Privacy Policy
Last updated: 21 July 2026
1. Introduction
Welcome to the Brigid product family. We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we, DJG Media Limited (trading as MedPro AI), CRO No. 762838, collect, use, share, and protect your personal data when you visit our website (medproai.com), use Ask Brigid, Meet Brigid, or Brigid Dictate, or interact with Brigid, the AI assistant embedded in those services. These are product names, not separate legal entities.
This policy is designed to help you understand your privacy rights and how you can exercise them.
2. Who We Are and Our Roles
We are DJG Media Limited (trading as MedPro AI), CRO No. 762838, a company registered in Ireland with our registered office at Coliemore House, Coliemore Road, Dalkey, Dublin, Ireland. For the purposes of the General Data Protection Regulation (GDPR), our role depends on the context of our interaction with you:
- When you visit our website, contact us directly, or create an account for Ask Brigid: DJG Media Limited is the Data Controller. We determine the purposes and means of processing your personal data.
- When a healthcare provider (our "Customer") uses Ask Brigid to manage patient information: The Customer is the Data Controller of the patient data, and DJG Media Limited is the Data Processor. We process this data on behalf of and under the instruction of the Customer, as governed by the Data Processing Agreement (DPA) we have with them.
This distinction is important. If you are a patient of one of our Customers, you should direct any privacy-related questions to your healthcare provider in the first instance.
3. What Data We Collect
We collect different types of data depending on your interaction with us:
- When you visit our website:We collect technical data such as your IP address, browser type, and operating system, as well as information about your browsing activity (our "Website Data").
- When you contact us or sign up:We collect your name, email address, and any other information you provide in your communications with us (our "Communication Data").
- When you use our platform:We collect account information such as your name, email address, role, and payment information (our "Account Data"). We also collect data on how you use the platform, such as features accessed and actions taken (our "Usage Data"), and we maintain detailed logs for security and auditing purposes (our "Log Data").
- When we process data for our Customers:We process patient demographic and clinical data on behalf of our Customers (our "Patient Data"). This is special category data and is handled with the highest level of security and confidentiality, as detailed in our DPA.
4. Lawful Bases for Processing
We only collect and process your personal data when we have a legal basis to do so. The purposes for which we use your data include:
- Contract fulfillment: To provide and manage the service.
- Legitimate interest: To secure and monitor our platform, communicate with you, and improve our services.
- Consent: For marketing and cookies (where required).
- Legal obligation (Art. 6(1)(c)): Where retention or processing is required by law — for example statutory audit trails under the Health Act 2014 and financial-record retention under Irish Revenue rules.
5. Health Data Processing (Special Category)
Your medical record is "special category personal data" under GDPR Article 9 and Irish Data Protection Act 2018 §36 + §49. We process it under the following lawful bases:
- Patient explicit consent — GDPR Art 9(2)(a) — captured via the first-sign-in consent gate in the Meet Brigid patient app.
- Healthcare delivery — GDPR Art 9(2)(h) + Irish DPA 2018 §53 — permits processing necessary for medical diagnosis, the provision of health or social care or treatment, or management of health systems.
- Public interest in the area of public health — GDPR Art 9(2)(i) — applies to specific public-health functions (e.g. notifiable disease reporting).
Every read or write to your record is recorded in an append-only audit trail (Irish Health Act 2014 §73 patient confidentiality + audit-trail requirements, plus EU AI Act Art 12 logging for any AI inference on the record). You can request a copy of the log at any time under your GDPR Art 15 access right.
What we do NOT do with your health data: we never sell it, never use it for advertising, never train AI models on it. Sub-processors are bound by no-training and zero-retention contractual terms.
6. AI Features ("Brigid") and Patient-Controlled Permissions
Brigid is the AI assistant embedded in Ask Brigid and the Meet Brigid patient app. Brigid actions are opt-in by patient and governed by per-patient toggles the patient owns and can change at any time under Me → What Brigid can do:
- Draft letters & referrals — Brigid pre-writes outbound letters and referrals for a clinician to review and sign. Default: enabled. Legal basis: performance of the care contract (Art. 6(1)(b) GDPR) + Art. 9(2)(h) for special-category health data.
- Summarise visits — Plain-English visit recaps after each consultation.Default: enabled. Same legal bases as above.
- Send reminders — SMS/email/push reminders for appointments, repeats, screenings. Default: enabled. Legal basis: legitimate interest in continuity of care (Art. 6(1)(f) GDPR); patient may opt out at any time.
- Voice transcripts— Clinician-side audio capture to power Brigid's draft notes. Default: disabled. Requires explicit, informed patient consent (Art. 9(2)(a) GDPR). If off, the Ask Brigid clinician app refuses to start a recording.
- Anonymised research — Sharing de-identified data with Irish primary-care research initiatives. Default: disabled. Requires explicit consent (Art. 9(2)(j) GDPR for research) and is governed by a separate data use agreement.
These toggles persist in our database (medyou_brigid_permissions) and are enforced at the application layer: the clinician's app reads the patient's row before each action and refuses anything the patient has switched off. Anything turned off is impossible — there is no manual override.
Under the EU AI Act (Regulation 2024/1689), Brigid-assisted clinical decision support is classified as a high-risk AI system (Annex III, point 5 / safety component under Annex I when integrated with a medical device). We comply with the corresponding requirements, including transparency, human oversight, accuracy monitoring, logging, and our published AI risk-management documentation. AI outputs are decision support, not autonomous diagnosis: a registered clinician reviews and signs every clinical artefact before it is released.
8. Marketing & Outreach Communications
Non-clinical SMS, email, or in-app messages from Meet Brigid and your clinic — health tips, product announcements, surveys — are strictly opt-in under GDPR Art 6(1)(a) and the ePrivacy Directive 2002/58/EC + Irish PECR (S.I. 336/2011).
- We never sell your contact details or share them outside Meet Brigid and your clinic.
- Clinical reminders (appointments, prescription repeats, lab-result alerts) are not covered by this opt-in — they follow your separate Alerts settings under Me → Notifications and rely on the legitimate-interest-in-continuity-of- care basis (Art 6(1)(f) GDPR).
- One-tap unsubscribe links appear on every marketing message; you can also globally opt out under Me → What Brigid can do → Marketing & outreach.
9. Anonymised Research Use
With your explicit, optional consent (GDPR Art 6(1)(a)) and only where the study has been approved by a Research Ethics Committee under the Irish Health Act 2007, your data may contribute to clinical research in fully de-identified form.
- De-identification follows the ISO/IEC 27559:2022 standard. Names, patient IDs, contact info, addresses, dates, and any other direct or indirect identifiers are stripped before any researcher sees the data.
- Already-anonymised data cannot be linked back to you to remove — that is the point of de-identification. Going forward, opt-out under Me → What Brigid can do → Anonymised research stops any further inclusion.
- Active studies are listed under Me → Research participation when applicable.
10. Your Data Protection Rights
Under GDPR, you have several rights in relation to your personal data:
- Right to Access: Request a copy of the data we hold.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure:The "Right to be Forgotten".
- Right to Data Portability: Transfer data to you or a third party.
- Right to Object: Object to processing in certain cases.
Our Data Protection Officer is David Galvin, reachable at dpo@medproai.com. To exercise any of these rights, please contact our DPO at that address. You may also lodge a complaint with the Data Protection Commission at dataprotection.ie (Irish supervisory authority under GDPR Art 77 + Irish DPA 2018 §79).
11. How Long We Keep Your Data
Retention periods depend on the category of data (GDPR Art. 13(2)(a)):
- Account and billing data — for the duration of your contract, then deleted within 90 days of termination (export window: 30 days). Financial records are kept 7 years under Irish Revenue requirements.
- Patient records processed for clinics — retained on the instructions of the clinic (the controller), which is bound by Irish statutory medical-record retention periods (typically 8 years for adult records, longer for maternity, mental health, and paediatric records). On contract termination the clinic has a 30-day export window and data is permanently deleted within 90 days, except where law requires retention.
- Clinical audit logs — 8 years (Health Act 2014 §73). AI-inference technical logs — the lifetime of the device plus 10 years (EU MDR technical-documentation requirements).
- Voice recordings and transcripts — deleted on request or account deletion; soft-deleted items are permanently purged after a 30-day grace period by an automated nightly retention job.
- Cookie-consent records — 1 year. Newsletter and early-access sign-ups — until you unsubscribe or ask us to delete them.
12. International Transfers
Patient data at rest is stored exclusively in the EU (Supabase, Ireland — AWS eu-west-1), and clinical text inference runs EU-resident by default (GDPR Art. 13(1)(f)). A small number of processing flows involve transfers to the United States, each under a signed Art. 28 DPA plus an Art. 46 safeguard (Standard Contractual Clauses 2021/914 and/or the EU–US Data Privacy Framework adequacy decision):
- Voice transcription(ElevenLabs — the primary engine for dictation, push-to-talk and clinical sessions; Google Cloud STT in the EU is the fallback) and, only with your practice's explicit opt-in consent, a specialised US medical-dictation model.
- "Live with Brigid" real-time voice (Google AI Studio, US) — per-session explicit consent, pending migration to an EU endpoint.
- Telehealth recordings (Daily.co) — stored in the US unless your practice configures EU storage.
- Error monitoring (Sentry, US) — PHI is scrubbed before transmission.
- Messaging delivery (Twilio/Vonage/Resend) — EU + US routing.
We maintain a Transfer Impact Assessment for these flows. The authoritative list of every sub-processor, its location, and its transfer mechanism is our Sub-Processor Register.
13. Brigid Browser Extension (Meeting Notetaker)
We offer an optional Chrome browser extension, the Brigid meeting notetaker for Ask Brigid, that lets a clinician send our AI notetaker into their own Google Meet, Zoom, or Microsoft Teams calls. The extension is installed and used at the clinician’s discretion and is governed by this Policy and our Clinician Terms.
- What it accesses: when you are signed in to Ask Brigid, the extension reads your authenticated session token from your browser so it can act on your behalf, and the URL of the meeting tab you choose to record. With your permission it reads the titles, times, and join links of your upcoming calendar meetings to offer a pre-meeting reminder. It does not read the content of other websites, your browsing history, or any tab you have not explicitly chosen to record.
- What it does:when you click “Record with Brigid”, the extension asks our servers to send the Brigid notetaker into that meeting as a visible participant. The meeting is recorded and transcribed by our processing provider; a summary is then made available to you inside Ask Brigid to review and, if appropriate, file to a patient record. The extension itself does not capture audio or video from your device.
- What it stores: your Ask Brigidsession and refresh token and a short list of upcoming meetings are stored only in the extension’s local storage on your own device, so it can stay signed in and remind you before calls. This data never leaves your device except to authenticate you to Ask Brigid. Signing out of Ask Brigid clears it.
- Consent to record: you are responsible for ensuring all participants are informed that the meeting is being recorded and transcribed, as required by applicable law and professional obligations. Brigid joins as a clearly named, visible participant.
The extension does not sell data, serve advertising, or use your data for any purpose beyond providing this feature. You can remove it at any time from your browser’s extensions page; doing so stops all of the above.
14. The Meet Brigid Patient App
Meet Brigid (formerly MedYou) is our patient app for iPhone and the web. Everything in this policy applies to it; this section adds the practices specific to using Meet Brigid on your own device.
- Who the controller is: when your Meet Brigidaccount is linked to a clinic, that clinic remains the data controller of your medical record and we process it on the clinic’s behalf. When you use Meet Brigid standalone — a personal health record you build yourself (conditions, allergies, medications, vitals, documents, family links) without a connected clinic — DJG Media Limited (trading as MedPro AI), CRO No. 762838 is the data controller of that record.
- Data the app itself sends us:your device’s push-notification token (so alerts you enable can be delivered), crash and diagnostic reports (hosted in the EU), photos and documents you choose to upload, and payment records when you pay a clinic invoice or subscribe to an optional feature. Payments are processed by Stripe — your card number never touches our servers.
- What stays on your device:Face ID / biometric unlock happens entirely on the device via Apple’s frameworks; no biometric data ever leaves your phone. Your session is stored in the device keychain.
- Location:if you use “find nearby clinics”, your location is used only to answer that search and is not stored.
- Your rights, in the app:you can export your data (Me → Download my data) and permanently delete your account (Me → Login & security → Delete account) at any time. Deletion removes your Meet Brigid account, standalone record, uploads, family links, and device registrations. Medical records held by a treating clinic are retained by that clinic for the statutory medical-record retention period — deleting your Meet Brigidaccount does not (and legally cannot) erase the clinic’s own copy of your care record.
- App Store privacy labels: the privacy details published onMeet Brigid’s App Store product page mirror this section. We collect no data for advertising and do not track you across other companies’ apps or websites.
Related legal documents
Terms of Service · Meet Brigid Terms of Service · Clinician Terms · Data Processing Agreement · Medical Device Declaration · Cookie Policy · Acceptable Use Policy · Accessibility Statement · Compliance Overview