← Back to QA toolExpert Witness QA

Privacy notice

This privacy notice explains how Expert Witness QA handles personal data in connection with this website and the Expert Witness QA prototype.

Working draft — prototype use

This is a working privacy notice for prototype use. It should be reviewed by a data-protection professional before any wider pilot involving identifiable or potentially re-identifiable patient or claimant data.

A. Who we are

Company and controller details to be finalised before wider release.

Expert Witness QA Limited

[Company number — to be confirmed]

[Registered address — to be confirmed]

Contact: contact@medicolegalqa.com

B. Our roles

For website account management and platform administration, Expert Witness QA Limited may act as controller for limited user-account, authentication, security and support data.

For uploaded report content, the intended model is that the user or their organisation remains responsible for determining the lawful basis, authority and governance for uploading the material. Depending on the final commercial model, Expert Witness QA Limited may act as processor for report content or as an independent controller for limited operational/security purposes. This role allocation must be finalised before processing identifiable or potentially re-identifiable case material.

Current prototype position

The platform should currently be used only with anonymised, synthetic or appropriately authorised documents. Users must not upload identifiable patient, claimant, witness or third-party information unless they have appropriate authority and governance in place.

C. Types of personal data

Website/account data may include:

  • name and contact details;
  • login/authentication information;
  • technical information needed for security and operation;
  • support or enquiry messages.

Uploaded report content may include, if the user chooses to upload it:

  • information from solicitor letters of instruction;
  • expert report text;
  • medical history;
  • injury details;
  • employment, care, rehabilitation and financial information;
  • special category health data;
  • litigation-related information;
  • information about third parties.

During prototype testing, identifiable or confidential case-specific information should not be uploaded unless appropriately authorised.

D. Purpose of processing

The platform processes uploaded documents to:

  • extract text from the letter of instruction and report;
  • apply automated redaction/pseudonymisation;
  • allow user review of the redacted preview;
  • generate an AI-assisted QA review;
  • display and export the QA output;
  • maintain service security and reliability.

E. Lawful basis

Users/controllers are responsible for determining and documenting the appropriate lawful basis for any case-specific personal data they upload. In litigation and medicolegal contexts, this may involve processing for the establishment, exercise or defence of legal claims, but users must make their own assessment and obtain advice where required.

Where special category data is involved, the user/controller must identify an Article 9 UK GDPR condition and any applicable Data Protection Act 2018 Schedule 1 condition. Users should also consider whether an Appropriate Policy Document is required.

F. Redaction and pseudonymisation

The platform includes automated redaction/pseudonymisation designed to identify and replace categories such as names, dates of birth, NHS numbers, hospital numbers, addresses, telephone numbers, email addresses, postcodes, employer names, hospital names and reference numbers.

This process is a safety measure, not a guarantee of anonymisation. Users must review the redacted preview before proceeding. If identifiers remain visible, the user should not continue until the document has been corrected or redacted manually.

G. AI processing and subprocessors

The prototype uses selected third-party cloud services to operate the application. These may include:

  • hosting/deployment provider: AWS Amplify Hosting (or current hosting provider)
  • authentication/database provider: Supabase (or current provider)
  • AI model provider: AWS Bedrock Runtime using Anthropic Claude Sonnet 4.6 in Europe (London)
  • document/export libraries running within the application environment

AWS Bedrock Runtime is used to process redacted/pseudonymised text for the purpose of generating the QA review. The production route is configured for the Europe (London) region and the current model-access policy is restricted to the selected Claude Sonnet model.

Until confirmed contractually and through a completed DPIA, this platform does not claim on-premises processing or approval for identifiable live medicolegal material. Users requiring those assurances should not use this prototype for identifiable material.

H. Data retention

Developer note

Check implementation before publishing this section. Do not state deletion/retention claims that are not technically true.

Current intended prototype behaviour:

  • Uploaded files should not be deliberately retained after processing unless the user explicitly downloads or saves outputs.
  • Generated QA outputs are displayed to the user and may be downloaded as PDF or Word.
  • The application avoids storing original uploaded report content unless this is explicitly implemented, documented and governed.
  • Operational logs should not contain report text, solicitor instructions, identifiers or AI prompts.
  • Account and technical data may be retained for security, support and legal purposes.

I. Security

Current security measures include, where implemented:

  • authenticated access;
  • environment-variable secret management;
  • redaction/pseudonymisation workflow before AI processing;
  • user review step before AI processing;
  • limited operational logging;
  • HTTPS in production;
  • no intentional use of uploaded content for model training by the application.

No external certification has been obtained at this stage.

J. User responsibilities

Users must:

  • ensure they have authority to upload material;
  • avoid uploading identifiable data during prototype testing unless appropriate governance exists;
  • check redaction before processing;
  • verify all outputs against source material;
  • make their own decisions about report amendments;
  • comply with instructions, professional duties, privilege, confidentiality and data-protection obligations.

K. Contact

For privacy questions, contact: contact@medicolegalqa.com