Privacy Policy

1. Data controller

WTTT Systems operates the WTTT Health product. For any privacy question, or to exercise rights over your data, contact tomas@wttt.me.

2. Data processed

The product is designed to operate on scheduling references rather than the clinical content of patient records. Processed data corresponds to administrative information necessary to coordinate an appointment.

3. Purpose

Data is used solely to triage, confirm and record requests for care. It is not used for profiling, advertising, or disclosure to third parties outside service delivery.

4. Legal basis and controller responsibility

The contracting clinic acts as controller of its patients' data. ${site.company} acts as processor, handling data solely according to that clinic's documented instructions.

5. Data and language models

The architecture is designed so that clinical data stays decoupled from the prompt sent to language models. The agent operates on identifiers and references; access to the data remains inside the clinic's systems.

6. Retention

Audit records and execution traces are kept for the period agreed with the contracting clinic, then deleted or anonymised.

7. Security

Role-based access controls, strict input and output validation, and traceability of system actions are applied. The controls described in the architecture section of this site reflect the current design.

8. Data subject rights

Rights of access, rectification, erasure and portability are exercised with the responsible clinic, which holds its patients' data. ${site.company} assists with legitimate requests forwarded by that clinic.

9. Changes

This policy may change as the product evolves. The version in force is the one published at this address.