Privacy Notice
Effective and last updated: 27 August 2026
This Privacy Notice explains how Regspire Ltd collects, uses, stores and shares personal information when you visit our website, join our waitlist, create an account or use the Regspire service. It also explains your rights under UK data protection law.
Important: Regspire is not designed or authorised for identifiable or pseudonymised patient information. Do not enter information that identifies, or could reasonably identify, a patient or any other individual.
1. Who we are
Regspire is operated by Regspire Ltd, a company registered in England and Wales under company number 17358603. Our registered office is 4 Foley Church Close, Sutton Coldfield, B74 3JX.
You can contact us about this notice or our use of personal information at admin@regspire.co.uk.
Regspire Ltd is registered as a data protection fee payer with the Information Commissioner's Office under registration reference ZC219445.
Regspire Ltd is the controller of the personal information used to manage your account, subscription, support requests and use of the service. This means that we decide why and how that information is processed.
Regspire is not currently offered to NHS organisations, universities or other institutions as a data processor. You must not use Regspire to process personal data on behalf of an organisation unless Regspire has expressly agreed appropriate written arrangements with that organisation, including a data processing agreement where required.
2. What this notice covers and where information comes from
Regspire supports healthcare professionals, students and researchers carrying out activities such as clinical audits, quality improvement projects and systematic reviews. This notice covers:
- information you provide when joining a waitlist, creating an account, subscribing or contacting us;
- technical and usage information generated when you use the website or service;
- project content saved within your account;
- information processed when you choose to use an artificial intelligence feature; and
- information submitted through collaborative collection features linked to your projects.
We obtain information:
- directly from you, including through account, payment, project, support and waitlist forms;
- automatically from your browser or device when you use Regspire;
- from service providers such as Stripe, where they confirm a payment or subscription event; and
- from people contributing to a project through a sharing code, QR code or other collaborative feature.
This notice does not apply to third-party websites or services that you access through an external link. Those organisations are responsible for their own privacy practices.
3. Information we collect and how we use it
3.1 Waitlist
Information collected. Your email address and the date you joined the waitlist.
Purpose. To contact you about the launch and availability of the Founding Clinician Programme.
Lawful basis. Your consent. You may withdraw consent at any time by emailing admin@regspire.co.uk. See Sections 10 and 11 for retention and your rights.
3.2 Account and subscription
We collect:
- your email address;
- your password in securely hashed form, which means we cannot read the original password;
- two-factor authentication information, if you enable it;
- account and subscription status;
- a customer, transaction or payment reference received from Stripe; and
- limited payment information such as the card type and last four digits, where Stripe provides it to us.
We use this information to create and authenticate your account, provide access to projects and paid features, keep your work available across devices, manage subscriptions, issue service communications, prevent fraud and provide support.
We rely on performance of our contract with you to create and operate your account and manage your subscription. We rely on our legitimate interests to protect accounts, prevent abuse, maintain security and operate the service. We rely on legal obligations where we must keep financial, tax or regulatory records.
3.3 Payments
Payments and subscription management are provided by Stripe. Regspire does not receive or store your full card number or card security code. Stripe processes payment information under its own contractual and privacy arrangements and may act as a separate controller for some of its activities.
3.4 Service usage and support
We may collect:
- IP address and approximate location derived from it;
- Sign in times and authentication events;
- browser, device and operating system information;
- features used, request counts and rate limit information;
- technical, security and error logs; and
- information contained in support requests, correspondence or feedback.
We use this information to provide and maintain Regspire, secure accounts, detect and prevent fraud or abuse, troubleshoot errors, respond to support requests, understand how features perform and improve the service.
We rely on performance of our contract where processing is necessary to provide the service or support you request. We rely on our legitimate interests in maintaining a secure, reliable and useful service for security monitoring, fraud prevention, troubleshooting and proportionate service improvement.
3.5 Information you must provide
To create an account, you must provide an email address and the authentication information needed to secure the account. If you subscribe, you must provide Stripe with the billing and payment information it requires. Without required information, we cannot create or secure your account, process your subscription or provide the relevant service. Project content, feedback, two-factor authentication and AI requests are optional, although a feature may not work if you do not provide the information it needs. You are not legally required to provide personal information to Regspire.
4. Project data and patient information
4.1 What project data means
Project data includes audit standards and measures, quality improvement information, data collection tables, results, analyses, screening decisions, study information, draft reports and other material you enter or create as part of your work.
4.2 Do not enter identifiable or pseudonymised information
Regspire is not a patient record system and is not designed for personal data about patients, research participants, colleagues or other third parties. Our Terms of Service require you not to enter such information.
Do not enter information that identifies, or could reasonably be used to identify, an individual. This includes:
- names, initials or photographs;
- NHS, hospital, study or other unique identification numbers;
- addresses, telephone numbers or email addresses;
- full dates of birth or exact dates linked to an individual's care;
- free text descriptions of individual circumstances; and
- combinations of rare, distinctive or small group information that could enable identification.
Pseudonymised information remains personal data where an individual can be identified using separately held information. Replacing a name with a code does not necessarily make information anonymous. Before entering project information, ensure that it has been effectively anonymised and that no person is reasonably identifiable.
If information originated from an NHS organisation, healthcare provider, university or another institution, you are responsible for confirming that your proposed use of Regspire complies with that organisation's information governance, confidentiality, research and data protection requirements. If you are unsure, contact the relevant information governance, data protection or research team before using Regspire.
4.3 Accidental uploads
If you accidentally enter identifiable or pseudonymised personal information, stop using the affected project and contact admin@regspire.co.uk promptly. We may restrict access to, remove or delete information that breaches these requirements. Where necessary, we may process limited information to investigate, contain and document the incident, relying on our legitimate interests in protecting individuals and the service and on any applicable legal obligation.
4.4 How project data is used and stored
Saved project data is stored on our infrastructure and associated with your account so that you can access and continue your work across devices. This includes information saved in project data collection tables. Access controls are used to separate accounts and reduce the risk of unauthorised access.
To the extent that project content constitutes your personal information because it is associated with your account, we process it as necessary to perform our contract with you. We may also process limited account linked information for security, abuse prevention and legal claims based on our legitimate interests.
5. Collaboration, uploaded files and device storage
5.1 Collaborative data collection
Some features allow you to share a project using a code or QR code so that other people can contribute. Anyone who receives a working sharing code may be able to access the relevant collection interface or submit information. You are responsible for sharing codes only with appropriate people and for withdrawing or replacing access where necessary.
Before information is displayed through the collaborative collection feature, Regspire applies filtering designed to withhold free text and identifier fields. The collection system may also reject values resembling NHS numbers, unusually long entries or structured data. These safeguards reduce risk but are not guaranteed to identify every form of personal information and are not a substitute for checking information before it is entered or shared.
5.2 Uploaded PDFs
Where a feature is described as browser based, an uploaded PDF is processed locally in your browser and the original file is not uploaded to Regspire's servers. If you expressly use an AI-assisted feature on information extracted from a PDF, relevant extracted text may be sent to Anthropic as described in Section 6. Do not use an AI-assisted PDF feature for identifiable or pseudonymised information.
5.3 Local storage on your device
Recent project information and service preferences may be stored in your browser's local storage so that parts of Regspire can work efficiently or offline. Local information is separated by account, and information belonging to another account is cleared when a different user signs in on the same device. You should sign out and clear browser data when using a shared or public device.
Local browser storage is not a backup service. Export and securely retain important work in accordance with your organisation's requirements. Sections 10 and 13 explain retention and the storage technologies we use.
6. Artificial intelligence and automated decision making
6.1 When AI is used
Some optional features use artificial intelligence. When you choose one of these features, information relevant to your request may be sent to Anthropic to suggest or improve wording, help locate published guidance, assist with screening records or draft part of a report.
Using an AI feature causes the relevant information to leave Regspire's systems for processing by Anthropic, which may process it in the United States. Do not include identifiable or pseudonymised patient information, confidential clinical records or other personal information about third parties in an AI request.
6.2 Lawful basis and provider processing
We rely on performance of our contract with you when you request an AI-assisted feature. We rely on our legitimate interests for proportionate security monitoring, abuse prevention and technical troubleshooting connected with that feature.
Under the standard Anthropic API arrangements applicable to our use, API inputs and outputs are not used to train Anthropic's generative models unless the customer expressly opts in. Regspire has not opted in to model training. Section 10 explains how long AI inputs, outputs and saved project content are normally retained.
6.3 Human review and significant decisions
AI-generated content is assistance only. It may be incomplete, inaccurate or misleading, including where it appears confident or authoritative. You remain responsible for checking, editing and deciding whether to use any AI-generated content before relying on it, submitting it, publishing it or presenting it.
Regspire does not use your personal information to make solely automated decisions that produce legal effects or similarly significant effects on you. AI features do not make professional, academic, employment, regulatory or clinical decisions on your behalf.
7. Statistical computation
Regspire's numerical calculations are produced using defined statistical or mathematical methods rather than a language model. This includes confidence intervals, run chart calculations and signal rules, effect estimates and pooled meta-analysis estimates.
For meta-analysis, Regspire may send study level information to a dedicated statistical service hosted through Hugging Face. This may include effect sizes, sample sizes and study labels taken from published research. The service is designed to send study level information only. You must not include patient level information or private contact information in material submitted for statistical computation.
We process this information as necessary to perform our contract with you and provide the calculation you request.
8. Anonymised and aggregated information
We may produce and use genuinely anonymised and aggregated information to understand service performance and improve Regspire, for example to understand how many projects progress from one audit cycle to another. Data protection law does not apply to information that has been effectively anonymised so that no person is identifiable.
We do not attempt to identify individuals from anonymised information or use project content for advertising or to profile patients, users or organisations.
If we propose a materially different use of project information, we will assess the legal requirements and provide further information or obtain permission where required before the new processing begins.
9. Sharing, service providers and international transfers
9.1 Service providers
We use specialist service providers to operate Regspire. They may process information on our behalf only for the relevant service and subject to contractual and security requirements. Our main providers are listed below.
| Provider | Purpose | Information involved | Processing location |
|---|---|---|---|
| Supabase | Database and authentication | Account information, authentication events and saved project data | United Kingdom (London) |
| Vercel | Hosting and application delivery | Technical request data, IP addresses and application content needed to deliver the service | European Economic Area and United States |
| Anthropic | Optional AI-assisted features | Information submitted to an AI feature and the resulting output | United States |
| Hugging Face | Statistical computation | Study level calculation inputs and technical request information | United States |
| Resend | Transactional email | Email address and the content of service messages | United States |
| Upstash | Rate limiting and security | IP address, request identifiers and request count information | Ireland |
| Stripe | Payments and subscriptions | Contact, billing, payment and subscription information | United Kingdom, European Economic Area and United States |
9.2 Other disclosures
We may disclose information to professional advisers, insurers, auditors, regulators, law enforcement bodies or courts where reasonably necessary to obtain advice, protect legal rights, investigate wrongdoing or comply with a legal obligation. If Regspire Ltd is involved in a sale, merger, restructuring or transfer of its business, information may be disclosed to relevant parties subject to appropriate confidentiality and data protection safeguards.
We do not sell personal information or share it with advertisers. Stripe may act as a separate controller for certain payment and compliance activities under its own privacy notice.
9.3 International transfers
Some providers or their subprocessors may process information outside the United Kingdom, including in the European Economic Area and the United States.
Where a transfer is restricted under UK data protection law, we use an applicable transfer mechanism. Depending on the destination and provider, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another lawful safeguard. Where required, we also assess the transfer and consider supplementary technical or organisational measures.
You may contact admin@regspire.co.uk for further information about the safeguard used for a particular transfer, subject to any confidentiality restrictions.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute resolution requirements.
We do not operate an automated deletion schedule. In practice, information connected to an account is kept while that account exists and is deleted when you ask us to delete it, rather than after a fixed period has passed.
Asking us to delete your information. Email admin@regspire.co.uk from the address on your account and tell us you would like your account deleted. We normally respond within one month, as described in section 11. Deleting an account removes your account record and the projects you own. Where you have contributed to a project shared with colleagues, that project remains, with your name and account removed from it, so that their work is not destroyed.
| Category | How long we keep it |
|---|---|
| Waitlist information | Until you ask to be removed. Email admin@regspire.co.uk at any time and we will remove you. |
| Account and authentication information | While the account exists, and until you ask us to delete it. |
| Project data | While the account exists, and until you ask us to delete it, subject to the position on shared projects above. |
| Usage, technical and security logs | Kept by our hosting, database and security providers on their own retention schedules rather than ours. Those providers are listed in section 9. |
| Support requests and correspondence | Kept in our email records and deleted on request, unless they are needed for an ongoing dispute or a legal requirement. |
| Payment, tax and accounting records | Kept for the periods required by company and tax law, normally six years. We cannot delete these earlier, and a deletion request does not remove them. |
| AI inputs and outputs | Anthropic normally deletes API inputs and outputs from its backend within 30 days, subject to applicable safety, usage policy enforcement, legal or separately agreed retention exceptions. Saved outputs remain in the relevant Regspire project until that project is deleted. |
| Browser local storage | Until it is cleared by Regspire, the browser or the user, or replaced when a different account signs in on the same device. |
Information you ask us to delete may remain in our database provider's routine backups until those backups are overwritten on the provider's own schedule.
We may delete information sooner where it is no longer needed. We may retain limited information for longer where required by law, necessary to establish, exercise or defend legal claims, or needed to protect the service and its users.
11. Your data protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- ask for access to the personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to delete personal information in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on our legitimate interests;
- receive certain information in a structured, commonly used and machine readable format;
- ask for that information to be transferred to another organisation where technically feasible;
- withdraw consent at any time where we rely on consent.
Your right to object. Where we rely on legitimate interests, you may object to our use of your personal information. We will stop the processing unless we have compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
These rights are not absolute. A right may not apply where an exemption or another lawful reason allows us to continue processing. Withdrawing consent does not affect processing that took place before withdrawal.
To exercise a right, email admin@regspire.co.uk. We may ask for information needed to verify your identity. We normally respond within one month, although the law allows an extension in some circumstances.
We do not normally charge a fee. We may charge a reasonable fee or refuse to act where the law permits, including where a request is manifestly unfounded or excessive.
12. Security and personal data breaches
We use technical and organisational measures designed to protect information processed through Regspire. These measures include encryption in transit, access controls, account level separation, securely hashed passwords, optional two-factor authentication, rate limiting, security monitoring and testing designed to identify attempts to bypass access controls.
No internet service can be guaranteed to be completely secure. You are responsible for using a strong and unique password, keeping login credentials and sharing codes confidential, enabling two-factor authentication where available, signing out on shared devices and promptly telling us if you suspect unauthorised access.
If we become aware of a personal data breach, we will investigate and assess the likely risk to individuals. Where required, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where a breach is likely to result in a high risk to affected individuals, we will also notify them without undue delay unless the law provides otherwise.
13. Cookies and similar technologies
Regspire uses cookies and similar storage technologies only where necessary to deliver the service requested by you, keep you signed in, protect accounts, maintain security, remember essential preferences or support requested functionality. These technologies may include:
- authentication or session cookies used to sign you in and maintain a secure session;
- security tokens used to prevent unauthorised requests;
- rate limiting identifiers used to protect the service from abuse; and
- browser local storage used for recent project information, account separation and offline functionality.
Session technologies normally expire when the relevant session ends. Persistent essential technologies remain only for the period needed for their stated function or until cleared through your browser or device settings.
We do not currently use advertising cookies or third-party behavioural tracking cookies. If we introduce a technology that is not strictly necessary, we will provide clear information and obtain any consent required by law before using it.
14. Users under 18
You must be at least 18 years old to create an account or use Regspire. We do not knowingly offer the service to children or intentionally collect their personal information. If you believe that a person under 18 has provided personal information to Regspire, contact admin@regspire.co.uk so that we can investigate and take appropriate action.
15. Changes to this notice
Regspire is a developing service and our processing may change as features, providers or legal requirements change. The date at the beginning of this notice shows when it was last updated.
If we make a material change to how we use personal information, we will take reasonable steps to bring it to your attention before the new processing begins, normally by email, through the service or by a prominent website notice. Where the law requires consent, we will ask for it.
16. Contact and complaints
If you have a question, wish to exercise a right or are unhappy with how we have handled your information, contact us first at admin@regspire.co.uk.
We aim to acknowledge your contact within five working days and to provide a substantive response as soon as reasonably possible.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO), the United Kingdom's supervisory authority for data protection. Raising a concern with us first does not affect that right.
You may contact the ICO at ico.org.uk, by telephone on 0303 123 1113, or by post at Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. You may also seek a judicial remedy.