PatientsCann UK Web App — Privacy Policy


PatientsCann UK CIC — Company No. 14211389

Web App Privacy Policy

Last updated: 3 May 2026
ICO registration: ZB345466
Version: 2.1

1Introduction

This Privacy Policy explains how PatientsCann UK CIC (“we”, “us”, or “our”) collects, uses, and protects information when you use our Know Your Journey web application at app.patientscann.org.uk.

PatientsCann UK CIC is the Data Controller for any personal data processed through this application, registered with the ICO (No. ZB345466). We comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The app is built with a Privacy by Design approach. The vast majority of data you enter never leaves your device. This policy explains precisely what does and does not.

2Contact details

Data Protection Officer
Email: dpo@patientscann.org.uk
Registered Office: 27 Old Gloucester Street, London, England, WC1N 3AX

3What we process and why

The app has three distinct data processing activities.

3a — Data stored only on your device (never transmitted)

The following is stored exclusively in your browser’s local storage and is never transmitted to PatientsCann or any third party:

You can permanently delete all locally stored data via My Treatment → Settings → Delete all my treatment data, or by clearing your browser. PatientsCann cannot recover this data.

3b — E-learning analytics (session-based, no personal data)

When you use the e-learning parts of the app — Patient Mode, Professional Mode, quizzes, the chapter hub, the science library, the travel guide, and other educational features — we collect anonymised usage data to understand how the content is being used and improve it.

Data item What it is Purpose
Session ID A random UUID created when the app loads. It is never stored — it exists only for that session and is discarded when you close or refresh. Groups events from a single session without identifying you across sessions.
Section visited Which part of the app was opened (e.g. “Chapter Hub”, “Science Library”, “My Treatment”, “Travel Guide”). Understanding which content is most used, to prioritise improvements.
Mode Whether you are in Patient Mode or Professional Mode. Distinguishing which user group each section serves.
Quiz performance Whether a question was answered correctly or incorrectly, and approximately how long it took. No question text or personal responses — only chapter index and a correct/incorrect flag. Identifying difficult questions so content can be improved.
No personal data is involved in e-learning analytics. The session ID is ephemeral, never stored, and cannot identify you. This processing falls under Legitimate Interests (UK GDPR Art. 6(1)(f)) — improving educational content for UK medical cannabis patients is a proportionate and legitimate purpose.

3c — My Treatment anonymised data (optional, consent required)

If you use the My Treatment section and choose to opt in, we collect a small amount of anonymised data to understand how UK patients use medical cannabis at a population level. This is entirely optional — all features work without it.

Data item What it is Purpose
Device identifier (UUID) A random code generated on your device and stored in your browser. Not linked to your name, email, clinic, or any identifying information. Prevents duplicate records. Allows deletion of your specific record if you withdraw consent.
Product category The broad type of product prescribed (e.g. “flower”, “oil”, “cartridge”). Not the specific product name or brand. Population-level insight into which product types UK patients use, to inform content and advocacy work.
Quantity bracket A broad banding of your prescribed quantity (e.g. “10–20g”). Not the exact amount. Understanding typical prescription volumes at population level.

We do not collect your name, email, clinic name, specific product names, diary entries, dosing notes, appointment details, or any other personal information through this feature.

Note on the device UUID: Although not directly identifying, a persistent pseudonymous identifier may be personal data under UK GDPR. We treat it as such, process it only under consent, and delete it on request.

4Lawful basis for processing

Activity Lawful basis
Data stored only on your device Not applicable — never reaches our systems
E-learning analytics (session ID, page views, quiz results) Legitimate Interests — UK GDPR Art. 6(1)(f). No personal data involved. You can opt out at any time.
My Treatment anonymised data (UUID, product category, quantity bracket) Consent — UK GDPR Art. 6(1)(a). Explicit opt-in required. Withdrawable at any time.
Incident reports (submitted voluntarily) Consent — UK GDPR Art. 6(1)(a), and Art. 9(2)(a) for any health-related content voluntarily included.

5How consent works

When you first open the app, a consent banner explains both types of data collection. You can accept or decline each. Consent is:

If you decline My Treatment data sharing, you will be prompted again after 7 days in case you change your mind. If you opt in, you will not be prompted again.

6Data retention

Data type Retention
Data stored only on your device Until you delete it or clear your browser. We cannot access or recover it.
E-learning analytics events Up to 12 months, after which older events are automatically purged.
My Treatment anonymised data (UUID, category, quantity bracket) Retained as anonymous aggregates for service improvement. Deleted immediately on withdrawal of consent, either via the in-app button or by emailing our DPO.
Incident reports Retained for as long as required to act on the report, or as stated at submission.

7Your rights under UK GDPR

Right of access

Request a copy of any personal data we hold about you.

Right to rectification

Ask us to correct inaccurate personal data.

Right to erasure

For My Treatment data, use the in-app Withdraw consent button in Settings. This also triggers deletion of your server-side record.

Right to restrict processing

Ask us to pause processing while a dispute is resolved.

Right to data portability

Receive your data in a machine-readable format where applicable.

Right to withdraw consent

Withdraw at any time via the toolbar privacy icon or My Treatment → Settings, without affecting the lawfulness of prior processing.

Right to object

Object to Legitimate Interests processing (e-learning analytics) via the privacy icon in the toolbar.

Data stored only on your device is held exclusively in your browser. We cannot action access or erasure requests for that data — only you can delete it.

To exercise any right: dpo@patientscann.org.uk. We will respond within one calendar month.

8Data sharing and third parties

We do not sell personal data. We do not share personal data with third parties for marketing. Data may be shared only with trusted infrastructure providers under a Data Processing Agreement, or where required by law. Anonymised aggregate statistics may be referenced in published reports or shared with partner organisations for research and advocacy.

9Security

10How to complain

PatientsCann UK DPO
dpo@patientscann.org.uk

If you remain unsatisfied, you have the right to complain to the ICO:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113  —  ico.org.uk

11Changes to this policy

We may update this policy to reflect changes in the app or legal requirements. The “Last updated” date at the top will always reflect the most recent version. Material changes affecting personal data processing will be communicated via the app before taking effect, and will require fresh consent where consent is the lawful basis.