Skip to content
ProductsClinical modelGovernance
Book a walkthrough
ProductsClinical modelGovernance
Book a walkthrough

Sparrow Telehealth

Privacy Policy

How Sparrow and your healthcare provider collect, use and protect your information.

Document control

Document
Sparrow Privacy Policy (Privacy Notice)
Owner
Sparrow Telehealth Ltd
Status
Draft — for legal and DPO review
Version
0.1
Date
12 July 2026
Applies to
Patients, clinicians and administrators using the Sparrow platform and the Sparrow Connect app
Regulatory basis
UK GDPR; Data Protection Act 2018; PECR; NHS information-governance standards

On this page

  1. 1 · Who we are
  2. 2 · Scope
  3. 3 · What we process
  4. 4 · Where it comes from
  5. 5 · Why, and our legal bases
  6. 6 · Who we share it with
  7. 7 · Support screenshots
  8. 8 · Storage and transfers
  9. 9 · How long we keep it
  10. 10 · Your rights
  11. 11 · Security and cookies
  12. 12 · Complaints and changes

Draft — not yet in force

This document is version 0.1 and is published here for review. It has not yet been approved by a qualified solicitor or, where relevant, a Data Protection Officer, and should not be relied upon as the binding terms of the service. Details still to be confirmed are marked in the text.

Section 1

Who we are and how to contact us

Sparrow is a telehealth platform for respiratory care. It is operated by Sparrow Telehealth Ltd (“Sparrow”, “we”, “us”, “our”), a company registered in England and Wales (company number to be confirmed), registered office to be confirmed. We are registered with the Information Commissioner’s Office (registration number to be confirmed).

How to contact Sparrow about privacy
How to reach usDetail
General privacy enquiriesprivacy@sparrowtelehealth.com
Grievances and complaintsRahul Bhatt — rahul@sparrowtelehealth.com
Data Protection Officername to be confirmed — dpo@sparrowtelehealth.com
Postregistered address to be confirmed

Controllers and processors

The roles under data-protection law depend on the information in question:

  • Your healthcare provider (the NHS body, GP practice or clinic responsible for your care) is the controller of the clinical records held about you. It decides how your care information is used. Sparrow acts as its processor, handling that information on its documented instructions under a Data Processing Agreement.
  • Sparrow is the controller for the limited information needed to provide and secure the platform itself — for example your app-account details, sign-in and security data, support requests, and system audit logs.

This notice explains both, so you have the full picture. For questions about your clinical record specifically, your provider is also able to help; their own privacy notice will name them as controller.

Section 2

Scope of this notice

This notice covers personal data processed through:

  • the Sparrow Connect mobile app used by patients;
  • the Sparrow Doctor Portal used by clinicians;
  • the Sparrow administration console and the backend services that support them; and
  • the enquiry form on this website.

It does not cover third-party websites or services that we link to, which have their own privacy notices.

Section 3

The information we process

We process the following categories of personal data. Not all of it applies to every person — for example, professional-registration details apply only to clinicians.

3.1 Identity and contact information

Name; email address; date of birth; NHS number and its verification status; postal address and postcode; telephone contact details; gender; ethnic category and residential status (where recorded in the clinical record); and details of your registered GP practice.

3.2 Health and care information (special-category data)

Because Sparrow supports clinical care, we process information about your health. This is “special-category” data and is given extra protection under the law. It includes:

  • Self-recorded symptoms and wellbeing (for example breathlessness, cough and sputum);
  • Questionnaire results such as the COPD Assessment Test (CAT) and mMRC breathlessness grade;
  • Vital-sign readings — oxygen saturation, heart rate, blood pressure, respiratory rate, temperature and peak flow — and breathing (NEWS2) observations;
  • Records of flare-ups (exacerbations), medication adherence and inhaler use;
  • Clinical assessments and classifications (including spirometry values and GOLD-related grading), clinical notes, care plans, medication recommendations and prescriptions, referrals, and clinician alerts; and
  • Appointment and consultation information.

3.3 Account, authentication and security information

Sign-in identifiers; one-time passcodes (stored only in a hashed form and short-lived); hashed passwords for staff accounts; session and refresh tokens (stored only as secure hashes on our servers); consent records (when you gave or withdrew consent and to which version); and, on your own device only, an app-lock PIN held as a salted hash that is never sent to us.

3.4 Clinician and administrator information

For platform users who are staff: name, work email, job title, professional registration number (such as GMC, GPhC or NMC), speciality, qualifications, languages and a short professional biography; and, where NHS Care Identity (CIS2) sign-on is used, the identifier that links your NHS identity to your account.

3.5 Technical and audit information

To keep the platform secure and to meet information-governance requirements, we log activity — including the user who acted, the action taken, the patient context, and technical details such as IP address, device or browser information, and timestamps. The app also stores your device platform for reminder functionality.

3.6 Support requests and screenshots

If you or a member of staff report a problem through our support process, we process the information you provide about the issue. This may include screenshots you choose to attach to help us diagnose the problem, which may show whatever was on the screen at the time. Section 7 explains how support screenshots are stored and deleted.

3.7 Website enquiries

If you complete the enquiry form on this website, we process the name, email address, organisation (if you give one) and message you submit, so that we can reply. This is handled by Sparrow as controller, on the basis of our legitimate interest in responding to people who contact us, and it is delivered to us by email through our email provider. It is not health information, is not added to any clinical record, and is not used for marketing. We keep enquiry correspondence only for as long as needed to deal with it and for a short period afterwards — period to be confirmed.

What we do not collect

Sparrow does not use third-party advertising or tracking technologies, does not use analytics or profiling SDKs in the patient app, and does not collect payment-card details. We do not process device location, photo-library, microphone or contacts data.

Section 4

Where the information comes from

  • Directly from you — for example when you register, verify your identity, complete questionnaires, record readings or contact support;
  • From your healthcare provider and your clinical team — for example your demographic details, care plan, assessments and prescriptions;
  • From NHS national services — for example NHS number verification and, for staff, NHS Care Identity (CIS2) sign-on; and
  • Automatically from your use of the platform — for example security logs and technical information.

Section 5

Why we use your information and our legal bases

We only use your information where the law allows. Because health information is special-category data, we rely both on a lawful basis under Article 6 of the UK GDPR and on a specific condition under Article 9. In most cases health information is processed for the provision of health care under the control of a health professional (Article 9(2)(h)), supported in the UK by the Data Protection Act 2018.

Purposes and legal bases
PurposeLawful basis (Art. 6)Condition for health data (Art. 9)
Providing care through the platform — recording and sharing your information with your clinical teamPublic task (NHS care) or legitimate interests; contract for the app serviceHealth or social care (Art. 9(2)(h))
Creating and securing your account and verifying your identityContract; legitimate interests in securityExplicit consent, where health data is involved (Art. 9(2)(a))
Sending service messages (e.g. sign-in codes, appointment confirmations)Contract; legitimate interestsNot generally special-category
Keeping the platform safe, and audit loggingLegitimate interests; legal obligationHealth or social care; substantial public interest
Meeting legal, clinical-safety and regulatory dutiesLegal obligationHealth or social care; substantial public interest
Responding to support requestsLegitimate interests; contractHealth or social care, where relevant
Improving the platform using anonymised informationLegitimate interests (using data that no longer identifies you)Not applicable once anonymised

Where we rely on consent (for example your consent to use the Sparrow Connect app), you can withdraw it at any time — see section 10. Withdrawing consent does not affect processing already carried out, and does not remove records your provider is legally required to keep.

Section 6

Who we share it with

We do not sell your information and we do not share it for marketing. We share it only as needed to provide the service:

  • Your healthcare provider and clinical team, who use it to deliver your care;
  • Service providers (processors) who help us run the platform, under contract and only on our instructions;
  • NHS national services, for identity verification and staff sign-on; and
  • Others where the law requires or permits it — for example to comply with a legal obligation, to protect someone’s vital interests, or in connection with safeguarding.

Our main service providers (sub-processors)

Sub-processors
ProviderWhat they doInformation involvedLocation
Cloud hosting provider provider to be confirmedHosts the platform’s servers and infrastructureAll platform data, encrypted in transit and at restregion to be confirmed
Managed database (MongoDB Atlas)Stores the platform’s recordsAll stored personal and health dataregion to be confirmed
Object storage (Cloudflare R2)Stores support-ticket screenshots in a private bucketScreenshots attached to support ticketsUK / EEA
Email delivery (Resend)Sends sign-in codes and appointment messagesEmail address, name, appointment detailsOutside UK — appropriate safeguards (see section 8)
NHS Care Identity (CIS2)Verifies NHS staff identity at sign-inStaff NHS identity attributesUK (NHS)

The definitive list of providers, their regions and the safeguards that apply is being confirmed against the live deployment and will be published here before this notice takes effect.

Section 7

Support screenshots and how they are stored

When a screenshot is attached to a support ticket, it is handled with particular care:

  • Private storage. Screenshots are stored in a private object-storage bucket that is not publicly accessible. Files cannot be reached by a public web address.
  • Time-limited access. When an authorised member of the support team needs to view a screenshot, the system generates a short-lived, single-purpose “pre-signed” link that expires automatically after a brief period. There are no permanent public links.
  • Deletion on resolution. Screenshots are retained only for as long as they are needed to resolve the ticket. When the support request is completed, the associated screenshots are deleted from storage.

Section 8

Where your information is stored and international transfers

Sparrow’s intended arrangement is that personal and health data is stored on secure infrastructure located in the United Kingdom or the European Economic Area (EEA), which benefit from equivalent data-protection standards. The hosting region for the live service is being confirmed and migrated; this section will state the confirmed position before the notice takes effect.

Some limited operational processing may involve a provider based outside the UK — for example our email-delivery provider, which processes an email address, name and appointment details in order to deliver messages. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as the UK’s International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with any additional measures required. You can ask us for more detail about these safeguards using the contacts in section 1.

Section 9

How long we keep it

Retention periods
InformationRetention approach
Clinical recordsRetained by your healthcare provider in line with the NHS Records Management Code of Practice and their own retention schedule. Sparrow retains them as processor for as long as instructed by the provider.
App-account and consent dataKept while your account is active and for a limited period afterwards, as needed for legal, audit and safety purposes — period to be confirmed.
Sign-in codes and session tokensShort-lived; one-time passcodes and expired sessions are automatically removed.
Audit and security logsRetained for a defined period to meet information-governance and security requirements — period to be confirmed.
Support tickets and screenshotsScreenshots deleted when the request is completed; ticket records kept for a limited period — period to be confirmed.

Section 10

Your rights

Under UK data-protection law you have rights over your personal data. Depending on the circumstances and the lawful basis we rely on, these include the right to:

  • be informed about how your data is used (this notice);
  • access a copy of your data;
  • have inaccurate data corrected;
  • have data erased in certain circumstances;
  • restrict or object to certain processing;
  • data portability, where processing is based on consent or contract and is automated;
  • withdraw consent at any time, where we rely on consent; and
  • complain to the Information Commissioner’s Office.

Because your clinical record is controlled by your healthcare provider, some requests — particularly access to or correction or erasure of clinical information — may be handled by, or with, your provider. To exercise a right, contact us using the details in section 1, or speak to your provider. We will respond within one month, as the law requires. Note that some rights are limited where we have a legal duty to keep certain records (for example clinical records).

Section 11

Security, cookies, children and automated decisions

11.1 How we protect your information

We use technical and organisational measures appropriate to the sensitivity of health data, including: encryption of data in transit (HTTPS/TLS) and encryption at rest provided by our infrastructure; strong password hashing and hashed, short-lived sign-in codes for staff and patients; secure, rotating session tokens stored only as hashes; role-based access controls and least-privilege access; audit logging; and encrypted storage of sensitive values on patient devices. No system can be guaranteed completely secure, but we work to protect your information and to detect and respond to incidents.

11.2 Cookies and similar technologies

The Sparrow web portals use a small number of strictly necessary cookies to keep you signed in securely (for example secure, HTTP-only session cookies). These are essential to the service and are not used for advertising or third-party tracking. The Sparrow Connect mobile app does not use advertising cookies or third-party trackers.

11.3 Children

Sparrow Connect is intended for adults aged 18 or over who are under the care of a participating provider (minimum age to be confirmed). If younger patients are enrolled by a provider, additional safeguards and consent arrangements will apply and will be described separately.

11.4 Automated decision-making

The platform generates scores, trends and suggestions to support clinicians (for example CAT, mMRC, NEWS2 and GOLD-related outputs). These are decision-support tools: a qualified clinician reviews them and makes the clinical decisions. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement.

Section 12

Complaints and changes to this notice

If you have a concern about how your information is handled, please raise it with our grievance contact, Rahul Bhatt, at rahul@sparrowtelehealth.com, or use the other details in section 1, so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) — ico.org.uk, helpline 0303 123 1113.

We may update this notice from time to time. If we make a significant change, we will bring it to your attention through the app, the portal or by email. The version and date shown in the document control panel show when it last changed.

Sparrow

A respiratory-specialty EHR ecosystem by HYGO Technology. Built for NHS clinics.

Products

  • Dr Sparrow
  • Sparrow Connect
  • Sparrow Mothership
  • Sparrow Central

Company

  • Information governance
  • Clinical model
  • Book a walkthrough
  • Support

Legal

  • Privacy Policy
  • Patient Terms & Conditions
  • Doctor Terms of Service
  • Grievances

© 2026 HYGO Technology Ltd. Sparrow is a supplier to NHS clinics and is not an NHS body.