Privacy Policy

Last updated: 5th December 2025

The Lathbury Group Ltd trading as Jump EHR (Use Jump) ("Jump", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store and protect information when you use Jump EHR, our electronic health record and clinical workflow system.

Company Details

The Lathbury Group Ltd trading as Jump EHR

Company Number: 15291957

Registered Office: Mayfield House, 256 Banbury Road, Oxford, England, OX2 7DE

Data protection contact: hello@usejump.co.uk

1. Scope and Roles

1.1 Who This Policy Applies To

This Privacy Policy applies to:

  • Healthcare organisations using Jump EHR
  • Authorised users such as clinicians and administrators
  • Patients whose data is processed through Jump EHR
  • Visitors to our websites and support services

1.2 Controller and Processor Roles

For Clinical and Patient Data

  • Data Controller: The healthcare organisation
  • Data Processor: Jump

The healthcare organisation determines why and how patient data is processed. We process that data only on their instructions and under our Data Processing Agreement.

For Account, Usage and Support Data

  • Data Controller: Jump
  • We determine how we process data relating to customer accounts, users and system usage.

2. Information We Collect

2.1 Clinical and Patient Data (Processor Role)

Healthcare organisations may input:

  • Patient demographics
  • Medical history, diagnoses, notes and observations
  • Prescriptions and medication information
  • Test and investigation results
  • Appointment records
  • Communications sent to patients
  • Clinical documents and uploads
  • Care plans, tasks and workflow data

The legal basis for this processing is determined by the healthcare organisation.

2.2 Account and User Data (Controller Role)

We collect:

  • Organisation details
  • User names, emails and job roles
  • Authentication data
  • Professional registration details
  • Billing and subscription information

Legal basis: contract performance, legal obligations and legitimate interests.

2.3 Usage and Technical Data

We automatically collect:

  • Feature usage and activity logs
  • Device and browser information
  • IP addresses
  • Error logs and performance data
  • Security and access logs
  • Aggregated analytics data

Legal basis: legitimate interests and contract performance.

2.4 Communications Data

Support emails, feedback, surveys and service communications.

Marketing communications are only sent with consent.

3. How We Use Information

3.1 Clinical and Patient Data

We process this data only to:

  • Store and retrieve patient records
  • Support clinical documentation and workflows
  • Enable scheduling and communications
  • Provide AI-supported tools when enabled
  • Support document and report generation
  • Enable integrations chosen by the organisation

We do not sell, market, or use patient data for our own commercial purposes.

3.2 Account and User Data

We use this to:

  • Manage accounts and access
  • Provide support
  • Process payments
  • Improve the system
  • Maintain security
  • Send service communications

4. Sub-Processors and Data Sharing

4.1 Core Sub-Processors

We use service providers including:

  • Microsoft Azure for hosting
  • Azure OpenAI for optional AI features
  • Supabase for database services
  • Communication providers for email and SMS
  • Monitoring and analytics providers
  • Stripe for subscription billing

All sub-processors operate under contractual data protection obligations.

4.2 Customer-Enabled Integrations

When you enable integrations, those providers may act as independent controllers or processors under their own terms. You are responsible for appropriate agreements with them. Jump provides the technical connection but does not determine how those third parties process data.

4.3 Legal Disclosures

We may disclose data where legally required to regulatory authorities, law enforcement or courts.

5. Data Location and Transfers

  • Clinical data is primarily stored in the UK or EU.
  • Some service providers may transfer data outside these regions using recognised legal safeguards such as standard contractual clauses.
  • Azure OpenAI processes data within EU regions and does not use customer data to train models.

6. Data Security

We implement security measures including:

  • Encryption in transit and at rest
  • Role-based access controls
  • System monitoring and logging
  • Security testing
  • Incident response procedures
  • Business continuity planning

These align with recognised industry information security practices.

7. Data Retention

Clinical Data

Retention is determined by the healthcare organisation according to applicable medical record retention guidance and professional standards.

Account Data

Retained while subscription is active and for a limited period after termination.

Logs and Analytics

Retained according to operational and security needs, with anonymisation where appropriate.

8. Patient Rights

Patients should contact their healthcare provider to exercise rights of access, rectification, erasure, restriction or objection.

9. Healthcare Organisation and User Rights

Organisations can access, update or export their data and request corrections or deletion subject to legal requirements.

10. Cookies

We use essential, functional and analytics cookies. Users can control cookies through browser settings.

11. Clinical Safety and Data Quality

We support data quality and may process information to identify system safety issues and improve reliability.

12. Children's Data

Patient data about children is processed under the responsibility of healthcare organisations. User accounts are limited to adults.

13. Marketing

Marketing communications are optional and can be unsubscribed at any time.

14. Data Breach Handling

We notify healthcare organisations without undue delay if a breach occurs and support their regulatory obligations.

15. Changes to This Policy

We may update this policy and will notify users of material changes.

16. Contact and Complaints

Email: hello@usejump.co.uk

You may also complain to the UK Information Commissioner's Office.