Product Our Concept Pricing FAQ
Contact Support Sign In

Privacy Policy

1. Controller and processor roles

Vitals is used by clinics to manage their own patients' data. Two distinct roles apply, and it's important to understand which applies to which data:

2. Our access to your clinic's data

Vitals is architected so that one clinic can never see another clinic's data — enforced at the database level (Row Level Security), not just in the application interface. OST Automation may access clinic and patient data solely for legitimate operational purposes, such as providing technical support you've requested, investigating a security issue, or reviewing aggregate, non-identifying usage statistics to maintain the platform. We do not access patient data to read, use, or disclose it for any other purpose, and we never sell it.

3. Information we collect

From clinics and staff

Patient data entered by clinics

Usage data

4. How we use information

We do not use patient data for advertising, and we do not sell personal data of any kind, to anyone, under any circumstances.

Where UK GDPR applies, we (or the relevant clinic, for patient data) rely on the following legal bases: performance of a contract (providing the service a clinic has signed up for), legitimate interests (maintaining and securing the platform), and consent (where a clinic has separately obtained a patient's consent for a specific purpose, such as WhatsApp reminders).

6. Who we share data with

We use a limited number of trusted subprocessors to operate Vitals:

We do not share data with any party for their own marketing purposes. We may disclose data where required by law, or to protect the rights, safety, or property of OST Automation, our customers, or others.

7. Where data is stored

Vitals' production database is hosted in West Europe (London, UK). Data is encrypted both in transit and at rest.

8. Data retention

We retain data for as long as a clinic's account remains active. If an account is closed, associated data is deleted within 30 days, unless the clinic requests an export beforehand (available at any time via the in-app Backup & Import tool) or longer retention is required by law. All processing takes place within the UK and European Economic Area — we do not transfer clinic or patient data outside the UK/EEA.

9. Security & breach notification

We apply industry-standard safeguards, including encryption in transit and at rest, hashed credential storage, and database-level access controls (Row Level Security) ensuring one clinic's data is never accessible to another. No system is perfectly secure. In the event of a personal data breach affecting a clinic's data, we will notify the affected clinic without undue delay, and, where required by law, support the clinic in notifying the relevant supervisory authority within 72 hours of becoming aware of the breach.

10. Your rights

If you are a clinic, you can access, export, or delete your data at any time from within Vitals, or by contacting us. If you are a patient and have a question about how your data is handled, please contact your clinic directly — they control your records, and we act only on their instructions. Where UK GDPR applies, individuals have rights including access, rectification, erasure, restriction, portability, and objection, subject to applicable exemptions.

11. Special category (health) data

Patient medical information constitutes "special category data" under UK GDPR, warranting a higher standard of protection. Clinics using Vitals to store such data act as the data controller and are responsible for ensuring they have an appropriate lawful basis (typically, provision of healthcare, or explicit patient consent) for processing it. We support this by applying strict technical access controls so that patient data is only ever accessible to the clinic that entered it.

12. Cookies

Our website and application use only essential cookies required for authentication and core functionality. We do not use third-party advertising or tracking cookies.

13. Children's data

Vitals may be used by clinics to store medical records belonging to minors, entered and controlled by the clinic as part of standard patient care, with the same protections applied as to any other patient record. Vitals itself is not directed at children as end users of the software.

14. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to clinic administrators. Continued use of Vitals after a change constitutes acceptance of the updated policy.

15. Contact us

Questions about this policy, or requests relating to your data, can be sent to contact@ostautomation.co.uk.