Trust
Compliance & Security
Ciel Healthtech Ltd · SC836646 · Dundee
Safeguarding data is at the heart of everything we do
We are committed to upholding the highest standards of data privacy, security, and clinical safety to support healthcare professionals and protect sensitive information.
At GeneralPractice.AI, clinical safety and data protection aren’t just tick-box exercises — they’re fundamental to everything we build. We’ve embedded compliance into our design process from day one, aligning with standards such as DCB0129, DTAC, DSPT, GDPR, and the Australian Privacy Act. Our team prioritises security at every level, implementing strict controls, proactive risk assessments, and independent audits to ensure our platform is both safe and trusted for healthcare settings.
Clinical safety
GeneralPractice.AI complies with NHS DCB0129 standards, with oversight from a qualified Clinical Safety Officer. Our clinical risk assessments and safety case have been thoroughly reviewed to ensure the platform supports safe and effective use in clinical settings.
Every plan is approved by a clinician before a patient sees it. Long-term condition plans wait for sign-off; the clinician can edit any part of the plan, and the assessment flags anything that needs attention on the same screen.
GeneralPractice.AI is not a medical device. It supports clinical judgement and does not diagnose, treat, monitor or prevent any condition.
Data protection
GeneralPractice.AI complies with UK GDPR, the EU GDPR and the Australian Privacy Act 1988, ensuring strong safeguards around data collection, storage, and access. To request a copy of our Data Protection Impact Assessment (DPIA), please email info@generalpractice.ai.
Full detail of what we process, on what lawful basis, and how to exercise your rights is in the Privacy Policy. Where we act as a processor for a practice, we do so only under that practice’s documented instructions and an appropriate data processing agreement.
Security
Access is role-based and least-privilege. Data is encrypted in transit, systems are patched on a regular schedule, and the platform is subject to vulnerability scanning and independent review. Staff are bound by confidentiality agreements and trained on information governance.
Asking for our documentation
Practices, ICBs, PHNs and procurement teams can request the DPIA, the DCB0129 clinical safety case, our DTAC response and the current sub-processor list by emailing info@generalpractice.ai.