes. When they go live: - NHS login & Personal Demographics Service (PDS) — you will be able to sign in with NHS login so we can verify your NHS number against the NHS Personal Demographics Service; - Summary Care Record / GP Connect (a later phase) — only with your explicit consent, your prescriber will be able to retrieve relevant NHS records (such as your medication and allergy history) to prescribe safely.
You will always be able to decline, and to withdraw consent. We will update this notice as each NHS integration becomes available, and we describe here only what the platform actually does at the time you read it.
6. Why we process data & our lawful bases
| Purpose | Lawful basis (Art 6) | Health-data condition (Art 9) |
|---|---|---|
| Providing care, prescribing and dispensing (platform) | Performance of a contract (6(1)(b)); legal obligation (6(1)(c)) | Provision of health/social care (9(2)(h)) |
| Controlled-drug records, GP notification, safety reporting, records retention | Legal obligation (6(1)(c)) | Health/social care (9(2)(h)) |
| Verifying prescriber registration / NHS number | Public task / legitimate interests (6(1)(e)/(f)) | — |
| Security, audit, fraud prevention, service operation | Legitimate interests (6(1)(f)) | — |
| Account administration & billing (business contacts) | Contract (6(1)(b)); legitimate interests (6(1)(f)) | — |
| Website enquiries | Legitimate interests (6(1)(f)) | — |
| Marketing communications | We do not currently send marketing communications, so we do not rely on consent (6(1)(a)) for this. If we introduce them, they will be on a PECR-compliant opt-in basis and you will be able to opt out at any time | — |
For clinical care on the platform, the lawful basis is determined by your controller (your treating clinic or pharmacy) and flowed down to us through our data-processing agreement with them. Depending on the controller, that basis is a public task (Art 6(1)(e)), the performance of your treatment contract (Art 6(1)(b)), or a legal obligation (Art 6(1)(c)); the health-data condition is Art 9(2)(h) (provision of health and social care), met because the processing is carried out by, or under the responsibility of, professionals bound by a duty of confidentiality (Art 9(3)). Cannexis acts as the processor, on the controller's instructions.
7. Automated processing & the Shared Care Agreement engine
The platform includes a Shared Care Agreement (SCA) engine that runs automated checks to help clinicians prescribe safely within agreed limits — for example flagging when a request falls outside the parameters a specialist has set. These checks support, and do not replace, the judgment of a registered clinician, who remains responsible for clinical decisions. We are not engaged in solely automated decision-making that produces legal or similarly significant effects without human involvement. If an automated check affects your care, you have the right to ask for a human review.
8. Who we share data with
Our service providers (“sub-processors”) act on our instructions under a written contract. The principal recipients are: | Recipient | Purpose | Location | Status | |---|---|---|---| | Amazon Web Services (AWS) | Secure hosting, database and storage — the platform's core infrastructure | UK (London / eu-west-2) | Live | | Twilio SendGrid | Transactional email (e.g. notifications; no clinical detail) | USA — safeguarded (see section 9) | Live | | Twilio | SMS notifications (no clinical content) | USA — safeguarded | Live | | Daily (video) | Secure video consultations between you and your clinician — this channel carries clinical content (the consultation itself) | USA — safeguarded; transfer risk assessment in progress (section 9) | Live | | Microsoft (Microsoft 365) | Our corporate email and IT (business contacts and staff data; not patient clinical records) | UK / EU | Live | | Payment providers (the pharmacy's own Stripe / GoCardless merchant) | Taking patient and tenant payments. Cannexis does not hold card details. | UK / USA — safeguarded | Not yet live (pharmacy-direct model) | | Couriers (DPD, Royal Mail, DHL) | Delivering medication (name & address only) | UK | Not yet live | | Error / performance monitoring providers | Keeping the service reliable (data minimised, EU/UK region) | UK / EU | Where enabled | | NHS services & regulators (PDS, NHS login, GMC/GPhC) | Verification and, with consent, record retrieval | UK | Phased — see section 5 |
A current, detailed sub-processor register is maintained by our DPO and is available on request. Each provider acts on our instructions under a written data-processing agreement. We may also disclose data where required by law, regulation, or a court order.
9. International transfers
The platform's patient and clinical data is hosted in the UK (AWS, London / eu-west-2). Some service providers process limited data outside the UK, principally in the USA:
| Provider | What is transferred | Safeguard |
|---|---|---|
| Twilio (SMS) and Twilio SendGrid (email) | Contact details and non-clinical message metadata | UK-US Data Bridge (provider DPF-certified) |
| Daily (video) | The video consultation (clinical content) | UK-US Data Bridge or UK IDTA + transfer risk assessment — being confirmed and assessed |
| Microsoft 365 | Corporate email/IT (business-contact and staff data) | UK/EU data residency; UK-US Data Bridge for any US transfer |
| Payment providers (when live) | Payment metadata | UK-US Data Bridge where US; UK provider = no transfer |
Where we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) the recipient is certified under that framework; otherwise we use the UK International Data Transfer Agreement / Addendum supported by a transfer risk assessment. We maintain a transfer-risk-assessment register and will provide further detail on request.
10. How long we keep data
We keep data only as long as necessary, or as the law requires. Health records in particular are subject to statutory retention rules that can override a request to delete them (see section 12). | Data | Retention period | Basis | |---|---|---| | Clinical records (consultations, prescriptions, shared-care) | 8 years after the conclusion of treatment (adults); children until 25th birthday (or 26th if treatment ended at 17) | NHS Records Management Code of Practice 2021 | | Controlled-drug register entries | 7 years from last entry | Misuse of Drugs Regulations 2001 (2-year minimum; retained longer as good practice) | | Audit logs (clinical-action subset) | 10 years | NHS RM Code / audit-retention standard | | Audit logs (operational) | 7 years | DSPT / ICO operational standard | | FP10PCD prescription scans | 8 years (held as part of the clinical record) | NHS RM Code / Misuse of Drugs Regs | | Billing & invoice records | 7 years | HMRC tax record-keeping (6-year minimum) | | Website enquiry / marketing data | Until you withdraw, or it is no longer needed | Consent / legitimate interests | | Data subject request case records | 6 years from closure | UK GDPR accountability |
Retention schedule reviewed and confirmed by LHI Consulting (DPO), and signed off as part of the full policy suite on 26 June 2026.
11. How we keep data secure
- Encryption — sensitive data is encrypted at rest (including field-level encryption of health identifiers) and in transit;
- UK data residency — patient and clinical data is hosted in the UK;
- Access control — role-based access on a least-privilege basis, with multi-factor authentication for clinical and administrative users;
- Tamper-evident audit — every access to clinical data is recorded in an append-only, integrity-checked log;
- Assurance — we work to recognised standards including Cyber Essentials and the NHS Data Security and Protection Toolkit.
12. Your rights
Under the UK GDPR you have the right to: be informed; access; rectification; erasure (subject to legal retention rules); restriction; portability; object (to legitimate-interests processing, and to direct marketing at any time); and to request human review of any automated check that significantly affects your care.
Erasure of health records — the honest position. Health records must, by law, be kept for set periods, and during that time they must remain available to be produced. So a request to erase clinical data may be refused where retention is legally required, and we will explain why. Where erasure is appropriate and the data is no longer legally required, your clinic (as controller) directs it and we securely delete it. When a clinic stops using the platform, we first export its records to the clinic so it can keep meeting its legal retention duty; only then is our residual copy rendered permanently unreadable by crypto-shredding (destroying the encryption key). We do not use crypto-shredding to make records that are still within their statutory retention period unavailable — those remain retrievable by the controlling clinic until that period ends.
13. How to make a request
See our companion notice, UK GDPR & Your Data Rights. In short: patients can use the “Request my data” tools in the platform, or contact our DPO (section 16). We respond within one month (extendable by up to two further months for complex or numerous requests, in which case we will tell you). Requests are normally free.
14. Cookies
The Website uses a minimal set of cookies. Non-essential cookies (such as analytics) are only set with your consent via our cookie banner. Full detail is in our Cookie Policy.
15. Children's data
Where the platform is used to treat a patient under 18, additional safeguards apply, including age-appropriate information and parental/guardian involvement where relevant. Children's clinical records are subject to specific NHS retention rules.
16. Our Data Protection Officer & how to contact us
We have appointed an independent Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY. Please contact the DPO with any data-protection question, or to exercise your rights.
17. Complaints
We hope to resolve any concern directly. If you wish to make a formal data-protection complaint, please use our Data Protection Complaints Procedure — we will acknowledge it within 30 days (we aim for 5 working days) and respond. You also have the right to complain to the Information Commissioner's Office (ICO) at any time: ico.org.uk · helpline 0303 123 1113.
18. Changes to this policy
We review this policy at least annually and update it when our processing changes. The current version is always the one published on the Website, with its effective date shown above.
Data Protection Officer: LHI Consulting — info@lhiconsult.com · c/o Cannexis Biopharma Ltd, 142-143 Parrock Street, Gravesend, Kent, DA12 1EY
