Privacy Policy
Last updated: 29 September 2026
Version: 2026-09-29_v16 Effective: 29 September 2026 Last updated: 29 September 2026 Provider: DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838, Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland Governing law: Ireland
1. Introduction
Welcome to the Brigid product family. We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we, DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838, collect, use, share, and protect your personal data when you visit our website (askbrigid.com), use Brigid or MyBrigid (previously called Brigid Patient), or use an enabled Brigid feature. The features that are switched on, the ones that are switched off, and your optional AI choices are explained in section 6. Where a feature processes patient information, the applicable clinic instructions, lawful basis and access and permission checks apply. These are product names, not separate legal entities.
This policy is designed to help you understand your privacy rights and how you can exercise them.
2. Who We Are and Our Roles
We are DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838, a company registered in Ireland with our registered office at Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland. For the purposes of the General Data Protection Regulation (GDPR), our role depends on the context of our interaction with you:
- When you visit our website, contact us directly, request a demo or early access, receive a letter from us, or create an account for Brigid: DJG Media Limited is the Data Controller. We determine the purposes and means of processing your personal data.
- When a healthcare provider (our "Customer") uses Brigid to manage patient information: The Customer is the Data Controller of the patient data, and DJG Media Limited is the Data Processor. We process this data on behalf of and under the instruction of the Customer, as governed by the Data Processing Agreement (DPA) we have with them.
This distinction is important. If you are a patient of one of our Customers, you should direct any privacy-related questions to your healthcare provider in the first instance.
3. What Data We Collect
We collect different types of data depending on your interaction with us:
- When you visit our website: We collect technical data such as your IP address, browser type, and operating system, as well as information about your browsing activity (our "Website Data"). Optional analytics run only if you opt in, as described in the Cookie Policy.
- When you contact us or sign up: We collect your name, email address, and any other information you provide in your communications with us (our "Communication Data"). On the early-access form that is your name, work email, your role and an optional phone number; on the demo form it is your name, work email and anything you choose to tell us. With each request we also keep where the visit began, so we can see which link or page worked: the campaign details in the link you followed, the site that referred you, the first page you landed on, the page you were on when you sent the form, and your country (worked out from your IP address). We use your IP address to slow down repeated submissions, and keep only a one-way hash of it for that purpose, not the address itself. We use these details to reply to you or ring you, and to understand which of our own pages and campaigns lead people to ask. We do not add you to a newsletter or a mailing sequence because you sent a request.
- When you use our platform: We collect account information such as your name, email address, role, and payment information (our "Account Data"). We also collect data on how you use the platform, such as features accessed and actions taken (our "Usage Data"), and we maintain detailed logs for security and auditing purposes (our "Log Data").
- When we process data for our Customers: We process patient demographic and clinical data on behalf of our Customers (our "Patient Data"). This is special category data and is protected by the technical and organisational measures set out in our DPA.
Data we hold that did not come from you
Four datasets are not collected from the people they concern, and Article 14 of the GDPR requires us to say so.
1. Irish pharmacies. We maintain a directory of Irish pharmacies — name, address, telephone, opening hours, and in some cases an email address — so that patients can find and contact their pharmacy, and so that clinic staff can look one up when arranging a prescription. It is built from two public sources: the statutory register of retail pharmacy businesses maintained by the Pharmaceutical Society of Ireland, and OpenStreetMap. Where the PSI register names the owner of a pharmacy, that name is held with the entry.
We rely on Article 6(1)(f) — our legitimate interest, and that of patients, in an accurate pharmacy directory. We have not written to each pharmacy owner individually, relying on Article 14(5)(b): the information concerns businesses, it is drawn from a public register those businesses are already listed in, and individual notification would be a disproportionate effort. Publishing this section is the measure we take instead.
If you are a pharmacy owner and would rather your details were not held here, write to privacy@askbrigid.com and we will remove the entry.
2. Emergency contacts and next of kin. When a patient (or a clinic, for a patient) records an emergency contact or next of kin, we hold that person's name, relationship to the patient and telephone number, and nothing else about them. The patient or the clinic gave us those details; the person named did not. They are held so the clinic can reach someone if the patient's care requires it. Where the patient's record belongs to a clinic, the clinic is the controller and we process the details for it. We rely on Article 6(1)(f) — the legitimate interest of the patient and the clinic in being able to reach someone in an emergency. We do not write to each person named: the details are given to protect the patient, we hold nothing else about the person, and notifying each one would be a disproportionate effort (Article 14(5)(b)). Publishing this section is the measure we take instead. The details are used only to contact that person about the patient, and are not used for marketing. If you are named as someone's emergency contact and would like the details removed or corrected, tell the patient or their clinic, or write to privacy@askbrigid.com and we will pass your request to the right controller.
3. People a patient invites to a family link. When an account holder invites a family member in MyBrigid, we send that person one email using the address the account holder gave us. That email is the notice under Article 14: it says who asked, and it links to this policy. We hold the address to deliver the invitation and to record the answer.
4. Practices and clinicians we write to. DJG Media Limited writes by post to consultants and practice managers at Irish private practices to ask for their help with Brigid. For each letter we hold the recipient's name, role, practice name and postal address, taken from publicly available details about the practice. The letter is printed, handwritten in style and posted by Cardly, a card and letter printing service, which receives only those details and the text of the letter; Cardly is established outside the EU, so the transfer safeguards for it are listed in our Sub-Processor Register and in section 12. DJG Media Limited is the controller. We rely on Article 6(1)(f) — our legitimate interest in asking the practices Brigid is built for what they think, by a single letter to a business address. The letter itself tells the recipient who we are and where the details came from, which meets Article 14(3)(a). You can object at any time by writing to privacy@askbrigid.com; we will stop writing to you and record that you asked us not to. The retention target for these details is in section 11.
Children and family access. Own MyBrigid accounts and clinic staff accounts require age 18 or over for this release. Clinics may hold children's information to provide healthcare, subject to the clinic's lawful basis, confidentiality and safeguarding duties. An authorised parent or guardian can request access to a child under 16 through an adult account; the clinic verifies the authority and approves the permitted access before information is shared. A family relationship alone does not confer access. The guardian link ends when the child turns 16. For ages 16–17, contact the clinic about record access; the app does not create an independent under-18 account or continue the guardian link automatically. These product rules do not replace the applicable law on children's data, capacity or confidentiality.
4. Lawful Bases for Processing
We only collect and process your personal data when we have a legal basis to do so. The purposes for which we use your data include:
- Contract fulfilment: To provide and manage the service.
- Legitimate interest: To secure and monitor our platform, communicate with you, understand which of our pages and campaigns lead people to contact us, write to practices about Brigid, and improve our services. You may object to processing based on legitimate interest at any time (section 10).
- Consent: For marketing and cookies (where required).
- Legal obligation (Art. 6(1)(c)): Where retention or processing is required by law — for example tax and accounting records retained under Irish Revenue rules.
5. Health Data Processing (Special Category)
Your medical record is "special category personal data" under GDPR Article 9. Where applicable, the Irish Data Protection Act 2018 §36 requires suitable and specific safeguards, while §52 addresses health and social-care processing and §53 addresses public-health processing. The relevant bases include:
- Explicit consent — GDPR Art 9(2)(a) — used only for optional processing that genuinely relies on consent, such as certain recording, sharing, and research choices. Consent can be withdrawn without affecting prior lawful processing.
- Healthcare delivery — GDPR Art 9(2)(h) + Irish DPA 2018 §52 — permits processing necessary for medical diagnosis, the provision of health or social care or treatment, or management of health systems.
- Public interest in the area of public health — GDPR Art 9(2)(i) — applies to specific public-health functions (e.g. notifiable disease reporting).
The platform records security and access events defined in the clinic's approved logging specification. Logging coverage, access to log data and retention are documented in the clinic agreement and evidence pack; this notice does not claim that every database event is captured. You may request access to personal data held in those logs under GDPR Article 15, subject to the rights of other people and applicable restrictions.
What we do NOT do with your health data: we never sell it or use it for advertising, and DJG Media Limited does not use it to train its own AI models. Provider processing, retention and training restrictions differ by service and are disclosed in our Sub-Processor Register; we do not describe every provider as zero-retention.
6. What Brigid Does, What Is Switched Off, and Your AI Choices
Brigid is practice-management software with AI built in. The AI helps the clinic prepare its work. A clinician or other responsible staff member reads the source and approves a draft before it is signed, sent, filed or relied on, and a draft stays a draft until then. AI can make mistakes and leave things out. Brigid is not intended to provide diagnosis, clinical triage, medical risk scores, treatment recommendations or autonomous clinical decisions. This section lists what is switched on today. If a clinic has not enabled a feature, or a patient has refused it, it does not run for that clinic or that patient.
Switched on:
- Recording and speech-to-text. A clinician can record a consultation or dictate a note. The audio is turned into text by Google Cloud Speech-to-Text on an EU endpoint. The clinic's recording notice and permission procedure apply. The original audio is kept only briefly (section 11).
- Note and letter drafting. Brigid drafts a clinical note or a letter from the transcript, from what the clinician dictated or typed, and, when the clinician asks, from the patient's chart. It can also tidy dictated text and draft one section of a note again. This uses Google's Gemini model (currently Gemini 3.5 Flash) on Google Cloud Vertex AI in Frankfurt, Germany (europe-west3). Drafted text is labelled as drafted by AI. It is a draft: the clinician reads it, edits it and signs it, and Brigid does not file, sign or send it. Brigid is instructed to write down only what was said and what is already recorded, and not to diagnose, grade urgency or risk, triage, assign clinical codes, or recommend investigations, treatment or follow-up that was not already stated. When a draft is made for a patient, the patient's AI choice below is checked first.
- Administrative helpers. A factual summary of the chart before a consultation; reading an uploaded document to work out what it is and file it in the right place; sorting the clinic's own email and filing emailed attachments to the right chart; the onboarding assistant; and an in-product assistant for staff that runs administrative tasks and can look up public reference sources such as PubMed, drug-label databases and terminology services (see section 12).
- Clinic email and calendar. Where a clinic connects a Google Workspace (Gmail, Google Calendar) or Microsoft 365 (Outlook) account, authorised staff may use the connection, including attachments, for the clinic's documented purposes. The clinic must explain that processing and establish its own lawful basis and any required permission. Email and attachments that are not linked to a patient are not automatically checked against an individual patient's AI choice.
Switched off for this release: AI that diagnoses, triages, ranks urgency, scores risk or recommends treatment; a live "copilot" during a consultation; Brigid Live real-time voice; video-consultation recording; meeting-bot and browser-extension capture; ElevenLabs speech and voice-agent calls; SMS and WhatsApp outreach to patients; and any AI that sends messages to patients on its own. Consent does not switch any of these on.
In MyBrigid. The MyBrigid app does not currently offer you an AI chat, a symptom checker or an AI-written reply. AI touches your information only through the clinic's staff, in the ways listed above and only if you have not refused it.
Patient-linked AI and transcription. Staff must have permission to access the record and must check the patient's applicable AI choice before using patient information with AI or cloud transcription. This applies to a clinician dictating a note about a patient as well as recording a consultation. A consultation recording also follows the clinic's recording notice and permission procedure. General administrative recordings must contain no patient information.
Where the check is automatic. Every request to draft a note or letter for a patient carries that patient, and the server checks the patient's AI choice before the request is sent to the model. A refusal stops the request and tells the clinician to record the patient's consent. On 28 September 2026, when we last checked, the same automatic check had not yet been deployed for every other path (patient notes and chat outside the drafting route, transcription, and reuse of saved conversation material). Where it is not automatic, clinics must verify the applicable permission before using that path and must not process information against a refusal or withdrawal. If you believe your choice has not been honoured, contact your clinic or privacy@askbrigid.com so the processing and your request can be investigated. We will update this notice when the deployed controls are verified.
Your choice. The Clinical intelligence choice is optional, off unless enabled through the applicable patient process, and withdrawable without loss of non-AI care. Refusal or withdrawal means further processing covered by that choice must stop. It does not retrospectively invalidate lawful processing or automatically erase a clinical record. Sharing between clinics and non-clinical product updates have separate choices. Account or terms acceptance is not consent to all optional processing.
Chat history. Patient-linked chat and retrieved records require the applicable permission and access checks when reused. We have prepared an update that excludes old conversation material with unverified patient scope from new AI input while keeping it available for authorised staff viewing; when we last checked, on 28 September 2026, it had not been deployed. We do not claim to identify every patient's identity from arbitrary text.
Consent settings do not by themselves establish every lawful basis or enable an unavailable feature. The clinic must document the relevant Article 6 basis, Article 9 condition and DPIA where required. No patient choice overrides provider terms or applicable law. Medical-device and AI Act classification is assessed separately against the actual functions and intended use. Under the EU AI Act, you are told when you are dealing with an AI system and AI-written text is labelled before anyone relies on it.
7. Cross-Clinic Data Sharing & Record Portability
Cross-clinic record sharing is offered to you in the MyBrigid app as an explicit choice — presented as Share your records, off unless you turn it on, and withdrawable at any time. Turning it off is intended to prevent further access through the sharing permission. It does not automatically erase a copy already lawfully received by another clinic: that clinic handles its copy under its own responsibilities. The current release must verify the applicable database and sharing-path enforcement before relying on that control.
Before any clinic is enabled to receive a share, its controller must have approved the purpose, Article 6 basis, Article 9 condition, recipient verification, access and revocation behaviour, transparency text and any required DPIA. Your permission does not substitute for that approval; both are required.
- No blanket pre-consent — a general toggle will not authorise any clinic to read the complete record.
- No implied lawful basis — a patient action is recorded, but the relevant controller must still identify and document the lawful basis and safeguards.
- Fail closed — no production share may open until recipient identity, expiry, revocation, logging and deletion tests are in the release evidence.
8. Marketing & Outreach Communications
Marketing messages sent by DJG Media Limited require a valid permission or another applicable ePrivacy route and a working opt-out. A clinic is responsible for determining and documenting the lawful basis and ePrivacy rule for its own patient communications. SMS and WhatsApp outreach to patients are switched off, and Brigid does not send messages to patients on its own. The only SMS we send is a sign-in code to a member of staff who chose to receive codes by text.
- We do not sell your contact details. Where needed to provide a requested service, we disclose them to authorised service providers described in this notice and the applicable supplier information. Marketing use requires the applicable legal basis or permission and an effective opt-out.
- Appointment or care-related reminders are not automatically marketing, but the clinic must classify each purpose and document its GDPR and ePrivacy basis; this policy does not assign one blanket basis to every reminder.
- One-tap unsubscribe links appear on every marketing message; you can also globally opt out using the instructions supplied with the communication or by contacting the sender.
- Our letters to practices are described in section 3. They are postal letters to a business address, not electronic marketing.
9. Research Use
No patient-data research programme is authorised for the first-clinic release. We will not describe data as anonymous merely because direct identifiers have been removed.
- Any future research use requires a separately documented protocol, controller decision, Article 6 basis, Article 9 condition, data-minimisation and disclosure analysis, and any required ethics or DPIA approval.
- A future notice will distinguish anonymous information from pseudonymised personal data and explain withdrawal or objection rights for the approved study.
10. Your Data Protection Rights
Under GDPR, you have several rights in relation to your personal data:
- Right to Access: Request a copy of the data we hold.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: The "Right to be Forgotten".
- Right to Data Portability: Transfer data to you or a third party.
- Right to Object: Object to processing in certain cases, including processing based on our legitimate interest.
- Right to Restriction: Ask us to pause processing while a dispute is resolved.
- Right to Withdraw Consent: Where we rely on consent (marketing, optional cookies) you may withdraw it at any time without affecting earlier processing.
We respond within one month, extendable by two months for complex requests, in which case we tell you. Providing your name and email for a staff account or the early-access list is needed to provide that service; you are not otherwise obliged to give us data. We do not make decisions producing legal or similarly significant effects about you by solely automated means.
Our published privacy contact is privacy@askbrigid.com. The formal Article 37 DPO appointment decision and, if applicable, DPC notification are launch-evidence items; this mailbox alone is not represented as proof of appointment. To exercise any of these rights, contact us at that address. You may also lodge a complaint with the Data Protection Commission at dataprotection.ie (GDPR Article 77; Data Protection Act 2018, Part 6, sections 107–109). Current postal and online contact details are available on the DPC contact page.
11. How Long We Keep Your Data
Retention periods depend on the category of data (GDPR Art. 13(2)(a)):
- Account and billing data — for the duration of your contract, then handled under the signed contract and approved retention schedule after termination. Irish tax and accounting records are generally kept for six years, subject to any longer period required for a particular record or proceeding.
- Closed staff accounts — when a staff account is closed, we keep it closed for up to one month in case you change your mind, and then erase the account and profile records (profile, roles and permissions, sign-in session records, consent and communication preferences, and the links to the clinics you belonged to). Clinical records belong to the clinic and are not part of the account.
- Patient records processed for clinics — retained on the instructions of the clinic (the controller) under its documented retention schedule, applicable law and professional guidance. On contract termination the clinic has the export window agreed in its order form (currently proposed at 30 days); deletion is then initiated as described in the DPA, subject to lawful retention and the encrypted backup-deletion cycle.
- Platform security and clinical-access audit logs — the policy period for the specified audit-record classes is six years, subject to a documented necessity assessment, applicable controller instructions and legal holds. This is not a claim that automatic deletion across every log and backup has been verified.
- Voice recordings and transcripts — original consultation audio is deleted within 24 hours after the clinician accepts the transcript or note, and in any case no later than seven days after it was recorded, unless the clinic has given a written instruction to keep it or a documented legal hold applies. Filed transcripts and clinical notes follow the clinic record schedule; deleting audio does not automatically delete those records. While a recording is waiting to upload, an encrypted copy is kept on the clinician's device and removed once the server confirms the save (see the Cookie Policy). Copies in encrypted backups expire with the backup cycle.
- MyBrigid accounts you delete — when you delete your MyBrigid account we keep it closed for up to one month in case you change your mind, and then erase the account and the personal record it held. While it is held closed it is not used for anything else. Records held by your clinic are not part of it (section 14).
- Early-access and demo contacts, and practices we have written to — the policy target is 24 months from our last contact with you. Cookie-consent records — the policy target is 12 months from the choice (see the Cookie Policy). Automatic purge and backup-expiry coverage for these categories are being verified; these targets are not a statement that every historical copy has already been deleted. Contact privacy@askbrigid.com to request removal or information about a specific record.
12. International Transfers
Brigid's primary patient-record database and object storage are provisioned in the EU (Supabase, Ireland — AWS eu-west-1). Our database provider, Supabase Pte. Ltd., is incorporated in Singapore and its support staff can access the service; that access is covered by the EU Standard Contractual Clauses (Module Three) incorporated in its data processing agreement. Our server functions run in the same EU (Ireland, eu-west-1) region as the database. The applicable Article 28 terms, Chapter V transfer mechanism, transfer assessment and provider configuration must be evidenced per route. Some legacy scope statements and release evidence are under review; inclusion in the register is not itself proof of supplier authorisation. Where each supplier is located, what it receives and the safeguard we rely on are set out in our Sub-Processor Register. In summary:
- AI drafting and administrative helpers use Google Gemini on Google Cloud Vertex AI in Frankfurt, Germany (europe-west3), inside the EU. Google Generative AI is used for the administrative routes and note and letter drafting described in section 6; it is not an approved clinical decision-support provider. Embeddings are produced in europe-west4 (the Netherlands).
- Voice transcription uses Google Cloud Speech-to-Text on an EU endpoint. ElevenLabs and the US medical-dictation model are not transcription routes.
- Brigid Live real-time voice is switched off. Its only release candidate is a server-controlled Vertex AI route in europe-west4, restricted to administrative tools. The former Google AI Studio / US-audio route is disabled.
- Telehealth recording remains disabled unless the clinic-specific Daily.co region, retention and agreement evidence has been approved.
- Error monitoring (Sentry) receives error reports at its EU (Frankfurt) region. Health data and direct identifiers are scrubbed before an error report leaves the application. Sentry's parent company is established in the United States, and the transfer is covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.
- Email (Resend) is stored in the United States, under an Article 28 agreement and Standard Contractual Clauses. SMS (Twilio, EU and US routing) is used only for staff sign-in codes; SMS reminders and campaigns are switched off.
- Payments and identity checks (Stripe) are processed by Stripe's Irish entity and global card networks.
- Push notifications (Apple) carry a device token and a short notification label to your iPhone. For MyBrigid the label never carries clinical detail.
- Maps (Mapbox, United States) draw the map in MyBrigid's clinic finder and in a clinic's public listing settings. Mapbox receives your IP address and the map area being viewed (and, in the clinic's settings, the address or Eircode being placed on the map).
- Public reference lookups. When staff ask Brigid to look something up, it may send a search term, such as a condition, a drug name or a code, to public services: NCBI PubMed and Europe PMC, US drug-label databases (openFDA, DailyMed), the US NPI registry and SNOMED and ICD terminology servers. We do not send patient records to these services, and we do not authorise patient identifiers in a search. They are public services without a contract with us.
- Hosting and website analytics. Our websites are hosted by Vercel (United States and EU edge). Optional analytics on askbrigid.com use Google Tag Manager and Google Analytics (Google Ireland Limited, with processing possible in the United States) only if you opt in.
- Letters to practices are printed and posted by Cardly (section 3). Cardly is established outside the EU. Its data processing terms and transfer safeguard are being documented in our supplier register, and the letters carry only a name, role, practice and postal address.
Transfer assessments and agreement/configuration evidence remain release gates where an international route applies. The current provider register is our Sub-Processor Register.
13. Browser Extension and Meeting Capture
The browser-extension meeting notetaker, meeting recording, AI meeting summaries and filing of meeting-derived clinical content are disabled for the first-clinic release. Installing software or clicking a record control would not, by itself, establish the controller's lawful basis or satisfy participant transparency requirements.
- Reopening conditions: approved purpose and lawful basis, participant notice/permission procedure, role and access mapping, provider agreement/residency, retention/deletion test, DPIA, incident path and production evidence.
- No consent shortcut: a participant's permission, where required, does not authorise a prohibited provider route or replace the clinic's GDPR analysis.
- Fail closed: no clinic meeting may be captured through this route until the release gate is approved and the clinic has supplied its required notice and staff procedure.
This section describes the launch boundary, not an offer that meeting capture is currently approved or available.
14. The MyBrigid app
Launch status: MyBrigid is available. It was released on 16 September 2026. What follows is the privacy boundary that applies to the app as it stands today. It opens only for an adult (18 or over) whose link to their clinic has been confirmed by the clinic. Personalised medical advice and symptom triage are outside the intended release scope, and the app has no AI chat (section 6). Where AI is applied to your record it is governed by the permission you give in the app (section 6), and cross-clinic access is governed by Share your records (section 7).
- Who the controller is: when your MyBrigid account is linked to a clinic, that clinic remains the data controller of your medical record and we process it on the clinic’s behalf. A standalone record — a personal health record kept in MyBrigid without a connected clinic (conditions, allergies, medications, vitals, documents, family links) — is not something a new user can start in this release, because the app opens only with a confirmed clinic link. Some accounts created before that rule still hold such a record. For those, DJG Media Limited (trading as askbrigid.com and myBrigid), CRO No. 762838 is the data controller. We hold that record only so the account owner can see it and use it. Our basis is Article 6(1)(b) (providing the account the person asked for) and, for the health information the person entered into their own record themselves for their own use, Article 9(2)(a) (their explicit consent, which they can withdraw at any time by deleting entries or deleting the account). We use that record for nothing else, and do not share it. If you hold such a record and would rather we did not, delete it in the app or write to privacy@askbrigid.com.
- Data the app itself sends us: your device’s push-notification token (so alerts you enable can be delivered), minimised crash and diagnostic reports, photos and documents you choose to upload, and payment records when you pay a clinic invoice or subscribe to an optional feature. Payments are processed by Stripe — your card number never touches our servers.
- Notifications: alerts are delivered through Apple’s push service. The notification says what kind of update it is; clinical kinds read only "New update in your record". No clinical detail is put in the notification.
- What stays on your device: Your session is stored in the device keychain.
- Face ID or Touch ID unlock (optional): you can choose to unlock MyBrigid with Face ID or Touch ID on your iPhone (Me → Login & security). Your iPhone does the check itself: your face or fingerprint data never leaves it, and we never receive, see or store it. We store only, in your device's keychain, whether you turned the setting on for your account. It is off unless you turn it on, you can turn it off at any time, and your password always works instead.
- Identity verification: before you can add a family member, request a repeat prescription or book a remote visit in the app, we ask you to confirm you are the account holder. Stripe carries out this check for us: you photograph an identity document (a passport, driving licence or national identity card) and take a live selfie, and Stripe compares your face with the photo on the document. This is biometric processing. Before anything is captured, Stripe asks for your explicit consent to this on its own consent screen, and we rely on that consent (GDPR Article 9(2)(a)). You can decline, or withdraw by stopping part-way, and nothing more is captured; you can keep using MyBrigid, but family links, repeat prescription requests and remote-visit booking in the app stay unavailable until you verify, and you can still contact your clinic directly. We receive the result and the details Stripe read from the document, and we use only your surname and date of birth, which we compare with your clinic record, or with your own profile if no clinic is linked. We keep the outcome, whether those details matched and a reference number for the check, not the document, the selfie or the details on it. Once Stripe has checked the document and we have compared those details, whether or not they matched, we ask Stripe to delete the session, including the document images and the selfie. Stripe also keeps some verification data as an independent controller, under its own privacy policy; you can ask Stripe about that data at privacy@stripe.com.
- Location and maps: if you use “find nearby clinics”, the app can use your device’s location to centre the map. We do not store your location. The map itself is drawn by Mapbox (United States), which receives your IP address and the area of the map you are looking at, as any map service does.
- Emergency contact: you can record an emergency contact. We hold the name, relationship and telephone number you enter, for your clinic to use if your care requires it. The person named is covered by section 3.
- Family access to a child’s record: where a family member asks to see a child’s record, the link is held until the child’s clinic confirms that the person asking has parental responsibility. Nothing is shared until then.
- Your rights, in the app: there are two ways to take your data with you. Download my data (Me → Download my data) gives you a summary of what the app shows: your details, your medication list, your letters and documents and your test results, as files and spreadsheets. It is not a complete copy: it leaves out next of kin and emergency contacts, insurance details, advance directives, follow-up tasks, your full appointment history, portal messages, consent and communication-preference records, and anything the clinic has not yet released to you. My full record (on the same screen) builds a complete copy of your record, including those additional items, as a download. You can make up to three full-record requests in 24 hours; write to us if you need more. For anything else, write to privacy@askbrigid.com. To delete your account, use Me → Login & security → Delete account. The deletion covers account information, personal-record information and uploads we control, family links and device registrations, subject to applicable retention exceptions and backup expiry. We keep the account closed for up to one month in case you change your mind, and then erase it (section 11). Deleting MyBrigid does not automatically delete records held by your clinic. The clinic assesses requests about its records under applicable data-protection law, retention requirements and professional duties. Where retention is necessary, the clinic should explain the reason and period. Contact privacy@askbrigid.com about data for which DJG Media is controller, and your clinic about its records.
- Advertising and tracking: we do not use patient health data for advertising and do not authorise cross-company advertising tracking in the launch release. The App Store privacy information describes the app version distributed there; material differences should be reported to privacy@askbrigid.com.
Related legal documents
Terms of Service · MyBrigid Terms of Service · Clinician Terms · Data Processing Agreement · Software qualification · Cookie Policy · Acceptable Use Policy · Accessibility Statement · Compliance Overview
This page renders the policy itself, not a summary of it. The version is fingerprinted, so the exact wording in force on any date can be established:
SHA-256: 0f83af6bf18bda65dbb737cd38bff23b270f5fc71a4131e31a21fc1a8d6669bc
Source: docs/legal/PRIVACY_POLICY_2026-09-29_v16.md