1. Who is responsible
Doctalis is a product published by CodHash Agency Ltd, a private limited company registered in England and Wales under company number 15446527, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For the public website, demo requests, account administration, security and billing records, CodHash Agency Ltd acts as data controller. Contact: [email protected].
2. Roles for clinical data
For patient and consultation data entered by a healthcare practice, the practice normally determines why and how the data is used and therefore acts as controller. Doctalis acts as processor under the practice’s documented instructions and the applicable data processing agreement.
The practice remains responsible for informing patients, establishing the applicable legal basis, collecting consent where required, managing professional secrecy and deciding retention. Doctalis does not make autonomous medical decisions.
3. Data we process
Depending on how you interact with Doctalis, we may process:
- demo and contact data: professional email, name, role, organisation, phone number, country and message;
- technical data: IP address, device/browser information, selected market, timestamps and security logs;
- account and practice data: identity, authentication, membership, professional profile and configuration;
- clinical data, only in an authorised clinical environment: patient identifiers, consultation audio, transcripts, clinical notes, documents, signatures and audit events;
- commercial data: subscription, invoices and payment status, without storing full payment-card details ourselves.
4. Purposes and legal bases
We use personal data only for defined purposes:
- answering demo and commercial requests, based on steps requested before a contract and our legitimate interest in responding;
- creating accounts and providing the contracted service;
- protecting accounts, investigating incidents, preventing abuse and meeting legal obligations;
- processing clinical information on the healthcare practice’s documented instructions;
- sending optional communications only where a valid consent or another lawful basis applies.
5. Health data and AI
Never place real patient or health data in a public demo or contact form. A clinical environment may receive such data only after the required contract, privacy configuration, provider approval and regulatory formalities have been completed.
Doctalis produces drafts. The clinician must review, correct, validate and sign every final medical document. Automated output is not a diagnosis, prescription or certified clinical decision.
6. Providers and recipients
Access is limited to authorised CodHash personnel and providers needed to operate the service. The public site currently relies on Railway for hosting, Cloudflare for network delivery and protection, and Discord for restricted internal notifications about demo requests.
The active speech-to-text integration is Gladia for live and pre-recorded transcription. Audio is sent to Gladia only for an environment and customer for which that provider, its region and the required contractual safeguards have been explicitly enabled. Other categories may include transactional email, object storage and malware scanning, structured text generation and payment providers, as documented in the applicable service agreement.
7. International transfers
Doctalis is published by a UK company and uses providers that may operate in the United Kingdom, European Union, Morocco or other countries. When a transfer is subject to a legal safeguard, we use the appropriate contract, regional configuration and transfer mechanism. Where Moroccan Law 09-08 applies, required CNDP notification, authorisation and foreign-transfer formalities must be completed before the relevant processing is activated.
8. Retention
Demo-request data is retained until the request is closed and, where no commercial relationship follows, for no longer than 24 months after the last meaningful contact. Account, contract and billing records are kept for the relationship and applicable statutory periods.
Clinical data is retained according to the healthcare practice’s documented settings and instructions. Audio retention is configurable. Security logs are kept for the shortest operational period compatible with incident investigation and legal duties. Data is then deleted or irreversibly anonymised, subject to a legal hold or mandatory archive.
9. Security
We apply access controls, encryption in transit, restricted storage grants, audit trails, tenant isolation, signed clinical states and incident procedures. No internet service can guarantee zero risk. Please use the coordinated disclosure process on the Security page rather than sending sensitive evidence through a demo form.
10. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing, and may withdraw consent without affecting prior lawful processing. Write to [email protected] and specify that the request concerns Doctalis. We may need to verify identity without collecting excessive information.
For patient data controlled by a healthcare practice, contact that practice first; we will assist it as processor. You may also complain to the Moroccan CNDP, the UK ICO or the competent authority in your country.
11. Updates and contact
We may update this policy when the product, provider list or law changes. Material changes will be highlighted on this page or in the product. Privacy questions and rights requests: [email protected].