Legal
Privacy Policy
Last updated: 26 May 2026
Neutropy Ltd. ("Neutropy", "we", "us") provides AI-driven patient scheduling software to healthcare providers. This policy explains what personal data we process when you use our website at neutropy.ai or our scheduler product, and how we keep it safe.
We process personal data in line with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") and the Irish Data Protection Act 2018. Where we act as a processor for a healthcare provider, the provider remains the data controller and our processing is governed by the Data Processing Agreement signed with that provider.
1. Who we are
Neutropy Ltd., a company registered in Ireland. Address: Dublin, Ireland. Contact: luke@neutropy.ai.
2. Data we collect
From our website (neutropy.ai)
- Information you submit to us through forms or email (e.g. your name, work email, clinic name).
- Basic analytics: pages visited, device type, approximate location derived from IP, referrer. We do not use third-party advertising cookies.
From the Neutropy scheduler product
- Referral content received via GP referral letter, email, or PDF, including patient name, date of birth, contact details, referring GP, specialty, urgency, and clinical reason.
- Call transcripts, recordings (where the operating clinic has opted in), and event logs generated when our AI employees place outbound calls and schedule appointments.
- Records of scheduled appointments written back to the clinic's PMS or EHR.
3. How we use it
- To deliver the scheduling service to the operating clinic (legal basis: contract with the clinic and, for special-category clinical data, GDPR Art. 9(2)(h), provision of health care).
- To improve and secure the service (legal basis: legitimate interest, balanced against the rights of the data subject).
- To respond to enquiries and contractual communications (legal basis: legitimate interest).
- To meet our legal and regulatory obligations.
4. PII never reaches the language model
Before any clinical text is sent to a large language model for extraction, personal identifiers (name, PPSN, IHI, phone number, address, email) are stripped from the payload and replaced with tokenised handles. Re-identification happens inside Neutropy's infrastructure, never inside the model provider's environment.
5. Where we store data
Patient data is processed and stored on EU-resident infrastructure. We do not transfer patient data outside the EU/EEA. Operational telemetry that contains no patient identifiers may be processed by EU-resident sub-processors used for monitoring, logging, and email delivery.
6. How long we keep it
- Call transcripts and audit logs: as agreed with the operating clinic in our DPA, typically for the statutory retention period for clinical records.
- Recordings: by default not retained. Where the clinic has opted in, retained per the DPA.
- Website enquiry data: 24 months from your last contact, unless a contractual relationship is in place.
7. Your rights
Under GDPR you have rights of access, rectification, erasure, restriction, portability, and objection. For data processed by Neutropy on behalf of a healthcare provider, please direct requests to that provider in the first instance. We will assist them in responding. For data we hold as a controller (e.g. website enquiries), contact luke@neutropy.ai.
8. Complaints
If you believe we've handled your data improperly, please contact us first so we can put it right. You also have the right to lodge a complaint with the Irish Data Protection Commission.
9. Changes to this policy
We'll update this page when the policy changes and revise the "Last updated" date at the top. Material changes will be communicated to active customers in writing.