Security · Data handling

Where your records go, who can see them, and how long they exist

This is the page for the partner, COLP or data-protection lead who has to sign off before a firm uploads a client's medical records to a service it has not used before. Plain statements, no badges we have not earned, and the things we will put in writing.

Last reviewed 21 September 2026 · Applies to med-legal.co.uk and med-legal.net

The short version

Where records are storedThe live service uses Hetzner servers in Germany (EU). Encrypted recovery copies are also stored on a restricted UK backup computer. AI processing may occur outside the UK and EU.
In transitHTTPS/TLS only. HTTP Strict Transport Security is enforced for a year with subdomains included, so a browser will not fall back to plain HTTP.
How long originals existOriginal uploads become due for deletion 24 hours after upload; active jobs delay cleanup. Extracted text, OCR, cached facts and generated outputs stay with the claim until deletion. Bundles contain copies of record pages. Encrypted recovery copies rotate separately; see retention details.
Training on your dataMed-Legal does not train its own models on uploaded records. The current connection uses the xAI API. Its published enterprise terms describe no training on business inputs and outputs unless the customer agrees otherwise, including some credit programmes. Verification of the active account’s contractual coverage and data-sharing settings is still pending. Please obtain written confirmation from us before uploading records that require these assurances.
Who can see a claimThe account that created it and authorised staff providing administration or support. Other customer accounts cannot access it. The audit records supported claim, generation, review and download events; it is not a record of every possible action.
Card detailsHandled by Stripe. We never see or store a card number.
PaperworkA Data Processing Agreement on request; your executed Agreement Record as a PDF at signup; our Privacy Policy and Terms & Fees are public.
What we are notNot ISO 27001 certified, not Cyber Essentials certified, not HIPAA-certified, and we do not currently offer a US Business Associate Agreement. We would rather you knew.

Roles: who is the controller

For the medical records you upload, your firm is the data controller and Med-Legal is a processor acting on your instructions. Your firm decides why the records are processed and holds the Article 9 condition for health data (in a litigation context, ordinarily the establishment, exercise or defence of legal claims). We process the records only to produce the chronology, fact ledger and bundle you asked for. For your own account and billing data, we are the controller. The full statement of both roles is in section 2 of the Privacy Policy.

What happens to a file, step by step

  • Upload. Files travel over TLS to our server in Germany and are stored against the single claim you created. Nothing is shared between claims or accounts.
  • Processing. Page text is extracted (scanned pages are OCR'd on our own server) and passed, as text, to a specialist AI provider acting as our sub-processor to build the chronology. Every extracted fact carries the document and page it came from, and the quoted text is checked in our own code against that page.
  • Output. The chronology, the fact ledger and, if ordered, the paginated bundle are written to your account. They are yours to download and delete.
  • Deletion of originals. Original uploads become due for deletion after 24 hours; active jobs delay cleanup. Extracted text, OCR, cached facts and generated outputs remain with the claim. If you later need a bundle, which requires the originals, you re-upload the records.
  • Review. Every output is an AI-assisted draft. It says so on the document, and it passes a review gate: a qualified professional at your firm approves it against the cited pages before it is used.

Sub-processors

Hetzner Online GmbHHosting and storage. Germany (EU).
xAI APIProcesses record text to generate summaries and indexes. Processing can occur outside the UK and EU. Active-account contractual coverage, data-sharing settings and the applicable transfer arrangement are awaiting verification; see the current disclosure.
StripeCard payments. Handles card data directly. EU / USA.
Google / MicrosoftOptional "sign in with" authentication, only if you choose it.
Email delivery providerService emails: welcome, document-ready, receipts.

We will tell account holders before adding a sub-processor that will touch uploaded records.

Technical controls in place today

  • TLS on every connection, with HSTS (max-age=31536000; includeSubDomains).
  • A restrictive Content Security Policy (default-src 'self', no third-party scripts, frame-ancestors 'none'), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, a strict referrer policy, and camera, microphone, geolocation, payment and USB permissions disabled for the page.
  • Passwords stored only as salted hashes. Sign-in with Google or Microsoft available if your firm prefers SSO.
  • Administrative access to the server is by SSH key only; password login is disabled, a host firewall exposes only web and administrative SSH traffic, and failed-login lockout runs on the SSH service.
  • Per-claim scoping of every record and output, with an audit log of actions in the app that you can see.
  • Original-file cleanup after 24 hours, with active jobs protected. Generated bundles can contain record pages, and extracted text remains until claim deletion.
  • Only the cookies needed to sign you in and to keep payments secure. No advertising or third-party tracking cookies.

If something goes wrong

We will notify affected account holders and the ICO of a reportable personal-data breach as HIPAA-aware requires, and assist your firm with any claimant rights request that concerns records processed through the service. Email info@med-legal.net; a real person reads it.

Outside the UK

The hosting and deletion controls described here apply to customers in every country. The outstanding AI-account verification also applies across countries. Each country edition's Country Schedule in the Terms names the local privacy regime your firm must satisfy on its side. For the United States that means applicable federal and state law including HIPAA where the firm is a covered entity or business associate; we describe our posture as HIPAA-aware, not HIPAA-certified, and we do not currently offer a Business Associate Agreement.

Want it in writing? Reply to your welcome email or write to info@med-legal.net and ask for the Data Processing Agreement. Want to test before anyone signs anything? Your first chronology and indexed bundle are free, once per account with no card, and a closed or redacted file works as well as a live one.

Start free →

This page summarises the controls actually in place on the date shown; where it and the Privacy Policy or Terms & Fees differ, those documents govern. General information, not legal advice.