Data protection policy

Last updated: October 4, 2026

This policy describes how PCL Health protects patient and user data held on the PCL Health platform and apps for US customers.

Our role. Healthcare providers and RPM companies that use PCL Health decide what patient data is collected and why. Under HIPAA they are covered entities, or act for one, and PCL Health acts as a business associate. PCL Health handles protected health information only to provide the platform and as each agreement allows.

Business associate agreements. A business associate agreement (BAA) is in place before any patient data is entered. Where a US partner contracts with the healthcare provider, the partner signs the BAA with the provider and PCL Health acts as the partner's subcontractor under a written agreement.

Where data is held. US patient data is hosted in the United States on Amazon Web Services (AWS).

What the platform holds. Patient profile and contact details; insurance details recorded at enrollment; vitals readings, care plans, alerts, clinical notes, forms and questionnaire responses; consent records; AI voice call summaries and related call records; Care Circle information where a patient invites family caregivers; staff accounts, roles and activity logs.

Safeguards. Role-based access: each user sees only what their role and facility permit. Consent management: patient consent is recorded in the platform. Audit logs: activity is logged for compliance review. Encryption: patient data is encrypted in transit and at rest. Staff access: PCL Health staff, based in the United Kingdom, access patient data only when needed for support or maintenance.

Patients and caregivers. Patients use the patient app under the direction of their healthcare provider. Family caregivers see a patient's information in the Care Circle app only after the patient invites them. Patients who want to access, correct or delete their records should contact their healthcare provider; PCL Health will support the provider in responding.

AI voice calls. Automated calls prompt patients about missed readings and deliver monthly reports on behalf of the patient's provider. A summary of each call is added to the patient's care plan. Calls do not make clinical decisions.

Subprocessors. PCL Health uses a limited number of service providers bound by written agreements that protect patient data. Current subprocessors: Amazon Web Services (hosting) and Vapi (AI voice calls).

Retention and return of data. PCL Health keeps patient data for the term of the customer agreement. When an agreement ends, PCL Health returns or deletes patient data within 30 days and removes it from backups within 90 days, as the agreement and BAA require.

Security incidents. If PCL Health becomes aware of a breach of unsecured protected health information, it will notify the affected customer without unreasonable delay and no later than 10 days after discovery, or sooner where the BAA requires.

No sale of patient data. PCL Health does not sell patient data or use it for advertising.

Contact. info@pcl-health.com, or Poonyah Care Limited, trading as PCL Health, 124 The Vale, London, NW11 8SL, United Kingdom.