MediConcierge logo

Privacy policy

Last updated: August 2026

Introduction

RSE Labs Ltd, trading as MediConcierge ("we", "us" or "our"), operates the service. A clinic is the controller for patient data it provides and RSE Labs Ltd acts as its processor. RSE Labs Ltd is the controller for this website, its own customer records and business outreach. This policy explains how we collect, use, disclose and safeguard personal data across those activities.

1. What data we collect

We collect information from you when you use or contact the service. Business outreach data may instead come from the sources described in section 5.

  • Contact information: Name, email address, phone number, clinic name and address when you sign up or contact us.
  • Patient information: Through your use of MediConcierge, you may provide patient data including appointment preferences, medical history summaries (processed by AI) and appointment notes. You are the data controller for this information.
  • Usage data: Information about how you interact with our platform, including IP address, browser type, pages visited, time spent and clickstream data.
  • Cookies and tracking: We use cookies and similar technologies (see section 7).
  • Payment information: Billing address, payment method and transaction history (processed by payment providers).

2. How we use your data

We use collected data for the following purposes:

  • Providing and maintaining MediConcierge services to you
  • Processing transactions and sending related information
  • Sending administrative and promotional communications
  • Responding to your enquiries and providing customer support
  • Monitoring and improving our service and platform
  • Complying with legal and regulatory obligations
  • Preventing fraud and keeping the platform secure

3. Legal basis for processing (GDPR)

Under the UK General Data Protection Regulation (UK GDPR), we process your personal data based on the following legal bases:

  • Contract performance: Processing necessary to provide our services to you.
  • Legal obligation: Compliance with UK law and regulations.
  • Legitimate interests: Improving our service, preventing fraud, keeping the platform secure and sending relevant business-to-business marketing (balanced against your rights).
  • Consent: For opted-in marketing communications and optional features (you may withdraw consent at any time).

4. Data retention

We retain personal data only for the stated purpose. The specific period for business outreach appears below. Patient data follows the clinic's retention instructions. Once you delete your account, anonymised usage data may be retained for up to 12 months for analytics unless the law requires a longer period. You can request deletion at any time.

5. Business outreach data

RSE Labs Ltd, trading as MediConcierge, is the controller when we contact a clinic decision-maker about MediConcierge. The record contains the person's name and work email address. We may also hold their role plus one public fact about the clinic.

A name plus work email may come from Lusha, a business-data provider. A reviewed clinic inbox or role inbox plus clinic facts may come from the clinic's public website. We remove the named contact from a role-inbox record because the address belongs to the clinic rather than one person. We use official company records to decide whether the proposed recipient is a corporate subscriber. We do not seek health information or other special-category data about the business contact.

We use this limited record to send relevant business-to-business marketing under UK GDPR Article 6(1)(f). Our legitimate interest is introducing a clinic operations product to a person responsible for the clinic's operations. We consider whether the contact is necessary and balance that interest against the person's rights before release.

Mailbox, source-data, private code-hosting and device-sync suppliers may process the record for us. Some processing may occur outside the UK. The applicable provider uses an adequacy route or contractual transfer terms where the law requires one. You can ask us for the relevant details. We do not sell the record or track email opens or clicks. Automated scheduling decides when to send. It makes no decision with legal or similarly significant effect about the recipient.

A contacted prospect record is kept for six months after our last contact. A record for someone we never contact is deleted within six months of collection. If the person objects or opts out, we keep the minimum address record needed to prevent another approach. That suppression record is retained indefinitely for this purpose.

The person can object to direct marketing at any time. They can ask to see the record or have it corrected. They can ask us to restrict or delete it and may complain to the ICO. Replying to the email reaches the sender; privacy requests can also go to info@mediconcierge.ai. The person does not have to respond.

6. Your rights under UK GDPR

You have the following rights:

  • Right of access: You can request a copy of your personal data we hold.
  • Right to rectification: You can correct inaccurate or incomplete data.
  • Right to erasure: You can request deletion of your data (subject to legal obligations).
  • Right to restrict processing: You can limit how we use your data.
  • Right to data portability: You can request your data in a portable format.
  • Right to object: You can object to processing for marketing or legitimate interests.
  • Right to withdraw consent: You can withdraw consent for optional processing at any time.

To exercise any of these rights, please contact us at info@mediconcierge.ai.

7. Cookies and tracking technologies

We use three kinds of cookies:

  • Essential cookies: Required for authentication and platform functionality.
  • Preference cookies: Remember your settings and preferences.
  • Analytics cookies: Help us understand how you use our platform.

You can control cookie preferences through your browser settings. Disabling cookies may affect platform functionality.

8. AI processing and third-party processors

MediConcierge uses AI to answer patient enquiries and assist with appointments. We use the following third-party processors:

  • Anthropic (Claude AI): For AI-powered patient communication and appointment assistance. To generate a reply, patient message text is sent to Anthropic's API on US infrastructure. MediConcierge stores the prompt and response in its UK audit log. Anthropic deletes API inputs and outputs from its systems within 30 days under its standard policy, subject to its stated exceptions. These transfers are covered by the Standard Contractual Clauses and the UK IDTA.
  • Cloud hosting (Vercel and Neon): Application hosting and the Postgres database, both in the UK (London): Vercel functions execute in London (lhr1) and the Neon database is in AWS eu-west-2 (London). Vercel is US-incorporated, so its Standard Contractual Clauses and UK International Data Transfer Agreement terms apply.
  • Twilio: For UK phone numbers, call routing and SMS delivery. Twilio carries a live call to the voice processor. A number may use Twilio's US or EU processing region under its contractual transfer terms.
  • Voice-processing provider: For speech recognition, turn-taking and voice generation on live calls. The service receives caller audio and conversation text. The current account uses US storage and can retain conversation data. Zero-retention mode is not enabled. We identify the provider and its terms in the clinic's contractual sub-processor schedule before a patient line goes live.

Processor terms and data processing agreements apply according to each service. A clinic receives the current sub-processor schedule before patient processing starts.

9. Data security

We protect your personal and patient data with:

  • Encryption in transit (TLS) and at rest
  • Encryption at rest for stored data
  • Tenant data scoped per clinic, with least-privilege database access
  • Access controls and role-based permissions
  • Incident response procedures

10. International data transfers

Patient data is stored at rest in London. Application compute also runs in London. AI inference sends patient message text to Anthropic's US infrastructure. Live voice can send caller audio and conversation text to the voice provider's US service. Twilio may process call or message content in its US or EU region. Business-outreach suppliers may also process work contact records outside the UK. Where the destination is not covered by UK adequacy regulations, the relevant provider's contractual transfer terms apply. You can ask us for details of the safeguard relevant to your data.

11. Contact information

For privacy enquiries, data access requests or to exercise your rights:

RSE Labs Ltd, trading as MediConcierge

Company number: 17175071

Registered in England and Wales

Registered office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ

Email: info@mediconcierge.ai

Website: mediconcierge.ai

We aim to respond to all data access requests and privacy enquiries within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

12. Updates to this policy

We may update this privacy policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes by updating the "Last updated" date and, if required, by obtaining your consent.