Skip to main content
Data governance

Clinical patient data handled with the seriousness it deserves

Amilis processes health data under UK GDPR's special category provisions. Here is what that means in practice for your clinic.

Data category Art. 9 special category
Your clinic's role Data controller
Amilis role Data processor
Data residency UK only
UK GDPR and health data

Your clinic's obligations, our responsibilities

Fertility patient data is special category health data under UK GDPR Article 9. That classification places specific obligations on how it is collected, processed, and retained.

Controller and processor roles

Your clinic is the data controller under UK GDPR: you determine why patient data is collected and what it is used for. Amilis acts as a data processor: we handle that data only on your clinic's documented instructions, for the specific purpose of presenting the patient timeline. A Data Processing Agreement (DPA) is included with every plan and sets out these responsibilities in writing.

UK data residency

Patient records processed through Amilis are stored and processed on UK-based infrastructure. No patient data is transferred to servers outside the United Kingdom. This supports your clinic's obligations under the UK GDPR data transfer provisions introduced by the Data Protection Act 2018.

No secondary use of patient data

Patient data imported to Amilis is used for one purpose only: constructing the timeline view that clinicians read. It is not used to train machine learning models, not aggregated for research purposes, and not accessed by Amilis staff except during a directly requested support session with your clinic's knowledge and consent.

Right to erasure (Article 17)

If a patient exercises their right to erasure under UK GDPR Article 17, your clinic can request deletion of that patient's records from Amilis. Deletion is complete within 30 days of a written request and confirmed in writing. Backup retention follows a 90-day rolling window before full removal.

How it works technically

How patient data moves through Amilis

These are design principles, not certification claims. We describe what we actually do.

Encryption at rest and in transit

All patient data stored in Amilis is encrypted at rest using AES-256. Data moving between your clinic's browser and Amilis infrastructure uses TLS 1.2 or higher. File imports are encrypted on receipt and never stored in plain form.

Clinician-level access controls

Access to patient records is scoped at the individual clinician level. Clinic administrators assign who can view which patient records. A clinician without access to a patient's record cannot retrieve it, even by direct URL.

Audit logging of record access

Every access to a patient record within Amilis is logged: which clinician, which record, at what time. Clinic administrators can export access logs on request. This supports your clinic's internal audit obligations for special category health data.

Purpose limitation by design

The Amilis system architecture does not have a pathway by which imported patient data can reach any component outside the timeline rendering function. There is no analytics pipeline, no export to third-party tools, and no API endpoint that would allow data extraction beyond the patient record view.

Data governance questions

Questions about how we handle your clinic's data?

If you have specific questions about the DPA, data flows, or how Amilis fits within your clinic's UK GDPR obligations, send them to [email protected]. We do not use a chatbot for data governance questions.