Elm Digital Health
  • Home
Log InGet Started
Data Compliance

Information Asset Register & ROPA

A complete record of the information we store, share, and receive, and how we keep it safe.

Last Updated: 1 February 2026
1

About This Document

To be compliant with data protection legislation, including the UK GDPR and Data Protection Act 2018, we maintain a register of all information we store, share, and receive. This document serves as our combined Information Asset Register (IAR) and Record of Processing Activities (ROPA).

Information Asset Register (IAR)

Details where and how information is held and how we keep it safe across all our systems and processes.

Record of Processing Activities (ROPA)

Lists the types of personal data we share with others, how it is shared, and the safeguards in place.

Data Controller: Elm Digital Health Limited, London, United Kingdom
Contact: support@elmdigitalhealth.com

2

Information Asset Register

The following table details all information assets held by Elm Digital Health, including where they are stored, their format, and security measures in place.

Asset NameDescriptionData CategoriesFormatLocationRetention
Document Management SystemClinical documents, letters, and correspondence processed through our platformPatient health records, clinical correspondence, referral lettersElectronicUK Data CentreAs per NHS retention schedule or client agreement
Patient Index DatabaseIndex of patient identifiers for document matching and retrievalNHS number, name, date of birth, addressElectronicUK Data CentreDuration of service agreement + 1 year
User Account SystemHealthcare staff accounts for accessing the platformName, email, job role, organisation, login credentialsElectronicUK Data CentreDuration of employment + 6 years
Audit Trail SystemComplete record of all user actions and document accessUser IDs, timestamps, actions performed, documents accessedElectronicUK Data Centre8 years
Customer Enquiry RecordsContact form submissions and support communicationsName, email, phone, organisation, enquiry detailsElectronicUK Data Centre3 years from last contact
Integration LogsRecords of data exchanges with NHS systems (GP Connect, MESH, etc.)Transaction IDs, timestamps, status codes, error logsElectronicUK Data Centre2 years
Backup SystemsEncrypted backups of all operational dataAll data categories as aboveElectronicUK Data Centre (Geographically Separate)90 days rolling
Contract and Agreement RecordsService agreements, Data Processing Agreements, contractsOrganisation details, signatory names, contract termsBothUK Secure StorageDuration of contract + 6 years
3

Record of Processing Activities

The following table details all processing activities where personal data is shared with or received from other parties.

Processing ActivityPurposeData SubjectsData SharedRecipientsLawful Basis
Document Processing for GP PracticesClassifying, routing, and managing clinical correspondence on behalf of GP practicesPatients registered at client practicesClinical letters, test results, referrals, discharge summariesGP practice clinical systems (EMIS, SystmOne, Vision)Contract (Data Processor)
NHS Spine IntegrationVerifying patient demographics and retrieving GP registration detailsPatients requiring document routingNHS number, demographic queriesNHS Personal Demographics Service (PDS)Contract / Legal Obligation
GP Connect Data RetrievalAccessing patient records to support clinical workflowsPatients at participating practicesStructured clinical records as per GP Connect specificationsNHS GP Connect / SpineContract (Data Processor)
MESH Message ExchangeSecure transfer of clinical documents between NHS organisationsPatients whose documents are being transferredClinical documents, patient identifiersNHS MESH network participantsContract / Legal Obligation
Customer SupportResponding to enquiries and providing technical supportHealthcare staff, practice managers, prospective customersContact details, enquiry content, support ticket historyInternal support team onlyLegitimate Interest / Contract
Analytics and Service ImprovementAnalysing aggregated, anonymised usage data to improve servicesN/A (anonymised data only)Aggregated usage statistics (no personal data)Internal analytics teamLegitimate Interest
Regulatory ReportingCompliance with legal and regulatory requirementsAs required by regulationAs required by regulationICO, CQC, NHS Digital (as legally required)Legal Obligation

International Transfers

We do not transfer any personal data outside the United Kingdom. All data processing, storage, and backup systems are located exclusively within UK-based data centres. Our subprocessors are contractually required to process data only within the UK.

4

Security Measures

We implement comprehensive technical and organisational measures to protect all information assets:

Encryption at Rest

All data encrypted using AES-256 encryption in UK data centres

Encryption in Transit

TLS 1.3 encryption for all data transmissions

Role-Based Access Control

Granular permissions ensuring staff access only what they need

Complete Audit Trail

Every access and action logged with user, timestamp, and details

Multi-Factor Authentication

MFA required for all administrative and clinical access

Session Management

Automatic timeout and session monitoring for inactive users

Automated Backups

Daily encrypted backups to geographically separate UK location

Incident Response

24/7 monitoring with documented breach response procedures

Certifications and Compliance

  • NHS Data Security and Protection Toolkit (DSPT) compliant
  • ISO 27001 aligned information security practices
  • Cyber Essentials certified
  • UK GDPR and Data Protection Act 2018 compliant
  • National Data Opt-Out compliant
5

Data Subject Rights

Where we act as a Data Processor on behalf of healthcare organisations, data subject requests should be directed to the relevant GP practice or healthcare provider (the Data Controller).

For personal data where we are the Data Controller (e.g., customer enquiries, staff accounts), individuals have the following rights:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your data (where applicable)
  • Right to restriction: Request limitation of processing
  • Right to portability: Request transfer of your data
  • Right to object: Object to certain types of processing

To exercise these rights, contact us at support@elmdigitalhealth.com.

6

Review and Updates

This Information Asset Register and Record of Processing Activities is reviewed and updated:

  • Annually: Full review of all assets and processing activities
  • When changes occur: New systems, processes, or data sharing arrangements
  • Following incidents: Any data breach or security incident triggers a review
  • Regulatory updates: Changes to data protection legislation or guidance

Document Owner: Data Protection Lead, Elm Digital Health Limited
Last Review Date: 1 February 2026
Next Scheduled Review: 1 February 2027

7

Contact Us

If you have any questions about this document or our data handling practices, please contact us:

Elm Digital Health Limited

Email: support@elmdigitalhealth.com

London, United Kingdom

Elm Digital Health

Quick Links

  • Home
  • Upload Documents
  • Storage
  • Patient Records

Features

  • Reports & Analytics
  • Analytics
  • AI Classification
  • Integrations

Contact Us

  • support@elmdigitalhealth.com
  • London, United Kingdom

© 2025 Elm Digital Health. All Rights Reserved.

Privacy PolicyTerms of UseData Opt-OutIAR & ROPACookie Policy