Languages, Current Language: en-GB
English (UK)
Welcome to the privacy policy of MedAscend. This Privacy Policy describes how Medical Ascend Limited (“MedAscend,” “we,” “us,” or “our”) collects, uses, stores, and protects personal data processed through the MedAscend platform.
MedAscend complies with the UK GDPR, the Data Protection Act 2018, and applicable higher-education data governance standards.
Latest Update: 17 January 2026
MedAscend processes personal and performance data on behalf of educational institutions for the purpose of delivering clinical communication training.
Institutions act as Data Controllers. MedAscend acts as a Data Processor.
We do not sell, trade, or misuse personal data.
We do not store raw passwords.
We do not use personal or performance data for AI model training.
We do not share identifiable data with third parties unless legally required or authorised by the institution.
All data is stored exclusively within UK and EU regions.
When you access the platform, we automatically collect certain technical and usage data, including:
We do not use tracking cookies, advertising cookies, or third-party marketing cookies.
When you create or access an account via your institution, we collect:
We do not collect:
Data Controller:
Your university or educational institution
Data Processor:
Medical Ascend Limited
All data is processed under strict access controls and encryption.
Data is processed using:
Student identifiers are pseudonymised before being sent to Vertex AI.
All personal and performance data is stored exclusively within UK and EU regions:
No identifiable data is transferred outside the UK or EU.
Retention periods are determined by the institution.
By default:
We process data strictly for:
We do not use personal data for advertising or unrelated commercial purposes.
We process data under the following legal bases:
Where pseudonymised data is used for research purposes, processing is based on the Data Controller’s lawful basis under Article 6(1)(e) or 6(1)(f), as applicable, and carried out by MedAscend under Article 28 instructions.
As a Data Processor, MedAscend shares:
Only with the relevant institution.
We use vetted sub-processors, including:
All sub-processors are UK GDPR compliant and reviewed regularly.
Data may be disclosed if required by law or regulatory authority.
MedAscend may, where expressly authorised by the relevant Data Controller, use pseudonymised performance data for the purposes of:
Such data:
MedAscend shall remain a Data Processor for all such processing.
MedAscend may create temporary demo accounts for evaluation purposes.
Demo accounts:
Demo data is not used for AI training, marketing, or reporting unless fully anonymised.
We do not transfer identifiable data outside the UK or EU.
If required, appropriate safeguards such as SCCs, UK Addendum, and encryption will be applied.
We implement industry-standard security controls, including:
You have the right to:
Requests are handled via your institution.
To exercise your rights, contact your institution or email:
We use only essential and security-related cookies.
We do not use advertising or behavioural tracking cookies.
Blocking essential cookies may limit platform functionality.
We may update this policy periodically. Significant changes will be communicated via email or platform notifications.
Medical Ascend Limited
7E Abbotsford Street
Dundee
DD2 1DE
📧 Email: hello@medascend.ai
You may lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your rights have been violated.