Body Navigator — Privacy Policy
Last updated: 9 September 2026 Supersedes: version of 20 August 2026
- Introduction
This Privacy Policy explains how Andrew Jackson Physiotherapy (“we”, “us”, “our”), the developer and operator of the Body Navigator platform (“the Platform”), collects, uses, stores, shares, and protects personal data in connection with the Platform.
Andrew Jackson Physiotherapy is a sole trader business operated by Andrew Jackson. It may in future incorporate as a limited company, in which case we will notify you in advance of any change in the identity of the data controller.
We are committed to protecting your privacy and to handling personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
This Policy applies to:
(a) registered healthcare professionals who hold an account with us (“Users”, “Subscribers”, “Clinicians”);
(b) visitors to our website;
(c) prospective users who contact us, sign up to a waitlist, or attend a demonstration; and
(d) — to the extent we process patient data on behalf of Clinicians — patients of those Clinicians (“Patients”).
We are the data controller in respect of personal data about Users and website visitors. We act as a data processor in respect of Patient data that Users input into the Platform; the User remains the data controller for that information. This distinction is set out in more detail in section 9 below.
- Who we are and how to contact us
Andrew Jackson Physiotherapy UNTIL, 1 Orchard Street, London W1H 6HJ. ICO registration number: ZC164950
Data protection contact: office@thebodynavigator.com
If you have any questions about this Policy, wish to exercise your rights under UK GDPR, or have a concern about how we handle your data, please contact us using the details above.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection: website ico.org.uk; helpline 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO.
- The personal data we collect
3.1 Information you provide directly
When you register for an Account, communicate with us, or use the Platform, we collect:
- Full name and professional title
- Professional registration details (e.g. HCPC number) where relevant
- Employment context (practice or organisation, role)
- Contact details (email address, telephone number)
- Username and securely hashed password
- Billing and payment information (processed by our payment provider — see section 5)
- Communications you send to us (support requests, feedback, correspondence)
- Information you input into the Platform during clinical use, including text describing patient consultations, case notes, and clinical reasoning
- Documents you upload to the Platform, and their contents
- Audio you record within the Platform for transcription, and the resulting transcript
- Questions you put to the Clinical Assistant chat
3.2 Information collected automatically
When you use the Platform, we automatically collect:
- Authentication and session data (logins, session timestamps)
- Technical data necessary for the Platform to function (IP address, browser type, device type, operating system)
- Usage data relating to your interaction with the Platform (features used, prompts run, timestamps)
- A record of the considerations you rule in and rule out within a case, and the order in which you prioritise them — see 3.3 below
- Error logs and diagnostic information
3.3 Patient data
When you use the Platform in the course of clinical work, you may input information about Patients. The Platform separates Patient information into two areas, which are handled differently.
Patient identifier field (e.g. patient name, age)
This information is stored in our application database hosted by Google Firebase in the European Economic Area (Belgium). It is not transmitted to our AI sub-processors (OpenAI, Pinecone). It remains within the EEA throughout its life on the Platform. Date of birth is not collected.
Case notes and clinical content
This includes clinical history, presenting complaint, examination findings, imaging or test results entered by you, working hypotheses, treatment plans, and any other clinical information you record in the case notes. Case notes are processed by our AI sub-processors, including OpenAI and Pinecone (for knowledge retrieval), to provide the Platform’s clinical reasoning support functions. This processing currently takes place under “Global” residency and may occur in the United States; we are migrating it to OpenAI’s European region. International transfer safeguards apply to this processing — see section 6. Case notes may contain patient identifiers where you type them, paste them, or where they appear in uploaded documents or transcripts; where they do, they are processed as part of the case-note content.
Case notes content also includes the following, each of which is processed in the same way:
- Documents you upload. You may upload documents such as scan reports, referral letters, or prior clinical records. The contents of an uploaded document are treated as case notes content and are processed by our AI sub-processors on the same basis. Please read the data-minimisation note below.
- Voice recordings and transcripts. You may record audio within the Platform, which is transcribed to text. The resulting transcript is treated as case notes content. [TO CONFIRM: identify the transcription provider, its location of processing, and whether the audio file is retained after transcription or discarded. Add the provider to the sub-processor table at section 5 and the retention table at section 7.]
- Case notes timeline. Where you add notes from subsequent sessions, these are retained alongside the original case notes and form a chronological record of the case. Notes added later are processed on the same basis as the original notes and are available to the Clinical Assistant chat as context.
- Clinical Assistant chat. Questions you put to the chat, together with the case context supplied to it, are processed by OpenAI on the same basis as other case notes content. [TO CONFIRM: are chat exchanges persisted against the case, or discarded at the end of the session? If persisted, add to the retention table at section 7.]
- Outcome measures. Where you complete a validated outcome measure with a Patient within the Platform, the responses and resulting scores are stored against the case. Where the Patient enters responses directly, that data is Patient Data for which you remain the data controller, and you are responsible for the lawful basis and for informing the Patient how their responses will be used.
- Objective test results. Where you record the result of an objective test against a working hypothesis, that result is stored as case notes content.
Clinician activity record
The Platform records your interaction with each case: which considerations were surfaced, which you ruled in, which you ruled out, the order in which you prioritised them, and any considerations you added yourself. This record forms part of the case and is available to you and to the Clinical Assistant chat. It is deleted when the case is deleted.
This record is not used by us to assess, rank, or monitor the professional performance of individual Clinicians. Where aggregated, de-identified metrics are derived from it for safety monitoring of the Platform, we act as data controller for those metrics — see section 10.
[TO CONFIRM: whether the Platform stores only the current in/out state of each consideration, or a timestamped history of each change.]
Data minimisation in case notes
Case notes content — including text you type, text you paste, uploaded documents, and voice transcripts — is processed by our AI sub-processor. In line with the data minimisation principle, we recommend you include only information that is clinically necessary and avoid unnecessary identifiers where you reasonably can.
We recognise that clinical correspondence, scan reports and referral letters routinely contain patient names, dates of birth and NHS numbers, and that uploaded documents and voice transcripts carry whatever they contain. Where such identifiers are present in case notes content, that content is transmitted to and processed by our AI sub-processor, and is protected by the safeguards described in sections 5.1 and 6 (contractual protections, no retrievable retention by OpenAI, encryption, and — once our migration is complete — European processing).
Direct patient identifiers you enter in the dedicated Patient identifier field are stored separately in the EEA and are not transmitted to the AI sub-processor.
Your responsibilities
You are responsible for the lawful basis and any necessary consents for inputting Patient Data. We process Patient Data only on your documented instructions, as your data processor (see section 9). Where you input identifiable Patient information, this constitutes special category personal data under UK GDPR. By inputting this data, you confirm that you have the lawful basis to do so under Article 9(2)(h) of UK GDPR (provision of health or social care by a health professional subject to professional confidentiality obligations) or another applicable lawful basis.
Where a Patient is present while you use the Platform — for example when completing an outcome measure together — you remain responsible for informing them appropriately, in line with your professional obligations and the CSP’s principles on the use of AI in practice.
We strongly recommend that you minimise identifiable information where it is not clinically necessary, in line with the data minimisation principle.
3.4 Special category data
Health data is special category data under UK GDPR Article 9. Both User information about your professional role in healthcare and Patient clinical information fall into this category. We process special category data only where one of the lawful conditions in Article 9(2) applies — most commonly Article 9(2)(h) (provision of health or social care) for Patient data, and Article 9(2)(a) (explicit consent) for User professional information.
- How we use your personal data and our lawful basis
Purpose | Lawful basis (Article 6) | Special category condition (Article 9) |
Creating and administering your Account | Contract performance | Explicit consent (Art. 9(2)(a)) for professional health-related role information |
Providing the Platform’s clinical reasoning support functions to you | Contract performance | Provision of health or social care (Art. 9(2)(h)) for Patient data, on your instructions as Controller |
Transcribing audio you record within the Platform | Contract performance | Art. 9(2)(h), on your instructions as Controller |
Processing documents you upload | Contract performance | Art. 9(2)(h), on your instructions as Controller |
Maintaining the case notes timeline and the record of your ruled-in and ruled-out considerations | Contract performance | Art. 9(2)(h), on your instructions as Controller |
Monitoring the clinical safety and performance of the Platform using aggregated, de-identified metrics | Legitimate interests in the post-market surveillance of a registered medical device | — |
Processing payments and managing subscriptions | Contract performance; legitimate interests in operating our business | — |
Communicating with you about the Platform | Contract performance; legal obligation | — |
Improving and developing the Platform using de-identified and aggregated data | Legitimate interests in maintaining a safe, accurate, and useful clinical reasoning tool | — |
Responding to support requests and feedback | Contract performance; legitimate interests | — |
Sending marketing communications (opt-in only) | Consent | — |
Complying with legal, regulatory, and professional obligations | Legal obligation | Substantial public interest where relevant (Art. 9(2)(g)) |
Establishing, exercising, or defending legal claims | Legitimate interests | Legal claims (Art. 9(2)(f)) |
Maintaining the security and integrity of the Platform | Legitimate interests | — |
- How we share your data — sub-processors and third parties
We share personal data with carefully selected third-party service providers (“sub-processors”) who help us operate the Platform. Each is bound by a written contract requiring them to handle data in accordance with UK GDPR and to provide appropriate security measures.
Sub-processor | Role | Data processed | Location |
Google (Firebase / Google Cloud — EU region) | Application database (Firestore) — storage of User accounts, Patient identifier fields, case notes, uploaded documents, transcripts, timeline entries and activity records | User account information; Patient identifier fields; case notes content | European Economic Area (Belgium) |
Google (Firebase Authentication) | User authentication | User email address (authentication only) | United States, with safeguards under the UK Addendum to EU SCCs |
OpenAI, L.L.C. | Large language model processing of case notes content, including uploaded document content, transcripts and Clinical Assistant chat exchanges | Case notes content, which may include patient identifiers present in the notes, uploaded documents, transcripts or chat. Patient identifier fields are stored separately and are not transmitted to OpenAI. | Currently “Global” residency (may include the United States), under the UK Addendum to EU SCCs; migration to European processing in progress |
Pinecone Systems, Inc. | Vector database for retrieval of curated knowledge in response to case notes content | Vector embeddings derived from case notes content | United States (AWS us-east-1), with safeguards under the UK Addendum to EU SCCs |
[TRANSCRIPTION PROVIDER — TO CONFIRM] | Speech-to-text transcription of audio recorded within the Platform | Audio recordings and resulting transcripts | [TO CONFIRM] |
Google (Drive, Colab) | Document storage and processing pipeline for the curated clinical knowledge base — no User or Patient data is processed in this pipeline | Curated knowledge base content only | EEA / Worldwide, with safeguards under the UK Addendum to EU SCCs |
Stripe Payments Europe Ltd / Stripe, Inc. | Payment processing | Billing information (no Patient data) | EU (primary) / US |
Microsoft 365 (Microsoft Ireland Operations Ltd) | Email and support communications | User correspondence (no Patient data unless included by you) | EU (primary) / Worldwide |
We may share personal data with additional categories of recipient where necessary: professional advisers (lawyers, accountants, auditors) under duties of confidentiality; regulators, law enforcement, and courts where required by law; and acquirers or investors in connection with a sale, merger, or financing of our business, subject to appropriate confidentiality. We do not sell your personal data, and we do not share it for advertising purposes.
5.1 OpenAI specifically
When you use the Platform, the case notes content you enter is transmitted to OpenAI’s API for processing by their large language models. This includes text you type, the contents of documents you upload, transcripts of audio you record, and questions you put to the Clinical Assistant chat together with the case context supplied to it.
Patient identifier fields (such as patient name and age) are stored separately within our EEA-based application database and are not transmitted to OpenAI. Case notes content, however, may contain identifiers where they appear in your notes, pasted text, uploaded documents or transcripts; where present, they are transmitted as part of that content.
We are bound by OpenAI’s Data Processing Addendum, which is automatically incorporated into our OpenAI Services Agreement. Our integration is configured so that:
- Data sent via the API is not used to train OpenAI’s models (this is OpenAI’s default position for API customers since March 2023);
- The Platform uses the Chat Completions API with the store parameter defaulting to false, so your content is not retained by OpenAI in a retrievable form; it is held only transiently for prompt caching and for abuse-monitoring/moderation (up to 30 days). We are applying for Zero Data Retention to remove this transient retention;
- Processing currently takes place under “Global” residency and may occur in the United States; we are migrating processing to OpenAI’s European region;
- Standard Contractual Clauses with the UK Addendum govern any international transfer of personal data to the United States.
We continue to encourage Users to minimise unnecessary identifiable Patient information in case notes content, in line with the data minimisation principle and the guidance in section 3.3 above.
- International data transfers
Patient identifier fields (such as patient name and age) are stored in Google Firebase’s European Economic Area (Belgium) region. The UK has recognised the EEA as providing an adequate level of data protection, so this is not a restricted international transfer.
Case notes content — including uploaded document content, transcripts, timeline entries and chat exchanges — is currently processed by OpenAI under “Global” residency, which may include the United States, and by other sub-processors as set out in section 5. We are migrating this processing to OpenAI’s European region, after which it will remain within the EEA. Case notes may contain patient identifiers, which are processed as part of that content.
User account email addresses are processed by Google Firebase Authentication in the United States for authentication purposes.
For each restricted international transfer, we rely on one or more of the following safeguards under UK GDPR Articles 44–49:
- UK Adequacy Regulations where the destination country has been deemed adequate by the UK government;
- The UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, signed with each relevant sub-processor;
- Transfer Risk Assessments, documenting our assessment of the legal regime in the destination country and the supplementary measures in place; and
- For US transfers, where applicable, the recipient’s certification under the UK–US Data Bridge.
You can request a copy of the relevant safeguard documentation by contacting us at the address in section 2.
- How long we keep your data
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
Category | Retention period |
Account information | For the life of your Account, plus 6 years after closure for tax and legal purposes |
Billing records | 6 years from end of relevant tax year (UK statutory requirement) |
Clinical inputs and Platform outputs — including case notes, uploaded documents, transcripts, timeline entries, outcome measure responses, objective test results and activity records | Retained for the duration of your Account, regardless of whether your subscription is currently active. A lapsed subscription does not trigger deletion. On Account closure or receipt of a deletion request, clinical data is deleted without undue delay and in any event within one month. Deleting a case deletes all content associated with it, including uploaded documents, transcripts, timeline entries and the activity record. |
Data processed by OpenAI | Not retained by OpenAI in a retrievable form (Chat Completions API with store defaulting to false); held only transiently for prompt caching and abuse-monitoring (up to 30 days). Zero Data Retention is being applied for to remove this. |
Audio recordings | [TO CONFIRM — state whether audio is discarded immediately after transcription or retained, and if retained for how long] |
Clinical Assistant chat exchanges | [TO CONFIRM — state whether persisted against the case or session-only] |
Aggregated, de-identified safety and usage metrics | Retained indefinitely; not personal data once aggregated |
Support correspondence | 3 years from last contact |
Marketing preferences | Until you withdraw consent, plus a record of withdrawal for compliance |
Server logs and security records | Up to 12 months |
Backups | Rolling backups overwritten on a defined cycle, typically within 90 days |
When you actively close your Account, or on receipt of a deletion request, we will delete or anonymise your personal data without undue delay and in any event within one month, subject to the retention periods in the table above where those apply, and subject to longer retention where otherwise required by law or for the establishment, exercise, or defence of legal claims.
A lapsed subscription does not constitute Account closure and does not trigger deletion of your data. Your case data remains intact during any period where your subscription is not active, so that it is available to you if you choose to resubscribe. You may request deletion of your data at any time regardless of your subscription status — see section 11.
7.1 The Platform and your clinical records
The Platform allows you to build a chronological record of a case over time. This supports your clinical record-keeping; it does not replace it. You remain responsible for maintaining clinical records in accordance with your professional obligations under the HCPC and CSP, including for the retention periods applicable to those records, in your own record-keeping system. The retention periods above apply to data held on the Platform and are not aligned to clinical record retention requirements.
- Security
We take the security of personal data seriously and have implemented technical and organisational measures appropriate to the risk of processing, including:
- Encryption in transit using TLS 1.2 / 1.3 for all data transmitted between your device and the Platform
- Encryption at rest using AES-256 for stored data
- Authenticated access — all Users must sign in with a valid account before any data can be accessed
- Server-side enforcement — every data request is validated at the server
- Per-User data isolation — each User account can only access their own patients
- Administrative access controls — each administrative interaction with the database is individually authorised
- Access logging — all administrative interactions with Patient data are logged at application level; Google Cloud additionally provides independent infrastructure-level logs [TO CONFIRM: confirm access logging is live, and that the DPA Schedule 3 and DPIA agree, before publication]
- Sub-processor due diligence and written data processing agreements with each named sub-processor
- Backup and disaster recovery arrangements
- A documented process for responding to suspected security incidents
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the ICO within 72 hours of becoming aware, and notify affected individuals where required.
- Our role: controller, processor, and your responsibilities
9.1 Where we are Controller
We are the data controller in respect of: your User Account information and contact details; billing and payment data; your communications with us; website visitor and technical data; and aggregated and de-identified data about Platform use, including safety monitoring metrics derived from clinician activity records.
9.2 Where we are Processor
We are a data processor in respect of Patient data and clinical content that you input into the Platform, including uploaded documents, transcripts, timeline entries, outcome measure responses and the record of your ruled-in and ruled-out considerations. For this data, you (the Clinician or your employing organisation) are the data controller. This means:
- You are responsible for determining the lawful basis and obtaining any necessary consents for inputting Patient data;
- You are responsible for ensuring your use of the Platform complies with your professional obligations and the data protection policies of any organisation under whose authority you act;
- You are responsible for handling data subject rights requests from your Patients;
- We process Patient data only on your documented instructions, as set out in this Policy, our Terms and Conditions, and the Data Processing Agreement that forms part of your contract with us.
9.3 Administrative access to Patient data
The Body Navigator administrator has the technical ability to access Patient data stored in the Platform for legitimate operational purposes. We commit to the following:
- Administrative access is undertaken only for legitimate operational purposes — responding to a User support request, investigating a specific technical issue or security incident, or where required by law;
- We do not access Patient data for marketing, training of third-party AI models, or general product browsing;
- We do not review individual clinician activity records for the purpose of assessing or monitoring professional performance;
- Administrative access to the database is individually logged at application level, with independent Google Cloud infrastructure-level logging;
- Other Users of the Platform have no ability to access your Patient data;
- The administrator acts in the capacity of a data processor when accessing Patient data.
- Aggregated and de-identified data
We may de-identify and aggregate data and use it for purposes such as maintaining and improving the Platform, quality assurance, developing new functions, and producing internal analytics. We do not use identifiable Patient health information to train third-party large language models.
Safety monitoring metrics. As the manufacturer of a registered medical device, we have post-market surveillance obligations. To meet them we may derive aggregated, de-identified metrics from Platform usage — including from the record of considerations Clinicians rule in and rule out — to monitor the clinical safety and behaviour of the Platform and to detect changes in its performance over time. For this purpose we act as data controller, relying on our legitimate interests in the safety monitoring of a registered medical device. Aggregation is carried out so that no individual Clinician or Patient is identifiable in the resulting metrics, and individual activity records are not reviewed for this purpose.
- Your rights
Under UK GDPR, you have the following rights in respect of your personal data:
- Right of access — to obtain a copy of the personal data we hold about you
- Right to rectification — to correct inaccurate or incomplete data
- Right to erasure — to ask us to delete your data, subject to legal exceptions
- Right to restrict processing — to ask us to limit how we use your data
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format
- Right to object — to object to processing based on legitimate interests, or to direct marketing
- Rights in relation to automated decision-making — Body Navigator does not make automated decisions that produce legal or similarly significant effects
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at office@thebodynavigator.com. We will respond within one month.
Where you need to respond to a request from one of your Patients, you may request an export of the case data we hold on your behalf, including the case notes timeline and associated content, to assist you in doing so.
- Cookies and tracking
The Platform uses only cookies that are strictly necessary for the operation of the Platform. We do not use cookies for advertising, profiling, or non-essential analytics. Please see our Cookies Policy at [INSERT URL ONCE COOKIES POLICY IS LIVE].
- Children
The Platform is intended for use by registered healthcare professionals only and is not directed at children.
- Automated decision-making and AI
The Platform uses artificial intelligence, large language models, and a retrieval-augmented generation (RAG) pipeline to produce written outputs that support clinical reasoning. These outputs are not automated decisions within the meaning of UK GDPR Article 22, are intended to be reviewed by a registered Clinician, and do not replace clinical decision-making.
Outputs are generated only from the case information you provide and from our curated knowledge base. No consideration carries forward from one stage of the Platform to the next unless you have affirmatively ruled it in.
The Clinical Assistant chat operates on the case in front of you and on the curated knowledge base. Where a response draws on the underlying model’s general clinical knowledge rather than on the curated knowledge base, it is explicitly labelled as such within the response. Content so labelled has not been through our knowledge base verification process and should be evaluated accordingly.
- Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top indicates when it was last revised. The current version is always available at https://thebodynavigator.com/privacy-policy/. For our full regulatory information see https://thebodynavigator.com/regulatory-detail/.
- Contact
Andrew Jackson Physiotherapy — office@thebodynavigator.com
If we cannot resolve your concern, you have the right to complain to the Information Commissioner’s Office (ico.org.uk).