Home Privacy notice
Privacy notice
This describes what Harmony Verify collects, why, how long we keep it and what you can ask us to do about it. It is written to be read rather than to be defensible, and where a practice is still developing we say so rather than describing a future state in the present tense.
Last updated 30 July 2026
1. Who we are
Harmony Verify provides clinical verification of AI-generated output for healthcare technology companies. For personal data you give us directly — an enquiry, an account, an expert application — we are the controller. For clinical material a customer sends us to review, the customer is the controller and we act as processor on their instructions, under a written agreement.
Questions, or to exercise any right below: privacy@harmonyverify.org.
2. What we collect and why
| Category | What | Why | Basis |
|---|---|---|---|
| Enquiries | Name, work email, organisation, message | To answer you and to assess fit | Legitimate interests |
| Accounts | Name, email, organisation, hashed password, session records | To operate the service you signed up for | Contract |
| Expert applications | Credentials, license number, institution, years practising, CV, professional profiles | To assess admission and to verify identity against a public register | Contract, legitimate interests |
| Reviewer payouts | Account holder name, bank name, encrypted account number, payout history | To pay reviewers for completed work | Contract, legal obligation |
| Clinical submissions | AI-generated output supplied by a customer, and any file attached to it | To perform the review the customer asked for | Processed on the customer's instructions |
| Technical logs | IP address, user agent, timestamps, audit records of who accessed what | Security, abuse prevention and the audit trail the service depends on | Legitimate interests, legal obligation |
| Analytics | Aggregated page views and navigation paths | To understand which pages answer people's questions | Consent — off unless you turn it on |
3. Patient data
Customers are asked to de-identify clinical material before sending it. Where identifiers nonetheless appear in a submission, that material is handled as special-category personal data on the customer's instructions: stored in private object storage rather than in database fields, reachable only through short-lived signed links, and visible only to the assigned reviewer and the customer who submitted it.
Submissions are never used to train models, never used for advertising, and never shared with an analytics provider.
4. Cookies and similar storage
Nothing but strictly necessary storage runs before you make a choice. Analytics and marketing categories are off by default and are only activated if you switch them on. You can change your decision at any time from , and withdrawing consent deletes the cookies in that category rather than merely stopping new ones.
| Category | Purpose | Default |
|---|---|---|
| Strictly necessary | Session, load balancing, and remembering this cookie choice | Always on — required for the site to work |
| Analytics | Aggregated, de-identified measurement of which pages are read | Off |
| Marketing | Whether a campaign led to a demo request | Off |
5. Who we share with
We use a small number of processors: cloud hosting and object storage, a transactional email provider, and a payment provider that handles card details so that they never reach our servers. Each is bound by a written processing agreement. A current sub-processor list is available on request.
Assigned reviewers see the clinical material for the case they are working on and nothing else. We do not sell personal data, and we have never done so.
6. International transfers
Reviewers practise in many countries, so a submission may be reviewed outside the country it originated in. Where that involves a transfer out of the UK or EEA, it is made under standard contractual clauses or an adequacy decision, and a customer can restrict reviewer jurisdictions contractually if their own obligations require it.
7. How long we keep things
- Enquiries — 24 months from last contact.
- Accounts — for as long as the account is open, then 30 days.
- Clinical submissions and reports — as instructed by the customer in their agreement; by default, for the life of the account.
- Audit and access logs — 12 months, because an audit trail that expires with the record it describes is not an audit trail.
- Payout records — as required by tax and financial reporting law, typically seven years.
8. Your rights
Depending on where you are, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you can withdraw it at any time without affecting what was done before.
Account holders can delete their account from within the product, which removes the account and the personal data attached to it, subject to records we are legally required to retain. Everyone else can write to privacy@harmonyverify.org. We respond within one month.
If a submission contains a patient's data, the customer who sent it is the controller, and a request about it should go to them. Tell us anyway and we will help route it.
9. Security
Passwords are stored as salted hashes and never in a table that a user query can return. Reviewer bank account numbers are encrypted at rest with a unique initialisation vector per record, and only the last four digits are ever displayed. Access is authorised server-side on every request rather than hidden in the interface. Every access to clinical material is written to an audit log.
Where a formal certification or attestation is in progress rather than complete, we say so and give the stage it has reached. Ask for the current status and you will get it in writing rather than a badge. See what we do not claim.
10. Complaints
Tell us first — privacy@harmonyverify.org — and we will look into it. You also have the right to complain to your local data protection authority, and you do not need to come to us first to do so.
11. Changes
When this notice changes materially we will say what changed and when, rather than silently updating the date at the top.