Privacy Policy

Wisebee Privacy Policy

Version 1.1. Last updated 12 August 2026.

1. Introduction

Wisebee Ltd (“Wisebee”, “we”, “us”) provides a software platform that pharmacies, clinics and other providers use to arrange and record consultations with the people they care for.

This policy explains what we do with personal data. It covers our website at wisebee.io and the Wisebee platform.

We handle personal data in two very different ways, and which one applies changes your rights and who you should contact. Section 2 explains the difference. If you are a patient, sections 2 and 4 are the ones that matter to you.

We are Wisebee Ltd, a company registered in Scotland under number SC725600, with our registered office at Unit 35, Camperdown Street, Dundee DD1 3JA. You can reach us at info@wisebee.app with any question about this policy or about personal data.

2. The two roles we play

Where we decide what happens to personal data, we are the controller. This covers people who visit our website, enquire about Wisebee, hold an account with us, or contact our support team. We decide why we hold that information and what we do with it, so this policy governs it and your rights under it are exercised against us.

Where a pharmacy or clinic decides what happens to personal data, we are only the processor. This covers patient information held in the platform: appointments, consultation notes, questionnaire answers, verification photographs and anything else a provider records about the people it cares for. The provider decides what is collected and why. We act only on their written instructions, under a data processing agreement with them. We do not decide what happens to that information, we do not use it for our own purposes, and we do not sell it or use it to train anything.

If you are a patient, this matters practically. Your pharmacy or clinic is responsible for your information, and their privacy notice is the one that governs it. If you want to know what is held about you, or want it corrected or deleted, contact them first. If you contact us instead, we will normally refer your request to them and assist them in responding to it, because the decision is theirs to make and not ours.

Nothing in this section limits what we are responsible for. Where the law makes a processor directly liable, we are directly liable.

3. What we collect where we are the controller

If you visit our website: technical information about your device, browser and connection, and information about which pages you looked at. Our cookie notice explains which cookies the website sets and how to control them.

If you use the Platform: the Platform itself sets only cookies that are strictly necessary for it to work — your session, protection against cross-site request forgery, and a “remember me” cookie if you choose that option. The Platform sets no analytics or marketing cookies.

Bot protection on public forms. Our booking pages use Google reCAPTCHA to distinguish people from automated systems. It sends your IP address and information about your browser to Google, and Google sets its own cookies in your browser. Without it, booking forms would be open to abuse.

If you enquire about Wisebee: your name, the organisation you work for, your email address and telephone number, and what you told us about what you are looking for.

If you hold an account: your name, email address, telephone number, job role, the organisation you belong to, your account credentials, and records of your activity on the platform. Where you administer an account we also hold billing and payment records.

If you contact support: whatever you tell us, and our record of how we handled it.

We do not buy contact lists, and we do not use data brokers to find prospective customers.

We do not collect special category data about you in this role. That means we do not collect information about your health, race, religion, sexual orientation, political opinions, trade union membership, genetics or biometrics for our own purposes, and we do not collect information about criminal convictions. This is confined to our role as controller. Health information about patients is held in the platform on a provider’s instruction, and section 4 covers it.

4. Patient data, where we are the processor

The platform holds information that providers record about the people they care for. Depending on what a provider has chosen to use, that can include:

  • name, contact details, address and date of birth
  • appointment and consultation records
  • consultation notes written by a clinician
  • questionnaire and assessment answers
  • transcripts of consultations, where the provider uses transcription
  • photographs of an identity document, of a person’s face, or showing body shape, weight or height, where the provider uses verification, together with the reviewer’s decision
  • payment records, where the provider takes payment through the platform

This information is held on the provider’s instruction. The provider determines the purposes and means of processing it and remains responsible for it as controller. We keep it secure, we make it available to the staff they authorise, and we delete it when they tell us to or when the retention period they have set expires. We do not use it for our own purposes — no advertising, no training, no sale, and nothing beyond operating the platform, keeping it secure and supporting it.

Consultation audio and video are never written to disk. Where a consultation is held through the platform, the audio and video pass through and are not stored at any point. Where transcription is switched on, only the resulting text is kept.

Verification photographs are captured through the device camera. The platform does not offer an option to choose an existing picture. A person reviews them, not a computer. We use no facial recognition and no automated system to identify anyone or to decide anything about them. Every occasion on which a verification photograph is viewed is recorded against the name of the person who viewed it.

5. Why we use personal data, and our lawful basis

Where we act as controller:

What we do Why Lawful basis
Respond to an enquiry To answer you and explain the product Legitimate interests, being the operation of our business
Provide the platform to a customer To deliver what was agreed Performance of a contract
Administer accounts, billing and renewals To run the commercial relationship Performance of a contract
Provide support To resolve problems Performance of a contract, and legitimate interests
Keep the platform secure, detect misuse, investigate incidents To protect the platform and the people whose data is in it Legitimate interests
Improve the platform To make it work better Legitimate interests
Send service messages about bookings, appointments and verifications Because you asked for the thing they relate to Performance of a contract
Send marketing To tell you about what we do Consent, or legitimate interests where you are an existing business contact
Keep financial and tax records Because we are required to Legal obligation

You can opt out of marketing at any time, using the link in any marketing message or by contacting us. Service messages cannot be switched off while you are using the service, because they are how the service works.

Where we act as processor, our lawful basis is not the relevant question. The provider establishes the lawful basis, and where health information is involved, the additional condition that Article 9 requires.

6. Who we share personal data with

We use a number of suppliers to run the platform and our business. They act on our instructions, they are bound by written data protection terms, and they may not use personal data for their own purposes.

A current list of every supplier with access to personal data held in the platform is available on request. Customers are given at least thirty days’ notice before we add or replace one, and may object.

We also share personal data:

  • with professional advisers, where we need advice
  • with a regulator or a court, where we are required to
  • with prospective purchasers or investors and their professional advisers, where reasonably necessary for a corporate transaction and subject to confidentiality and data protection safeguards

We do not sell personal data. We do not share it for anyone else’s marketing.

7. Sending personal data outside the United Kingdom

Some of the suppliers we use are outside the United Kingdom, so some personal data is transferred abroad. Section 8 identifies the transfers involving patient information, because those are the ones that matter most.

Where personal data leaves the United Kingdom to a country that has not been recognised as offering adequate protection, we put in place the safeguards the law requires: the Standard Contractual Clauses as modified by the Information Commissioner’s International Data Transfer Addendum. We also carry out and document an assessment of whether that safeguard is effective in the destination country, and we review it. Customers may request a copy of the safeguards we rely on by contacting us.

8. Artificial intelligence in the platform

Providers can choose to switch on features that use artificial intelligence. Where a provider has not switched them on, none of this applies and no information leaves the United Kingdom. Where a provider has switched them on:

Transcription. Audio from a consultation is sent, as it happens, to Deepgram, Inc. in the United States, which converts it to text and returns it. The audio is processed in memory and is never stored by that supplier, at any point. It is not used to train or improve anything. Only the resulting transcript is kept, and it is kept in the United Kingdom.

Document generation and the in-platform assistant. Consultation transcripts, clinical notes and questionnaire answers may be sent to Anthropic, PBC in the United States, which produces a draft document or answers a clinician’s question. That supplier does not retain the content, and does not use it to train its models. One exception is worth stating plainly: content that the supplier’s automated safety systems flag may be retained by them for up to two years.

Both transfers are covered by the Standard Contractual Clauses as modified by the UK International Data Transfer Addendum, and by a documented assessment of the transfer.

Nothing the platform generates is a decision. Transcripts and drafts are produced by software, they can be wrong, and a clinician is required to read and check them before relying on them, sending them to anyone, or putting them in a record. No decision about any person is made by software alone. You have a right not to be subject to a decision based solely on automated processing. The platform does not make decisions about individuals by automated means alone.

9. Keeping personal data secure

We take appropriate technical and organisational measures to protect personal data, and we review them.

All connections to the platform, and to every supplier, use encryption in transit. Consultation records – transcripts, clinical notes, questionnaire answers, generated documents, messages and verification photographs – are encrypted while stored. Access is limited by role, staff are subject to confidentiality obligations, and access to the systems that run the platform is restricted.

No internet service can be completely secure. If a breach affects personal data and is likely to result in a risk to people, we notify those we are required to notify, within the time the law allows. Where we hold data as processor, we notify the provider, who decides what to tell the people affected.

Customers can ask for a description of the measures in place, and receive one. It is also set out in full in the data processing agreement we enter into with every customer.

10. How long we keep personal data

Where we are the controller:

What How long
Enquiries that do not become customers Two years from last contact
Customer account records For the term of the agreement, then as below
Financial and transaction records Six years from the end of the relevant financial year, because tax law requires it
Support correspondence Two years from resolution
Marketing preferences Until you opt out, and then a record of the opt-out so that we respect it

Where we are the processor, the provider decides. Their retention settings determine how long information is kept, and we act on them. As a general position, information is retained for the term of our agreement with the provider and deleted afterwards in accordance with it.

Some periods are enforced automatically by the platform. Verification photographs are deleted permanently once the period the provider has set has passed. Notification records are deleted after ninety days and technical interface logs after thirty. Other information is retained for the term of the agreement.

If you are a patient and want to know how long your information is kept, ask your pharmacy or clinic. They set the period and we do not.

Copies of information persist in backups until those backups expire. Pending that, they are placed beyond use, are not processed for any purpose, and are deleted again if a backup is ever restored.

11. Your rights

You have the right to ask for access to your personal data, to have it corrected, to have it erased, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent where we relied on consent. Each of these rights is subject to the conditions and exemptions the law attaches to it, so not every right applies in every situation. Where a decision would be made about you by automated means alone, you have the right not to be subject to it, though as section 8 explains, we make no such decisions.

How to exercise them depends on which role applies.

If we are the controller — you are a website visitor, an enquirer, an account holder or a support contact — contact us at info@wisebee.app. We will respond within one month. If a request is complex we may take longer, and we will tell you why within that first month.

If you are a patient, contact your pharmacy or clinic. They hold the information and the decision is theirs. If you contact us, we will refer your request to them within five days and assist them in responding to it.

You will not be charged, unless a request is clearly unfounded or excessive.

12. Complaints

If you are unhappy with how we have handled your personal data, tell us first at info@wisebee.app and we will look into it.

You also have the right to complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it first.

Complaints about your care, your medicine or a decision made about you are matters for your pharmacy or clinic, not for us. We provide the software; we do not provide healthcare and we make no clinical decisions.

13. Changes to this policy

We update this policy when what we do changes, when the law changes, or when we add features.

Every version carries a version number and a date at the top. Where a change is significant we tell customers before it takes effect, and we do not apply changes retrospectively to something already done.

Glossary

Controller — the organisation that decides why and how personal data is used, and is responsible for meeting the obligations that apply to it as controller.

Processor — an organisation that uses personal data only on a controller’s instructions, and not for its own purposes.

Sub-processor — a supplier a processor engages to help it deliver the service, which also handles personal data.

Special category data — the most sensitive kinds of personal data, including anything about a person’s health. Extra conditions apply before it can be used.

Standard Contractual Clauses and the International Data Transfer Addendum — standard legal terms, approved for use in the UK, that protect personal data when it is sent to a country whose laws do not offer equivalent protection.

Enquire about Wisebee Enterprise

Launching very soon

Be the first to know when Wisebee Pro launches

Please email me when Wisebee Pro is available