Data & Compliance
Patient data. How we handle it.
OakStone was designed from the ground up to be GDPR-compliant by architecture, not by policy. Here is exactly what that means.
We do not store patient data.
OakStone never writes patient-identifiable information to its own systems. No patient names. No contact details. No appointment records. No medical information of any kind.
All patient data lives in your Practice Management System — and stays there. OakStone reads what it needs in real time, uses it in the moment, and writes nothing back to our systems.
This is not a policy choice. It is how the system is built.
What we do store.
OakStone stores operational outcomes — not identities. When the system sends an appointment reminder, it logs: appointment type, send timestamp, workflow name, location. Not the patient's name or number. When the AI receptionist handles a call, it logs: call type, resolution, whether a booking was made, estimated revenue value. Not the caller's identity.
This is the equivalent of a till receipt without a customer name — commercially meaningful, personally anonymous, and fully compliant with UK GDPR.
Consent.
Before every outbound patient communication, OakStone checks consent status via your Practice Management System's API. If a patient has not consented to communications, the system does not contact them.
Consent is never stored by OakStone — it is verified at the point of send, every time, directly from your PMS where the patient gave it.
Data residency and isolation.
Every client runs in a fully isolated environment. Your data cannot interact with another client's environment at any level.
UK-based data storage. Separate development, staging, and production environments — no cross-environment queries are possible by design.
Your obligations as a data controller.
Under UK GDPR, your practice group is the data controller for your patients. OakStone acts as a data processor on your behalf.
We provide a Data Processing Agreement (DPA) as standard — setting out exactly what data we process, for what purpose, and under what conditions. This is provided before onboarding begins.
ICO registration.
OakStone Digital is registered with the Information Commissioner's Office as a data processor. Our registration number is available on request.
CQC and information governance.
The way OakStone handles data is consistent with NHS and CQC information governance expectations. No patient-identifiable information leaves your clinical environment.
The system's design means there is no OakStone data room to breach, no patient records to expose, and no information governance risk introduced by the platform.
If your solicitor or compliance officer has questions, we welcome the conversation. This is one of the areas where we have thought hardest about getting it right.
hello@oakstone-digital.com