Acceptable Use Policy
Last updated: 28 September 2026
Published update — not yet the in-app acceptance version. This edition awaits legal review and activation. Existing acceptance records retain their original wording. Read the version currently linked from the app.
Version: 2026-09-28_v6 Published: 28 September 2026 Provider: DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838.
1. Scope
This policy applies to the clinic web and iOS apps, MyBrigid and the Brigid assistant. Use the services only for the lawful purposes and features made available to your account. Clinic staff act within the clinic's instructions, their role permissions and any applicable professional duties. Patients and representatives act within their own verified access rights.
2. Prohibited conduct
Do not use the services unlawfully; process information without authority; impersonate another person; share staff credentials; attempt to bypass access, security, consent or rate controls; interfere with audit records; introduce harmful code; or improperly scrape, extract or reverse engineer the service or its models.
Access patient information only where necessary for an authorised care or administrative purpose and within your permitted role. A family relationship, ownership of a clinic account or access to a mailbox does not by itself authorise every use of its contents.
3. AI purpose and human review
Use only the approved transcription, draft preparation, factual summary, administration and communication functions in the service schedule. Do not use Brigid to diagnose, clinically triage, score medical risk, recommend treatment, prescribe or make autonomous clinical decisions. Staff must check AI output against its source, correct errors and omissions, and approve a draft before it is signed, sent, filed or relied on.
An administrative label, human review or patient permission does not override provider restrictions or determine medical-device status. Report unintended clinical decision-support behaviour to support@askbrigid.com. Use supported releases and complete required terms updates; optional patient choices remain separate from terms acceptance.
4. Patient information and recording
Patient-linked AI requires the applicable record access and AI permission. Do not evade a refusal or withdrawal by using another account, pasting information into an unrelated chat or choosing General note. Select the patient before patient-note AI or transcription. General note is for administration containing no patient information and requires the staff member's confirmation.
Record a consultation only after the clinic's approved purpose, lawful basis, notice, applicable permission procedure and retention arrangements are in place. Stop recording when required by that procedure or the patient's applicable choice, and use the non-recorded workflow. A permission setting does not reopen an unavailable feature.
Follow the authorised sharing and representative-access process. Do not bypass a declined sharing choice, an expired authority or a revoked link. The clinic remains responsible for identifying the lawful basis and relevant confidentiality requirements; consent is not automatically the legal basis for every care-related disclosure.
5. Mailboxes, attachments and communications
Connect only mailboxes the clinic and account holder authorise for the stated purpose. The clinic must document the lawful basis, required notices and permitted uses of shared/clinic and individual staff inboxes and attachments. AI email assistance does not imply that every unlinked message has received an automatic patient-specific consent check. Staff must review drafts and obey the service's approval and sending controls.
Do not use patient information for unauthorised advertising or research. Marketing and service communications must follow the applicable GDPR, ePrivacy and professional rules, including required permissions and opt-outs.
6. Reporting and proportionate action
Report privacy, access and acceptable-use concerns to privacy@askbrigid.com, and technical or patient-safety concerns to support@askbrigid.com. Use the agreed urgent incident route for suspected security incidents. Do not include unnecessary patient information in a support report.
We may investigate and take proportionate protective action under the applicable terms, including urgent restriction where necessary for security, safety or law. Where practicable, we explain the reason and remediation route. An ordinary commercial dispute does not remove statutory data rights or the agreed means of obtaining records. Any suspension must account for continuity and lawful access/export obligations. Reports to regulators are made where required or otherwise lawful and appropriate.
Download the exact document (Markdown)
SHA-256: d1a14c310c9581750b0f409dc87be4f69d913904b0583b76a5b8b4948b844679
Source: docs/legal/ACCEPTABLE_USE_2026-09-28_v6.md