Acceptable use policy
Last updated: 29 September 2026
1. Spirit
Brigid, operated by DJG Media Limited (trading as Brigid), CRO No. 762838, is the staff-facing product within the Brigid product family. MyBrigid is the patient product, and Brigid is also the name of the AI assistant available within those products, including its voice dictation. These are product names, not legal entities. The products are for legitimate healthcare practice operations under the supervision of a licensed clinician. This policy explains what we expect of you and what we will not tolerate. It applies to every clinician, practice administrator, and authorised user of the platform.
2. You may not
- Use Brigid or another Brigid product for any unlawful purpose
- Process personal or special-category data you have no right to process
- Reverse engineer, scrape, or attempt to extract our source code or models
- Attempt to bypass security controls, access controls, or rate limits
- Use Brigid (or any AI feature) to make autonomous clinical decisions without human oversight
- Share clinician account credentials with another person — each clinician must have their own account, attested as licensed and indemnified
- Access patient records you do not have a legitimate clinical reason to access (GDPR Article 5 data minimisation + the Irish Medical Council Guide to Professional Conduct & Ethics Para 37.3)
- Falsify, delete, or attempt to circumvent the audit log. Doing so undermines the integrity, confidentiality and accountability controls required by this agreement and GDPR
3. Administrative-software boundary and human review
Brigid's launch intended purpose is administrative practice management. It is not authorised to diagnose, triage, monitor, recommend treatment, prescribe, or replace professional judgement. No medical-device CE mark is held or claimed, and the formal software-qualification record remains subject to accountable approval. See the software qualification statement.
- Permitted administrative AI output requires human review. Authorised staff must read and verify it before use. Clinicians author and check every clinical note, letter, referral, prescription and summary. Brigid can draft a note or letter for you to review; a draft is not the record until you have read, corrected and signed it.
- Do not use Brigid for an excluded clinical purpose. If a workflow appears to provide clinical decision support, stop that workflow and report it to support@askbrigid.com.
- Stay current. Use only supported versions of the platform. Significant updates may require re-acceptance of the consent gate.
Practices found to be using Brigid as an autonomous prescriber or diagnostician will have access suspended pending clinical safety review and may be referred to their professional regulator (the Medical Council, the Dental Council, NMBI, CORU or the PSI, as applicable).
4. Patient choices, lawful basis & disabled AI routes
Accepting Terms and Privacy is not blanket consent to health-data processing, international transfers, AI, research, recording or cross-clinic sharing. Optional processing that relies on consent requires a separate, specific and withdrawable choice. The clinic must document its own lawful basis and any applicable notice or professional requirement.
Patient-facing Generative AI, symptom triage, diagnosis or treatment recommendations and Brigid Live (real-time voice) are disabled for launch. A permission toggle, acknowledgement or controller instruction does not reopen a disabled route. You may not attempt to circumvent these boundaries:
- You must not record a consultation without the clinic's approved purpose, lawful basis, applicable notice/permission procedure and retention rule
- You must not use Brigid to produce a diagnosis, a triage decision, a prescription or medical advice, or to send a clinical message, referral or letter that a clinician has not read and signed. Brigid can draft a note or letter from what was said or recorded; the clinician must read, correct and sign it before it is filed or sent. The administrative record summary only restates information already in the record; authorised staff must read and verify it before relying on it
- You must obtain the patient's consent before sharing prescription details with a pharmacy. Brigid does not transmit prescriptions to pharmacies, so this is your obligation to discharge and record, not a step the platform performs or blocks
- You must not share a patient's record with another clinic if cross-clinic sharing is declined and no per-share QR code has been issued
Doing so is a serious breach of this policy and may breach GDPR Article 9 protections for special-category health data, GDPR security obligations, and applicable professional confidentiality duties.
You remain responsible for selecting and documenting the correct lawful basis, issuing accurate notices and honouring rights. Consent is only one possible basis and must not be requested where it is not freely given, specific, informed and withdrawable.
5. Reporting incidents
- Acceptable-use violations → privacy@askbrigid.com
- Patient-safety concerns or unintended clinical behaviour → support@askbrigid.com
- Data-protection concerns / SAR requests → privacy@askbrigid.com
- Accessibility issues → privacy@askbrigid.com
6. Enforcement
Violations may result in written warning, temporary suspension, or termination of platform access. We will give notice and opportunity to remedy where possible, except in cases of:
- Immediate patient safety risk — suspension is immediate
- Unlawful activity — suspension and law-enforcement reporting are immediate
- Repeated audit-log circumvention — suspension and regulator referral
Related documents
Brigid Terms of Service · Clinician Terms of Service · MyBrigid Terms of Service · Software qualification statement · Data Processing Agreement · Privacy Policy · Compliance Overview