Patient privacy notice template for clinics
Last updated: 2 October 2026
Version: 2026-10-02_v1 Effective: 2 October 2026 Provider: DJG Media Limited, CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland, which provides Ask Brigid and MyBrigid
This is a template. It is for a clinic that uses Ask Brigid. It is not a notice we give to your patients, and it is not legal advice.
1. How to use this template
Why it exists. Your clinic is the controller of its patients' records. Articles 13 and 14 of the GDPR say a controller must tell patients, in plain words, who it is, what it does with their information and why, who sees it, how long it keeps it, and what rights the patient has. DJG Media Limited is your processor: we keep and handle the records on your instructions, under the Data Processing Agreement. The patient notice is yours to give. We cannot give it for you.
What to do.
- Copy the notice in section 3 into your own document or web page.
- Fill in every field in [square brackets]. Where the text offers a choice, keep the one that is true for your clinic and delete the rest.
- Change anything that does not match what your clinic really does. Delete a paragraph that does not apply. Add a paragraph for any processing the template does not cover (for example, a camera in a waiting room, a research study, a patient survey or marketing).
- Remove sections 1, 2 and 4 of this document and every note marked "Note for the clinic", then publish the notice where patients will see it: your website, your waiting room and your new-patient form. Give a copy to any patient who asks.
- Review it when your processing changes, when we give notice of a new sub-processor, and at least once a year.
It is your decision. Adopting this text is the clinic's decision. It is a starting point written from our side of the relationship. We have not checked it against your clinic's own processing, your lawful bases, your contracts with insurers or the State, or your professional body's rules. Take your own advice before you adopt it, for example from your data protection officer, your solicitor or your professional body.
Things only you can decide. The template cannot choose these for you:
- your lawful basis under Article 6 for each purpose, and your condition under Article 9 for health information;
- how long you keep each kind of record;
- whether you have a data protection officer, and whether you must have one;
- whether you use the recording and AI features at all, and the permission you ask a patient for before you use them;
- who you share records with, and on what basis;
- how you handle children's records and requests from a parent or guardian.
2. What Ask Brigid does, so that you can check the notice is true
Section 3 repeats these facts about Ask Brigid. They come from our Privacy Policy, our Data Processing Agreement (version 2026-10-02_v6), our raw audio retention schedule and our sub-processor register. If any of them change, we will update those documents, and you should update the notice. Check the register for the current list before you publish.
- Where records are kept. The database, sign-in and file storage run in one project in Ireland (AWS eu-west-1, Dublin).
- AI. Transcripts and draft notes and letters are made with Google Cloud services in the European Union: Speech-to-Text on an EU endpoint, and Gemini on Google Cloud Vertex AI in Frankfurt (europe-west3), with the searchable-memory step in the Netherlands (europe-west4). A clinician reads, corrects and signs every draft. Ask Brigid does not make a diagnosis, grade urgency or risk, triage, or recommend treatment. DJG Media Limited does not use patient data to train its own AI models.
- Recordings. Ask Brigid asks the clinician to confirm that the patient has agreed before a recording starts. The raw audio is deleted 24 hours after the clinician accepts the note made from it, and in any case 7 days after it was recorded, whichever comes first. The transcript and the note stay, and follow your retention period. You can instruct a shorter or longer period in writing (see the audio retention schedule).
- Searchable copies. Ask Brigid keeps searchable copies of short summaries and excerpts so that staff can find earlier work. They are kept for 90 days from when they were last written or refreshed (some kinds for less, reference material for 1 year). They are deleted when you erase a patient's identity.
- Outside the EU. Clause 12 of the Data Processing Agreement lists the routes that involve processing outside the EU: email through Resend (United States), sign-in codes by text message for staff who choose that method (Twilio, EU and US routing), push notifications to the apps (Apple), subscription billing and card payments (Stripe), maps and place search (Mapbox, United States), web hosting (Vercel, United States and EU edge) and error monitoring (Sentry, EU region, United States parent company). Health data and direct identifiers are removed from error reports before they leave the application. A mailbox or calendar you connect yourself (Google Workspace or Microsoft 365) is processed where that provider holds your account.
- Messages to patients. Ask Brigid does not send text-message or WhatsApp messages to patients. Appointment emails and other messages are sent because your staff send them or you set them up. If a patient replies to an outreach email your staff approved and sent, Ask Brigid can send an AI-written reply automatically unless you have paused outreach; if you use outreach, say so in your notice. Only list the channels you really use.
- Patient choices you must honour. A patient can refuse the Clinical intelligence choice (AI use on their record). Our Privacy Policy, section 6, says which paths check that refusal automatically and which paths rely on your staff checking it. Read that section. It changes as we fix things. Your staff must not use a path against a patient's refusal.
- MyBrigid. MyBrigid is free for patients. When a patient's account is linked to your clinic, you remain the controller of their medical record and we process it on your behalf. DJG Media Limited is the controller of the MyBrigid account itself.
3. The notice
Copy from here. Fill in the [square brackets] and delete the notes marked "Note for the clinic".
How [clinic name] looks after your personal information
Version [version number], [date].
We are [clinic name]. We look after your health, and we also look after the information we hold about you. This notice tells you what we collect, why we collect it, who sees it, how long we keep it and what you can ask us to do. We have tried to use plain words. If anything is unclear, ask us.
Who we are
The organisation responsible for your information (the "controller") is:
[Clinic legal name], [registered number, if a company], [address].
You can reach us at [email], [phone] or at the front desk.
[Data protection officer, if the clinic has one: [name], [email], [address]. / We do not have a data protection officer. Our contact for privacy questions is [name or role], [email].]
What information we collect
Depending on why you come to see us, we collect:
- Who you are and how to reach you: your name, date of birth, address, phone number, email, and [PPS number / health insurance details / medical card details, if the clinic collects them].
- Your health information: the reasons you came, your history, medicines, allergies, test results, scans, referrals, letters, prescriptions and the notes we write about your care.
- Appointments and messages: when you were booked in, and the messages you send us or we send you.
- Payments: what you were charged and how you paid. [Your card details go to our payment provider and are not kept by us.]
- Your emergency contact or next of kin, if you give us one. We hold that person's name, how they are related to you and their phone number. You tell us their details, so please let them know.
- Recordings and transcripts, if you agree to us recording a consultation (see "Recording your consultation" below).
- [Anything else the clinic collects, for example photographs, insurer reference numbers, information from your GP or from another hospital.]
Most of this comes from you. Some comes from other people involved in your care, such as your GP, a hospital, a laboratory, a pharmacist or your insurer. [Add other sources.] If we get information about you from someone else, we tell you here, because the law says we must.
Why we use your information, and our legal reason
The law says we need a "legal reason" (a lawful basis) for each use, and an extra reason for health information. Ours are:
| What we use it for | Our legal reason | |---|---| | Looking after you: keeping your record, diagnosing and treating you, referring you, writing letters, prescribing, arranging follow-up. | Article 6(1)[(b) it is needed for the contract with you to provide your care / (e) it is needed for a task carried out in the public interest, where we are providing care under a public contract]. For health information: Article 9(2)(h) of the GDPR, together with section 52 of the Data Protection Act 2018. These allow health information to be used for medical diagnosis, for providing health care and treatment, and for managing health services, by people who are under a professional duty of confidentiality. | | Running the clinic: booking appointments, sending reminders you need, billing, taking payment, keeping accounts. | Article 6(1)[(b) contract / (c) a legal obligation, for example tax and accounts records]. For any health information involved: Article 9(2)(h) and section 52. | | Meeting our legal duties: keeping records as the law and our professional body require, reporting what the law requires us to report, answering a court order or the request of a regulator. | Article 6(1)(c), a legal obligation. For health information: [Article 9(2)(h) / Article 9(2)(i) for public health reporting / Article 9(2)(f) for legal claims]. | | Protecting our patients and our staff: keeping our systems secure, checking who has looked at a record, dealing with complaints and incidents. | Article 6(1)[(c) legal obligation / (f) our legitimate interests in keeping our patients' information safe]. For health information: Article 9(2)(h) and section 52, [and Article 9(2)(f) for legal claims]. | | Recording your consultation, only if you agree. | [Article 6(1)(a), your consent, and Article 9(2)(a), your explicit consent. / Another basis the clinic has chosen and recorded.] You can say no, or change your mind, at any time. | | [Optional: telling you about our services or newsletters.] | [Article 6(1)(a), your consent. You can opt out at any time, and every message says how.] | | [Anything else.] | [Basis.] |
Note for the clinic, delete before publishing. Choose the Article 6 and Article 9 conditions that match what you really do, and record your reasoning. Do not rely on consent for ordinary care. Section 52 of the Data Protection Act 2018 is the Irish provision that supports Article 9(2)(h); check its current wording and any conditions it attaches, such as the requirement that the person handling the information owes a duty of confidentiality. Using Ask Brigid, or a patient's tick in a box, does not on its own give you a lawful basis.
You do not have to give us your information, but we may not be able to look after you safely or properly without it.
The software we use, and who helps us
We use Ask Brigid, a practice-management system, to keep your records, book appointments, send messages and prepare paperwork. Ask Brigid is provided by DJG Media Limited, an Irish company (CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland). DJG Media Limited is our processor. That means it looks after your information for us and only on our instructions. It has the contract with us that the law requires, which forbids it to use your information for its own purposes and requires the people who handle it to be bound by confidentiality.
- Where your record is kept. Your record is stored in Ireland.
- Recording and writing up your visit. [If the clinic uses these features:] With your agreement, we can record a consultation. The sound is turned into a written transcript, and the software prepares a draft note or letter from the transcript, from what the clinician typed or dictated, or, when the clinician asks, from your chart. Your clinician reads the draft, corrects it and signs it. Nothing is filed, signed or sent without a person checking it first. The software prepares text. It does not diagnose, decide how urgent your condition is, work out your risk, or recommend treatment. Those are decisions for your clinician.
- Where that work is done. The transcript and the draft are produced by Google Cloud services in the European Union. DJG Media Limited does not use your information to train its own AI models.
- How long a recording lasts. The sound recording is deleted 24 hours after your clinician accepts the note made from it, and in any case no later than 7 days after it was recorded, whichever comes first. The transcript and the note stay in your record and are kept for the period set out below.
- Searching earlier work. So that staff can find earlier work again, the software keeps short, searchable copies of summaries and excerpts of your documents and notes. These copies are deleted automatically after at most 1 year (most after 90 days), and when we erase you from our records.
- Your choice about AI. [If the clinic uses AI features:] You can tell us you do not want your information used with AI tools. If you do, we will not use them on your record, and you will still get the same care. Tell us at the front desk or by email at [email].
- Other companies that help. Ask Brigid uses some other companies to run. Almost all of the work happens in the European Union. A few routes involve companies outside the EU. They are: Resend, which sends email for us (United States); Twilio, which sends sign-in codes by text message to staff (EU and US routing); Apple, which delivers the alerts on the MyBrigid app; Stripe, which takes card payments (Ireland and card networks worldwide); Mapbox, which draws maps and finds addresses (United States); Vercel, which delivers the web pages and apps to our devices (United States and EU); and Sentry, which receives error reports from which health information and names have been removed (EU region, United States parent company). Where information goes outside the EU, the law requires a safeguard, and DJG Media Limited uses one, such as the European Commission's standard contractual clauses or an adequacy decision. [If we connect our own Google or Microsoft email or calendar, those companies handle the messages we send and receive through them.] The up-to-date list is at askbrigid.com/sub-processors.
Note for the clinic, delete before publishing. Keep only the paragraphs that match the features you have switched on. If you do not record consultations or use AI drafting, delete those bullets. If you accept the Data Processing Agreement's authorisation of these routes, keep the list of outside-EU routes; it matches clause 12 of version 2026-10-02_v6. Update it if the register changes. Do not tell patients that AI is "never wrong". Do not describe the service as "GDPR compliant".
Recording your consultation
[Use this section only if the clinic records consultations.]
We will only record a consultation if you agree. Before we start, your clinician will ask you. If you say no, we do not record, and the clinician writes the note in the usual way. You will get the same care. If you say yes, you can ask us to stop at any time, and you can change your mind afterwards by telling us. The recording is used for one thing: to make a written transcript so that your clinician can write your note accurately. [Add any other use the clinic has decided on.] The sound recording is deleted as described above. The transcript and note are part of your medical record.
Who else sees your information
We keep your information confidential. We share it only when we need to, and only what is needed:
- People involved in your care, such as your GP, a specialist or hospital you are referred to, a laboratory, a radiology service or a pharmacy.
- Your health insurer, when you ask us to claim from them or to give them a report, and [as your policy requires].
- Other clinics, at your choice. If you use the MyBrigid app and choose to share your records with another clinic, that sharing happens only because you chose it. You can turn it off. Turning it off stops further access. It does not take back a copy the other clinic has already received, which that clinic looks after under its own responsibilities.
- Our processor DJG Media Limited and the companies it uses, as described above.
- Our professional advisers and insurers, where needed, for example to deal with a complaint or a claim: [list, if relevant].
- Courts, regulators and State bodies, where the law requires us to, for example the Data Protection Commission, the Health Information and Quality Authority, our professional regulator, the Revenue Commissioners, or a court order.
- [Anyone else, for example the HSE or a funding scheme.]
We do not sell your information. We do not use it for advertising.
MyBrigid
[Use this section only if the clinic offers MyBrigid.]
MyBrigid is a free app that lets you see your appointments, letters and results, message us, and pay a bill. To use it you create an account. When your account is linked to us, we remain responsible for your medical record, and DJG Media Limited looks after it for us. DJG Media Limited is responsible for the MyBrigid account itself (your sign-in details, your device and notification settings and the app's own use). It has its own privacy policy at askbrigid.com/privacy-policy, which tells you what it does. MyBrigid has its own terms at askbrigid.com/medyou-terms.
How long we keep your information
We keep each kind of record for as long as we need it for the reason we collected it, and for as long as the law and our professional body require. Our periods are:
| Kind of record | How long we keep it | |---|---| | Your medical record (notes, letters, results, prescriptions) | [Period, for example: for your lifetime and a number of years afterwards / a number of years after your last visit. For children: until they reach a stated age.] | | Recordings of consultations (sound) | 24 hours after the note is accepted, and no more than 7 days after the recording was made | | Transcripts of consultations | As part of your medical record | | Appointment and message records | [Period] | | Billing and accounts records | [Period, for example 6 years, as Irish tax and accounting rules generally require] | | Complaints and incident records | [Period] | | [Other] | [Period] |
When the time is up, we delete the record or make it anonymous so that it can no longer be linked to you. If you stop being our patient, we keep your record for the period above and no longer.
Note for the clinic, delete before publishing. You decide the periods. Professional guidance on how long to keep health records varies with the type of record, the age of the patient and the profession. A common recommendation is to keep an adult's record for the patient's lifetime plus a number of years afterwards (8 years is often mentioned), and a child's record until well after they become an adult. Check the guidance of your own professional body and any legal duty that applies to you, take your own advice, and then write your periods here. Ask Brigid keeps whatever you set. Tell us in writing if you want a shorter or longer period for a working copy, such as a recording (see the audio retention schedule).
Your rights
You have the right to:
- Be told what we do with your information. This notice is part of that.
- See your information (access). Ask for a copy of what we hold about you. It is free in most cases, and we reply within one month. Where the request is complex we may extend this by up to two further months, and we will tell you why.
- Have mistakes corrected (rectification). If something is wrong or incomplete, tell us. We will correct it. We may add a note to the record instead of deleting what was written, because a medical record has to show what was recorded at the time.
- Ask us to delete your information (erasure). This is not an absolute right. We cannot delete information we have to keep by law, or that we need to look after you or to deal with a legal claim. We will tell you if we cannot, and why.
- Ask us to limit what we do with it (restriction) while we look into a complaint, for example about accuracy.
- Object to our using your information where our reason is a public task or our legitimate interests. We will stop unless we have a strong reason that the law accepts.
- Take your information with you (portability) where we use it because you agreed or because of a contract, and we do it by computer. We will give it to you, or to another provider, in a common electronic format. [Delete if not applicable to the clinic's bases.]
- Take back your agreement at any time, where we rely on it (for example, for recording or for newsletters). This does not make what we did before lawful processing unlawful. You will still get the same care.
How to use your rights. Contact us: [name or role], [email], [phone], [address]. You may need to prove who you are, so that we do not give your information to the wrong person. You can also ask at the front desk. [If the clinic uses MyBrigid:] The MyBrigid app has a Download my data option and a My full record option that give you a copy of much of your information. You can also write to privacy@askbrigid.com about information for which DJG Media Limited is itself responsible. If your request is about your medical record, DJG Media Limited will pass it to us, because we are responsible for the record.
If you are not happy. Please tell us first so that we can put it right. You also have the right to complain to the Data Protection Commission, the Irish data protection authority, at www.dataprotection.ie, where its current contact details are listed.
Decisions made by a computer
We do not make decisions about you using only a computer or AI. Every decision about your care is made by a clinician. Software may prepare a draft or a summary. A person checks it before it is used.
Children and other people who ask on your behalf
[Describe how the clinic handles records for children and requests from parents, guardians or other representatives, including how it checks who they are. For example: A parent or guardian can ask to see a child's record. We check their identity and their authority first, and we may limit what we share to protect the child.]
Changes to this notice
If we change how we use your information, we will update this notice and put the new date at the top. [If a change matters to you, we will tell you directly.]
End of notice.
4. Before you publish: a checklist
- Every [square bracket] is filled or deleted, and every "Note for the clinic" is removed.
- The Article 6 and Article 9 reasons in the table are the ones you have decided on and recorded.
- The list of features (recording, AI drafting, MyBrigid, messages) is exactly what your clinic has switched on.
- The retention periods are yours, and Ask Brigid is set to match them.
- The list of outside-EU routes still matches the sub-processor register on the day you publish.
- You have a way to answer a request within one month, and you know who does it.
- You took your own advice.
Related legal documents
Privacy Policy · Data Processing Agreement · Raw consultation audio retention · Recording notice · Sub-processor register · Terms of Service · MyBrigid Terms of Service · Cookie Policy
This page renders the document itself. Its fingerprint identifies the exact wording published.
SHA-256: 29ddfaea1e446a793b7641a68679a736f9fb3b92ab7a00e831c39b04e85a12a6
Source: docs/legal/CLINIC_PATIENT_PRIVACY_NOTICE_TEMPLATE_2026-10-02_v1.md