How we collect, use and protect personal data — including the medical records you upload — under the UK GDPR and the Data Protection Act 2018.
This policy explains what Med-Legal does with personal data when you visit our website, create an account, and use our service to turn medical records into summaries and bundles. We’ve written it in plain English. It is a genuine description of how the service works — not boilerplate copied from another company.
Med-Legal (“Med-Legal”, “we”, “us”, “our”) operates the website and service at med-legal.co.uk, providing cited medical-records summaries and indexed bundles to UK legal practices.
For any questions about this policy or your data — or to exercise your rights under it — contact us at info@med-legal.co.uk.
It matters which “hat” we are wearing, because it determines who is responsible for what:
A separate Data Processing Agreement governing the records you upload is available on request and forms part of our Terms & Fees.
| Category | Examples |
|---|---|
| Account data | Your name, work email address, password (stored only as a secure hash), or — if you sign in with Google or Microsoft — the basic profile and email those services return. |
| Billing data | Your unit balance and purchase history, and a customer reference held with our payment provider. We never see or store your full card number — card details are handled directly by Stripe. |
| Uploaded content (special category) | The medical records you upload (GP, hospital, imaging, physiotherapy, etc.) and the summaries and bundles generated from them. These contain special-category health data about claimants. |
| Usage & technical data | Log records of actions in the app (claims created, outputs generated, sign-in events), your last-seen time, and standard server logs including IP address and browser type. |
| Communications | Messages you send us through the contact form, the live-chat widget, or by email. |
We do not use your data, or your clients’ records, for advertising, and we do not sell personal data to anyone.
Generating a summary or bundle means the text of your uploaded records is processed by a specialist third-party AI provider that acts as our sub-processor under contract. This is core to how the product works and we want to be straightforward about it.
Every fact in a generated output is traced back to its source page and quote-checked in our own code. Outputs are AI-assisted drafts: they must be reviewed and approved by a qualified fee-earner before they are relied upon, disclosed or filed (see our Terms & Fees).
We use a small number of trusted providers to run the service. Each is bound by a contract that limits them to processing data only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting & storage of your account data and uploaded records | Germany (EU) |
| Specialist AI provider | Generating summaries, chronologies and bundles from record text | Outside the UK |
| Stripe | Card payments and billing (handles card data directly) | EU / USA |
| Google / Microsoft | Optional “Sign in with” authentication — only if you choose it | EU / USA |
| Meta (WhatsApp) | Relaying messages you send through the website live-chat widget to our team | EU / USA |
| Email delivery provider | Sending service emails (welcome, receipts, notices) | EU / USA |
We may also disclose data where required by law, or to establish, exercise or defend legal claims. If our business is ever sold or restructured, data may transfer to the new owner under the same protections.
Your account data and uploaded records are stored on servers in Germany (within the EEA). Some sub-processors above operate outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on an applicable UK adequacy decision (“data bridge”) or, where none applies, the UK International Data Transfer Agreement / Addendum and appropriate technical safeguards, so that your data keeps an equivalent level of protection.
You can delete individual records and outputs at any time from within the app, and we act on account-deletion requests promptly.
Access is over encrypted (HTTPS/TLS) connections. Passwords are stored only as secure hashes, never in plain text. Access to live systems and stored records is restricted to authorised personnel, records are scoped to a single claim, and we keep an audit log of actions in the app. No system is perfectly secure, but we take appropriate technical and organisational measures to protect your data and will notify you and the ICO of a reportable breach as the law requires.
Under UK data protection law you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. To exercise any of these, email info@med-legal.co.uk.
If a claimant wants to exercise rights over the medical records in a matter, those requests should usually go to the instructing firm (the controller of that data); we will assist the firm in responding. You can also complain to the ICO at ico.org.uk, though we’d appreciate the chance to put things right first.
We use only the cookies needed to sign you in and to keep payments secure — we do not use advertising or third-party tracking cookies. Full details are in our Cookie Policy.
We may update this policy as the service evolves; we’ll change the “last updated” date above and, for material changes, tell account holders. Questions? Email info@med-legal.co.uk.