This policy explains how Panim Care ("Panim", "we", "us") handles personal
data in connection with the Panim platform and the Panim Scribe
browser extension and desktop companion, which help clinicians document
consultations that take place on video platforms such as Google Meet and Zoom.
1. Who we are and our role
Panim provides clinical documentation software to UK private clinics and
their clinicians. For personal data about patients, the clinic
(or clinician) that uses Panim is the data controller and Panim
acts as a data processor on their instructions, under a data
processing agreement. For account data about clinicians who
sign in to Panim, we act as controller. UK GDPR and the Data Protection Act
2018 apply.
2. What the scribe does with audio
Recording only starts when a signed-in clinician explicitly presses
Start, and stops when they press Stop. There
is no always-on capture.
Consultation audio (the clinician's microphone and the other
participants' audio) is streamed in real time for transcription. It is
processed ephemerally in memory and is never written to disk —
not on your device, not on our servers.
From the audio we produce a transcript, and from the
transcript an AI-assisted draft clinical note for the
clinician to review and sign.
3. Categories of data we process
Special-category health data — consultation transcripts
and clinical notes.
Clinician account data — name and email address from
your Google or Apple sign-in, and authentication tokens.
Patient identifiers shown to the clinician in the scribe
panel (e.g. patient name and prior-visit summary) so the note is filed to the
correct record.
Audit and operational metadata — e.g. session start/end
times, duration, platform, and whether a note was generated.
4. Legal basis
For health data processed on behalf of a clinic: UK GDPR Article 6(1)(b)/(f)
and, for special-category data, Article 9(2)(h) (provision of health care and
treatment) — with the clinic as controller.
For clinician account data: Article 6(1)(b) (performance of the contract to
provide the service).
Before first use, the clinician acknowledges an in-product disclosure that
audio will be processed by our transcription and AI note-generation providers
and that no audio is stored.
5. Sub-processors and recipients
We use a limited set of vetted providers, each under a data processing
agreement, to deliver the service:
Provider
Purpose
Data
Deepgram
Medical speech-to-text transcription
Consultation audio (transient, not retained by Panim)
Anthropic (Claude)
AI generation of the draft clinical note
Consultation transcript text
Amazon Web Services (S3, UK/EU regions)
Encrypted document storage
Clinical documents / notes
Railway
Application hosting
Application data in transit and at rest
We do not sell personal data, and personal data is
never used to train AI models.
6. Storage, security and retention
Audio is never stored. Transcripts and notes are stored
encrypted in transit (TLS) and at rest within your Panim
account.
Access is restricted to the clinician who created the record and
authorised clinic staff.
Records are retained for as long as the controlling clinic requires them
for clinical and legal purposes, in line with UK health-records retention
guidance, and then deleted or returned per the data processing agreement.
7. Browser-extension permissions
The Panim Scribe extension requests only the permissions it needs, and uses
them solely to provide the scribe:
Access to meet.google.com and zoom.us and tab audio
capture — to hear the consultation, only after you press Start.
Microphone — to capture the clinician's side of the
conversation.
Identity / sign-in and storage — to authenticate you to
your Panim account and hold your session token (session storage, cleared when
the browser closes).
8. International transfers
Where a provider processes data outside the UK, transfers are protected by
UK-approved safeguards (UK International Data Transfer Agreement / Addendum to
the EU Standard Contractual Clauses, and adequacy where applicable).
9. Your rights
Individuals have rights under UK GDPR including access, rectification,
erasure, restriction, portability and objection. As patient data is controlled
by the clinic, patient requests should be directed to the treating clinic;
Panim will support the clinic in responding. Clinicians may exercise their
rights over account data by contacting us. You may also complain to the UK
Information Commissioner's Office (ICO) at ico.org.uk.
Draft for review. Panim's DPO / legal adviser should confirm
the sub-processor list, retention periods, controller/processor framing, and
contact details before this is treated as final.