Last reviewed 7 September 2026 · Applies to med-legal.co.uk and med-legal.net
The short version
| Where records are stored | Servers operated by Hetzner Online GmbH in Germany (EU), for every customer in every country. |
|---|---|
| In transit | HTTPS/TLS only. HTTP Strict Transport Security is enforced for a year with subdomains included, so a browser will not fall back to plain HTTP. |
| How long originals exist | Original uploads are deleted automatically within 24 hours of upload (a courtesy email goes out an hour before). Generated outputs stay in your account until you delete them. |
| Training on your data | Never. The AI provider is a contracted sub-processor bound to use record text solely to provide the service to us. |
| Who can see a claim | Only the account that created it. Records are scoped to a single claim, and every action in the app is written to an audit log. |
| Card details | Handled by Stripe. We never see or store a card number. |
| Paperwork | A Data Processing Agreement on request; your executed Agreement Record as a PDF at signup; our Privacy Policy and Terms & Fees are public. |
| What we are not | Not ISO 27001 certified, not Cyber Essentials certified, not HIPAA-certified, and we do not currently offer a US Business Associate Agreement. We would rather you knew. |
Roles: who is the controller
For the medical records you upload, your firm is the data controller and Med-Legal is a processor acting on your instructions. Your firm decides why the records are processed and holds the Article 9 condition for health data (in a litigation context, ordinarily the establishment, exercise or defence of legal claims). We process the records only to produce the chronology, fact ledger and bundle you asked for. For your own account and billing data, we are the controller. The full statement of both roles is in section 2 of the Privacy Policy.
What happens to a file, step by step
- Upload. Files travel over TLS to our server in Germany and are stored against the single claim you created. Nothing is shared between claims or accounts.
- Processing. Page text is extracted (scanned pages are OCR'd on our own server) and passed, as text, to a specialist AI provider acting as our sub-processor to build the chronology. Every extracted fact carries the document and page it came from, and the quoted text is checked in our own code against that page.
- Output. The chronology, the fact ledger and, if ordered, the paginated bundle are written to your account. They are yours to download and delete.
- Deletion of originals. The original uploads are removed automatically within 24 hours. The outputs remain. If you later need a bundle, which requires the originals, you re-upload the records.
- Review. Every output is an AI-assisted draft. It says so on the document, and it passes a review gate: a qualified professional at your firm approves it against the cited pages before it is used.
Sub-processors
| Hetzner Online GmbH | Hosting and storage. Germany (EU). |
|---|---|
| Specialist AI provider | Generates the chronology and summary from record text. May be outside the UK, including the United States, under the UK data bridge or the International Data Transfer Addendum. Contractually barred from using the data for its own purposes or for training. |
| Stripe | Card payments. Handles card data directly. EU / USA. |
| Google / Microsoft | Optional "sign in with" authentication, only if you choose it. |
| Email delivery provider | Service emails: welcome, document-ready, receipts. |
We will tell account holders before adding a sub-processor that will touch uploaded records.
Technical controls in place today
- TLS on every connection, with HSTS (
max-age=31536000; includeSubDomains). - A restrictive Content Security Policy (
default-src 'self', no third-party scripts,frame-ancestors 'none'),X-Frame-Options: DENY,X-Content-Type-Options: nosniff, a strict referrer policy, and camera, microphone, geolocation, payment and USB permissions disabled for the page. - Passwords stored only as salted hashes. Sign-in with Google or Microsoft available if your firm prefers SSO.
- Administrative access to the server is by SSH key only; password login is disabled, a host firewall exposes only web and administrative SSH traffic, and failed-login lockout runs on the SSH service.
- Per-claim scoping of every record and output, with an audit log of actions in the app that you can see.
- Automatic deletion of originals within 24 hours, so the window in which a raw record set exists on our systems is short by design.
- Only the cookies needed to sign you in and to keep payments secure. No advertising or third-party tracking cookies.
If something goes wrong
We will notify affected account holders and the ICO of a reportable personal-data breach as UK GDPR requires, and assist your firm with any claimant rights request that concerns records processed through the service. Email info@med-legal.co.uk; a real person reads it.
Outside the UK
The same hosting, deletion and no-training commitments apply to every customer in every country. Each country edition's Country Schedule in the Terms names the local privacy regime your firm must satisfy on its side. For the United States that means applicable federal and state law including HIPAA where the firm is a covered entity or business associate; we describe our posture as HIPAA-aware, not HIPAA-certified, and we do not currently offer a Business Associate Agreement.
Want it in writing? Reply to your welcome email or write to info@med-legal.co.uk and ask for the Data Processing Agreement. Want to test before anyone signs anything? Your first ten units are free with no card, and a closed or redacted file works as well as a live one.
This page summarises the controls actually in place on the date shown; where it and the Privacy Policy or Terms & Fees differ, those documents govern. General information, not legal advice.