On your data

How we handle your data

Before work starts, we agree the scope in writing with your firm: the systems we work in and the kinds of data involved. These are the rules we follow.

AccessOnly what the build needs. The statement of work lists the systems and kinds of data involved, and we ask for named accounts with the least access the build needs.
Data-flow recordsEvery build has a written record before it goes live: each system it touches, the kinds of data, why, the vendor, how long the data is kept and who can reach it. You can read and print it in the Corwen dashboard. A build cannot be marked live without one.
Language modelsWhere a build sends your data to a language model, it goes through commercial API access, not a consumer chatbot subscription, and the data-flow record names the provider and how long it keeps the data.
Health informationNo patient health information in any Corwen system until business associate agreements (BAAs) are in place with your practice and with every vendor involved.
Tax returnsWe use tax return information only to do the work your firm asked for. Never for our own purposes, for marketing or to train a model.
Legal workWe work at your direction and under your supervision, keep what you share confidential and treat privileged material as privileged.

For this site and the Corwen dashboard, see the privacy policy.