Data Policies

Last Updated: 18 June 2026

This document summarises the data protection, data-handling and security principles that apply to Oati Lens and to the www.theoati.com website.

It is intended to explain our public data posture. It does not replace any Data Processing Agreement, commercial agreement, pilot agreement, research licence, or practice-specific documentation that may apply before Oati processes data for a customer or partner.

1. Who We Are

The Oati Worldwide Limited (“Oati”, “we”, “us”, or “our”) is a United Kingdom technology company focused on operational and revenue integrity solutions for healthcare organisations.

Company Number: 17221262
Registered in: England and Wales
Website: www.theoati.com
Contact Email: [email protected]

2. Core Data Principle

Oati Lens is designed around a local-first data model.

For live GP-practice deployments, the intended operating model is that identifiable patient records remain inside the practice environment. The Lens engine is designed to run inside the practice’s own secure local network, with clinical analysis, rules evaluation and action-list generation taking place locally wherever practicable.

The public website does not collect, store or process identifiable patient information.

3. Website Data

The Oati website is a marketing and informational website. It may collect limited information when a visitor contacts us, joins a waiting list, submits an enquiry, or uses website features.

This may include:

  • Name
  • Organisation or practice name
  • Job role or title
  • Email address
  • Telephone number
  • Information submitted through contact or waiting-list forms
  • IP address
  • Browser and device information
  • Website security, preference and basic usage information

Website data is handled in accordance with our Privacy Policy and Cookie Policy.

Visitors must not submit patient-identifiable information, clinical records or special category health data through the public website.

4. Product Data Roles

For live customer deployments, the GP practice or healthcare organisation is expected to remain the Data Controller for its patient records and local clinical data.

Where Oati processes personal data on behalf of a practice or healthcare organisation, Oati would normally act as a Data Processor and process that data only under written instructions and applicable contractual terms.

Before any live processing of customer-controlled personal data, Oati expects a suitable Data Processing Agreement or equivalent written agreement to be in place. That agreement should define the processing purpose, processing instructions, security measures, retention expectations, support responsibilities, and each party’s data protection obligations.

5. Healthcare and Patient Data

Oati Lens is designed to reduce unnecessary exposure of healthcare data.

The intended product model is:

  • Patient-identifiable information remains within the practice environment.
  • Local processing is preferred over cloud processing for clinical records.
  • Direct patient identifiers are not required by Oati’s central systems for ordinary product operation.
  • Raw free-text clinical notes are not intended to be sent to Oati cloud systems.
  • Patient data must not be used for advertising, insurance targeting, external resale, or unrelated secondary monetisation.

Any use of Oati technology in a setting that requires additional data sharing, secure upload, research access, pilot access, or remote support must be governed by the applicable agreement and access controls for that setting.

6. Local-First Product Architecture

The current Oati Lens design is based on a local application package running inside the practice environment.

The local Lens installation is intended to:

  • Analyse relevant practice data locally.
  • Convert local outputs into clear action lists for authorised practice staff.
  • Keep patient-identifiable lookup information within the local environment.
  • Use local audit and ledger records to support validation, reconciliation and accountability.
  • Send only limited non-clinical operational information to Oati where needed for licensing, health checks, uptime diagnostics, rule-update management, or aggregated non-identifying financial summaries.

Where any cloud communication is used, it should be limited to what is necessary for the relevant service function and should avoid transmitting patient-identifiable clinical records.

7. Data Minimisation

Oati applies a data-minimisation approach. We aim to collect and process only the information needed for the relevant purpose.

For the website, this means limiting collected data to enquiry handling, communication, website functionality, security, preferences and basic usage information.

For Oati Lens, this means designing processing so that unnecessary identifiers, raw clinical text, and unrelated data are not exported from the practice environment.

8. Access Controls

Access to Oati systems, customer support information, research information and internal company systems should be limited to authorised users with a legitimate need.

Our intended access-control principles include:

  • Named user access where practicable.
  • Least-privilege permissions.
  • Multi-factor authentication for administrative and infrastructure access.
  • No shared passwords.
  • Secure credential storage.
  • Removal or reduction of access when personnel no longer need it.

Customer-controlled practice systems remain under the responsibility of the relevant practice or healthcare organisation unless a separate written agreement says otherwise.

9. Information Security

Oati’s data-handling approach is aligned with the security principles in UK GDPR Article 32 and with the practical expectations of healthcare data governance.

Appropriate technical and organisational measures may include, depending on the context:

  • Encryption in transit.
  • Encrypted storage where technically available and appropriate.
  • Secure local deployment patterns.
  • Restricted access to sensitive material.
  • Separation between customer, research, development, marketing and operational data.
  • Monitoring for security issues and operational anomalies.
  • Security-conscious development and review practices.

No website, email, local installation or internet-connected system can be guaranteed to be completely secure, but Oati designs its systems to reduce exposure and keep sensitive healthcare data as close as possible to its source environment.

10. Research and Restricted Data

Where Oati is granted access to restricted research data, such as data made available under a CPRD-approved study or other controlled access model, that data must be handled separately from ordinary product, marketing, customer, insurance and general company systems.

Restricted research data should only be accessed by named authorised users, for the approved purpose, under the applicable licence, access model, research governance approvals and written instructions.

Restricted research data must not be copied into Oati production systems, customer environments, marketing systems, insurance systems, general company storage, personal storage, unsecured email, or shared development repositories unless expressly permitted by the relevant data provider or licence.

11. Retention and Deletion

Oati retains personal information only for as long as reasonably necessary for the relevant business, legal, operational, contractual or security purpose.

For website data, retention may include enquiry handling, waiting-list management, security records, business administration and legal compliance.

For customer deployments, retention and deletion responsibilities should be defined in the applicable agreement. Because the product is designed to operate locally within a practice environment, some data held on practice infrastructure may remain under the control and responsibility of the practice.

For restricted research data, retention, deletion, output checking and access revocation will follow the relevant licence, approved access environment and data-provider requirements.

12. Backups, Local Administration and Support

For local-first deployments, the practice or healthcare organisation is expected to remain responsible for its own local infrastructure, including local administrative access, local backups, local restore processes and local physical security, unless a separate agreement states otherwise.

If Oati needs access to a customer environment for support, installation, troubleshooting, pilot work or other operational reasons, the scope and method of that access should be defined explicitly and kept as narrow as practicable.

13. Incidents and Breaches

Oati expects suspected data breaches, security incidents or unauthorised access events to be investigated promptly.

Where Oati acts as a Data Processor for a customer, Oati would notify the relevant Data Controller in accordance with the applicable agreement and legal requirements.

Where a verified incident triggers regulatory or data-provider notification duties, Oati will work to meet the relevant notification timelines, including the UK GDPR 72-hour notification window where applicable.

14. Third-Party Services

Oati may use trusted third-party providers for website hosting, infrastructure, security, communications, development operations or other operational services.

Third-party providers may process limited information where necessary to provide those services. Oati aims to use providers and configurations that are appropriate for the sensitivity of the data being handled.

Customer or research data must not be moved to third-party services unless the relevant agreement, licence, access model or written instruction permits it.

15. What We Do Not Do

Oati does not sell personal information.

Oati does not use the public website to collect patient-identifiable clinical records.

Oati Lens is not designed to use patient data for behavioural advertising, third-party ad tracking, insurance targeting, external resale, or unrelated secondary monetisation.

16. Relationship With Other Documents

This Data Policies document should be read alongside:

If a signed agreement applies, that agreement will take precedence for the specific service, customer, pilot or research arrangement it covers.

17. Contact

For questions about these Data Policies, please contact:

The Oati Worldwide Limited
Company Number: 17221262
Website: www.theoati.com
Email: [email protected]

Back to the homepage