Data handling is designed around controlled access and minimisation.
Account information
The platform stores the name, email address, organisation, role, access status, access expiry, login timestamps, and security-session information necessary to operate an account.
Operational records
EPD records and daily handling logs are encrypted before being written to the database. The encryption key is stored separately from the database file. Users should not enter patient names or identifiers.
Calculation activity
The audit trail records the user, protocol code, protocol version, warning count, and event time. It does not store the entered patient weight or other calculator input values.
Images and OCR
OCR is disabled by default. When explicitly enabled and configured by an administrator, a cropped image is proxied to the configured OCR provider and is not retained by this application.
Location
Location lookup is optional. Coordinates may be sent through the server to a reverse-geocoding service to produce a place label.
Retention
Retention periods and deletion procedures should be defined by the deploying organisation. Administrators can disable user access, while users can delete their own operational records.