Back to Octave

UK GDPR at Octave

Last reviewed 13 August 2026

This page explains how Octave handles clinic data under the UK GDPR. It describes our current posture, not a certification.

The clinic stays the data controller. Octave acts as its processor under written instructions. The clinic's existing systems remain the records, clinical decisions remain with its clinicians, and no production patient data is accessed before the data-protection paperwork and risk assessment are complete.

Who is responsible for what

For patient and clinic-user data processed to provide Octave, the clinic determines the purposes and essential means of processing and remains the controller. Octave Systems Limited acts as processor, or as subprocessor where the clinic itself is processing for another controller.

The clinic is responsible for its lawful bases, Article 9 condition, privacy information, common-law confidentiality position and clinical governance. Octave is responsible for following documented instructions, protecting the data it handles, keeping appropriate processor records and helping the clinic meet its obligations.

For ordinary business contacts, enquiries and administration of our own contracts, Octave acts as an independent controller. Our privacy policy explains the public website position.

Minimum data, for an agreed purpose

Octave connects the systems a clinic already runs. Those systems remain the records. Where an installation needs an event layer, operational view or audit log, it holds only the fields agreed for that workflow, with pseudonymisation used where it is practical.

AI and automation

Octave does not use clinic data to train models. No AI service may process personal data, determine identity or eligibility, create individualised patient-facing content, or take clinical action unless the clinic and Octave first sign change control recording the provider, purpose, data, retention, no-training controls, transfers, testing, human oversight, and DPIA and clinical-safety outcomes.

Automated actions use deterministic patient matches approved for the installation. Ambiguous, conflicting or duplicate records are excluded and routed to a person. Agreed workflows include shadow mode, suppressions, rate limits, duplicate prevention, a stop control, human handoff and action logging. Octave does not make clinical decisions.

Security, location and suppliers

Production access uses named accounts, least privilege and multi-factor authentication. Production personal data and backups are encrypted in transit and at rest. Environments and credentials are separated, changes are controlled, failures are alerted, and restoration and manual fallback are planned for the selected platform.

Our standard intended hosting architecture uses a dedicated Supabase project in the London region. Supabase, Inc. is a US company and may provide support or administrative access from the US. Before any such live access, the clinic receives the subprocessor entry and the relevant safeguards must be completed, including the provider DPA, UK Addendum and transfer risk assessment. No vendor is authorised to process live data merely because it is named on this page.

Every live engagement has a written subprocessor register. A new or replacement subprocessor is notified in advance where reasonably practicable, with a 15-Business-Day objection window on reasonable data-protection grounds. Octave imposes equivalent Article 28 obligations and remains responsible for its subprocessors as required by law.

Rights, incidents and deletion

The clinic remains the first contact for its patients' data-protection requests. Octave promptly forwards requests it receives and provides appropriate assistance with access, correction, deletion, restriction, portability, DPIAs and regulator enquiries.

Octave notifies the clinic without undue delay after becoming aware of a personal-data breach and in sufficient time for the clinic to meet its own legal obligations. We preserve evidence, contain the affected processing and provide material information in phases rather than waiting for a final investigation report.

At the end of the services, the clinic may choose return or secure deletion. Deletion covers active data, logs, exports and temporary files, with encrypted backup copies expiring through the ordinary backup cycle unless UK law requires retention.


Questions about data protection can be sent to privacy@octave.ventures. The contractual terms are in our Data Processing Agreement.

Octave Systems Limited, company number 17354693, registered in England and Wales. This page describes the standard posture. A signed agreement, implementation record and subprocessor register control the details of a particular installation.