Digital Vitamins/Studio/Data

Named services. EU regions. Nothing hidden.

Clinics and firms cannot take “it’s secure” on trust, and should not have to. This is the page your practice manager or compliance officer can read before anyone books a call.

01 Residency

Where your data actually sits.

Named, not implied. Every service we would put in your build, what it holds, and which region it holds it in. If a service on this list is wrong for your regulator, we swap it before we build.

EU (Frankfurt)EU sending regionEU routingPCI, tokenisedNo ad pixels
Service · what it holdsRegion
D1Site & appStatic pages and application code. No client data at restEU (Frankfurt)
D2DatabaseBookings, contacts, notes you choose to store, audit logEU (Frankfurt)
D3File storageUploads, signed forms, certificates, treatment plansEU (Frankfurt)
D4BackupsEncrypted, 30-day rolling, restorable to a point in timeEU, same region
D5EmailTransactional only: reminders, confirmations, invoicesEU sending region
D6SMSReminders and confirmations, where you use themEU routing
D7PaymentsCard data never touches your systems or oursPCI, tokenised
D8AnalyticsCookieless, aggregate, no cross-site identifiers, no ad pixelsEU or none

02 By design

Minimum data. Maximum evidence.

Two rules that decide most of the arguments. Hold the least you can, and be able to prove what happened to it.

01

Data minimisation, enforced by design

If a field is not needed for the appointment, the matter or the invoice, we do not build the field. The most common thing we remove from an existing site is a free-text box that had quietly become a medical record.

02

Clinical records stay where they belong

For clinics and therapy practices we connect to your existing record system rather than duplicating it. Duplication is the thing that turns a booking tool into a health-data processor overnight.

03

Consent captured properly

Purpose-specific, timestamped, versioned to the wording that was actually shown, and withdrawable from the client’s own portal without emailing you.

04

Retention that runs itself

You set the period your professional body requires. The system deletes on schedule and writes the deletion to the audit log, so retention is something you can evidence rather than something you intended.

05

Encrypted, logged, least-privilege

TLS in transit, AES-256 at rest, access logged with who and when. Staff accounts see what their role needs and no more, which matters most on the day someone leaves.

06

Subject access without a fire drill

Export or erase one person’s record from one screen. A request that used to cost a morning becomes a task.

03 The paperwork

What we hand your regulator.

Available before you commit, not after. If your professional body or insurer needs to see these, ask and we will send them the same day.

Document · contentsWhen
P1Processor agreementGDPR Article 28 DPA, signed before any data existsBefore build
P2Sub-processor listEvery third party, what it does, where it runs, with 30 days notice of changePublished
P3Data mapEvery field, why it exists, how long it is kept, who can see itAt handover
P4Retention schedulePer record type, matched to your professional bodyAgreed with you
P5Breach procedureWho we call, in what order, inside what windowWritten
P6Access reviewWho can see what, revisited each quarter on the RitualQuarterly

04 Asked by every clinic

The questions a practice manager asks.

Are you a data processor or a controller?

You are the controller. We are a processor acting on your instructions, under a signed Article 28 agreement, and our sub-processors are listed and notified before they change. We never use your client data for anything other than running your system: no analytics, no product improvement, no training of anything.

Can we host it ourselves, or in our own tenant?

Yes, and for some clinics and firms it is the right answer. We can deploy into your own cloud account or your existing infrastructure. It costs a little more to set up and it means your IT policy governs the whole thing, which is sometimes the deciding factor for an insurer.

What happens to the data if we stop working with you?

Nothing. It is in your accounts already. That is the point of the ownership page. We lose access when you remove us; the data does not move, because it was never ours to move.

Do you use AI on our client data?

No. Nothing in your system sends client data to a model, ours or anyone else’s, unless you specifically ask for a feature that needs it. Then it is scoped, named in the data map, and switchable off. We would rather say this plainly than bury it in a policy.

We are a law firm. What about privilege and conflicts?

Matter data is segregated per matter with role-based access, and the conflict check runs at intake before a matter can be opened. We have built this for a firm before and we are comfortable being read by your compliance officer before you engage us.