Citrus AI is committed to protecting the privacy and confidentiality of patient and healthcare provider data. As an AI-powered medical scribing solution, we adhere to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, ensuring the secure and lawful processing of personal and sensitive data.
This policy outlines how Citrus AI collects, processes, and protects personal data in compliance with UK GDPR.
Citrus AI operates as a data processor when handling patient data on behalf of healthcare providers and as a data controller when managing user accounts and service-related data.
Under UK GDPR, Citrus AI processes personal data based on the following lawful grounds:
| Lawful Basis | Application to Citrus AI |
|---|---|
| Legitimate Interest | AI-assisted transcription and health record analysis for healthcare providers to streamline documentation. |
| Performance of a Contract | Providing our AI-powered services as per user agreements. |
| Legal Obligation | Compliance with medical, regulatory, and data protection laws. |
| Consent | When users opt-in for additional features, marketing, or research initiatives. |
Citrus AI does not use patient data for advertising or non-healthcare purposes.
Citrus AI processes the following types of data:
We never process genetic, biometric, or non-essential health data.
Citrus AI employs robust security measures to safeguard personal data, including:
For detailed security measures, visit our Security & Compliance Page.
Citrus AI does not sell or share patient data with unauthorized third parties.
We only share data with:
All third-party processors undergo rigorous security audits and sign Data Processing Agreements (DPAs).
Citrus AI retains personal and special category data only as long as necessary:
Users can request early deletion of their data by contacting admin@getcitrus.ai.
Under UK GDPR, users and patients have the following rights regarding their personal data:
| Right | Description |
|---|---|
| Right to Access | Request a copy of personal data processed by Citrus AI. |
| Right to Rectification | Correct inaccurate or incomplete data. |
| Right to Erasure (Right to Be Forgotten) | Request deletion of data if no longer necessary. |
| Right to Restrict Processing | Limit how data is processed under certain conditions. |
| Right to Data Portability | Receive a copy of data in a structured, commonly used format. |
| Right to Object | Object to processing based on legitimate interest. |
| Rights Related to Automated Decision-Making | Request human intervention in AI-driven processing. |
To exercise your rights, email admin@getcitrus.ai
Citrus AI stores and processes data within the UK & EEA to ensure compliance with UK GDPR.
For data transfers outside the UK/EEA, we ensure:
We never store patient data in regions with inadequate data protection laws.
Citrus AI has a strict incident response plan:
If a data breach occurs, we will:
For reporting a data breach, contact admin@getcitrus.ai.
To maintain regulatory compliance, Citrus AI undergoes:
For compliance documentation, request a report at admin@getcitrus.ai.
VMLP AI Healthcare, a UK based company with a vision and mission to leverage AI's cutting edge technology to improve quality of healthcare.