Privacy & GDPR policy

What personal data the platform touches, why, on what lawful basis, how long it is kept, and the rights people have.

ResiliSense · last updated 17 September 2026

Who is responsible for what

MedPsych Behavioral Health (“the practice”, “you”) is the controller of patient personal data: it decides why patients are contacted and on what basis. ResiliSense (“we”, “us”) acts as a processor, handling that data only on the practice's documented instructions under a written data-processing agreement.

For accounts of the practice's own staff who log in to the platform, we act as controller of the minimum needed to run and secure those accounts.

What data the platform handles

The design principle is minimisation. In production the platform holds only:

  • · Identity and contact: first name, last name, mobile number, contact preference, language.
  • · Scheduling context: appointment date, time, provider, status, and whether it was confirmed, cancelled or rebooked.
  • · Follow-up context: that a medication review is due — not the clinical content of the note.
  • · Conversation history: the messages sent and received, and the interpretation and action taken.
  • · Staff and audit data: who did what, when, and why.

What it deliberately does not hold

  • · Clinical notes, diagnoses and free-text clinical history — those stay in the record system.
  • · Payment card numbers or bank details.
  • · Special-category data beyond the fact that an appointment or review exists.

Why we process it (lawful bases)

Under the UK/EU GDPR the practice normally relies on:

  • · Legitimate interests or performance of a contract — administrative reminders about an appointment the patient already has.
  • · Consent — where messages go beyond administration, or where local messaging rules require prior agreement.
  • · Legal obligation — record keeping and responding to regulators.
  • · Article 9(2)(h) — where health data is processed for the provision of care, under professional confidentiality duties.

Automated decisions and profiling

Eligibility is decided by transparent rules the practice configures, not by opaque profiling, and the outcome is a message or an escalation — not a decision about a person's care or rights. Where a reply is unclear, a person decides. Patients can ask for human review of anything the platform did.

How long data is kept

  • · Conversation threads: for the retention period the practice sets, by default 24 months.
  • · Audit logs: kept longer where a regulator requires it, and never edited.
  • · Opt-outs: kept indefinitely, because forgetting one would mean contacting someone who said stop.
  • · Prototype data: synthetic, and deleted whenever the demonstration is reset.

Sharing and sub-processors

We share data only with sub-processors needed to run the service — hosting, messaging, and AI language models — each under a written agreement with confidentiality, security and no-training commitments. We keep a current list of sub-processors and tell the practice before adding a new one.

We do not sell personal data, and we do not use it for advertising.

International transfers

Where data leaves the UK or EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses with a transfer risk assessment. Hosting region can be pinned at the practice's request.

Security

Encryption in transit and at rest, least-privilege role-based access, individually attributed accounts, step-up authentication for sensitive actions, audit logging of every automated and manual action, and separation of duties for anything irreversible. See the security policy for detail.

Individual rights

People can ask for access, correction, erasure, restriction, portability, objection to processing, and withdrawal of consent, and can complain to their supervisory authority — in the UK, the Information Commissioner's Office.

Requests should go to the practice as controller. We assist within five working days and support the controller in meeting the one-month statutory deadline.

Personal data breaches

We notify the practice without undue delay and within 72 hours of becoming aware of a breach affecting its data, with what we know, what we are doing and what we recommend. The practice, as controller, decides on notification to regulators and individuals.

Health-information rules outside Europe

Where US health-privacy rules apply, we act as a business associate and will only handle protected health information under a signed business associate agreement, which is a prerequisite for go-live. India's DPDP Act, and other local regimes, are handled on the same principles: minimisation, purpose limitation, notice, and honoured opt-outs.

Contact

Privacy questions and data requests: hello@byov.ai.

Other policies

These policies are written for a prototype running on made-up patient data. They are a starting point for your own legal review, not legal advice, and they do not claim any certification.