By downloading, installing, or using Aaro, you confirm that you have read and understood this Privacy Policy. If you do not agree with this Policy, you must not use the application. 2. Who We Are Data Controller: CogniVerse Limited Registered Address: United Kingdom Company Number: (as registered at Companies House) Data Protection Contact: [email protected]
CogniVerse Limited is the data controller for personal data relating to Clinician Users' accounts and platform usage. In relation to patient personal data processed through the application, CogniVerse Limited acts as a data processor on behalf of the Clinician User or their employing organisation (the data controller). 3. Scope and Intended Users Aaro is intended solely for use by: Registered medical practitioners (doctors, consultants, GPs) Nurses, nurse practitioners, and allied health professionals Healthcare administrators working under clinical supervision Other registered clinicians operating within a professional healthcare context
Aaro is not intended for use by patients or members of the general public. It is not a consumer health application. Clinician Users are responsible for ensuring that their use of Aaro complies with their professional obligations, employer policies, and applicable data protection law. 4. Data We Collect 4.1 Account and Identity Data When you register to use Aaro, we collect: Full name and professional title Professional registration number (e.g. GMC, NMC, HCPC number) Email address and contact details Name of employing organisation or practice Username and encrypted password credentials 4.2 Clinical Consultation Data Aaro's core function involves capturing clinical consultation content. This may include: Audio recordings of consultations (where the clinician activates voice capture) Transcribed text generated from audio input AI-generated clinical notes, SOAP notes, referral letters, or summaries Structured clinical codes or tags applied during or after consultation Patient identifiers (name, date of birth, NHS number, hospital number) as entered by the clinician Clinical history, presenting complaint, examination findings, and management plans as dictated or typed
Important: Clinical consultation data constitutes special category data under UK GDPR (health data). CogniVerse Limited processes this data on behalf of the Clinician User and their organisation. You retain responsibility as data controller for ensuring lawful basis for processing patient data within your clinical setting. 4.3 Device and Technical Data Device type, operating system, and app version Unique device identifier (UDID) and device token for push notifications IP address and approximate geolocation (country/region level only) App usage logs, session duration, and error logs Crash analytics and performance data 4.4 Usage and Interaction Data Features accessed and frequency of use Settings and preferences configured within the app In-app feedback and support requests submitted 4.5 Data You Do Not Need to Provide You are not required to input identifiable patient data to use Aaro. Clinicians may use anonymised or pseudonymised identifiers in place of full patient details where clinically appropriate. 5. How We Use Your Data 5.1 Providing and Operating the Service Authenticating Clinician User accounts and managing access Processing audio input and generating transcriptions via AI models Producing clinical documentation drafts, letters, and summaries Storing consultation records within your secure account Enabling export and integration with clinical systems (where configured) 5.2 Improving Aaro Where you have provided explicit consent, or where data has been appropriately anonymised and aggregated, we may use data to: Train, evaluate, and improve AI transcription and note-generation models Test new features and functionality before release Conduct internal analytics on app performance and usage patterns
We will never use identifiable patient data to train AI models without explicit, documented consent from the data controller responsible for that data. 5.3 Legal and Compliance Obligations Complying with applicable data protection law and regulatory requirements Responding to lawful requests from regulators, courts, or law enforcement Maintaining records required under healthcare information governance frameworks 5.4 Security and Fraud Prevention Monitoring for unauthorised access or misuse of the platform Detecting and preventing security vulnerabilities Investigating suspected breaches and notifying relevant parties 6. Legal Basis for Processing We rely on the following legal bases under UK GDPR:
Contract (Article 6(1)(b)) Processing necessary to provide the Aaro service under your agreement with CogniVerse Limited, including account management and core application functionality. Legitimate Interests (Article 6(1)(f)) Processing for the purposes of security, fraud prevention, service improvement, and business analytics, where these interests are not overridden by your rights and interests. Legal Obligation (Article 6(1)(c)) Processing required to comply with applicable law, including data protection law, tax obligations, and regulatory requests. Consent (Article 6(1)(a)) Where we ask for your consent (e.g. for optional features, marketing communications, or use of anonymised data for model improvement), processing is conditional on your freely given, specific, and informed consent. You may withdraw consent at any time. Special Category Data — Health Data (Article 9(2)(h)) Processing of health data entered through Aaro is carried out for the purposes of the provision of health care and treatment, and management of health care systems and services, under Article 9(2)(h) UK GDPR and Schedule 1, Part 1(2) of the DPA 2018. Clinician Users bear responsibility for ensuring their own lawful basis for patient data processing within their clinical role. 7. Data Storage and Security 7.1 Where Data is Stored All Aaro data is stored on secure cloud infrastructure located within the United Kingdom and/or the European Economic Area (EEA). We do not transfer personal data outside the UK or EEA without appropriate safeguards in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the UK Information Commissioner's Office (ICO). 7.2 Security Measures CogniVerse Limited implements appropriate technical and organisational security measures including: End-to-end encryption of data in transit (TLS 1.2 or higher) Encryption of data at rest (AES-256 or equivalent) Role-based access controls (RBAC) limiting data access to authorised personnel Multi-factor authentication (MFA) for platform access Regular penetration testing and vulnerability assessments Incident response procedures aligned to ICO guidance on personal data breaches Annual data protection impact assessments (DPIAs) for high-risk processing activities 7.3 NHS Data Security and Protection Toolkit Where Aaro is deployed within NHS-connected environments, CogniVerse Limited is committed to aligning with the NHS Data Security and Protection Toolkit (DSPT) standards and supporting Clinician Users in meeting their own DSPT obligations. 8. Data Retention We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law. Our standard retention periods are:
Account data: Retained for the duration of the active account, plus 3 years after account closure Clinical consultation records: Retained for a minimum of 8 years from the date of creation (or 8 years after a child patient reaches the age of 18), in line with NHS Records Management Code of Practice guidelines. Clinician Users may request earlier deletion subject to their own legal and professional obligations. Audio recordings: Deleted within 30 days of transcription completion, unless extended retention is explicitly configured by the Clinician User Usage logs and technical data: Retained for up to 12 months Anonymised analytics data: May be retained indefinitely
Upon account deletion, we will securely erase or anonymise your personal data within 90 days, except where retention is required by law. 9. Sharing Your Data 9.1 Sub-processors and Third Parties We share data with carefully selected third-party sub-processors who assist in delivering the Aaro service. All sub-processors are bound by appropriate data processing agreements (DPAs) and are required to maintain standards of data protection equivalent to those required under UK GDPR. Sub-processors may include: Cloud hosting and infrastructure providers (UK/EEA-based) AI and machine learning service providers for transcription and note generation Identity verification and authentication service providers Application performance monitoring and analytics tools Email and communications service providers (for account notifications) 9.2 We Do Not Sell Your Data CogniVerse Limited does not sell, rent, or trade personal data or patient data to any third party for commercial purposes. 9.3 Legal Disclosures We may disclose personal data where required by law, including to the ICO, NHS England, MHRA, or other regulatory bodies with lawful authority to request such information. 9.4 Business Transfers In the event of a merger, acquisition, or sale of all or part of CogniVerse Limited's business, personal data may be transferred to the acquiring entity. You will be notified in advance of any such transfer, and the acquiring entity will be required to honour this Privacy Policy. 10. Your Rights As a data subject under UK GDPR, you have the following rights in relation to your personal data:
Right of Access (Article 15) You have the right to request a copy of the personal data we hold about you (a Subject Access Request). Right to Rectification (Article 16) You have the right to request correction of inaccurate or incomplete personal data. Right to Erasure (Article 17) You have the right to request deletion of your personal data, subject to legal and regulatory retention obligations (including clinical record-keeping requirements). Right to Restrict Processing (Article 18) You may request that we restrict processing of your data in certain circumstances. Right to Data Portability (Article 20) You may request that we provide your data in a structured, machine-readable format where processing is based on consent or contract. Right to Object (Article 21) You may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds. Rights Related to Automated Decision-Making (Article 22) Aaro does not make solely automated decisions that produce legal or similarly significant effects. AI-generated clinical notes are always presented as drafts for clinician review and approval.
To exercise any of your rights, please contact us at: Email: [email protected] We will respond to all rights requests within one calendar month. In complex cases, we may extend this by up to two further months, and we will notify you accordingly. 11. Audio Recording and AI Processing 11.1 Microphone Access Aaro requests access to your device microphone solely for the purpose of capturing clinical consultation audio when you explicitly activate the recording function. Microphone access is not used for background monitoring or any purpose other than consultation capture you initiate. 11.2 Transcription Audio is transcribed using AI-powered speech recognition technology. Transcriptions are used to generate structured clinical notes and documentation. Audio files are processed securely and deleted within 30 days unless you have configured extended retention. 11.3 AI-Generated Content All clinical notes, letters, and summaries generated by Aaro's AI are draft outputs intended to support, not replace, professional clinical judgement. You must review, edit, and approve all AI-generated content before it enters any clinical record. CogniVerse Limited accepts no liability for clinical decisions made on the basis of unreviewed AI output. 11.4 No Patient Consent Management Aaro does not manage patient consent for the recording of consultations. It is the Clinician User's sole responsibility to obtain appropriate consent from patients prior to activating audio capture, in accordance with GMC guidance, applicable law, and organisational policy. 12. Cookies and App Analytics Aaro is a mobile application and does not use browser cookies. However, the application may use equivalent device-based identifiers and analytics SDKs to: Diagnose crashes and application errors Measure feature usage and session behaviour Improve application performance and stability
These analytics tools do not link usage data to identifiable patients. You can review analytics data sharing preferences in the app settings. Where applicable, you may opt out of analytics collection without affecting core app functionality. 13. Children and Vulnerable Users Aaro is not designed for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe personal data of a minor has been submitted to Aaro other than as part of a legitimate clinical encounter, please contact us immediately at [email protected]. 14. Third-Party Integrations Aaro may offer optional integrations with third-party clinical systems, electronic health record (EHR) platforms, or productivity tools. Where such integrations are enabled, data may be shared with those third parties subject to your configuration and their own privacy policies. CogniVerse Limited is not responsible for the data practices of third-party platforms. We recommend reviewing the privacy policies of any third-party services you connect to Aaro. 15. Data Breach Notification In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, CogniVerse Limited will: Notify the ICO within 72 hours of becoming aware of the breach (where required under Article 33 UK GDPR) Notify affected Clinician Users without undue delay where the breach is likely to result in a high risk to their rights and freedoms Maintain a record of all data breaches, including those that do not meet the notification threshold
If you suspect a data breach involving Aaro or CogniVerse Limited systems, please report it immediately to [email protected]. 16. Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes to our practices, legal requirements, or the features of Aaro. Where changes are material, we will notify you via: In-app notification at next login Email to your registered address
Continued use of Aaro following notification of material changes constitutes acceptance of the updated Policy. The current version of this Policy will always be accessible within the application and on our website. 17. Complaints If you have a concern about how CogniVerse Limited handles your personal data, please contact us in the first instance at: Email: [email protected]
We take all privacy concerns seriously and will respond within 30 days. If you remain unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
ICO Website: https://ico.org.uk ICO Helpline: 0303 123 1113 ICO Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF 18. Contact Us For all data protection enquiries, subject access requests, or questions about this Policy, please contact:
CogniVerse Limited — Data Protection Team Email: [email protected] Subject line: Aaro Privacy — [Nature of Enquiry]
This Privacy Policy was prepared for Aaro, developed by CogniVerse Limited. It is intended to be read in conjunction with the Aaro Terms of Service and any applicable Data Processing Agreement entered into between CogniVerse Limited and the Clinician User's employing organisation. Nothing in this Policy constitutes legal advice.