eLogbookAI

Privacy Policy

Effective date: 1 Sep 2026Version: 1.0.1Apeiron Digital Labs Ltd (trading as eLogbookAI.)

1. Introduction

Apeiron Digital Labs Ltd ("We", "Us", "Our", "the Company") is committed to protecting the privacy and security of personal data processed through eLogbookAI. This Privacy Policy explains how we collect, use, and protect personal data when you use our automated surgical logbook service (the "Service").

For the purposes of the Data Protection Act 2018 ("DPA 2018") and the UK General Data Protection Regulation ("UK GDPR"), we are the Data Controller for subscriber account data. In respect of the patient data contained in the theatre lists you upload, you – the subscribing surgeon – are the controller of the logbook processing, and we act as your processor under Article 28 UK GDPR. The NHS Trust remains the controller of the theatre list as its own source record. This relationship is explained in Section 3.

Company Details

  • Registered Name: Apeiron Digital Labs Ltd
  • Registered Office: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF
  • Company Number: 16382596
  • ICO Registration Reference: ZB897727
  • NHS ODS Code: A5I1S
  • Privacy Contact: privacy@elogbook.ai

2. The data we collect

We collect and process the following categories of personal data:

Category A – Subscriber Account Data (persistent)

This is standard account data relating to you as a registered subscriber. We are the sole Data Controller for this category.

  • Identity data: name, GMC number, professional grade and surgical specialty.
  • Contact data: email address.
  • Authentication data: OAuth provider identifiers (Google, Microsoft or Apple). We do not store passwords; the Service is passwordless OAuth-only.
  • Third-party logbook credentials: an encrypted session token used to authenticate submissions to elogbook.org on your behalf. We do not store your elogbook.org password. Tokens expire after a defined period, after which you will be prompted to re-authenticate.
  • Financial and subscription data, if you use a paid offer: Stripe customer and subscription identifiers. We do not store card numbers; card handling is managed entirely within Stripe's PCI-compliant infrastructure.
  • Preferences and settings: favourite hospitals, consultants, notification preferences, and similar account configuration data.
  • Compliance records: your onboarding authorisation declaration, authorisation acknowledgement logs, GMC verification status, and marketing consent records.

Category B – Confidential Patient Information (transient)

This is the Special Category data contained in theatre list photographs uploaded by you. As the surgeon maintaining your own professional logbook, you are the controller of this processing; we act as your processor under Article 28 UK GDPR, processing it transiently and on your instructions as described in Section 3. It is not added to your account record or any long-term application datastore.

  • Theatre list images are uploaded by you to restricted, transient processing storage in Google Cloud Storage, processed by our AI extraction pipeline to identify logbook-relevant fields, and then permanently deleted under the controls described in Section 5.
  • Patient names may be read by the model during image processing but are discarded from the extracted result and are not displayed to you or submitted.
  • Dates of birth are converted to patient age at the point of extraction. The date of birth is discarded from the extracted result.
  • The fields passed through to elogbook.org are limited to those required by their schema: patient identifier (MRN or NHS number), patient age, procedure, CEPOD classification, laterality, ASA grade, supervision level, consultant, hospital, and operation date.
  • Under normal operating conditions, transient source images are permanently deleted as soon as processing completes successfully or reaches its final failed attempt, usually within seconds. Automated sweeps and a storage lifecycle rule provide additional deletion controls if immediate deletion does not complete.

Category C – Audit Log (persistent)

As controller, we maintain a persistent operational audit log of CPI-processing events for accountability, security, legal compliance, and incident investigation. It is designed to exclude patient names, patient identifiers, images, and clinical content, but it is personal data because it can include the surgeon identifier and a restricted system-generated object path. Depending on the event, it may also record the action type, timestamp, file size, MIME type, user agent, and other operational metadata. It does not contain a copy or cryptographic hash of the source image.

Category D – Technical, Security and Usage Data

We process limited technical and usage data to deliver, secure, troubleshoot, and improve the Service. This can include IP address, request URL and headers, user agent, device or browser information, TLS and edge-security signals, error diagnostics, a pseudonymous internal user identifier, and limited account, onboarding, validation, subscription, upload-status, or processing-status events. Optional browser analytics are collected only after cookie consent. Separate server-side operational events do not use analytics cookies and are processed under legitimate interests. Uploaded images, patient identifiers, and extracted clinical fields are not intentionally sent to analytics or error-monitoring providers.

3. How and why patient data is processed

When you record your surgical cases in your logbook, you process patient data for your own professional purpose: maintaining the GMC-mandated surgical logbook you are required to keep. For that processing you are the controller and eLogbookAI is your processor under Article 28 UK GDPR – we process only on your instructions and for no purpose of our own. Confidential Patient Information is not added to your account record or any long-term application datastore; transient processing copies are deleted under the controls described in Section 5. The Article 28 terms governing this relationship form part of our Terms of Service.

The lawful basis for processing patient data under Article 6 UK GDPR is legitimate interests (Article 6(1)(f)): the surgeon's professional obligation to maintain a contemporaneous surgical logbook, mandated by the GMC's Good Medical Practice framework and the training and revalidation standards of all four UK Royal Colleges of Surgery.

The condition for processing Special Category health data under Article 9 UK GDPR is Article 9(2)(h): processing necessary for the management of health or social care systems and services, read with section 10(2) of and paragraph 2 of Schedule 1, Part 1 to the DPA 2018. The surgical logbook underpins surgical training, revalidation, and clinical governance across the UK health system. The condition is further supported by Article 9(3): the processing is carried out under the responsibility of a GMC-registered doctor with a licence to practise who is subject to professional secrecy under UK law. Doctor status, GMC registration, and licence to practise are verified at account creation; accounts cannot be activated without this verification.

At account creation you provide a declaration confirming that you are authorised under your organisation's information governance and Caldicott framework to process theatre list data for logbook purposes using automated tools, and that you accept sole responsibility for ensuring that authorisation is in place before processing patient data through the Service. Before each upload you provide a further session-level confirmation via an authorisation acknowledgement dialog.

5. Data retention

  • Category B (patient data): not added to your account record or any long-term application datastore. Under normal operating conditions, source images are deleted as soon as processing completes successfully or reaches its final failed attempt, usually within seconds.
  • Automated deletion sweeps run every five minutes. A source image for a completed or failed job is deleted on the next sweep. If its job record is missing, it is preserved for a five-minute grace period and then deleted on the next sweep. If a job is active or retryable, its source image may be kept during a recovery window of up to 30 minutes and is then deleted on the next sweep. Processing results become eligible for deletion after five minutes and are deleted on the next sweep.
  • A one-day Google Cloud Storage lifecycle rule is an asynchronous final backstop if the immediate and automated sweep controls do not delete an object. Lifecycle deletion may occur after the object reaches one day old rather than at an exact 24-hour deadline.
  • Category A (account data): retained while your account remains open. During the invitation-only private beta, cancelling changes your subscription access but does not trigger an automated account purge. You may request erasure at any time by emailing privacy@elogbook.ai. We will assess and respond to the request within one calendar month and erase data where the right to erasure applies. Limited billing, audit, security, or legal records may be retained where there is a lawful reason to do so.
  • Category C (audit log): retained for up to 7 years under the current retention configuration for accountability, security, legal compliance, and incident investigation. We act as controller for this operational personal data associated with the surgeon. It is designed to exclude patient names, patient identifiers, images, and clinical content.
  • Category D (technical, security and usage data): retained for the shortest configured period reasonably needed for service delivery, security, troubleshooting, usage analysis, and the establishment or defence of legal claims. Provider-specific settings and contractual retention evidence are reviewed as part of our sub-processor governance.
  • MongoDB Atlas cluster backups: retained for 7 days. These backups can contain Category A account data, Category C audit data, and limited Category D technical or security metadata. The application is designed not to write uploaded images, complete extraction results, or clinical content to MongoDB.

6. Sub-processors and international transfers

We engage service providers in connection with the Service. Where a provider processes personal data on our behalf, it operates under applicable data processing terms; a provider may instead act as an independent controller for some activities, as explained in the Sub-Processor Register at https://elogbook.ai/legal/subprocessor-register. For an intended addition or replacement that will process patient data on our behalf, we will ordinarily provide at least 14 days' advance notice by email and update the Register. If an urgent security, legal, availability, or provider event makes advance notice impracticable, we will notify you as soon as reasonably practicable. You may object during the notice period on reasonable data-protection grounds by contacting privacy@elogbook.ai. The objection process and consequences are set out in clause 7 of Schedule 1 to the Terms of Service.

  • Google Cloud Platform (UK – London region for core workload resources): application hosting, restricted transient object storage, AI extraction, key management, and scheduled deletion controls. Google Cloud's data processing terms govern provider access and any applicable international transfer. Vertex AI customer data is not used for model training or improvement without the customer's permission or instruction.
  • Cloudflare (distributed network): edge security, routing, and reverse proxying for browser traffic. Browser uploads and result responses pass through Cloudflare in transit before and after the London-hosted application. Processing locations may vary; Cloudflare's applicable data processing and transfer terms govern that processing.
  • MongoDB Atlas (UK – London region): persistent storage of Category A account data and Category C audit log. The application is designed not to write uploaded images, complete extraction results, or clinical content to MongoDB.
  • Redis Cloud (provider-managed service): managed Redis for queue coordination, CPI-session validation, job progress and status, rate limiting, validation, other operational state, and procedure-taxonomy lookup caching. It may hold subscriber, session, and job references; restricted Google Cloud Storage object references; timestamps; request or validation metadata; and procedure-taxonomy cache entries. A cache entry maps a procedure label to the corresponding elogbook.org taxonomy entry and is keyed by a hash of that label alone. Cache entries have no subscriber linkage and are designed not to contain patient names, patient identifiers, dates of birth, operation dates, or hospitals. Uploaded image bytes and extracted-result payloads are not stored in Redis. Connections use TLS. Provider access, support processing, processing locations, and any international transfer are governed by Redis Ltd's applicable data processing and transfer terms.
  • Stripe (United States): payment processing and subscription management. Stripe receives billing and subscription data and is not intentionally sent uploaded patient content or extracted clinical fields. Transfer mechanism: UK Extension to the EU-US Data Privacy Framework (primary); UK International Data Transfer Addendum to EU SCCs (fallback).
  • Sentry (Frankfurt, EU): application error monitoring. Default personal-data collection is disabled and event filtering is configured so uploaded patient content and extracted clinical fields are not intentionally sent. Transfer mechanism: UK-EU adequacy decision.
  • PostHog (Frankfurt, EU): optional browser analytics are enabled only with cookie consent. Separate pseudonymous server-side operational events are processed under our legitimate interests in operating, securing, and improving the Service; they use an internal user identifier and limited status/event properties rather than email, name, GMC number, uploaded patient content, or extracted clinical fields. Session recording is disabled. Transfer mechanism: UK-EU adequacy decision.
  • Resend (United States): transactional email using subscriber contact details and non-clinical message content. Uploaded patient content and extracted clinical fields are not intentionally sent. Transfer mechanism: UK Extension to the EU-US Data Privacy Framework (primary); UK International Data Transfer Addendum to EU SCCs (fallback).
  • BetterStack (EU data storage): domain-level uptime and availability monitoring. The Company does not configure BetterStack to receive application content, request bodies, uploaded patient content, or extracted clinical fields. Transfer mechanism: UK-EU adequacy decision for EU-stored data; UK International Data Transfer Addendum to EU SCCs as fallback.

Core application, storage, and AI resources that handle uploaded patient content are configured in the Google Cloud London region. Browser uploads and result responses also pass through Cloudflare's distributed network in transit, where processing locations may vary. We do not intentionally send uploaded patient content to Stripe, Sentry, PostHog, Resend, or BetterStack. Where provider access or processing involves a restricted transfer, the provider's applicable contractual transfer safeguards apply.

7. Security measures

We implement a privacy-by-design and security-by-default approach. Key measures include:

  • Encryption in transit and at rest, including customer-managed encryption for transient uploaded images and additional field-level protection for stored authentication tokens.
  • Layered authentication and access controls for users, administrators, and service-to-service access.
  • Data minimisation and separation designed to prevent uploaded images, complete extraction results, and clinical content from entering long-term account storage or audit records.
  • Automated deletion, monitoring, incident-response, and recovery controls, including the transient-data deletion arrangements described in Section 5.

8. Your rights

Under UK GDPR you have the following rights in relation to your personal data:

  • Right of access (Article 15): to request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): to request correction of inaccurate personal data.
  • Right to erasure (Article 17): to request deletion of your personal data, subject to our legal retention obligations.
  • Right to restriction (Article 18): to request that we restrict processing of your personal data in certain circumstances.
  • Right to withdraw consent (Article 7(3)): where we rely on your consent – for marketing communications and optional browser analytics cookies – you may withdraw it through the relevant cookie or unsubscribe control, or by contacting privacy@elogbook.ai. Withdrawal does not affect processing carried out before withdrawal. Server-side operational events use legitimate interests rather than cookie consent; you may object to that processing under Article 21.
  • Right to data portability (Article 20): where the legal conditions apply, to receive personal data you provided to us in a structured, commonly used, machine-readable format. We assess this right against the content and legal basis of the records involved rather than excluding a record solely because it is labelled audit or technical data. Category B source images and processing results are transient processing artefacts rather than an account export.

To exercise any of these rights, please contact us at privacy@elogbook.ai. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) at any time. We would appreciate the opportunity to address your concerns before you contact the ICO.

9. Information for patients

If you are a patient whose data may have been processed through eLogbookAI, this section is for you. Your surgeon uses eLogbookAI to automate the entry of your procedure details into their surgical logbook – a professional record they are required to maintain by the GMC. This is the same information they would have recorded manually. Your data is held in restricted transient storage while the image is processed and the result is returned, then deleted under the controls and timings described in Section 5. It is not added to the surgeon's eLogbookAI account record or any long-term application datastore. Your surgeon is the controller of their professional logbook record; the NHS Trust that provided your care remains the controller of the theatre list and your clinical records; and eLogbookAI acts only as your surgeon's processor.

If you have questions about how your data has been used, or wish to exercise your data subject rights in relation to your procedure data, please contact the NHS Trust where your procedure took place, or your surgeon. If you have a complaint about eLogbookAI specifically, please contact us at privacy@elogbook.ai.

10. Cookies

We use strictly necessary cookies to facilitate user authentication and secure session management. With your consent, we use analytics cookies (PostHog) to understand how you use the Service and improve its features. You can manage your cookie preferences at any time via the cookie settings in the application. We do not use advertising cookies or tracking pixels.

11. Changes to this Policy

We will ordinarily notify you of legally material changes to this Privacy Policy by email to your registered address at least 14 days before the change takes effect. We may use a shorter period where a change is required urgently for law, security, patient protection, availability, or a provider restriction. The current version and effective date are shown at the top of this document. Previous versions are available on request.

12. Contact

For any questions about this Privacy Policy or our data protection practices, please contact us at privacy@elogbook.ai

Apeiron Digital Labs Ltd (trading as eLogbookAI.) · Version 1.0.1 · Effective 1 Sep 2026