Privacy Policy

Introduction

MessageGP Limited (“MessageGP,” “we,” “us,” or “our”) processes your personal data in compliance with the Data Protection Act 2018 (“DPA”) and the UK General Data Protection Regulation (“UK GDPR”) (collectively referred to as “Data Protection Legislation”). This policy outlines how we process your personal data, why we process it, and the safeguards in place to protect it.


Definitions
  • Personal Data: Information that identifies you or relates to you, such as your name, contact details, date of birth, and medical history.
  • Special Category Data: Data revealing racial or ethnic origin, political opinions, religious beliefs, or data concerning health, sex life, or sexual orientation.
  • Processing: Any operation performed on personal data, such as collection, storage, amendment, transfer, or deletion.


Our Responsibilities

MessageGP Limited acts as the data controller for the personal data you provide. We have appointed Dr. Arpit Srivastava as our Data Protection Officer (DPO), who oversees compliance with Data Protection Legislation and responds to data subject requests. You can reach the DPO at hello@messagegp.com


Why We Process Your Personal Data

We process your personal data for the following purposes:

  • To provide healthcare services you have requested.
  • To fulfil contractual obligations.
  • To comply with legal obligations and ensure public health and safety.
  • To enhance patient care and improve our services.





What Personal Data We Process


Patients:

  • Identity data: Name, date of birth, gender, marital status.
  • Contact data: Address, email, phone numbers.
  • Medical data: Health records, consultation history, medications, and test results.


Suppliers:

  • Identity data: Name, job title, and company details.
  • Contact data: Business address, email, and phone numbers.
  • Financial data: Payment details for service transactions.


Candidates:

  • Identity data: Name, date of birth, and contact details.
  • Background data: Education, career history, and skills.


How We Use AI & Your Data

MessageGP’s AI chatbot, provided by Superchat, assists users with general inquiries, such as symptom-based questions, platform guidance, and customer support. However, Superchat does not share or transmit personally identifiable information (PII), including names, phone numbers, or email addresses, to OpenAI or any third-party AI provider.


How We Protect Your Data in AI Interactions
  • Anonymous User Identification – Instead of transmitting personal data, Superchat assigns an anonymous ID to user interactions. OpenAI can only match this with an internal Superchat ID, ensuring that conversations remain unlinked to specific individuals.
  • No Personal Data Transmission – Names, contact details, and any other personally identifiable information are never sent to OpenAI or any AI provider.
  • No Data Retention Beyond a Session – AI-generated responses are not stored or retained after the interaction ends, maintaining privacy and minimizing exposure risks.
  • Strict Data Protection Controls – AI interactions comply with GDPR data minimization principles and are governed by a Data Processing Agreement (DPA) between Superchat and OpenAI, ensuring strict security measures are in place.

By using privacy-first AI technology, MessageGP ensures that AI-driven support is delivered efficiently without exposing user data to unnecessary risks.

For further details on how we process and protect your data, please contact our DPO at hello@messagegp.com


AI Usage

MessageGP employs an AI Chatbot through Superchat to assist patients by asking questions about symptoms and medical history. The chatbot operates under strict limitations and doesn’t make medical decisions. Patient consent is required before initiating any AI driven interaction, ensuring compliance with GDPR transparency requirements.


Legal Basis for Processing

We process your data based on:

  • Your explicit consent.
  • The performance of a contract.
  • Compliance with legal obligations.
  • Legitimate interests in providing healthcare services.
  • Protection of vital interests or public health.





Third-Party Processors

We may share your data with:

  • External service providers, such as diagnostic labs or specialists.
  • Our Electronic Patient Record system, Semble, for secure data storage.
  • Superchat: Superchat provides the main infrastructure for our services. As a data processor, they operate strictly under our instructions and adhere to a data processing agreement that ensures compliance with data protection legislation.
  • Heidi Health: Provides Transcription services to convert audio recordings into clinical notes. Audio is processed on UK AWS Servers, pseudonymized, and securely deleted after seven days. No audio recordings are stored, and all processing complies with GDPR. Heidi Health also transfers pseudonymized text data to Anthropic for AI processing under Standard Contractual Clauses (SCCs).





Partner suppliers including:
  • Inuvi for home blood tests, blood pressure, and BMI monitoring (Privacy Policy).
  • SignatureRx for electronic prescriptions (Privacy Policy).
  • SomerX for electronic prescriptions (Privacy Policy).
  • Communication platforms, including WhatsApp, which are used securely with guidance provided for patients on maintaining WhatsApp security (e.g. enabling biometrics, avoiding sharing phones, and deleting conversations after consultations).
  • Semble’s privacy policy can be found here.





WhatsApp GP Consultations


How We Use WhatsApp for Secure Communication
At MessageGP, we use WhatsApp Business API, provided by Superchat, to offer a secure and convenient way for patients to communicate with GPs.
When you message us via WhatsApp, you are communicating with an official, verified MessageGP business account, which operates under strict privacy and security standards. Superchat acts as an intermediary service, securely processing messages while maintaining compliance with UK GDPR and healthcare data protection regulations.

Data Privacy & Security
We prioritise patient confidentiality and implement robust security measures to safeguard your information. WhatsApp messages are end-to-end encrypted, meaning that neither Meta (WhatsApp’s parent company) nor any third party can access the content of your messages.

However, Meta does collect metadata, including:

  • Contact Details – The fact that you have messaged MessageGP’s WhatsApp business account.
  • Message Timestamps – When messages are sent and received.
  • Device & Network Data – Your phone model, operating system, and IP address (which may indicate general location)
  • App Usage Data – How often you interact with business accounts on WhatsApp.

Superchat securely handles messages in compliance with GDPR and medical privacy standards. These conversations may be stored in our secure clinical system for record-keeping and auditing where legally required.

How WhatsApp API Differs from Standard WhatsApp

Unlike personal WhatsApp accounts, our WhatsApp API system (via Superchat) provides additional security and compliance benefits:

  • Official Business Account – You are messaging a verified MessageGP business account, ensuring authenticity.
  • No Personal Numbers Required – Our system uses a dedicated business number, protecting your personal data.
  • Secure Message Handling – Conversations may be securely stored on our GDPR-compliant system for medical record-keeping and auditing purposes.





Actions You Can Take to Protect Your Privacy

To enhance the security of your conversations with MessageGP, we recommend the following best practices:

  • Disable chat backups in iCloud (iPhone) or Google Drive (Android), as these are not encrypted by WhatsApp.
  • Use a secure device with a strong passcode or biometric lock to prevent unauthorized access.


Enable Two-Step Verification in WhatsApp:


1. Open WhatsApp and go to Settings.

  1. Tap Privacy → Two-step verification → Enable.
  2. Set a six-digit PIN and enter your email for recovery.
  3. Tap Save, and two-step verification is now active.

Enable App Lock (Fingerprint/Face ID) for Extra Security:

  1. Open WhatsApp and go to Settings.
  2. Tap Privacy → Screen Lock (iPhone) or Fingerprint Lock (Android).
  3. Toggle Require Face ID / Touch ID / Fingerprint and set a time delay.
  4. Now, WhatsApp will require biometric authentication before opening.
  • Delete conversations with MessageGP after your consultation. We securely store the consultation on our clinical system for medical records.
  • Log out of linked devices if using WhatsApp Web.
  • Turn off message previews on your phone’s lock screen to prevent unauthorized viewing.
  • Do not forward medical messages to others or share GP chats in group conversations.

Data Transfers

We do not transfer your personal data outside the European Economic Area (EEA). Heidi Health utilises Anthropic for processing pseudonymized transcription data. All transfers comply with GDPR and are conducted under Standard Contractual Clauses (SCCs) to ensure data protection.


Data Security

We employ robust security measures, including encryption and access controls, to protect your personal data in compliance with our Information Security Management Policy.


Data Retention

We retain your personal data for three years unless a longer retention period is required by law. After this period, your data will be securely deleted or destroyed in compliance with our Secure Disposal Policy. Audio data processed by Heidi Health is securely deleted within seven days. Other data such as medical records stored in Semble is retained for three years, unless required by law for longer retention.


Cookies Policy

We use cookies to enhance your experience on our website and to understand how you interact with our services. Cookies are small data files stored on your device when you visit our website. The types of cookies we use include:

  • Essential Cookies: Necessary for the operation of our website. These cookies enable basic functionality like page navigation and access to secure areas.
  • Analytical Cookies: Help us understand how visitors use our website, enabling us to improve user experience. These cookies collect anonymized data.
  • Preference Cookies: Allow our website to remember your preferences, such as language settings.
  • Third-Party Cookies: May be set by third-party services embedded in our website, such as analytics tools.

You can manage your cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of the website. For more details, refer to our full Cookies Policy available on our website.


Your Rights

Under the Data Protection Legislation, you have the following rights:

  1. Access: Request access to your personal data.
  2. Rectification: Correct inaccurate or incomplete data.
  3. Erasure: Request deletion of your data under certain conditions.
  4. Restriction: Request suspension of processing under specific circumstances.
  5. Portability: Receive a copy of your data in a structured, machine-readable format.
  6. Objection: Object to processing based on legitimate interests or direct marketing.
  7. Withdraw Consent: Where we rely on your consent to process your data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.


To exercise these rights, contact our DPO at hello@messagegp.com.


Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you, the Information Commissioner’s Office (ICO), and relevant third-party processors within 72 hours, in line with our Data Breach Policy.


Updates to This Policy

This policy is reviewed regularly and updated to reflect changes in our data processing practices or applicable law.


Contact Us

For any questions about this policy or your data, contact:
MessageGP Limited
86-90 Paul Street, London, EC2A 4NE
Email hello@messagegp.com