Legal
Privacy Policy
How we collect, use, and protect your personal information on SimPatient.
Effective 5 June 2026 · Version 2.1 · Applies to simpatient.co.uk and app.simpatient.co.uk
1. Introduction
SimPatient ("SimPatient", "we", "us", "our") provides an AI-powered medical training simulation platform that enables learners to practise clinical communication with virtual patients in text, audio, and video modes.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to:
- Visitors to our marketing website at simpatient.co.uk
- Users of our application at app.simpatient.co.uk
- Prospective customers, learners (students), organisation administrators, and super administrators
If you are using SimPatient as part of a university, NHS organisation, or other institution, that institution is the Controller of your personal data for the purposes of the simulation service, and SimPatient acts as a Processor on its behalf. Where you have signed up directly as an individual, SimPatient is the Controller.
2. Who we are
SimPatient is operated by St Andrews Medical Innovations Limited (trading as SimPatient), a company registered in Scotland (SC705314).
- Registered address: Walter Bower House, Main Street, Guardbridge, St Andrews, Fife, KY16 0US
- Company number: SC705314
- ICO registration number: ZB284261
- Data Protection Officer: Mr Christopher Milne, Head of Information Assurance and Governance (dataprot@st-andrews.ac.uk)
- Contact: hello@simpatient.co.uk
3. Scope and summary
At a glance:
- We store all customer personal data on servers located in the European Union / United Kingdom.
- We do not transfer your personal data outside the EU/UK in identifiable form.
- Your conversation transcripts and any derived data are never used to train third-party AI models.
- SimPatient is designed for simulated clinical scenarios. You must not enter real patient data into the platform.
- You can request access, correction, deletion, export, or restriction of your personal data at any time by emailing hello@simpatient.co.uk.
4. Personal data we collect
4.1 Data you provide directly
| Category | Examples | When collected |
|---|---|---|
| Account data | Full name, email address, password (hashed), profile image, user role, organisation membership | Sign-up, profile updates, institutional invitations |
| Authentication data | Session tokens, multi-factor one-time codes | Login flow |
| Consultation data | Chat transcripts, audio recordings (where audio mode is used), video session data (where video mode is used) | Your use of the simulation |
| Reflection data | Free-text reflection answers after each consultation | Reflection step of the case flow |
| Feedback data | AI-generated feedback on your consultation (strengths, improvements) | Generated by our AI layer |
| Support data | In-app feedback, bug reports, screenshots you choose to attach | Optional feedback widget |
| Correspondence | Emails you send us, and our replies | Direct communication |
4.2 Data collected automatically
| Category | Examples | Notes |
|---|---|---|
| Device and log data | IP address, user agent, browser type, timestamps | Cookies and similar technologies |
| See section 11 below | ||
| Usage data | Which cases you open, session duration, credit consumption | |
| Consent records | Policy version you accepted, timestamp, IP address, user agent (kept as an audit trail) |
4.3 Data we do not collect
- We do not knowingly collect real patient medical data.
- We do not collect payment card data directly. Any future billing will be processed by a PCI-DSS-compliant payment processor.
- We do not purchase personal data from data brokers.
5. Special category data (Article 9)
SimPatient generates synthetic clinical scenarios. Simulated patient personas and the medical content within them are fictional and are not the personal data of any real person.
Your use of the platform may produce content that resembles health data (because you are practising clinical consultations). Because this content relates to a simulated patient and reflects your own educational performance, we do not treat it as Article 9 "special category" data about a real data subject.
You are contractually prohibited from entering real patient information, real clinical records, or any identifiable third-party health data into the platform. If you do so inadvertently, contact us immediately at hello@simpatient.co.uk and we will delete it.
We do not rely on the contractual prohibition alone. To reduce the foreseeable risk of real patient data being entered, we apply technical and organisational guardrails, including in-product warnings at the point of input, detection and redaction measures where feasible, and data-protection training for administrators. We assess this risk in our Data Protection Impact Assessment and keep these measures under review.
6. Why we use your personal data and our legal bases
| Purpose | Legal basis |
|---|---|
| Creating and managing your account; authenticating you; delivering the simulation service | Contract . Art. 6(1)(b) |
| Routing consultations through our AI providers to generate responses, voices, and avatars | Contract . Art. 6(1)(b) |
| Storing transcripts and feedback so you can review your progress | Contract . Art. 6(1)(b) |
| Keeping the platform secure, preventing abuse, enforcing acceptable use | Legitimate interests . Art. 6(1)(f) |
| Producing anonymised, aggregated analytics for service improvement | Legitimate interests . Art. 6(1)(f) |
| Recording your acceptance of this policy and other consents | Legal obligation . Art. 6(1)(c) / Legitimate interests . Art. 6(1)(f) |
| Sending transactional emails (invitations, password resets, verification codes) | Contract . Art. 6(1)(b) |
| Sending marketing communications (if you opt in) | Consent . Art. 6(1)(a) |
| Non-essential cookies and in-app feedback widgets | Consent . Art. 6(1)(a) |
| Complying with legal, regulatory, and tax obligations | Legal obligation . Art. 6(1)(c) |
| Establishing, exercising, or defending legal claims | Legitimate interests . Art. 6(1)(f) |
You can withdraw any consent you have given at any time by emailing hello@simpatient.co.uk or updating your preferences in the app. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
7. Who we share your personal data with
We share your personal data only with the sub-processors listed below, all of which are contractually bound by Data Processing Agreements and process your data exclusively on EU/UK infrastructure.
7.1 Sub-processors
We use a small number of carefully selected sub-processors (for cloud hosting, database and authentication, AI model inference, voice and avatar generation, transactional email, and in-app support) to deliver the Service. Each is bound by a written Data Processing Agreement, processes personal data exclusively on EU/UK infrastructure, and is contractually prohibited from using your data to train AI models.
A current, itemised list of our sub-processors (including the specific providers, their role, the data they process, and their processing region) is available to customers and prospective customers on request, by emailing hello@simpatient.co.uk. We will notify customers at least 90 days before adding or replacing a sub-processor that handles personal data. Institutional customers may object in accordance with their Data Processing Agreement.
7.2 Other recipients
We may also share your personal data with:
- Professional advisers: lawyers, accountants, auditors, bound by confidentiality
- Regulators and law enforcement: where we are legally required to do so
- A successor entity: in the event of a merger, acquisition, or sale of assets, subject to the same privacy protections
We do not sell your personal data, and we do not share it with advertising networks.
8. International transfers
All sub-processors listed above have committed to processing SimPatient customer personal data on infrastructure located within the European Union or the United Kingdom.
Where a sub-processor is a US-headquartered company (for example, OpenAI, ElevenLabs, Resend, Userback, Vercel, or Google Cloud), your personal data is nevertheless processed exclusively in an EU or UK region under a Data Processing Agreement that restricts the transfer of personal data outside those regions in identifiable form.
In the limited circumstances where a transfer outside the UK/EU becomes necessary (for example, support engineering access), we rely on:
- The UK International Data Transfer Addendum to the EU Standard Contractual Clauses; or
- The UK International Data Transfer Agreement (IDTA),
together with supplementary technical measures including encryption in transit (TLS 1.2+), encryption at rest, and role-based access controls. A copy of the transfer mechanism in use for any particular sub-processor is available on request.
9. How long we keep your personal data
We keep your personal data only for as long as necessary for the purposes described in this policy.
| Category | Retention period |
|---|---|
| Account data (name, email, role, organisation) | For the life of your account, plus 90 days after deletion |
| Consultation transcripts and messages | 24 months from creation, or the term of your institution's contract, whichever is longer |
| Audio recordings (held on ElevenLabs) | 24 months, subject to sub-processor retention policy |
| Reflection and feedback data | 24 months from creation |
| Consent records (audit trail) | 6 years after the consent was given or withdrawn |
| Invitation records | 3 months, or until accepted/revoked |
| One-time codes (MFA) | Up to 5 minutes, then automatically deleted |
| Activity / session tracking | Deleted automatically when a user is inactive beyond the platform threshold |
| Anonymised, aggregated analytics | Indefinitely (no longer personal data once anonymised) |
| Support correspondence | 3 years from last contact |
When you request account deletion, we delete or irreversibly anonymise your personal data within 30 days, subject to any legal obligation that requires us to retain specific data for longer (for example, financial records).
10. Your rights under UK GDPR
You have the following rights in relation to your personal data:
- Right of access (Art. 15): obtain a copy of the personal data we hold about you.
- Right to rectification (Art. 16): ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17): ask us to delete your personal data ("right to be forgotten").
- Right to restriction (Art. 18): ask us to limit how we process your data.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on legitimate interests, including profiling and direct marketing.
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.
- Right not to be subject to solely automated decision-making (Art. 22): we do not make legally significant decisions about you through automated means.
To exercise any of these rights, email hello@simpatient.co.uk. We will respond within the applicable time period under the UK GDPR. That period runs from the latest of: the date we receive your request, the date we have verified your identity (where we reasonably need to do so), and the date we receive any fee we are permitted to charge. It is normally one month, extendable by up to two further months for complex or numerous requests (we will tell you if an extension applies).
We may need to verify your identity before acting on a request. This is to protect your data from unauthorised disclosure.
Complaining to us first. If you are unhappy with how we have handled your personal data, we ask that you raise it with us first by emailing hello@simpatient.co.uk, so we have the opportunity to put things right. We will acknowledge your complaint within 30 days of receiving it, keep you informed of our progress, and aim to provide a substantive response within three months. We provide this complaints route in accordance with section 164A of the Data Protection Act 2018.
Complaining to us does not remove your right to complain to the UK's supervisory authority. You may complain to us, to the Information Commissioner's Office, or both:
- Information Commissioner's Office (ICO)
- Website: https://ico.org.uk/
- Helpline: 0303 123 1113
11. Cookies and similar technologies
We use a small number of cookies and similar technologies:
| Cookie | Purpose | Type | Lifespan |
|---|---|---|---|
| next-auth.session-token (prod: __Secure-next-auth.session-token) | Keeps you signed in across pages | Essential | Up to 30 days |
| superadmin_token | Authenticates super administrators | Essential | Session |
| pendingInviteToken | Carries an invitation through single sign-on so the right role and organisation are applied when you redeem it | Essential | Short-lived (cleared once the invite is applied) |
| Userback session | Runs the in-app feedback and bug-report tool for signed-in users (functional support tool, not analytics or advertising) | Essential | Session |
All of the cookies we currently use are essential: they are strictly necessary to sign you in, keep you signed in, authenticate administrators, apply invitations, and run the in-app feedback and support tool. Under the Privacy and Electronic Communications Regulations (PECR) these may be set without consent. We do not use analytics, advertising, or third-party tracking cookies in the app.
If in future we introduce any non-essential cookies (for example, analytics), we will not set them until you have given explicit consent through a cookie banner that lets you accept or reject them with equal prominence, and you will be able to change your choice at any time.
Full details are available in our separate Cookie Policy at simpatient.co.uk/cookies.
12. Security
We take the security of your personal data seriously. Our measures include:
- Encryption in transit via TLS 1.2 or higher
- Encryption at rest for all database and file storage
- Password hashing with bcrypt (salted, 10 rounds)
- Role-based access control enforced on every server-side route
- Server-side-only database access (no direct client-to-database writes)
- JWT-based session tokens with HttpOnly and Secure flags
- Multi-factor authentication for privileged administrator accounts
- Audit logging of administrator access to learner data
- Backups and disaster recovery via Google Cloud's resilient infrastructure
- Regular security reviews of our codebase and dependencies
No system is 100% secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you without undue delay.
13. Children and age
SimPatient is designed for adult medical learners (age 18+) using the platform in an educational context, either through an institution or as an individual learner.
You must be at least 18 years old to create an account as an individual. Where a learner under 18 uses the platform under institutional supervision (for example, a university or NHS trust), the institution is responsible for obtaining any necessary parental or guardian consent before inviting the learner.
Where any user of the platform is under 18, we treat their personal data as meriting higher protection. We have regard to the heightened protections for children's data under the Data (Use and Access) Act 2025 and to the ICO's Age Appropriate Design Code (the Children's Code), and we assess the processing of any under-18 user's data in our Data Protection Impact Assessment. The UK age at which a child can consent to information society services on their own behalf is 13; we do not rely on a child's own consent as a lawful basis for the simulation service, which is instead provided to institutional learners under the institution's lawful basis.
If you believe a child has provided us with personal data outside an institutional arrangement, contact hello@simpatient.co.uk and we will delete it.
14. Automated decision-making and profiling
We do not make decisions about you that produce legal or similarly significant effects using solely automated means (Art. 22 UK GDPR).
Our platform uses AI models to generate simulated patient responses and educational feedback. These outputs are educational in nature and are not decisions about you that have legal effect. A human (you, and where applicable your tutor) remains in control of any educational evaluation.
The AI-generated feedback is a formative learning aid. It is not designed or intended to be used as an automated assessment, grading, or examination tool, and it must not be used as the sole basis for any academic or professional decision about a learner. Any summative assessment remains the responsibility of the learner's institution and its human assessors.
15. Marketing
Where you have opted in, we may send you occasional emails about new features, product updates, or SimPatient-related educational content.
You can unsubscribe at any time via the link in every marketing email, or by emailing hello@simpatient.co.uk. Unsubscribing from marketing does not affect transactional emails (such as invitations, password resets, and service notices), which you cannot opt out of while you hold an account.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Publish the updated policy at simpatient.co.uk/privacy and app.simpatient.co.uk/privacy
- Increment the version number and update the "Effective date"
- Notify registered users by email and/or in-app notification where the change materially affects how your data is processed
Previous versions are available on request.
17. Contact us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details below.
Contact
St Andrews Medical Innovations Limited (trading as SimPatient) Data Protection Officer: Mr Christopher Milne, Head of Information Assurance and Governance DPO email: dataprot@st-andrews.ac.uk General email: hello@simpatient.co.uk Post: Walter Bower House, Main Street, Guardbridge, St Andrews, Fife, KY16 0US This Privacy Policy is governed by the laws of Scotland.
Related documents