Privacy
Version 0.1 draft · Last updated date
Margot is inbox software for private medical secretaries. It reads an enquiry and drafts a reply. This page sets out what happens to personal data along the way, including patients' data, which is the part that matters most.
Margot never sends anything. Every draft is read by the secretary, who decides what is sent and sends it herself.
Who is responsible for what
Two different kinds of personal data pass through Margot, and the responsibility for each sits in a different place.
Your data as a customer
When you book a call or take a trial, we decide how your name, email and telephone number are used. For that data we are the controller.
Patient data inside the practice
When you paste a patient's enquiry into Margot, we act only on your instruction. We do not decide what to do with it. For that data we are a processor, and the practice — or you, depending on how your engagement with the practice is written — is the controller.
Whether the secretary or the practice is the controller of patient data has not been settled, and it changes who signs the data processing agreement. A solicitor should determine this before any customer uses the product.
Who we are
| Entity | registered or trading name |
|---|---|
| Address | registered address |
| Contact | hello@margotoffice.co.uk |
| ICO registration | registration number — required before processing patient data |
What we collect from you
| What | Why | Lawful basis |
|---|---|---|
| Name, email, telephone, preferred call time | To arrange your set-up call and open your trial | Steps taken at your request before a contract |
| Practice configuration — fees, venues, clinicians, published answers, tone of voice | To draft replies that match the practice | Performance of our contract with you |
| Billing details | To take payment after the trial | Performance of our contract with you |
Practice configuration is business information about a practice, not patient information. It may include the names and titles of consultants, which is personal data about them.
Patient data
This is the section that matters. When you paste a patient's email into Margot, that text may contain their name, contact details, and information about their health. Health information is special category data and carries the strictest protection under UK GDPR.
What happens to it
- The text is read in your browser by a set of keyword rules. This happens on your own machine and the text does not leave it.
- The text is then sent to a language model, which extracts facts from it — what is being asked, which procedure is mentioned, whether there is anything urgent. The model does not decide whether to refuse; the rules do.
- The extracted facts and the practice's own data produce a draft.
- The draft appears on your screen. Nothing is sent to anyone.
Where it goes
| Who | What they receive | Where |
|---|---|---|
| Microsoft Azure | Hosting. Enquiry text passes through the application server in transit. | West Europe (Netherlands) |
| Anthropic | The text of the enquiry, for extraction | United States |
The transfer of special category health data to a provider outside the UK is the single most significant thing in this policy. The safeguard relied on — the UK addendum to the standard contractual clauses, an adequacy decision, or another mechanism — must be named here, and whether a zero-retention arrangement is in place must be stated. This cannot be left vague.
What is not stored
- We keep no database of enquiries. There is no account, no message history, no inbox on our side.
- Corrections you make to a draft are saved in your own browser and stay there. They are not sent to us and we cannot read them. Clearing your browser data removes them.
- Patient names and contact details are not written to any file we hold.
Whether the application server writes enquiry text to a log, and for how long any such log is kept, must be confirmed and stated here.
How long we keep things
| What | Kept for |
|---|---|
| Enquiry from a call booking | period |
| Practice configuration | While you are a customer, then period |
| Billing records | Six years, as required by HMRC |
| Patient enquiry text | Not retained by us |
Who else we use
| Supplier | What for |
|---|---|
| Microsoft Azure | Hosting the website and the application |
| Anthropic | Reading enquiry text |
| Cloudflare | Domain name records |
| Formspree | Receiving call bookings from the signup form |
| payment provider | Taking subscription payments |
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it being used. Where you have given consent, you can withdraw it.
Write to hello@margotoffice.co.uk. We will reply within one month.
If a patient asks us for their data, we will refer them to the practice. We hold it only on the practice's instruction and it is not ours to hand over.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
Cookies
This website sets no cookies and runs no analytics. The application stores your own corrections in your browser's local storage so they survive a refresh. That is not a cookie and is not shared with anyone, including us.
Security
- Everything is served over HTTPS.
- Each practice's data is held in a separate file. Nothing is shared between practices.
- Access to the application is protected by a code held by the practice.
A per-practice access code is not authentication. Before a paying customer this needs proper accounts, and the security section should describe what is actually in place at that point rather than what is in place today.
Changes
If this policy changes in a way that affects you, we will tell you by email before it takes effect.