Privacy Policy — SYNERGY Patient App
Last updated: 01/09/2026
Version: 1.0
Applies to: the SYNERGY patient app for iOS and Android.
1. Who we are
MEDIDERMDG, trading as SYNERGY ("we", "the clinic"), is the data controller for the personal
information described in this policy. That means we decide how and why your information is used, and we are responsible for
looking after it.
- Registered address: 29 Cherry Orchard Way, Maidstone, Kent, ME16 8TJ
- ICO registration number: ZB847774
- Data protection contact: Mr Dushyanth Gnanappiragasam, Dushyanth28@gmail.com, 07912382980
- General contact: synergy.help.queries@gmail.com
If you are an NHS patient, this app is provided by the clinic in connection with your care. It does
not replace any NHS service, and it is not run by the NHS.
2. What this app is — and what it is not
The app lets you ask questions about a procedure you are having or have had at our clinic. It
answers practical and procedural questions only: how to prepare, what happens on the day,
aftercare, timings, and common questions.
It does not give medical or clinical advice. It cannot diagnose anything, interpret your
results, or tell you whether a symptom is serious. If you ask something clinical, or describe a
symptom that needs a clinician's attention, the app does not attempt to answer — it passes your
message to our clinical team and tells you someone will follow up.
The app is not for emergencies and is not monitored around the clock.
If you notice spreading redness, pus or a fever, call 111. If you feel very unwell, call 999.
Messages you send can be reviewed by clinic staff
Monday–Friday, 9am–5pm, excluding bank holidays.
Outside these hours, no messages are reviewed. Never use this app to report an urgent problem.
3. What information we collect
3.1 Information already held in your clinic record
To use the app you must already be a patient of the clinic. We use the record we already hold:
| Information | Why we hold it in the app |
|---|---|
| Your name | To identify you and to address you in replies |
| Your date of birth | To verify it is really you before showing any personal information |
| Your mobile phone number | To identify you and to send you a one-time security code |
| Your appointments — procedure, body site, date, and status | So answers relate to your actual procedure and where you are in your recovery |
| Your preferred language | So we reply in your language |
| Medication | So that the information you are given can be filtered against what your procedure guidance says |
We may also hold other clinical details as part of your wider medical record, including allergies,
medications and comorbidity flags where applicable.
3.2 Information you give us when you use the app
- The messages you send, and the replies the app sends you.
- Your agreement to the notice shown when you first sign in, together with the date and the
version of the wording you agreed to.
3.3 Information collected automatically
- Technical and security logs — records of sign-in attempts, security codes issued, and errors,
used to keep the service secure and working. These are held by our hosting provider.
- We do not use advertising trackers, and we do not sell or share your information for
marketing.
Health information. Most of the above is information about your health. UK data protection law calls this special category data and gives it extra protection. We explain our legal grounds in §5.
4. How we use your information
- To confirm who you are. Because a phone can be shared, lost or reassigned, a phone number
alone is not enough to prove identity. We check your surname and date of birth, then send a
one-time code by text to the number we hold for you. You must enter that code before the app
will show you anything personal. We ask you to confirm your date of birth again periodically.
- To answer your questions. When you send a message, we use your upcoming or recent
appointment to work out which procedure you are asking about, then answer from the clinic's own
written guidance for that procedure.
- To pass clinical questions to a clinician. If your message needs clinical input, we create an
escalation record and email our clinical team so they can respond.
- To keep a record of the conversation. We keep a log of messages sent and received. This is
part of your care record and our audit trail: it lets us check what advice you were given.
- To keep the service safe, secure and working.
We do not use your information to make any automated decision about you or your care. The app
provides information and routes questions to people; decisions about your treatment are made by
clinicians.
5. Our legal basis for using your information
Under UK GDPR we rely on:
- Article 6(1)(f) — legitimate interests for using your personal information.
- Article 9(2)(h) — provision of health care and treatment. This is our basis for using
information about your health, and it is the basis that applies to the substance of this service.
We do not rely on your consent as the legal basis for providing this service. That matters in
practice: the notice you agree to when you first sign in is there so you understand what the service
is. It is not a consent mechanism, and withdrawing it does not erase records we are required to keep
as part of your medical record. You can stop using the app at any time, and doing so
will not affect your care in any way.
You can always contact the clinic by phone or email instead.
6. Who we share your information with
We do not sell your information and we do not share it for marketing. We share it only with:
| Who | What they receive | Why |
|---|---|---|
| Our own clinical and administrative staff | Your messages, escalations and appointment details | To answer your questions and provide your care |
| Amazon Web Services (AWS) | All app data — it is stored and processed on AWS | Our hosting and infrastructure provider (a data processor acting on our instructions) |
| Our text-message delivery provider, via AWS | Your mobile number and the one-time code | To deliver your security code by text |
Each of these providers acts on our written instructions under a data processing agreement. They are
not permitted to use your information for their own purposes.
We may also disclose information where the law requires it, or where necessary to protect someone's
vital interests.
7. Artificial intelligence, and how we control it
The app uses an AI language model, provided through Amazon Bedrock, to help write replies.
We think you should understand exactly what that means.
What the AI receives. When you send a message, we send the AI: your message, the last few turns
of your current conversation, your name, and details of your appointments (procedure, body site,
date and status). It also receives the clinic's own written guidance for your procedure.
What the AI does not do.
- It is not used to make decisions about you or your treatment.
- It is not trained on your messages. Under the AWS Service Terms (section 50.3), Amazon Bedrock
is excluded from the services whose content AWS may use to develop and improve its AI services,
and the model provider does not receive your messages. Your messages are not retained after your
request is processed.
- It is not permitted to invent clinical information. It answers only from the clinic's own
written guidance, and every reply is automatically checked before it reaches you. If a reply
cannot be supported by that guidance, it is not sent — your question goes to a clinician instead.
Human oversight. Any message that looks clinical, describes a concerning symptom, or asks about
medication is routed to a clinician rather than answered by the AI.
Where the AI processing happens. Your data is stored in the UK/EEA (see
§8), but the AI model is invoked through a
cross-region inference profile, which means the processing of your message may take place in
any AWS region within the EU, not only the region where your data is stored.
8. Where your information is stored
Your information is stored on AWS servers in London. The production environment is configured
for the AWS London region.
Where information is processed in Ireland or elsewhere in the EEA, that transfer is covered by the
UK's adequacy regulations for the EEA, which recognise EEA countries as providing equivalent
protection to UK law.
9. How long we keep your information
| What | How long |
|---|---|
| Your conversation history | 36 months, after which it is deleted automatically |
| Message log (record of messages sent and received) | 36 months, after which it is deleted automatically |
| Escalations sent to clinicians | 36 months, after which it is deleted automatically |
| One-time security codes | 5 minutes |
| Sign-in sessions | 7 days |
| Your clinic record | For as long as you are a patient of the clinic. After that, it is kept in our system so that you can still ask us to delete your information through the app or the web |
Where a message forms part of your medical record, we keep it for as long as we are required to keep
your medical records, even if you stop using the app.
10. How we protect your information
- You must verify your identity with a one-time code before any personal information is shown.
- Repeated failed verification attempts are rate-limited and can lock the account.
- All information is encrypted in transit and encrypted at rest.
- On your phone, your sign-in session is held in the device's secure keystore (iOS Keychain /
Android Keystore), and the app can be locked with your fingerprint, face or device PIN.
- Access by staff is restricted to those who need it for your care, and access is logged.
11. Your rights
Under UK data protection law you have the right to:
- Be told how your information is used — that is what this policy is for.
- Get a copy of the information we hold about you (a "subject access request").
- Have mistakes corrected.
- Ask us to delete information. This right is limited where we must keep your medical records.
- Object to, or ask us to restrict, how we use your information.
- Complain — see §13.
Deleting your app account. You can ask us to close your app account and delete your app data at
any time, by telling your clinician or doctor, or by emailing synergy.help.queries@gmail.com. You
can also request deletion on our Delete my app account page. Closing your app
account does not delete your medical record, which we are required to keep.
To exercise any right, contact synergy.help.queries@gmail.com. We will respond within one month.
12. Children
The app is only made available to patients aged 18 and over.
13. How to complain
Please contact us first at synergy.help.queries@gmail.com — we would like the chance to put things
right.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's
data protection regulator:
- ico.org.uk/make-a-complaint
- 0303 123 1113
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
If your concern is about your clinical care rather than your data, please email us at
synergy.help.queries@gmail.com.
14. Changes to this policy
If we change this policy we will update the date at the top and, where the change is significant,
tell you in the app. Material changes require the in-app notice version to be updated so you are
shown the new wording.
15. Contact us
MEDIDERMDG (trading as SYNERGY)
29 Cherry Orchard Way, Maidstone, Kent, ME16 8TJ
Email: synergy.help.queries@gmail.com
Data protection contact: synergy.help.queries@gmail.com