01 Who We Are
WardFlowOS is a Software-as-a-Service (SaaS) product operated by TEYEOS Ltd, a private limited company registered in England and Wales.
Product: WardFlowOS (wardflowos.com / wardflowos.web.app)
Contact: hello.wardflowos@teyeos.com
Jurisdiction: England and Wales, United Kingdom
As the data controller, TEYEOS Ltd determines the purposes and means of processing personal data collected through the WardFlowOS platform. If you have any questions about this policy or your personal data, please contact us at hello.wardflowos@teyeos.com.
02 What Data We Collect
We collect the minimum data necessary to provide the WardFlowOS service. This falls into two categories:
Account and profile data (provided by you):
- Display name (e.g. "Dr. Smith" — as entered by you)
- Email address
- Professional role (e.g. Doctor, Nurse, AHP)
- Account creation date and timestamp
- Avatar customisation preferences
Usage and operational data (generated by use):
- Ward space names and codes you create or join
- Task descriptions and status updates entered into the platform
- Patient identifiers as entered — bed numbers, age, gender, general clinical condition descriptions
- Timestamps of actions (task completion, delegation, login)
- Subscription and billing status (managed via Stripe)
- AI Priority Planner usage counts
Technical data (collected automatically):
- IP address (used for rate limiting and security only, not profiling)
- Browser type and device information (for compatibility and support)
- Service worker and PWA installation status
03 How We Use Your Data
| PURPOSE | LEGAL BASIS | DATA USED |
|---|---|---|
| Providing the WardFlowOS service | Contract performance | Account data, ward spaces, tasks |
| User authentication and security | Contract / Legitimate interest | Email, password hash, session tokens |
| Processing subscription payments | Contract performance | Email, billing status (via Stripe) |
| AI Priority Planner feature | Contract performance | Task descriptions sent to Anthropic API |
| Rate limiting and abuse prevention | Legitimate interest | IP address, usage timestamps |
| Sending transactional emails | Contract / Legitimate interest | Email address |
| Product improvement and analytics | Legitimate interest | Anonymised usage patterns |
| Legal compliance | Legal obligation | As required by law |
We do not use your data for advertising, do not sell your data to third parties, and do not use it to build profiles for marketing purposes.
04 Third-Party Services and Data Processors
We use the following third-party services to operate WardFlowOS. Each acts as a data processor under our instructions:
| SERVICE | PURPOSE | DATA TRANSFERRED | LOCATION |
|---|---|---|---|
| Google Firebase | Authentication, database, hosting | Account data, ward data, tasks | EU (europe-west1, Belgium) |
| Anthropic | AI Priority Planner (Claude API) | Task descriptions only | United States |
| Stripe | Payment processing | Email, billing info | United States / EU |
| Google Fonts | Typography | IP address (standard CDN) | United States |
Firebase: Your account and ward data is stored in Google Firebase's europe-west1 (Belgium) region, ensuring data residency within the European Economic Area. Firebase is compliant with GDPR under Standard Contractual Clauses.
Anthropic API: When you use the AI Priority Planner, the task descriptions you have entered are sent to the Anthropic API (Claude) for processing. No patient names, NHS numbers, or account information are transmitted. Task text is processed and not retained by Anthropic beyond the API response. By using the AI Priority Planner, you confirm that any data submitted does not contain directly identifiable patient information.
Stripe: Payment processing is handled by Stripe, Inc. Your card details are never seen or stored by TEYEOS Ltd. Stripe is PCI-DSS compliant and GDPR-compliant under Standard Contractual Clauses. For Stripe's privacy practices, see stripe.com/gb/privacy.
05 Data Retention
We retain your data for as long as necessary to provide the service and comply with our legal obligations:
- Active accounts: Data retained for the duration of your account
- Cancelled subscriptions: Account and ward data retained for 90 days after cancellation, then deleted
- Expired ad-hoc / trial spaces: Space data deleted automatically after expiry
- Billing records: Retained for 7 years as required by UK tax law
- Security logs (IP, timestamps): Retained for 30 days then deleted
You may request deletion of your account and associated data at any time by contacting hello.wardflowos@teyeos.com.
06 Your Rights Under UK GDPR
As a data subject under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restriction: Request that we limit how we process your data
- Right to data portability: Request your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Rights related to automated decision-making: We do not make automated decisions with legal or significant effects about individuals
To exercise any of these rights, please email hello.wardflowos@teyeos.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
07 Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- All data encrypted in transit using TLS (HTTPS enforced on all endpoints)
- All data encrypted at rest within Google Firebase infrastructure
- Firebase database security rules restricting access to authorised users only
- API keys stored in Firebase Secret Manager — never exposed in client code
- Rate limiting and session timeouts to prevent unauthorised access
- Email verification for new accounts
- Server-side access controls enforced independently of client-side checks
In the event of a data breach that poses a risk to individuals, we will notify the ICO within 72 hours and affected users without undue delay, as required by UK GDPR.
08 Cookies and Local Storage
WardFlowOS uses minimal browser storage:
- Firebase Authentication tokens: Stored in browser storage to maintain your login session. These are session cookies and are cleared when you sign out.
- Session preferences: Font size settings and UI preferences stored in sessionStorage. These are not transmitted to our servers and are cleared when you close the browser.
- Service Worker cache: Static app files cached locally for offline/low-connectivity use. No personal data is stored in the service worker cache.
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent banner is required as we only use strictly necessary functional storage.
09 NHS and Clinical Data Governance
WardFlowOS is a task coordination tool, not a clinical information system. It is not a regulated medical device under the Medical Devices Regulation and is not a replacement for your organisation's Electronic Patient Record (EPR) system.
Users who are NHS employees must ensure their use of WardFlowOS complies with:
- Their organisation's Information Governance (IG) policies
- The NHS Data Security and Protection Toolkit (DSPT) requirements
- The Caldicott Principles for patient data
- Their employment contract obligations regarding patient confidentiality
TEYEOS Ltd is working towards DTAC (Digital Technology Assessment Criteria) compliance for NHS procurement purposes. For enterprise deployments, a Data Processing Agreement (DPA) is available upon request.
10 International Data Transfers
Some of our third-party processors (Anthropic, Stripe) are based in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place under UK GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the ICO
- Adequacy decisions where applicable
- Data minimisation — only the minimum necessary data is transmitted to US-based processors
Your core account and ward data is stored in the EU (Firebase europe-west1, Belgium) and is not transferred to the United States.
11 Children's Data
WardFlowOS is intended for use by healthcare professionals aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has registered an account, please contact us at hello.wardflowos@teyeos.com and we will delete the account promptly.
12 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or product features. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify registered users by email where the changes are significant
- Display an in-app notice for active users
Continued use of WardFlowOS after changes become effective constitutes acceptance of the updated policy.
13 Contact Us
Data Controller Contact Details
Company: TEYEOS Ltd
Product: WardFlowOS
Email: hello.wardflowos@teyeos.com
Website: wardflowos.com
Registered in: England and Wales
For data protection enquiries, subject access requests, or to exercise your rights under UK GDPR, please email hello.wardflowos@teyeos.com with the subject line "Data Protection Request". We aim to respond within 30 days.