Privacy Policy
Last updated: 5th December 2025
The Lathbury Group Ltd trading as Jump EHR (Use Jump) ("Jump", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store and protect information when you use Jump EHR, our electronic health record and clinical workflow system.
Company Details
The Lathbury Group Ltd trading as Jump EHR
Company Number: 15291957
Registered Office: Mayfield House, 256 Banbury Road, Oxford, England, OX2 7DE
Data protection contact: hello@usejump.co.uk
1. Scope and Roles
1.1 Who This Policy Applies To
This Privacy Policy applies to:
- Healthcare organisations using Jump EHR
- Authorised users such as clinicians and administrators
- Patients whose data is processed through Jump EHR
- Visitors to our websites and support services
1.2 Controller and Processor Roles
For Clinical and Patient Data
- Data Controller: The healthcare organisation
- Data Processor: Jump
The healthcare organisation determines why and how patient data is processed. We process that data only on their instructions and under our Data Processing Agreement.
For Account, Usage and Support Data
- Data Controller: Jump
- We determine how we process data relating to customer accounts, users and system usage.
2. Information We Collect
2.1 Clinical and Patient Data (Processor Role)
Healthcare organisations may input:
- Patient demographics
- Medical history, diagnoses, notes and observations
- Prescriptions and medication information
- Test and investigation results
- Appointment records
- Communications sent to patients
- Clinical documents and uploads
- Care plans, tasks and workflow data
The legal basis for this processing is determined by the healthcare organisation.
2.2 Account and User Data (Controller Role)
We collect:
- Organisation details
- User names, emails and job roles
- Authentication data
- Professional registration details
- Billing and subscription information
Legal basis: contract performance, legal obligations and legitimate interests.
2.3 Usage and Technical Data
We automatically collect:
- Feature usage and activity logs
- Device and browser information
- IP addresses
- Error logs and performance data
- Security and access logs
- Aggregated analytics data
Legal basis: legitimate interests and contract performance.
2.4 Communications Data
Support emails, feedback, surveys and service communications.
Marketing communications are only sent with consent.
3. How We Use Information
3.1 Clinical and Patient Data
We process this data only to:
- Store and retrieve patient records
- Support clinical documentation and workflows
- Enable scheduling and communications
- Provide AI-supported tools when enabled
- Support document and report generation
- Enable integrations chosen by the organisation
We do not sell, market, or use patient data for our own commercial purposes.
3.2 Account and User Data
We use this to:
- Manage accounts and access
- Provide support
- Process payments
- Improve the system
- Maintain security
- Send service communications
4. Sub-Processors and Data Sharing
4.1 Core Sub-Processors
We use service providers including:
- Microsoft Azure for hosting
- Azure OpenAI for optional AI features
- Supabase for database services
- Communication providers for email and SMS
- Monitoring and analytics providers
- Stripe for subscription billing
All sub-processors operate under contractual data protection obligations.
4.2 Customer-Enabled Integrations
When you enable integrations, those providers may act as independent controllers or processors under their own terms. You are responsible for appropriate agreements with them. Jump provides the technical connection but does not determine how those third parties process data.
4.3 Legal Disclosures
We may disclose data where legally required to regulatory authorities, law enforcement or courts.
5. Data Location and Transfers
- Clinical data is primarily stored in the UK or EU.
- Some service providers may transfer data outside these regions using recognised legal safeguards such as standard contractual clauses.
- Azure OpenAI processes data within EU regions and does not use customer data to train models.
6. Data Security
We implement security measures including:
- Encryption in transit and at rest
- Role-based access controls
- System monitoring and logging
- Security testing
- Incident response procedures
- Business continuity planning
These align with recognised industry information security practices.
7. Data Retention
Clinical Data
Retention is determined by the healthcare organisation according to applicable medical record retention guidance and professional standards.
Account Data
Retained while subscription is active and for a limited period after termination.
Logs and Analytics
Retained according to operational and security needs, with anonymisation where appropriate.
8. Patient Rights
Patients should contact their healthcare provider to exercise rights of access, rectification, erasure, restriction or objection.
9. Healthcare Organisation and User Rights
Organisations can access, update or export their data and request corrections or deletion subject to legal requirements.
11. Clinical Safety and Data Quality
We support data quality and may process information to identify system safety issues and improve reliability.
12. Children's Data
Patient data about children is processed under the responsibility of healthcare organisations. User accounts are limited to adults.
13. Marketing
Marketing communications are optional and can be unsubscribed at any time.
14. Data Breach Handling
We notify healthcare organisations without undue delay if a breach occurs and support their regulatory obligations.
15. Changes to This Policy
We may update this policy and will notify users of material changes.
16. Contact and Complaints
Email: hello@usejump.co.uk
You may also complain to the UK Information Commissioner's Office.
17. Legal Framework
This policy aligns with:
- UK GDPR
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations
- Common law duty of confidentiality
- Relevant professional standards