AgilusOrganic software.
The Agilus platform · Layer 05

Our approach to data.

Architecture matched to the sensitivity of the data.

Most software companies answer the data question with a map. They tell you which country the servers sit in and expect that to settle it.

It does not settle it. Where a server sits is a geography question. Who can be compelled to hand over what it holds is a jurisdiction question, and those are not the same thing.

This page sets out what we actually do, where the limits are, and what we are not willing to claim.

First, a correction worth making

You will hear a great deal about owning your data. It is a comforting phrase and it does not describe a legal right.

Personal data is not property. In England and Wales, the Court of Appeal held in Your Response Ltd v Datateam Business Media Ltd [2014] EWCA Civ 281 that an electronic database is not tangible property capable of being possessed, so no common law possessory lien could arise over it. Scots law reaches the same practical destination by a different route.

Two recent statutes are sometimes cited against this, and they do not disturb it. The Property (Digital Assets etc) Act 2025, in force in England, Wales and Northern Ireland since 2 December 2025, removes an obstacle rather than creating a right: it confirms that a thing is not prevented from being the object of personal property rights merely because it is neither a thing in possession nor a thing in action. The Digital Assets (Scotland) Act 2026, in force since 1 July 2026, requires that a thing arising from an electronic system be rivalrous and exist independently of the legal system before it can be an object of property.

Rivalrousness is the hinge, and personal information does not turn on it. Copying a record does not deprive anyone of theirs. Both Acts are aimed at crypto-tokens and similar assets, and neither converts a patient’s information into something anyone owns.

Distinguish the information from the artefact, because rights do attach to artefacts. The file is a thing. Copyright subsists in the clinical note as a literary work. Database right can subsist in a collection. Those rights belong to the practice, and they are worth having. None of them amounts to owning the personal data recorded inside them, which is the claim being made when a supplier tells you the data is yours.

So ownership is the wrong question. The right questions are these. Who decides what happens to the information. Who holds the keys. Who can be made to produce it, by whom, and would you ever find out.

Those are the questions we design around.

What data residency does, and what it does not do

Holding data in a United Kingdom or European region is worth doing. It reduces latency, it simplifies your record of processing activities, and it removes a set of international transfer questions you would otherwise have to answer.

What it does not do is make you compliant, because compliance is a property of how you process rather than of where the server sits. Nor does it place the data beyond the reach of a foreign legal order.

Under the United States CLOUD Act, which amended the Stored Communications Act at 18 US Code section 2713, a provider subject to American jurisdiction must produce data within its possession, custody or control regardless of where that data is physically stored. A United Kingdom region operated by a provider subject to that jurisdiction remains within its reach. Corporate parentage is a strong signal of that exposure rather than the legal test itself, and the test is possession, custody or control.

This is not a theoretical concern raised by campaigners. On 10 June 2025, Microsoft’s director of public and legal affairs in France was asked, under oath before a French Senate commission of inquiry, whether he could guarantee that French public data would never be passed to American authorities without French agreement. He answered that he could not give that guarantee. His technical colleague told the same committee that European customer data no longer leaves the European Union at rest, in transit or in processing. Both statements are true at once, and together they make the point precisely: residency and contractual undertakings are real measures, and they do not determine what a provider can be compelled to produce. What determines that is whether the provider holds the means to produce readable data at all. Hold that thought, because it is the foundation of everything below.

Nor is this only an American question. In January 2025 the United Kingdom Home Office served Apple with a technical capability notice under section 253 of the Investigatory Powers Act 2016. Apple withdrew Advanced Data Protection for new United Kingdom users the following month rather than comply, and the resulting litigation is still before the Investigatory Powers Tribunal. Notices of that kind carry a duty of secrecy, which is the part that should concern you: the affected customers were never told.

The conflict this creates is recognised in law. Article 48 of the UK GDPR provides that a judgment or decision of a third country authority requiring disclosure is only recognisable where it rests on an international agreement such as a mutual legal assistance treaty. Read precisely, that does not mean a foreign authority can never lawfully obtain the data. It means the foreign order is not itself the thing that authorises the transfer, so the provider must find a lawful basis and a valid transfer route of its own, or refuse. Frequently it must make that choice under a legal duty not to tell you it was asked.

So we tier it

Not every business runs the same risk, and pretending otherwise would be its own kind of dishonesty. Article 32 of the UK GDPR asks for measures appropriate to the risk. Appropriate is the operative word.

Standard workloads

A table booking, a retail order, a job sheet, a class registration, a maintenance record. This is ordinary personal data. It carries no duty of confidence, it is not special category data, and it is a far less likely target for compelled access than a clinical record. That is a difference of degree rather than an absolute, and we treat it as one.

For this work we use managed cloud infrastructure, with every service pinned to a United Kingdom or European region where the provider offers that choice. Several do not. Authentication, push delivery and crash diagnostics run on global infrastructure, and we name them individually below rather than rounding the whole platform up to a region it does not occupy. Encryption in transit and at rest, automatic backup, continuous monitoring, role-based access and audit trails. This is the right answer for this class of data, and running it on hardware in your back office would make your business less resilient rather than more secure.

We name our sub-processors in full, below, rather than describing them as regions. You are entitled to know the whole chain, not the first link.

Clinical and confidential workloads

A consultation. A patient record. A treatment note. This is special category data under article 9 of the UK GDPR, and it also sits inside a common law duty of confidence that operates entirely separately from data protection law. A supplier can hold a lawful basis, a signed processor agreement and a valid transfer mechanism, and still be exposed on confidence, because the duty arises from the circumstances in which the patient gave the information rather than from any statute.

The cleanest answer to a duty of confidence is not to make the disclosure at all.

So for this work, processing happens on your hardware, in your building. Transcription and summarisation run locally. The record store is encrypted at application level rather than relying on disk encryption alone, so administrative access to the machine does not produce readable clinical data. Keys are bound to the machine using its hardware security module and released only to an authenticated clinician, so neither the machine nor the person is sufficient alone.

Backup is encrypted before it leaves the building and stored in immutable form, which means a compromised machine cannot destroy its own backups. The recovery key is split into shares held by parties you nominate, typically the practice, your accountant, your solicitor and ourselves, with any two required to reconstruct it. No single holder can decrypt, and no single holder can lock you out. The threshold is a policy choice rather than a technical limit, so you can raise it. What it does not do is defend against two custodians colluding, or two being compromised together, and you choose the custodians precisely so that this is difficult.

The consequence is the part that matters. An order served on the backup host produces ciphertext and nothing else, because the host has never held the means to read it. To obtain readable records, someone must reach two independent professionals inside this jurisdiction, each of whom owes you a duty and each of whom would know they had been asked. A silent disclosure by a foreign supplier becomes a domestic legal process you can see and contest.

We do not train on your data

Your records are not used to train, fine-tune or improve any model, ours or anyone else’s.

This is not only a promise, it is a legal boundary. Under article 28(10) of the UK GDPR, a processor that infringes the Regulation by determining the purposes and means of processing is considered a controller in respect of that processing, and carries controller liability for it. A supplier that quietly repurposes clinical records for model improvement has changed its legal status without telling anyone, and it cannot carry across the article 9 condition it relied on for clinical care, because improving a product is not the provision of health care. Other conditions exist, including scientific research under article 9(2)(j) and explicit consent under article 9(2)(a), and both carry requirements a standard processor agreement does not meet. The point is that the supplier needs a condition of its own and must be able to name it.

Where our software needs training material, we build it synthetically. That is slower and more expensive than harvesting real records, and it is the only route that leaves this promise intact.

The question to ask any supplier, including us. On what lawful basis was your training data obtained, and who is the controller if that basis is challenged? A supplier with a good answer will produce it immediately. A supplier without one will talk about de-identification. That is not an answer to the question asked, because stripping identifiers is itself processing of the identifiable source, and it requires its own basis before it can begin. Genuine anonymisation does take information outside UK GDPR. Removing names from a clinical narrative rarely achieves it.

Our sub-processors

These are the third parties that process personal data on behalf of our customers. We list corporate jurisdiction alongside data region, because region alone does not determine who can be compelled.

Sub-processorPurposeData regionCorporate jurisdiction
Cloudflare, Inc. DNS, CDN, DDoS protection, and termination of TLS at the edge nearest your visitor, which means Cloudflare handles that traffic in readable form rather than relaying it sealed Global edge. Cloudflare’s Data Processing Addendum states that Cloudflare and its sub-processors may process personal data outside the United Kingdom and European Economic Area, with standard contractual clauses applying to restricted transfers United States
Google Cloud EMEA Limited (Firebase) Database, file storage, serverless functions europe-west2, London Ireland. Ultimate parent Alphabet Inc, United States
Google Cloud EMEA Limited (Firebase Authentication) Account creation and sign-in United States only. Google documents that Firebase Authentication runs solely from United States data centres Ireland. Ultimate parent Alphabet Inc, United States
Google Cloud EMEA Limited (Firebase Cloud Messaging, Crashlytics, Performance Monitoring) Android push delivery, crash and performance diagnostics Global Google infrastructure. No data location selection is offered for these services Ireland. Ultimate parent Alphabet Inc, United States
Amazon Web Services EMEA SARL (Amazon Bedrock) Large language model inference eu-west-2, London, on a single-region model identifier Luxembourg. Ultimate parent Amazon.com Inc, United States
Apple Distribution International Ltd Push notification delivery to iOS devices Ireland Ireland. Ultimate parent Apple Inc, United States

Where a Google service offers a data location selection we take a United Kingdom region. Where it does not, Google’s terms permit processing anywhere it maintains facilities, and we list those services separately rather than let one row imply a residency the service does not have.

Each provider above publishes its own sub-processor list, so you can follow the chain yourself: Cloudflare · Firebase · Google Cloud · AWS · Apple

Card payment providers. Where a customer takes card payments, processing runs through Dojo, a trading name of Paymentsense Limited, registered in England under company number 06730690 and authorised by the Financial Conduct Authority under FRN 738728, and through Worldpay (UK) Limited, registered in England under company number 07316500.

These act as independent controllers rather than as our processors, because they carry their own obligations under card scheme rules, the Payment Services Regulations 2017 and anti-money-laundering law, which we cannot instruct them out of.

Worldpay is now part of Global Payments Inc, a Georgia corporation, which completed its acquisition of Worldpay on 9 January 2026. Paymentsense Limited is the only party in this list without a United States corporate parent. Our booking software also carries a Global Payments integration.

Who is not on this list. Anthropic. We reach Claude through Amazon Bedrock, and AWS states that inputs and outputs are not shared with model providers and are not used to train any model, with each model provider isolated in a deployment account it cannot access. The model provider receives nothing.

Clinical and confidential workloads have no sub-processor for clinical content. No third party receives consultations, records or treatment notes, in readable form or otherwise, except the backup host, which receives ciphertext it cannot decrypt. Be clear about what that does not cover: licence validation, software updates, crash diagnostics and push notification delivery involve technical data such as device identifiers and network addresses, which are personal data even though they contain no clinical information. We would rather name that distinction than let the phrase “nothing leaves the building” do more work than it can bear.

What we do not claim

A supplier can honestly say its software is designed to support compliance with UK GDPR. What no supplier can honestly say is that buying it makes your organisation compliant, because compliance is a property of how you process data, not a badge attached to a piece of software. What a supplier can do is make compliance achievable and describe its own part honestly. That is what this page is for.

We will also say plainly where our own arrangements are imperfect, and where local processing costs you something.

Our standard tier runs on infrastructure operated by companies with United States corporate parents, in United Kingdom and European regions where those are offered and on global infrastructure where they are not. That is the same arrangement we argue is insufficient for clinical data. We think it is proportionate for a restaurant booking and not proportionate for a consultation, and we would rather set that out than let you discover it.

Running on your own hardware moves responsibility onto you. Physical security of the machine becomes yours. Update discipline becomes a scheduled task rather than something that happens invisibly. Backup verification matters, because an untested backup is not a backup, and article 32(1)(d) requires a process for regularly testing the effectiveness of your measures. There is no large supplier to pursue if something goes wrong.

Everything above about our clinical architecture is a claim about implementation, and you should not take it from a web page. We will provide a data flow diagram, the key management design including hardware security module ownership and recovery, backup and restore test evidence, and our article 28 agreement, before you sign anything. If a supplier will not do that, the architecture on their website is decoration.

We are not selling the absence of risk. We are selling risk you can see, hold and control, kept inside the confidential relationship, rather than risk sitting in a jurisdiction you cannot reach and cannot audit.

For most businesses, on most data, managed cloud is the right and proportionate answer. For a consultation between a clinician and a patient, we do not think it is. Anyone offering you a single architecture for every class of data is selling you something.

Who is responsible for what

You are the data controller. You determine why and how patient or customer information is processed, you carry the obligations under article 24, and you answer to the Information Commissioner.

Where we process on your behalf, we are your processor, governed by a written agreement under article 28 that limits us to your documented instructions.

Where processing happens entirely on your premises, we are not processing your data at all. We supply and maintain software. The records never come to us.

We will support your data protection impact assessment, which is mandatory under article 35(3)(b) for large-scale processing of special category data, and we will give you the technical detail it requires rather than a marketing summary.

Talk to us about it

If you want to go through this properly, including the parts where we are weaker than the alternative, that is the conversation we would rather have.

Start a conversation

Last reviewed: 6 September 2026. This page describes our architecture. It is not legal advice.