This document is an initial draft and requires legal review before being published as a final policy.
Privacy Policy
WTTT Systems · WTTT Health
1. Data controller
WTTT Systems operates the WTTT Health product. For any privacy question, or to exercise rights over your data, contact tomas@wttt.me.
2. Data processed
The product is designed to operate on scheduling references rather than the clinical content of patient records. Processed data corresponds to administrative information necessary to coordinate an appointment.
3. Purpose
Data is used solely to triage, confirm and record requests for care. It is not used for profiling, advertising, or disclosure to third parties outside service delivery.
4. Legal basis and controller responsibility
The contracting clinic acts as controller of its patients' data. ${site.company} acts as processor, handling data solely according to that clinic's documented instructions.
5. Data and language models
The architecture is designed so that clinical data stays decoupled from the prompt sent to language models. The agent operates on identifiers and references; access to the data remains inside the clinic's systems.
6. Retention
Audit records and execution traces are kept for the period agreed with the contracting clinic, then deleted or anonymised.
7. Security
Role-based access controls, strict input and output validation, and traceability of system actions are applied. The controls described in the architecture section of this site reflect the current design.
8. Data subject rights
Rights of access, rectification, erasure and portability are exercised with the responsible clinic, which holds its patients' data. ${site.company} assists with legitimate requests forwarded by that clinic.
9. Changes
This policy may change as the product evolves. The version in force is the one published at this address.