This policy explains what information Clinstrux collects, why, and what rights you have over it — including the specific rules that apply to clinical case data, the Clinby AI companion, and the Clinby Community.
Last updated: 6 July 2026Clinstrux ("Clinstrux", "we", "us", "our") provides a clinical workflow platform for pharmacists at app.clinstrux.com, a companion community at clinby.clinstrux.com, and this marketing site at clinstrux.com (together, the "Services"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, register for an account, use the platform, interact with our Clinby AI companion, or participate in the Clinby Community.
This policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are located outside the United Kingdom, your information may still be processed in accordance with this policy and applicable local law.
Important
Clinstrux is currently provided for demonstration and educational purposes and is not intended to replace professional clinical judgment or for direct patient care decisions. Please read Section 4 carefully — it explains what you should and should not enter into the platform.
The data controller responsible for your information is:
Clinstrux Ltd
Registered in England and Wales
Registered office: London, United Kingdom
Company number: [to be inserted upon incorporation]
Email: clinstrux@clinstrux.com
References to "Clinstrux" throughout this policy mean Clinstrux Ltd unless the context requires otherwise.
When you create an account — either directly or via Google Sign-In — we collect your name, email address, job title, profile picture or avatar selection, and (optionally) your institution or employer. If you register on behalf of an organisation, we also collect your organisation's name and the roles assigned to its members (individual, admin, or member).
If you create or join an Organisation on the platform, we process invitation records, membership roles, and administrative actions (such as adding, removing, or promoting members). Organisation administrators have read-only visibility into certain case metadata for members of their organisation — see Section 4 for what this does and does not include.
The core function of the platform is to let you enter clinical scenarios (diagnoses, medications, allergies, renal function, and similar structured variables) into a workflow (such as ABX, MEDREV, POLY, CKD, HF, DM, COPD, ANTICOAG, or DEPRESC) in order to generate a structured recommendation. This is described fully in Section 4.
When you interact with Clinby — our in-platform AI companion — we process the messages you send it, the workflow context it is given in order to answer you, and its responses. See Section 5.
If you participate in the Clinby Community, we collect the posts, comments, and votes you submit, along with your community profile (display name, avatar, and role). See Section 6.
If you submit our "Request Access" form, we collect your name, email address, role, institution, and any free-text answers you provide about your intended use case, workflow gaps, or feature requests.
We use a small number of cookies and browser storage mechanisms, described in full in Section 13.
Like most web services, our hosting and analytics infrastructure automatically logs technical information such as IP address, browser type, device type, referring URL, pages visited, and timestamps, for security and service-improvement purposes.
Do not enter real, identifiable patient information
Clinstrux is provided for demonstration and educational purposes only. It is not a certified medical device, is not intended for direct patient care decisions, and should not be used as the sole basis for any clinical decision. You should not enter patient names, NHS numbers, dates of birth, addresses, or any other information capable of identifying a real individual into any workflow, case record, or Clinby conversation.
Where a user nonetheless enters clinical scenario data — including data that describes a real patient in a de-identified or hypothetical form — we process that data as follows:
If you are a healthcare organisation considering using Clinstrux with real patient data as part of a clinical service, please contact us at clinstrux@clinstrux.com before doing so, so that we can discuss appropriate safeguards, a data processing agreement, and whether the platform is currently fit for that purpose.
Clinby is an LLM-powered clinical companion built into the platform. When you interact with Clinby — whether via chat, an in-context explanation, or a proactive suggestion — the platform sends relevant context (such as your current workflow step and the clinical variables you have entered) to our underlying AI model provider(s) in order to generate a response.
We take reasonable steps to work with AI model providers who offer appropriate data protection commitments, and we do not permit our AI sub-processors to use your data to train their general-purpose models without a specific agreement in place. Clinby's suggestions are generated using structured, explainable workflow logic combined with language-model assistance; they are informational in nature and do not constitute medical advice. You, the pharmacist, remain solely responsible for any clinical decision made using the platform.
The Clinby Community (hosted at clinby.clinstrux.com) is a moderated discussion space for pharmacists, sharing the same account and login as the main platform. When you post, comment, or vote in the community:
If you believe a post contains identifiable patient information or otherwise breaches our community guidelines, please report it or contact clinby@clinstrux.com.
Under UK GDPR, we rely on the following legal bases depending on the purpose of processing:
| Purpose | Legal basis |
|---|---|
| Creating and administering your account | Performance of a contract with you |
| Processing clinical case data you submit to generate recommendations | Performance of a contract with you; your explicit instruction |
| Organisation admin oversight of member case metadata | Legitimate interests (clinical governance and accountability), as agreed by your organisation |
| Operating the Clinby Community | Performance of a contract with you; legitimate interests in maintaining a safe community |
| Responding to Request Access / contact form submissions | Legitimate interests in responding to enquiries; consent where indicated |
| Security, fraud prevention, and service analytics | Legitimate interests in keeping the Services secure and reliable |
| Non-essential cookies | Consent (see Section 13) |
| Legal compliance and enforcement of our Terms | Legal obligation; legitimate interests |
Some of our sub-processors operate outside the United Kingdom, including in the United States and the European Economic Area. Where we transfer personal information internationally, we rely on appropriate safeguards recognised under UK GDPR, such as the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses (as incorporated into UK law), or a determination that the recipient jurisdiction offers an adequate level of protection.
We retain personal information for as long as necessary to provide the Services and for the following periods thereafter:
We may retain information for longer where required by law, to resolve disputes, or to enforce our agreements.
We apply industry-standard technical and organisational measures to protect your information, including encryption in transit (TLS/HTTPS), database-level access controls and row-level security policies restricting who can view case and organisation data, authentication safeguards, and least-privilege access for our own team. No method of transmission or storage is 100% secure; if you believe your account has been compromised, please contact us immediately at clinstrux@clinstrux.com.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at clinstrux@clinstrux.com. We will respond within one month, as required by law. We may need to verify your identity before actioning certain requests.
Clinstrux is intended for use by qualified or trainee healthcare professionals and is not directed at, or intended for use by, children. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, please contact us so that we can delete it.
Clinstrux's workflows and Clinby's suggestions use structured logic and AI assistance to surface recommendations, explanations, and flags. These outputs are decision-support only: no automated process makes a final clinical decision, and no automated process produces a legal or similarly significant effect concerning you without the involvement of the pharmacist using the platform. The pharmacist using Clinstrux is always the human decision-maker of record.
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or the Services themselves. We will update the "Last updated" date at the top of this page, and where changes are material, we will take reasonable steps to notify registered users (such as by email or an in-platform notice).
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your information, please contact:
General enquiries: clinstrux@clinstrux.com
Clinby Community: clinby@clinstrux.com
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
ico.org.uk — Helpline: 0303 123 1113