Patient Watch Ltd operates the Patient Watch service as described in our published policies. Depending on your contractual and clinical model, an NHS trust, independent sector provider, or other organisation may act as data controller for some processing when using the platform for care, audit, or research workflows. That organisation is responsible for its own information governance records and for approvals required in its context (for example NHS Data Security and Protection Toolkit submissions where they apply).
We publish technical and privacy context so you can reference the service consistently: see our Privacy Policy, Data Security & Privacy, and Records of processing (summary). For how your organisation may approach consent and the duty of confidentiality alongside deployment, see Consent and confidentiality for organisations. The diagram below is a simplified illustration only; your DPO or IG team should align it with your DPIA, contracts, and RoPA.
Typical information flow (simplified)
Arrows show direction of responsibility for defining purposes and controls in many deployments, not every legal transfer of data.
Care organisation
Often defines purposes for its deployment, lawful bases for its use of the service, and local approvals (e.g. SIRO oversight of registers).
Patient Watch
Platform and operations described in our published policies; processing as controller or processor as set out in the Privacy Policy and Data Processing Agreement where relevant.
Infrastructure & tools
Subprocessors and suppliers (e.g. hosting, messaging) operate under contract and are summarised on our Subprocessors page. For the core hosting path we retain a signed Supabase Data Processing Addendum and transfer diligence materials; your organisation may need these named in your own register.
This page does not replace legal advice. For contractual terms between your organisation and Patient Watch Ltd, use the agreed Data Processing Agreement where applicable.