Sparrow Telehealth
Privacy Policy
How Sparrow and your healthcare provider collect, use and protect your information.
Who we are and how to contact us
Sparrow is a telehealth platform for respiratory care. It is operated by Sparrow Telehealth Ltd (“Sparrow”, “we”, “us”, “our”), a company registered in England and Wales (company number to be confirmed), registered office to be confirmed. We are registered with the Information Commissioner’s Office (registration number to be confirmed).
| How to reach us | Detail |
|---|---|
| General privacy enquiries | privacy@sparrowtelehealth.com |
| Grievances and complaints | Rahul Bhatt — rahul@sparrowtelehealth.com |
| Data Protection Officer | name to be confirmed — dpo@sparrowtelehealth.com |
| Post | registered address to be confirmed |
Controllers and processors
The roles under data-protection law depend on the information in question:
- Your healthcare provider (the NHS body, GP practice or clinic responsible for your care) is the controller of the clinical records held about you. It decides how your care information is used. Sparrow acts as its processor, handling that information on its documented instructions under a Data Processing Agreement.
- Sparrow is the controller for the limited information needed to provide and secure the platform itself — for example your app-account details, sign-in and security data, support requests, and system audit logs.
This notice explains both, so you have the full picture. For questions about your clinical record specifically, your provider is also able to help; their own privacy notice will name them as controller.
Scope of this notice
This notice covers personal data processed through:
- the Sparrow Connect mobile app used by patients;
- the Sparrow Doctor Portal used by clinicians;
- the Sparrow administration console and the backend services that support them; and
- the enquiry form on this website.
It does not cover third-party websites or services that we link to, which have their own privacy notices.
The information we process
We process the following categories of personal data. Not all of it applies to every person — for example, professional-registration details apply only to clinicians.
3.1 Identity and contact information
Name; email address; date of birth; NHS number and its verification status; postal address and postcode; telephone contact details; gender; ethnic category and residential status (where recorded in the clinical record); and details of your registered GP practice.
3.2 Health and care information (special-category data)
Because Sparrow supports clinical care, we process information about your health. This is “special-category” data and is given extra protection under the law. It includes:
- Self-recorded symptoms and wellbeing (for example breathlessness, cough and sputum);
- Questionnaire results such as the COPD Assessment Test (CAT) and mMRC breathlessness grade;
- Vital-sign readings — oxygen saturation, heart rate, blood pressure, respiratory rate, temperature and peak flow — and breathing (NEWS2) observations;
- Records of flare-ups (exacerbations), medication adherence and inhaler use;
- Clinical assessments and classifications (including spirometry values and GOLD-related grading), clinical notes, care plans, medication recommendations and prescriptions, referrals, and clinician alerts; and
- Appointment and consultation information.
3.3 Account, authentication and security information
Sign-in identifiers; one-time passcodes (stored only in a hashed form and short-lived); hashed passwords for staff accounts; session and refresh tokens (stored only as secure hashes on our servers); consent records (when you gave or withdrew consent and to which version); and, on your own device only, an app-lock PIN held as a salted hash that is never sent to us.
3.4 Clinician and administrator information
For platform users who are staff: name, work email, job title, professional registration number (such as GMC, GPhC or NMC), speciality, qualifications, languages and a short professional biography; and, where NHS Care Identity (CIS2) sign-on is used, the identifier that links your NHS identity to your account.
3.5 Technical and audit information
To keep the platform secure and to meet information-governance requirements, we log activity — including the user who acted, the action taken, the patient context, and technical details such as IP address, device or browser information, and timestamps. The app also stores your device platform for reminder functionality.
3.6 Support requests and screenshots
If you or a member of staff report a problem through our support process, we process the information you provide about the issue. This may include screenshots you choose to attach to help us diagnose the problem, which may show whatever was on the screen at the time. Section 7 explains how support screenshots are stored and deleted.
3.7 Website enquiries
If you complete the enquiry form on this website, we process the name, email address, organisation (if you give one) and message you submit, so that we can reply. This is handled by Sparrow as controller, on the basis of our legitimate interest in responding to people who contact us, and it is delivered to us by email through our email provider. It is not health information, is not added to any clinical record, and is not used for marketing. We keep enquiry correspondence only for as long as needed to deal with it and for a short period afterwards — period to be confirmed.
Where the information comes from
- Directly from you — for example when you register, verify your identity, complete questionnaires, record readings or contact support;
- From your healthcare provider and your clinical team — for example your demographic details, care plan, assessments and prescriptions;
- From NHS national services — for example NHS number verification and, for staff, NHS Care Identity (CIS2) sign-on; and
- Automatically from your use of the platform — for example security logs and technical information.
Why we use your information and our legal bases
We only use your information where the law allows. Because health information is special-category data, we rely both on a lawful basis under Article 6 of the UK GDPR and on a specific condition under Article 9. In most cases health information is processed for the provision of health care under the control of a health professional (Article 9(2)(h)), supported in the UK by the Data Protection Act 2018.
| Purpose | Lawful basis (Art. 6) | Condition for health data (Art. 9) |
|---|---|---|
| Providing care through the platform — recording and sharing your information with your clinical team | Public task (NHS care) or legitimate interests; contract for the app service | Health or social care (Art. 9(2)(h)) |
| Creating and securing your account and verifying your identity | Contract; legitimate interests in security | Explicit consent, where health data is involved (Art. 9(2)(a)) |
| Sending service messages (e.g. sign-in codes, appointment confirmations) | Contract; legitimate interests | Not generally special-category |
| Keeping the platform safe, and audit logging | Legitimate interests; legal obligation | Health or social care; substantial public interest |
| Meeting legal, clinical-safety and regulatory duties | Legal obligation | Health or social care; substantial public interest |
| Responding to support requests | Legitimate interests; contract | Health or social care, where relevant |
| Improving the platform using anonymised information | Legitimate interests (using data that no longer identifies you) | Not applicable once anonymised |
Where we rely on consent (for example your consent to use the Sparrow Connect app), you can withdraw it at any time — see section 10. Withdrawing consent does not affect processing already carried out, and does not remove records your provider is legally required to keep.
Who we share it with
We do not sell your information and we do not share it for marketing. We share it only as needed to provide the service:
- Your healthcare provider and clinical team, who use it to deliver your care;
- Service providers (processors) who help us run the platform, under contract and only on our instructions;
- NHS national services, for identity verification and staff sign-on; and
- Others where the law requires or permits it — for example to comply with a legal obligation, to protect someone’s vital interests, or in connection with safeguarding.
Our main service providers (sub-processors)
| Provider | What they do | Information involved | Location |
|---|---|---|---|
| Cloud hosting provider provider to be confirmed | Hosts the platform’s servers and infrastructure | All platform data, encrypted in transit and at rest | region to be confirmed |
| Managed database (MongoDB Atlas) | Stores the platform’s records | All stored personal and health data | region to be confirmed |
| Object storage (Cloudflare R2) | Stores support-ticket screenshots in a private bucket | Screenshots attached to support tickets | UK / EEA |
| Email delivery (Resend) | Sends sign-in codes and appointment messages | Email address, name, appointment details | Outside UK — appropriate safeguards (see section 8) |
| NHS Care Identity (CIS2) | Verifies NHS staff identity at sign-in | Staff NHS identity attributes | UK (NHS) |
The definitive list of providers, their regions and the safeguards that apply is being confirmed against the live deployment and will be published here before this notice takes effect.
Support screenshots and how they are stored
When a screenshot is attached to a support ticket, it is handled with particular care:
- Private storage. Screenshots are stored in a private object-storage bucket that is not publicly accessible. Files cannot be reached by a public web address.
- Time-limited access. When an authorised member of the support team needs to view a screenshot, the system generates a short-lived, single-purpose “pre-signed” link that expires automatically after a brief period. There are no permanent public links.
- Deletion on resolution. Screenshots are retained only for as long as they are needed to resolve the ticket. When the support request is completed, the associated screenshots are deleted from storage.
Where your information is stored and international transfers
Sparrow’s intended arrangement is that personal and health data is stored on secure infrastructure located in the United Kingdom or the European Economic Area (EEA), which benefit from equivalent data-protection standards. The hosting region for the live service is being confirmed and migrated; this section will state the confirmed position before the notice takes effect.
Some limited operational processing may involve a provider based outside the UK — for example our email-delivery provider, which processes an email address, name and appointment details in order to deliver messages. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as the UK’s International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, together with any additional measures required. You can ask us for more detail about these safeguards using the contacts in section 1.
How long we keep it
| Information | Retention approach |
|---|---|
| Clinical records | Retained by your healthcare provider in line with the NHS Records Management Code of Practice and their own retention schedule. Sparrow retains them as processor for as long as instructed by the provider. |
| App-account and consent data | Kept while your account is active and for a limited period afterwards, as needed for legal, audit and safety purposes — period to be confirmed. |
| Sign-in codes and session tokens | Short-lived; one-time passcodes and expired sessions are automatically removed. |
| Audit and security logs | Retained for a defined period to meet information-governance and security requirements — period to be confirmed. |
| Support tickets and screenshots | Screenshots deleted when the request is completed; ticket records kept for a limited period — period to be confirmed. |
Your rights
Under UK data-protection law you have rights over your personal data. Depending on the circumstances and the lawful basis we rely on, these include the right to:
- be informed about how your data is used (this notice);
- access a copy of your data;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict or object to certain processing;
- data portability, where processing is based on consent or contract and is automated;
- withdraw consent at any time, where we rely on consent; and
- complain to the Information Commissioner’s Office.
Because your clinical record is controlled by your healthcare provider, some requests — particularly access to or correction or erasure of clinical information — may be handled by, or with, your provider. To exercise a right, contact us using the details in section 1, or speak to your provider. We will respond within one month, as the law requires. Note that some rights are limited where we have a legal duty to keep certain records (for example clinical records).
Security, cookies, children and automated decisions
11.1 How we protect your information
We use technical and organisational measures appropriate to the sensitivity of health data, including: encryption of data in transit (HTTPS/TLS) and encryption at rest provided by our infrastructure; strong password hashing and hashed, short-lived sign-in codes for staff and patients; secure, rotating session tokens stored only as hashes; role-based access controls and least-privilege access; audit logging; and encrypted storage of sensitive values on patient devices. No system can be guaranteed completely secure, but we work to protect your information and to detect and respond to incidents.
11.2 Cookies and similar technologies
The Sparrow web portals use a small number of strictly necessary cookies to keep you signed in securely (for example secure, HTTP-only session cookies). These are essential to the service and are not used for advertising or third-party tracking. The Sparrow Connect mobile app does not use advertising cookies or third-party trackers.
11.3 Children
Sparrow Connect is intended for adults aged 18 or over who are under the care of a participating provider (minimum age to be confirmed). If younger patients are enrolled by a provider, additional safeguards and consent arrangements will apply and will be described separately.
11.4 Automated decision-making
The platform generates scores, trends and suggestions to support clinicians (for example CAT, mMRC, NEWS2 and GOLD-related outputs). These are decision-support tools: a qualified clinician reviews them and makes the clinical decisions. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement.
Complaints and changes to this notice
If you have a concern about how your information is handled, please raise it with our grievance contact, Rahul Bhatt, at rahul@sparrowtelehealth.com, or use the other details in section 1, so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO) — ico.org.uk, helpline 0303 123 1113.
We may update this notice from time to time. If we make a significant change, we will bring it to your attention through the app, the portal or by email. The version and date shown in the document control panel show when it last changed.