CarefulAI
  • About Us
Definitions
​

SRO: the Senior Responsible Officer in your organisation that wishes to send data to a Customer via CarefulAI’s systems.
Customer: the Senior Responsible Officer in your organisation’s customer who wishes to receive your data via CarefulAI.
DRN: a reference number that links your data to this Data Sharing Agreement.
Controller, Processor, Sub-Processor, Personal Data, Data Subject: have the meanings given in the UK GDPR and the Data Protection Act 2018.

Roles of the parties

This Agreement records the basis on which Personal Data is shared through CarefulAI’s systems. Where CarefulAI processes Personal Data on behalf of a client for healthcare purposes, the client is the Controller and CarefulAI is the Processor, acting only on the Controller’s documented written instructions. Where two organisations jointly determine the purposes and means of processing, they shall put in place a joint controller arrangement under UK GDPR Article 26.

Purpose of the DRN

The purpose of the DRN is to enable you to answer questions your Customer may have about the representation of your data.

Where data is processed

Personal Data shared for healthcare purposes through CarefulAI’s systems is processed and stored exclusively on Amazon Web Services (AWS) and Microsoft Azure data centres located in the United Kingdom, and is not transferred outside the United Kingdom. Where any other Personal Data is transferred outside the United Kingdom or EEA, CarefulAI ensures an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses is in place, supported by a Transfer Risk Assessment, before the transfer occurs.

Security and sub-processors

Personal Data shared through CarefulAI’s systems is protected by encryption in transit and at rest, role-based access control on a least-privilege basis, and access logging. CarefulAI engages sub-processors (for example cloud hosting and, where applicable, AI model providers) only under written contracts imposing the data protection obligations required by UK GDPR Article 28, and maintains a register of sub-processors and their hosting locations. The Customer provides general written authorisation for such sub-processors, and CarefulAI will inform the Customer of intended changes, giving an opportunity to object.

Recommended content of your own policy

We accept no responsibility for your organisation’s Privacy Policy or Data Sharing Policy, or that of the Customer.

We encourage you to ensure these include:

who can access your information and the person responsible for data protection (for example the DPO);
why they hold your data and the lawful basis on which they use or process it;
where they obtained the data and whether they cross-reference it with other data;
who they share data with and how, including any sharing outside the organisation;
how long they keep your data;
how to request access to, correction or deletion of your data;
how to complain to the Information Commissioner or designated body;
whether they make automated decisions or carry out profiling;
how they refresh, securely delete or destroy data once no longer needed;
how they keep electronic data secure (for example encryption, passwords, backups);
how they train staff who handle personal data on their responsibilities; and
what they do if something goes wrong, including breach assessment and notification thresholds.

Terms of this Data Sharing Agreement

As a CarefulAI system user you control if and how your data is shared with a Customer. By completing a Consent Notification in one of our systems you confirm agreement to: your SRO’s Privacy Policy; the Customer using your data in line with their Privacy Policy and Data Sharing Agreement; CarefulAI using your data in line with its Privacy Policy and this Data Sharing Agreement; and the CarefulAI system transmitting data to the Customer.
Each Consent Notification is recorded with a timestamp and the DRN so that the existence, scope and withdrawal of agreement are auditable. Where processing of NHS patient data relies on a lawful basis other than consent, the Consent Notification records the data-sharing authorisation rather than the lawful basis for processing.

Your rights once data is shared

Once you have submitted your data to the Customer you have the right to contact the Customer to:
be told what data they hold about you and what they do with it;

request a copy of the data they hold;
rectify inaccurate data;
delete and destroy your data;
restrict processing;
request your data be moved to another business; and
request they stop using your data.

Where CarefulAI acts as Processor, it will assist the Controller in responding to these requests within the statutory timescales, and will notify the Controller of any personal data breach without undue delay and in any event within 24 hours of becoming aware of it.
Privacy Policy     Terms of Service     Cyber Essentials Plus Certification 

 IP Asset Register     Modern Slavery Statement      Quality Management System      Information Governance System

AI Governance System      Environmental Governance System       Carbon Reduction Plan     
  • About Us