Privacy policy
Last updated: August 2026
This policy explains what data CardioBridge processes, why we process it, and the rights you have over it. CardioBridge is a service of TeqDr, operated by Hippocrates Digital Ltd (trading as TeqDr).
1. Introduction
CardioBridge is a service of TeqDr, operated by Hippocrates Digital Ltd (trading as TeqDr). We are committed to protecting the privacy and security of the personal and health data processed through our platform. This Privacy Policy explains how we collect, use, and safeguard information when you use our ECG interpretation service, and it should be read alongside the TeqDr privacy notice at teqdr.com/PrivacyPolicy, which governs TeqDr's wider services and provides further detail on your rights.
2. Who we are (data controller)
The data controller for CardioBridge is Hippocrates Digital Ltd, trading as TeqDr, a company registered in England and Wales under company number 13280534. We are registered with the UK Information Commissioner's Office (ICO) under registration number ZB044070. We have appointed a Data Protection Officer, who is responsible for overseeing how we handle personal and health data and who can be reached at cardiobridge@teqdr.com. The same officer serves as our designated Data Protection Officer for the purposes of Singapore's Personal Data Protection Act. For any question about this policy or about how we handle your data, you can contact us at that address.
3. Data we collect
We process two categories of data: (a) business contact data submitted via our lead form — including your name, email, organisation, role, and message; and (b) patient health data routed through the platform for ECG interpretation — including patient identifiers, ECG recordings, and clinical notes. Patient health data is special category data under the UK and EU GDPR, and sensitive or special-category information under comparable laws elsewhere. We hold patient-identifying data for as long as a case is in progress, together with a limited identity index used to match a patient to their existing record and avoid duplicates. Where an individual buys an ECG interpretation directly rather than through a clinic — including where an AI agent places the order on their behalf through our MCP server — we hold their email address and the payment reference from the moment the order is created, before any clinical data is provided; the ECG and the accompanying patient details are collected only after payment. Retention is described in section 9.
4. How we use your data
Lead form data is used to contact prospective clients and manage business relationships. Patient health data is used solely to route ECGs to cardiologists for interpretation and to return results to the requesting clinic. We do not use patient data for marketing, research, or any purpose beyond the requested service. Where an individual buys an ECG interpretation directly rather than through a clinic, we also create a CardioBridge account for them automatically, using the email address the order was placed with, at the point the ECG is submitted — including where an AI agent submitted it on their behalf, in which case the account is created without the person visiting our website. We do this so the report belongs to an account the patient controls and can return to, rather than existing only as an email; there is no password, and signing in means requesting a link sent to that address. The account holds only that email address and the ECGs submitted under it, it is never used for marketing, and you can ask us to erase it at any time under section 8.
5. Data sharing and sub-processors
Patient data is shared only with the consultant cardiologist assigned to perform the interpretation and the requesting clinic. We do not sell or rent personal data to third parties. We rely on a small number of named sub-processors, each processing data on our behalf under a data processing agreement: Semble (EU/UK) as the clinical system of record; Supabase (UK, London) for authentication, service data, ECG file staging and in-flight patient data; Resend for transactional email, which sends from Ireland but holds account data and delivery logs in the United States; Stripe for payments, which never exposes card details to us; and Base44 (US), GitHub and GoDaddy for frontend hosting, source control and DNS, none of which hold patient data. Our public website additionally loads Google (Analytics and Tag Manager) and Meta (advertising pixel), both in the United States, which receive website usage data only after you consent and are never loaded on the signed-in clinical application — see section 10. The current list is also published on our Trust center at cardiobridge.teqdr.com/security.
6. Where we store and process your data
We serve patients and clients internationally, but patient data always lands in the same place. The clinical record is held in the EU/UK in our clinical system of record. Identity, service data, in-flight patient data and staged ECG files are held in the United Kingdom (London). No clinical content — ECGs, reports or patient records — is stored outside the EU or UK, wherever in the world the ECG was recorded. Two narrow categories of non-clinical personal data are processed in the United States, and we would rather name them than imply otherwise: email delivery logs held by our email provider, which contain a name and an email address but no clinical detail; and the consented website analytics described in section 10, which run only on our public site. Both rely on standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework and its UK extension. If you are located outside the UK, submitting an ECG involves a transfer of your data to the United Kingdom, and where that transfer requires a specific safeguard we rely on the relevant mechanism — an adequacy decision where one applies, or standard contractual clauses under Articles 44 to 46 of the GDPR. Any processing by a sub-processor outside the EEA takes place only under those safeguards.
7. Data security
We implement encryption in transit and at rest, access controls, and full audit logging. All data in transit is encrypted using TLS. Access to patient data is restricted to authorised personnel and is logged for audit purposes. We conduct regular security reviews and compliance assessments.
8. Your rights (GDPR)
Under the UK GDPR and EU GDPR, you have the right to access, rectify, erase, or restrict the processing of your personal data. You also have the right to data portability and to object to processing. Comparable rights exist under the data protection laws of the other countries we serve, and we honour them on the same basis. To exercise any of these rights, contact us at cardiobridge@teqdr.com. If you are not satisfied with our response, you may lodge a complaint with the UK Information Commissioner's Office under Article 77 of the GDPR, or with the data protection authority in your own country — for example the Data Protection Commission in Ireland, the OAIC in Australia, the PDPC in Singapore, or the Information Regulator in South Africa.
9. Data retention
Lead form data is retained for the duration of the business relationship and for a reasonable period thereafter. Uploaded ECG files are deleted from our staging storage once delivered to the clinical record. Patient-identifying data in our processing pipeline is automatically purged 90 days after a report is issued. Submissions that never complete are purged sooner rather than later: an incomplete intake is purged after 90 days, and a submission that is paid for but never completed is purged after 7 days. After purging we keep only non-identifying references needed for operations, billing and audit. The clinical record itself is retained in our clinical system of record for the period required by medical record-keeping obligations. You can request erasure at any time — see section 8.
11. Browser extension (Semble to CardioBridge)
Our "Semble to CardioBridge" Chrome extension has a single purpose: to let a clinician send an ECG document from a patient's record in Semble to CardioBridge for consultant interpretation. The extension only acts when you click "Send to CardioBridge" on a document. When you do, it retrieves that document from Semble using Semble's official API and submits it — together with the patient identifiers already on the record (such as name and email) needed to route and return the report — to CardioBridge at api.cardiobridge.teqdr.com. The extension stores only the credentials you enter (your CardioBridge API key and your Semble API token) in your browser's local extension storage; these are never transmitted to any party other than the service they authenticate (the Semble token is sent only to Semble's API, and is never sent to CardioBridge). The extension does not use analytics or tracking, does not collect browsing history, and never logs patient names, dates of birth, or document contents. Data handled by the extension is used solely to provide this single feature and is not sold, rented, or used for advertising or any unrelated purpose.
12. Browser extension (CardioBridge Connect)
Our "CardioBridge Connect" Chrome extension has a single purpose: to let a clinician send an ECG to CardioBridge for consultant interpretation from whatever software the ECG is displayed in, and to read the signed report back. It acts only when you use it: you supply the ECG image or file yourself by pasting, attaching, dragging or screen-snipping it, then enter the patient details and click Submit after a confirmation step. The extension requests no host permissions for any site other than api.cardiobridge.teqdr.com, does not read, scan, or inject into any web page you visit, and has no access to your browsing history or the content of other tabs. A screen-snip captures only the region you select, only when you start one. What is transmitted to CardioBridge is the ECG you supplied plus the patient details you typed — the patient's email (needed to return the report), and optionally name, date of birth, sex, a clinical question, your own medical record number (MRN) for the patient, and your name or initials. The extension stores in your browser's local extension storage only your CardioBridge API key, your submitter label, and the last MRN you used, so the panel can pre-fill; it uses no analytics or tracking, and sets no cookies. Data handled by the extension is used solely to provide this single feature and is not sold, rented, or used for advertising or any unrelated purpose.
13. Country-specific information
Some of the countries we serve require particular statements, which we set out here rather than burying them elsewhere. Hong Kong: we collect the personal data described in section 3 for the purposes described in section 4; supplying it is voluntary, but we cannot interpret an ECG without the clinical information needed to report on it. The classes of person to whom it may be transferred are our clinical system-of-record provider, our hosting and infrastructure providers, our transactional email provider, our payment provider, and the consultant cardiologist reporting your study — as listed in section 5. You have the right to request access to and correction of your personal data, and to be informed of our policies and practices, by writing to the Data Protection Officer at cardiobridge@teqdr.com. India: for questions or complaints about how your personal data is handled, contact our grievance officer at the same address; we will acknowledge and respond to grievances raised under the Digital Personal Data Protection Act 2023. South Africa: requests under POPIA, including access and objection, should be sent to the same address for the attention of the Information Officer. Singapore: our designated Data Protection Officer under the PDPA is contactable at that address, as stated in section 2.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through our platform or by email. Continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact the Data Protection Officer at Hippocrates Digital Ltd (trading as TeqDr), cardiobridge@teqdr.com. The name of the current officer is available on request. Accessibility feedback is welcome at the same address, and our accessibility statement is published at /accessibility.