Privacy Policy
How Doctopass handles personal data, and health data in particular — across the Doctopass Android application on Google Play and the web platform at doctopass.com.
- Published by
- DOCTOPASS SARL
- Applies to
- The Doctopass Android application on Google Play, and the Doctopass web platform at doctopass.com
- Privacy contact
- contact@doctopass.com
- Delete your account
- doctopass.com/delete-account/
- Version
- 1.1
In short
Doctopass is clinical software for doctors, secretaries and patients in Tunisia. These are the categories of data the Android app collects, and what each is for.
- Account and profile data — your name, e-mail address, telephone number and professional details, so you can sign in and be identified to your practice.
- Health data — consultation notes, dictated audio and its transcript, documents and clinical images, appointments and prescriptions. This is the clinical record, and it is held for the practice you work with or are treated by.
- Device permissions you grant — camera, photos and files, microphone, location, contacts, and notifications. Each is asked for at the moment the feature needs it, each can be declined, and each is explained in section 19.
- Device and diagnostic data — device model, Android version, app version, IP address, crash reports and in-app usage events, so the app can be operated and repaired.
We do not sell your data, the app shows no advertising, and health data is never used for advertising or profiling. Data is encrypted in transit and at rest; the security measures are in section 10 and the parties who may receive data are in section 11. You can delete your account and its data at any time — how, what goes, what must legally stay, and how long it takes are in section 20.
Doctopass is not a medical device and does not diagnose, treat, cure or prevent any disease. Every clinical decision stays with the treating clinician.
Document control
- Document
- Privacy Policy (Politique de Confidentialité)
- Platform
- Doctopass
- Data controller (operational data)
- DOCTOPASS SARL
- Data Protection Officer
- contact@doctopass.com
- Version
- 1.1
- Effective date
- 1 September 2026
- Mobile application
- Doctopass for Android, on Google Play — see section 19
- Primary supervisory authority
- INPDP (Tunisia) — submitted
1. Introduction and Scope
1.1This Privacy Policy explains how personal data is handled in connection with the Doctopass platform (“Platform”) operated by DOCTOPASS SARL (“DOCTOPASS”, “we”, “us”).
1.2It applies to Doctors, Patients, and Secretaries who use the Platform, and to visitors who interact with us in connection with the Platform.
1.3This Policy should be read together with the Terms of Use and, for Doctors and healthcare-provider users, the Advanced Data & Privacy Agreement (Data Processing Agreement).
1.4Frameworks. The Platform is designed to align with:
- Tunisia — Loi organique n° 2004-63 du 27 juillet 2004 relative à la protection des données à caractère personnel, and the requirements of the INPDP (the operative framework at launch);
- European Union — Regulation (EU) 2016/679 (“GDPR”), where and when we process the personal data of individuals in the EU;
- United States — the Health Insurance Portability and Accountability Act (“HIPAA”), where and when we act as a business associate of a U.S. covered entity; and
- Information security — an information-security management system aligned to the ISO/IEC 27001 control set. We do not claim ISO/IEC 27001 certification.
2. Our Role: Controller and Processor
The Platform involves two distinct data-protection relationships. Understanding which applies is important to your rights.
2.1DOCTOPASS as processor / business associate — clinical data. For health and medical data that a Doctor processes about their Patients (for example consultations, diagnoses, prescriptions, examination findings, imaging, and medical records), the Doctor (or their practice/clinic) is the data controller — and, under HIPAA where applicable, the covered entity. DOCTOPASS processes that data on the Doctor’s behalf, as a processor (business associate), under documented instructions and under the Data Processing Agreement. For that data, you should direct requests about your rights primarily to your Doctor; we will support your Doctor in responding.
2.2DOCTOPASS as independent controller — operational data. For certain data, DOCTOPASS determines the purposes and means of processing and therefore acts as an independent controller. This includes account and identity data, authentication and security-log data, billing data for the use of the Platform, product-operation and diagnostic data, and irreversibly anonymised data used to improve the Service. This Policy governs that processing.
2.3Patients as data subjects. Patients interact with us directly (their own account, messaging, uploads, consents). Where a Patient provides data directly to us for account, authentication, communication, or billing purposes, we act as controller for that limited processing, as described in this Policy.
3. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Health data / special-category data — personal data concerning health, which receives heightened protection under Applicable Law.
- Processing — any operation performed on personal data (collection, storage, use, disclosure, erasure, etc.).
- Controller — the party that determines the purposes and means of processing.
- Processor — the party that processes personal data on behalf of a controller.
- Anonymised data — data rendered so that individuals are not, and cannot reasonably be, identified; anonymised data is not personal data.
- Sub-processor — a third party engaged by a processor to process personal data.
4. Categories of Personal Data We Process
The categories depend on your Role.
4.1All Users — account and identity data. Name, professional or personal identifiers, email address, telephone number, password (stored only as a salted hash), Role, preferences, and authentication data (including two-factor authentication secrets, kept in protected form).
4.2Security and technical data. IP address, device and browser information, session identifiers, timestamps, access and audit logs, and error-diagnostic data. This data is processed to secure the Platform and to maintain the audit trail required for health data.
4.3Doctors — professional and practice data. Professional details, practice configuration, service catalogue, secretary assignments and permissions, availability, and billing/revenue data relating to the practice.
4.4Patients — health and medical data (special category). Where entered by or on behalf of a Doctor or Patient: vitals, medications (current and past), allergies, conditions, family history, vaccinations, consultations (including, with the Patient’s consent, consultations recorded by other Doctors), examination findings, diagnoses, treatment plans, prescriptions, laboratory results, imaging, surgery history, and uploaded documents.
4.5Communications data. Messages exchanged through the Platform, and metadata about invitations and notifications.
4.6Billing and payment data. Invoices, line items, amounts, currency, payment status, and limited transaction data. Full card/payment-instrument details are handled by the payment providers, not stored by us.
4.7Data derived for Service improvement. Irreversibly anonymised data, including data derived from the difference between AI-generated drafts and clinician corrections, from which individuals cannot be identified (see Section 7.4).
We do not intentionally collect special-category data beyond what is necessary for the Service, and we do not use Patient health data for advertising.
5. Purposes of Processing and Legal Bases
The table below sets out, for the processing for which DOCTOPASS is controller, the purposes and the legal bases. For clinical data where DOCTOPASS is processor, the legal basis is determined and maintained by the Doctor as controller.
| Purpose | Data used | Legal basis (Tunisia / GDPR) |
|---|---|---|
| Create and manage Accounts; authenticate Users | Account, identity, authentication data | Performance of the contract (Terms of Use); consent of the data subject where required under Tunisian law |
| Provide the Service to Doctors as processor | Clinical data (as processor) | Instruction of the Doctor as controller; the controller’s own basis (e.g. provision of health care; explicit consent) |
| Secure the Platform; prevent fraud and abuse; maintain audit trails | Security, technical, audit data | Legitimate interests in security; compliance with legal obligations (including audit obligations for health data) |
| Operate billing and process payments | Billing and limited payment data | Performance of the contract; compliance with accounting/tax obligations |
| Communicate service and security notices | Contact data | Performance of the contract; legitimate interests / legal obligation |
| Support and respond to requests, including rights requests | Relevant data | Legal obligation; legitimate interests; consent where applicable |
| Improve and develop the Service and its models | Irreversibly anonymised data only | Not personal data once anonymised; the anonymisation step is carried out under legitimate interests / with the necessary basis before anonymisation |
| Comply with legal obligations and defend legal claims | Relevant data | Compliance with legal obligations; establishment/exercise/defence of legal claims |
Where we rely on consent, you may withdraw it at any time (Section 12); withdrawal does not affect the lawfulness of processing before withdrawal. Where processing of health data requires explicit consent under Applicable Law, that consent is obtained and maintained by the relevant controller.
6. Health Data — Specific Safeguards
6.1Health data is special-category data and is subject to heightened protection. It is processed strictly for the purpose of enabling the Doctor to provide care and to operate their practice, and for the security and audit purposes described above.
6.2Access to health data is restricted on a need-to-know basis, enforced by (a) role-based access control and (b) per-record ownership checks, so that a User can access only the health data they are authorised to access.
6.3Cross-Doctor access is consent-gated. A Doctor other than the one who created a record can view a Patient’s records only where the Patient has given explicit, revocable consent, granted per Doctor. Every such cross-Doctor access is recorded in the audit trail.
6.4Every read and write of Patient data is logged in an audit trail, which is available to the responsible Doctor and retained as described in Section 9.
7. Artificial Intelligence, Automated Decisions, and Model Improvement
7.1Doctor-only assistance. AI features assist Doctors only — for example, by drafting a structured medical report from brief clinician input. They are not offered to Patients and are not used for patient self-diagnosis or triage.
7.2No solely-automated decisions with legal or similarly significant effect. AI outputs are drafts. A Doctor must review and explicitly confirm them before they are used. No decision producing legal effects concerning you, or similarly significantly affecting you, is taken solely by automated means. A qualified Doctor is always responsible for the outcome (meeting the human-involvement requirement of GDPR Article 22 where applicable).
7.3AI processing on a self-hosted model. All artificial-intelligence processing is performed on a large language model self-hosted by DOCTOPASS within the applicable jurisdiction. This covers speech-to-text as well as text generation: dictated audio recorded through the mobile application is transcribed on the same self-hosted infrastructure. No personal data, and no clinical input — including raw audio — is transmitted to any external artificial-intelligence, speech-recognition or third-party model provider. As a defence-in-depth measure, direct identifiers are additionally minimised within the processing pipeline. For the Tunisian service, all such processing and storage occurs within Tunisia (Section 8).
7.4Model improvement and research using irreversibly anonymised data only. To improve the Service and its models, and to conduct scientific, statistical, or clinical research, we — and research partners we engage — may use data that has been irreversibly anonymised, including data derived from the difference between an AI-generated draft and the corresponding clinician correction or interpretation (the “delta”). Before any such use or sharing, all identifiers are removed — including name, family name, national or other identifiers, email address, telephone number, residential address, photographs or images of a person, and any other element by which an individual could be identified — so that the resulting data does not permit identification of any individual, whether it is processed by our own model or by a third party. We do not share identifiable or pseudonymised (coded) personal data with research partners; any such sharing, were it ever contemplated, would require a separate research data-sharing agreement, a lawful basis, and any authorisation required by the INPDP, established in advance. We do not use identifiable personal data, and do not use patient images containing identifying features, to train models.
7.5Anonymisation standard. “Anonymised” means data that cannot reasonably be re-identified, whether alone or in combination with other data. We maintain a documented process, and conduct re-identification-risk assessment, to support this standard — including for free-text notes and medical images, which can carry latent identifiers.
7.6Budgets and caching. AI usage is subject to per-User and per-tenant budgets. Stable, non-personal reference lookups may be cached to reduce processing.
8. Data Residency and International Transfers
8.1In-country residency. The Platform is deployed on a per-jurisdiction basis. For the Tunisian service, clinical, account and billing data — including all health data — is stored and processed within the territory of the Republic of Tunisia. We do not transfer Tunisian health data outside Tunisia for hosting. The narrow categories that are processed elsewhere are named in 8.4; health data is not among them.
8.2No cross-border transfer of clinical data. Except as strictly necessary and lawful, we do not transfer clinical data across borders. Where a future jurisdiction is added, a separate, isolated deployment is established in that jurisdiction.
8.3Limited operational exceptions. Certain strictly operational processing may, depending on configuration, involve a provider located outside the jurisdiction — for example, an international card payment you choose to make (processed by the international payment provider under its own controls). Any such processing is limited to what is necessary and, for EU personal data, is carried out only under a valid transfer mechanism (such as an adequacy decision or Standard Contractual Clauses). No directly-identifying health data is transferred by these means.
8.4Mobile application and website telemetry. Two narrow categories are processed outside Tunisia, by Google, and are the exception to 8.1. First, the mobile application’s device and diagnostic data — device model, operating-system and app version, IP address, crash reports, in-app usage events and the push messaging token — is processed by the Google services named in 19.4. Second, the public marketing website at doctopass.com uses the measurement and advertising technologies described in 14.2. Neither carries clinical content: no consultation note, dictated audio, transcript, clinical image or identifiable patient record is transmitted to any of these providers. For EU personal data these transfers are made under a valid transfer mechanism, such as Standard Contractual Clauses.
9. Data Retention
We retain personal data only as long as necessary for the purposes described, or as required by Applicable Law.
| Data category | Retention |
|---|---|
| Clinical / medical records | Retained for ten (10) years from the last activity on the associated record or Account, then subject to secure deletion or anonymisation, unless a longer period is required by Applicable Law or a specific clinical/legal obligation. Clinical data is never hard-deleted while an obligation to retain it subsists; soft-deletion and access restriction apply in the interim. |
| Account and identity data | Retained for ten (10) years from the last activity, then securely deleted or anonymised, subject to Applicable Law — unless you ask us to delete your account sooner, in which case §20 governs and this period does not apply to you. |
| Billing and invoicing records | Retained for the period required by applicable commercial and tax law (in Tunisia, generally ten (10) years). |
| Security and audit logs | Retained for at least one (1) year, and longer where required to meet security or legal obligations. |
| AI prompt/response processing logs | Retained for up to thirty (30) days for operational and security purposes, then deleted. |
| Mobile app device and diagnostic data | Crash reports and in-app usage events are retained for up to fourteen (14) months, the maximum retention Google Analytics for Firebase and Crashlytics are configured to. The push messaging token is held only while the App remains installed and signed in, and is deleted on sign-out, on uninstall, or when your account is deleted. |
| Irreversibly anonymised data | May be retained indefinitely, as it is not personal data. |
On expiry of the applicable period, data is securely deleted or irreversibly anonymised.
10. Data Security
10.1We operate an information-security management system aligned to the ISO/IEC 27001 control set. Technical and organisational measures include, without limitation:
- Authentication — passwords stored using a strong, salted hashing function (argon2id); short-lived access tokens and rotated refresh tokens; optional and, for privileged access, encouraged two-factor authentication.
- Authorisation — two-layer access control: a role check and a per-record ownership check on every access to patient data.
- Auditability — an immutable audit trail of reads and writes of patient data.
- Encryption — encryption of data in transit; encryption at rest for stored data and files, including database-level cryptographic protection for sensitive fields; access to stored files via short-lived signed URLs.
- Segregation — per-jurisdiction deployment isolation.
- Minimisation — collection limited to what is necessary; redaction of direct identifiers before AI processing.
- Operational security — rate limiting, session management, monitoring with scrubbing of personal data from diagnostic telemetry, backup, and recovery procedures.
- Governance — access on a need-to-know basis, staff confidentiality obligations, and change-management controls.
10.2No system is perfectly secure. We continually review and improve our measures. A summary of technical and organisational measures is provided to Doctors as an annex to the Data Processing Agreement.
11. Recipients and Sub-Processors
11.1We share personal data only as necessary to provide the Service and as permitted by Applicable Law, with:
- service providers (sub-processors) engaged to host, secure, and operate the Platform, bound by data-protection terms and, for clinical data, engaged only in accordance with the Data Processing Agreement;
- payment providers, to process payments you initiate;
- your Doctor (for Patients) or authorised Secretaries (as configured by the Doctor); and
- authorities or third parties where required by Applicable Law or to establish, exercise, or defend legal claims.
11.2A current list of sub-processors for clinical data, including their role and location, is maintained in the Data Processing Agreement (Sub-processor annex). We do not sell personal data, and we do not use patient health data for advertising.
12. Your Rights
12.1Subject to the conditions and exceptions of Applicable Law, you have the right to:
- access your personal data and obtain information about its processing;
- rectify inaccurate or incomplete data;
- erase data in the circumstances permitted by law (subject to our obligation to retain certain clinical, billing, and audit data);
- restrict or object to processing in certain circumstances;
- data portability — receive certain data in a structured, commonly used, machine-readable format; and
- withdraw consent where processing is based on consent, without affecting prior lawful processing.
12.2How to exercise. For clinical data, please contact your Doctor (the controller), who is responsible for responding; we will support them. For data for which we are controller, contact us — or our Data Protection Officer — at contact@doctopass.com. We may need to verify your identity before responding.
12.3Response time. We (or the relevant controller) will respond within the period required by Applicable Law (under the GDPR, generally within one month, extendable where permitted).
12.4Complaints. You may lodge a complaint with the INPDP in Tunisia, or with your local supervisory authority where the GDPR applies. We ask that you contact us first so we can try to resolve the matter.
13. Children and Guardians
13.1The Platform is intended for Users aged eighteen (18) or over. A person under eighteen (18), or who otherwise lacks legal capacity, may be a Patient only where a parent or legal guardian has accepted the Terms of Use on their behalf and exercises the associated rights and consents.
13.2The Platform is not directed to children for unsupervised use. Where guardian-managed accounts are made available, the guardian is responsible for the minor’s data and consents, in accordance with Applicable Law.
15. Data Breach Notification
15.1We maintain procedures to detect, assess, and respond to personal-data breaches.
15.2Where DOCTOPASS acts as processor, we will notify the relevant controller (the Doctor) without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal-data breach affecting their data, and will cooperate in the controller’s response.
15.3Where DOCTOPASS acts as controller, we will notify the competent supervisory authority and affected individuals where and as required by Applicable Law (under the GDPR, notification to the supervisory authority generally within 72 hours where the threshold is met; under HIPAA, within the periods set by the Breach Notification Rule; and in Tunisia in accordance with INPDP requirements).
16. Changes to this Policy
16.1We may update this Policy. Material changes will be notified by reasonable means before they take effect. The “Version” and “Effective date” fields above indicate the current version.
17. Data Protection Officer and Contact
- Data Protection Officer
- contact@doctopass.com
- General data-protection enquiries
- contact@doctopass.com
19. The Doctopass Mobile Application (Android / Google Play)
This section describes the Doctopass mobile application for Android (the “App”), published on Google Play by DOCTOPASS SARL. It applies in addition to the rest of this Policy: everything stated above about health data, legal bases, security, sub-processors and your rights applies to the App as well as to the web platform.
19.1 Who publishes the App, and how to reach us
- Application
- Doctopass — Android application distributed on Google Play
- Publisher and data controller
- DOCTOPASS SARL
- Privacy contact
- contact@doctopass.com
- Account and data deletion
- https://doctopass.com/delete-account/
- This policy inside the App
- Linked from the App’s settings screen, and shown before you create an account.
19.2 Device permissions the App may request
Every permission below is requested in context — at the moment you use the feature that needs it, never at first launch as a block — and every one of them can be declined. Declining a permission disables only the feature it powers; the rest of the App continues to work. You can withdraw any permission at any time in Android Settings › Apps › Doctopass › Permissions.
| Permission | What it is used for | Does the data leave the device? |
|---|---|---|
| Camera | Photographing a clinical document, a referral letter, a lab result or a wound or lesion, and attaching it to the correct patient record. Used only when you open the camera from inside the App. | Yes — the image is uploaded to the patient record and is health data, handled under §6. |
| Photos and files | Attaching an existing image or document you choose to a patient record. The App uses the Android system picker, so it receives only the individual files you select and has no access to the rest of your gallery or storage. | Only the files you explicitly pick. |
| Microphone | Dictating a consultation note by voice. Recording starts only when you press record and stops when you stop it; the App does not listen in the background and has no always-on or wake-word listening of any kind. | Yes — the audio is transcribed and both the audio and the transcript are clinical content. See §7 for how AI processes it and §9 for how long it is kept. |
| Location | Showing nearby practices, clinics and pharmacies, and pre-filling an address. Requested in the foreground only, while you are using that feature. The App does not collect location in the background and does not track your movements. | Only to return the search result you asked for. It is not stored on your profile and is not used for advertising. |
| Contacts | Letting you pick a phone number from your device when adding a patient or a colleague, so you do not have to retype it. Doctopass receives only the entry you pick. | Only the single contact you choose. Your address book is never uploaded, copied or scanned in bulk. |
| Calling and messaging (no permission held) | Starting a call or opening a pre-filled message to a number you have tapped. The App holds no telephony or SMS permission to do this: it hands the action to your own phone or messaging app, and you confirm it there. It does not belong to Google Play’s restricted SMS or Call Log permission group. | No. The App does not read, receive, store or upload your SMS messages or your call log. |
| Notifications | Appointment reminders, schedule changes and clinically relevant alerts. Notifications carry no advertising and no third-party promotion. | A device messaging token is used to deliver them. See §19.4. |
The App requests no permission that is not tied to a feature described above. It does not use background location, does not read your SMS inbox or call log, does not use accessibility services to read the screen, and does not enumerate the other apps installed on your device.
19.3 Data the App collects automatically
Independently of the permissions above, the App records the following in order to run, stay secure and be diagnosable when it fails:
- Device and app information — device model, Android version, App version, language and time zone.
- Log and diagnostic data — IP address, timestamps, error and crash reports including the state of the App at the moment of the crash.
- A push messaging token — a per-installation identifier that lets a notification reach this device and no other.
- Usage events — which screens were opened and which actions were taken, used to fix problems and improve the App. These are recorded against your account, not against an advertising profile.
Crash and usage reporting is scoped to operating the App. Clinical content — consultation notes, dictated audio, transcripts, images and any identifiable patient data — is excluded from crash reports and analytics events by design.
19.4 Third-party services inside the App
| Service | Why it is present | What it receives |
|---|---|---|
| Google Play services | Distribution, updates and integrity checks on Android. | Device and app information, as required by the platform. |
| Firebase Cloud Messaging (Google) | Delivering appointment reminders and alerts. | The push token, App version and device/SDK versions. Notification payloads are kept free of clinical detail. |
| Firebase Crashlytics (Google) | Diagnosing crashes so they can be fixed. | Stack traces, app state at crash time, device metadata and a per-installation identifier. |
| Google Analytics for Firebase | Understanding which features are used, to prioritise work on the App. | App interaction events, device identifiers and approximate location derived from IP address. It does not receive clinical content. |
These are the third-party services integrated into the App. The infrastructure and sub-processors that hold platform data are listed in §11, and that list applies to the App identically. We do not add a service that receives personal data without updating this section and the Google Play Data safety declaration together.
19.5 No advertising, no sale, no profiling
- The App displays no advertising of any kind, and contains no advertising SDK.
- We do not sell personal or sensitive user data, and we do not share it with data brokers.
- Health data is never used for advertising, never used to build an advertising or marketing profile, and never transferred to an advertising network or data broker.
- Health data is never used to assess credit-worthiness, insurance eligibility or employment suitability, nor for any lending purpose.
- Data collected through the App is limited to operating the App and providing the features you use, consistent with Google Play’s limited-use requirements.
19.6 Consent inside the App
Before the App collects camera, photo, microphone, location or contacts data for the first time, it shows a disclosure naming the data and the reason for it, and asks you to accept or decline. Declining is a real choice and leaves the rest of the App usable. This in-app disclosure is in addition to this Policy, not a substitute for it.
19.7 The App is not a medical device
Doctopass is clinical record-keeping and practice software. It is not a medical device: it does not diagnose, treat, cure or prevent any disease or condition, and it does not replace the judgement of a qualified healthcare professional. Every clinical decision, and every note, code or prescription the software helps prepare, remains the responsibility of the treating clinician, who reviews and signs it. Nothing in the App should be relied on as medical advice.
20. Deleting Your Account and Your Data
You can ask us to delete your Doctopass account and the personal data held against it at any time, from inside the App or from the web, without giving a reason.
20.1 How to request deletion
- In the App — open Settings › Account › Delete account and confirm.
- On the web — use the request form at https://doctopass.com/delete-account/, which needs no account and no sign-in.
- By email — write to contact@doctopass.com from the address on the account.
20.2 What is deleted
- Your account, sign-in credentials and session tokens.
- Your profile: name, e-mail address, telephone number, professional details and profile photograph.
- Your App preferences and settings, and the push messaging token for every device you signed in on.
- Usage and analytics events attributable to you, and dictated audio still held for processing.
Deletion means deletion. We do not satisfy a deletion request by deactivating, disabling, suspending or freezing an account. Deletion instructions are also passed to the sub-processors that hold a copy.
20.3 What is retained, and why
Some records cannot lawfully be erased on request. This is the one limit on the deletion above, and it is stated plainly rather than buried:
| Retained | Why | For how long |
|---|---|---|
| Patient medical records | A clinical record belongs to the patient and to the treating practice, and the practice — not Doctopass — is its controller. Deleting a doctor’s or a secretary’s login cannot delete the patients’ records, which the practice is legally obliged to keep. Your access is removed; the record continues under the practice’s control. | Per §9 and the practice’s own legal obligations. |
| Billing and invoicing records | Commercial and tax law requires them to be kept. | As set out in §9. |
| Security and audit logs | Needed to investigate unauthorised access to health data and to meet security obligations. Reduced to the minimum that still serves that purpose. | As set out in §9. |
| Irreversibly anonymised data | It can no longer identify you, and is therefore no longer personal data. | Indefinitely. |
If you are a Patient: deleting your Doctopass account removes your login and your access to the App. It does not delete the medical record your doctor holds about you — that record belongs to the treating practice, which is legally obliged to keep it and is its controller. To ask for that record to be corrected, restricted or erased, contact the practice directly; §12 sets out those rights and we will help you reach the right contact.
20.4 How long it takes
- We acknowledge a request within 72 hours.
- The account and its data are deleted from live systems within 30 days.
- Encrypted backups age out on their own cycle and are fully purged within 90 days. A restored backup is re-processed for deletion.
- We confirm to you in writing when the deletion is complete.
Deleting your Doctopass account does not delete the App from your device, and uninstalling the App does not delete your account. Both are done separately.