Last updated: 1 September 2026

GDPR Statement

DoseScan processes sensitive health data on behalf of UK care providers. This statement explains our obligations under UK GDPR, how we meet them, and what your organisation's responsibilities are as the data controller.

Our six security and compliance commitments

These are the concrete measures DoseScan has in place to protect the data you entrust to us.

Data encrypted at rest and in transit

All data stored in DoseScan is encrypted at rest using AES-256. All data in transit is encrypted using TLS 1.2 or higher. This includes medication records, resident data, staff data, and authentication tokens.

UK and EEA hosting only

DoseScan data is stored exclusively on servers located within the United Kingdom and European Economic Area. We do not transfer personal data outside these regions. Our infrastructure provider (Supabase) is configured to use UK-region storage.

Role-based access control

Access to data is restricted on a need-to-know basis. Care organisation administrators can see all data within their organisation. Staff members using the mobile app can only see residents assigned to their location. DoseScan staff do not have routine access to customer data.

Defined retention periods

Medication records are retained for a minimum of 3 years in line with UK care sector guidance. Account, staff, and resident data is deleted within 30 days of account closure. Technical logs are purged automatically after 90 days.

Data Processing Agreements in place

DoseScan has Data Processing Agreements with all sub-processors who handle personal data on our behalf, including Supabase (database) and Vercel (hosting). These agreements require sub-processors to maintain equivalent data protection standards.

Breach notification procedures

In the event of a personal data breach, DoseScan will notify affected organisations and, where required, the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, in line with Article 33 of UK GDPR.

Your rights under UK GDPR

These rights apply to residents, staff, and administrators whose data is processed through DoseScan.

Right of access

Request a copy of all personal data we hold about you or your organisation.

Right to rectification

Ask us to correct any inaccurate or incomplete personal data.

Right to erasure

Request deletion of your data, subject to our legal retention obligations.

Right to restrict processing

Ask us to limit how we use your data while a query is investigated.

Right to data portability

Receive your data in a structured, machine-readable format (JSON or CSV).

Right to object

Object to processing based on legitimate interests.

Right to complain

Lodge a complaint with the ICO at any time at ico.org.uk.

To exercise any of these rights, email hello@dosescan.co.uk. We will respond within 30 days.

Overview

DoseScan Ltd is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement sets out how DoseScan meets its obligations as a data processor for care organisations using the platform.

If you are a care organisation using DoseScan, you are the data controller for all personal data entered into the platform — including resident data, staff data, and medication records. DoseScan acts as your data processor, processing that data only for the purposes of providing the service described in our Terms of Service.

Lawful basis for processing

DoseScan processes personal data on behalf of care organisations under the following lawful bases:

Contract (Article 6(1)(b)): Processing necessary to deliver the DoseScan service under our Terms of Service.

Legitimate interests (Article 6(1)(f)): Technical and security logs collected to maintain platform integrity, where these do not override individuals' rights.

Legal obligation (Article 6(1)(c)): Where we are required by UK law to retain records for specified periods.

For special category data — specifically health-related resident data — we rely on Article 9(2)(h): processing necessary for the provision of health or social care under a contract with a health professional. Care organisations, as data controllers, are responsible for maintaining their own lawful basis for processing this data and for obtaining any necessary consents from residents.

Controller and processor responsibilities

As data controller, your care organisation is responsible for:

Ensuring you have a lawful basis to process resident and staff personal data in DoseScan.

Obtaining any necessary consents from residents and their families for digital medication record-keeping.

Responding to subject access requests from residents or staff within the required timescales.

Maintaining your own record of processing activities (ROPA) that includes your use of DoseScan.

As data processor, DoseScan is responsible for:

Processing data only on documented instructions from the controller.

Ensuring appropriate technical and organisational security measures are in place.

Notifying the controller without undue delay of any personal data breach.

Assisting the controller in responding to data subject rights requests where the data is held in DoseScan.

Deleting or returning all personal data on termination of the service.

These responsibilities are set out in detail in our Data Processing Agreement, available on request at hello@dosescan.co.uk.

Sub-processors

DoseScan uses the following sub-processors, each under a Data Processing Agreement:

Supabase Inc — database infrastructure and authentication. Data stored in UK/EEA regions. Supabase's GDPR compliance documentation is available at supabase.com/privacy.

Vercel Inc — web application hosting. Processes request metadata but does not have access to stored personal data. Vercel's data processing terms are available at vercel.com/legal/dpa.

We do not use any other sub-processors that have access to personal data. We will notify account administrators of any changes to our sub-processor list with at least 30 days' notice.

Data Protection Impact Assessments

DoseScan has conducted a Data Protection Impact Assessment (DPIA) for the processing of special category health data within the platform. The DPIA identified the following key risks and mitigations:

Risk: Unauthorised access to resident health data. Mitigation: Role-based access control, device-level authentication, encryption at rest and in transit.

Risk: Data breach affecting sensitive health records. Mitigation: Breach detection procedures, 72-hour ICO notification process, customer notification within 24 hours.

Risk: Data retained beyond necessary period. Mitigation: Automated deletion schedules, clear retention policy communicated to customers.

A summary of our DPIA is available on request for care organisations conducting their own due diligence.

ICO registration

DoseScan Ltd is registered with the Information Commissioner's Office (ICO) as a data controller and processor under the Data Protection Act 2018.

If you have a complaint about how DoseScan has handled your personal data that we have been unable to resolve, you have the right to contact the ICO directly:

Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF ico.org.uk | 0303 123 1113

Request our Data Processing Agreement

If you require a signed Data Processing Agreement for your compliance records or procurement process, email hello@dosescan.co.uk. We will provide a completed DPA within 5 business days.