Privacy Policy
Updated 13 June 2026This policy explains how Joint Operations Ltd (“we”, “us”) collects, uses, stores, shares and protects personal data when you use the Joint Operations App, and the rights you have over it. We are the data controller and are committed to handling your information lawfully, fairly and transparently under the UK GDPR and the Data Protection Act 2018. Read it together with our Terms & Conditions, Cookies Policy and Data Deletion Policy.
1. Who we are and how to contact us
The Joint Operations App is operated by Joint Operations Ltd (company number 11817255), registered office Unit 11 Bincknoll Lane, Royal Wootton Bassett, Swindon, England, SN4 8SY. We are the data controller for the personal data described here and are registered with the UK Information Commissioner’s Office (ICO). For any data-protection question or to exercise your rights, contact support@jointoperations.co.uk or write to us at the address above.
2. Who this policy applies to
The App is a closed, professional-use platform made available only to verified medical professionals and authorised company representatives. The App is not offered to, and we do not knowingly collect personal data from, members of the general public or anyone under 18.
3. The data we collect
- Account and identity data: your name, professional title, the email address you were invited with, organisation/employer, role, and where relevant professional registration details used to verify eligibility.
- Authentication data: credentials used to secure your account (passwords are stored only in a hashed, irreversible form).
- Content you submit: information, queries, messages and other content you enter, including inputs to the AI features.
- Usage data: how you interact with the app and the AI features, including the prompts you submit and the outputs generated.
- Device and technical data: device type, operating system, app version, IP address, identifiers, and diagnostic and performance data.
- Communications: messages you send us, including support requests.
- Information from third parties: verification and authorisation data from your employer, our tenant partner or professional sources, used to confirm your eligibility.
We do not ask for, and you should not submit, patient-identifiable or special-category clinical information through the app unless you are lawfully entitled to do so and the app is designated for that purpose.
4. How we use your data and our lawful bases
- Create, verify and manage your account and provide access — contract; legitimate interests in a secure professional platform.
- Operate, maintain and provide the app’s features, including AI features — contract; legitimate interests.
- Verify your eligibility (professional status / authorisation) — legitimate interests; legal obligation where applicable.
- Monitor and analyse usage of the app and the AI features to operate, secure, troubleshoot and improve it — legitimate interests.
- Derive insights from usage and AI interactions and use your contact details to market our own products and services — legitimate interests, and/or consent where required by law.
- Secure the app and prevent and detect fraud, misuse and security incidents — legitimate interests; legal obligation.
- Communicate with you about the app, including service and security notices — contract; legitimate interests; legal obligation.
- Comply with legal, regulatory, audit and record-keeping obligations, and establish, exercise or defend legal claims — legal obligation; legitimate interests.
Where we rely on legitimate interests, we have assessed that they are not overridden by your rights; you can ask us about that assessment. Where we rely on consent, you may withdraw it at any time without affecting your use of the app.
5. Usage monitoring, AI interactions and marketing
We monitor and analyse how you use the app, including your interactions with the AI features, to operate, secure and improve it, and we may use insights from that monitoring, together with your contact details, to market Joint Operations’ own products and services to you. We use this only for our own first-party marketing — we do not sell your personal data, and we do not share it with third parties for their marketing. You can opt out at any time using the unsubscribe link in our messages or by contacting us; opting out will not affect your use of the app. We will still send essential service and security messages, which are not marketing.
6. AI features and your data
We process AI inputs and outputs using Microsoft Azure / Azure OpenAI within our cloud environment. Your inputs and outputs are not used to train Microsoft’s or OpenAI’s foundation models and are not accessible to OpenAI. As part of its standard service, Microsoft may temporarily retain a sampled subset of inputs and outputs for up to 30 days for abuse monitoring, accessible only by authorised Microsoft reviewers, after which it is deleted. This is separate from the usage records we keep. Do not input patient-identifiable or confidential information into the AI features unless you are lawfully entitled to do so.
7. Automated decision-making
We do not make any decision producing legal or similarly significant effects about you based solely on automated processing. We may analyse usage to understand how the app is used and to personalise the content you see, which does not have a legal or similarly significant effect on you.
8. Who we share it with
We do not sell your personal data. We share it only with:
- Service providers acting on our instructions under contract — Microsoft (Azure / Azure OpenAI) for hosting, identity and AI; email and messaging providers; and analytics, monitoring, security and support tooling providers.
- Your employer or our tenant/organisation partner, to verify eligibility and administer your access.
- Regulators, law enforcement and other authorities, where required or permitted by law.
- Professional advisers (such as lawyers and auditors) where necessary.
- A successor or buyer, if we reorganise our business or transfer assets, subject to appropriate safeguards.
9. International transfers
Our primary hosting is in the United Kingdom (Microsoft Azure, UK South, with UK backups). Where any personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — such as an adequacy decision/regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
10. Cookies
We use a small number of cookies and similar technologies to operate, secure and analyse the app. Some are strictly necessary; others are used only where permitted. See our Cookies Policy.
11. How long we keep it
- Account and identity data: while your account is active, then deleted or anonymised within 30 days of closure or a valid deletion request, unless a longer period is required by law.
- Usage and AI interaction records: up to 25 months, then deleted or anonymised.
- Security, access and audit logs: up to 12 months (longer for an incident or legal obligation).
- Support communications: up to 24 months from your last contact.
- Marketing opt-out records: kept on a suppression record for as long as needed to honour your choice.
- Records for legal claims: up to 6 years, reflecting the limitation period under the Limitation Act 1980.
Where the law requires us to keep certain information, we retain it for that period even after you close your account. See our Data Deletion Policy.
12. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, access controls, tenant isolation, hashing of credentials, network protection, and logging and monitoring, with access restricted on a need-to-know basis. No system is perfectly secure, but we take steps to protect your data and to detect, manage and report incidents in line with our legal obligations.
13. Data breaches
We maintain procedures to detect, report and investigate personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where required, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will inform you without undue delay.
14. Special-category data
The app is not designed to collect special-category data (such as health data) about you, and you should not input it unless you are lawfully entitled to do so and the app is designated for that purpose. Where we do process any special-category data, we will only do so where an additional condition under Article 9 UK GDPR and the Data Protection Act 2018 applies.
15. Children
The app is for professional users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
16. Your rights
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (see the Data Deletion Policy).
- Restriction and objection — limit or object to certain processing, including direct marketing at any time.
- Portability — receive certain data in a structured, commonly used, machine-readable format.
- Withdraw consent — at any time, where we rely on consent.
To exercise any right, contact support@jointoperations.co.uk. We will respond within the time limits set by law (usually one month) and may need to verify your identity first. Some rights are not absolute and may not apply in every case. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
17. Changes
We may update this policy from time to time. We will record the date of the latest version at the top of this page and, where changes are significant, ask you to review it again.
This document is provided for transparency and is kept under review. If anything here is unclear, contact us through the support form on the sign-in screen.