Security & data

Saphe Tech holds special category health data about children. That sets the bar for how the platform is built, not the other way round.

Encryption

Data is encrypted in transit with TLS and at rest at the storage layer. Credentials are hashed; we never store plaintext passwords.

Least-privilege access

Every record is protected by row-level security tied to organisation membership and role. There is no shared or global read access.

Audit logging

Reads and writes against personal records are logged with actor, action, subject and timestamp, so your organisation can investigate and evidence access.

Data minimisation

We ask for the smallest set of fields that make the workflow work. Free-text clinical detail is optional and clearly marked as such.

Retention & deletion

Your organisation sets retention periods. Records can be exported in full and permanently deleted on request, including from backups within the stated backup window.

Sub-processors

We maintain a current list of sub-processors and the regions they operate in, and give notice before any change.

Roles under UK GDPR

Your organisation is the data controller: it decides what is collected, why, and for how long. Saphe Tech is the data processor: we act only on your documented instructions, under the written data processing agreement you accept during onboarding.

Because the records concern health, they are special category data. Your organisation must identify both a lawful basis under Article 6 and a condition under Article 9 before entering them. Our onboarding prompts you to record which ones you rely on.

Rights of the people in your records

Children, and the parents or carers acting for them, can ask your organisation to:

  • Be told what records the organisation holds about them
  • Get a copy of those records
  • Have inaccurate records corrected
  • Have records erased where there is no lawful basis to keep them
  • Restrict or object to certain processing
  • Withdraw consent at any time, without affecting past lawful processing

Saphe Tech gives your administrators the tools to fulfil each of these directly. If a request reaches us instead, we forward it to your named contact and assist you in responding.

Reporting a security issue

If you believe you have found a vulnerability, please contact us before disclosing it publicly. We will acknowledge your report and keep you updated while we investigate. Please do not access, modify or exfiltrate data belonging to anyone else while testing.