SheldonDx Privacy Policy
Effective Date: October 5, 2026
Working toward GDPR & HIPAA readiness — not yet certified
We are actively implementing technical and organisational measures aligned with GDPR (EU/UK) and the HIPAA Security Rule. SheldonDx is not currently certified under either framework. India DPDP Act 2023 is our primary compliance obligation. See § GDPR and § HIPAA below for current status.
The data controller for SheldonDx is ZEBRA HEALTH LTD (“SheldonDx”, “we”, “us”).
Contact
info@sheldondx.comPrimary data store
Firebase asia-south1 (Mumbai, India)
For Indian patients whose clinical records are held by a clinician using SheldonDx, the registered clinician acts as the independent data controller. SheldonDx acts as data processor on their behalf.
Clinician account data
- Full name, email address, professional role
- NHS number (UK clinicians only)
- Practice / clinic name and address
- Professional credentials and qualifications
- Verification status and method
OAuth credentials (integration tokens)
When you connect Zoom or Google Calendar, we store OAuth access and refresh tokens in an encrypted Firestore sub-collection. These are used solely to create meetings and manage your calendar. You can disconnect integrations at any time from Settings.
Google Calendar user data
SheldonDx requests the Google Calendar calendar.events permission only after a clinician chooses Connect Google Calendar. We access the OAuth credentials issued by Google and send the appointment details entered in SheldonDx — title, date and time, duration, optional attendee email, and consultation description — to Google Calendar to create that clinician-authorised event and its Google Meet conference link. We do not list, search, import, analyse, or display the clinician's existing calendars or events.
Google Calendar user data is used only to provide this scheduling feature. It is not sold, used for advertising, shared with data brokers, sent to Gemini or another third-party AI service, or used to develop, improve, or train any general-purpose AI or machine-learning model. We do not create aggregated or anonymised datasets from Google Calendar user data.
OAuth credentials are encrypted in transit and at rest and stored in a restricted server-side Firestore sub-collection. They are retained only while the integration remains connected and are deleted when the clinician disconnects Google Calendar. Appointment records created in SheldonDx retain the returned Meet URL as part of the clinician's scheduling record, subject to the retention periods in §7 below. Google receives the event details solely to provide Google Calendar and Google Meet functionality under Google's own privacy terms.
SheldonDx's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Patient referral data (processed on your behalf)
- Patient name, email, date of birth, phone number
- Assessment type (ADHD / autism / combined)
- Demographic variant (standard, female phenotype, LGBTQ+, late-diagnosed)
- Age group and respondent type
- Clinical referral notes
Informant / caregiver data
Name, email, and relationship to the patient for each invited informant (parent, caregiver, teacher). This is processed only to deliver and track the informant assessment questionnaire.
LEADS marketplace profile
Session style, age group specialisations, trauma focus, LGBTQ+ affirming status, and neurodiversity experience level — collected during LEADS onboarding. This information is used to match clinicians to patients in the finder.
SheldonDx processes health data that qualifies as Article 9 “special category” under GDPR and “sensitive personal data” under India’s DPDP Act. This data is processed only with explicit clinician attestation and (for session recordings) explicit patient/caregiver consent.
Live session transcripts
Verbatim speech transcribed from Zoom/Google Meet sessions via Recall.ai and Deepgram nova-3-medical. Transcripts include speaker diarization (who said what) and are tagged with session instrument (ADOS-2 or ADI-R).
Behavioral coding events
ADOS-2 item scores (0–3), shorthand notation (eye contact, joint attention, echolalia, etc.), AI-suggested codings, and clinician rationale notes. These constitute clinical health records.
Screening and assessment scores
ASRS, CAT-Q, RAADS-R, ADI-R domain totals (A, B, C, D), ADOS-2 Calibrated Severity Scores (CSS), and free-text symptom responses from the adaptive question engine.
AI-generated clinical analysis
Differential diagnosis probability weights (ASD, ADHD, social anxiety, female phenotype, trauma), clinical synthesis summaries, masking indicators, and session narrative summaries generated by the AI review system.
SheldonDx uses Recall.ai to deploy a notetaking bot into Zoom or Google Meet sessions. The bot:
- Announces itself in chat: “Session Notes is capturing this consultation for the medical record. You can ask to remove it anytime.”
- Records audio and video (speaker view or gallery view)
- Sends audio to Deepgram nova-3-medical for transcription with speaker diarization
- Returns transcript chunks to SheldonDx in real time
Clinician obligations
Before starting any session recording you must obtain explicit written consent from the patient or (for children) their caregiver/guardian. SheldonDx enforces a consent confirmation gate in the interface before the bot joins. The consentGranted flag is written to the session record when you confirm. You are responsible for retaining the signed consent form in your own clinical records.
Dictation (real-time notes)
The microphone dictation feature streams clinician speech to Deepgram (EU endpoint: api.eu.deepgram.com) for real-time transcription of clinical notes. No patient audio is sent through this path — it is a clinician-only dictation tool.
Data residency
Deepgram dictation uses the EU endpoint. Session transcripts via Recall.ai pass through Recall’s infrastructure; refer to Recall.ai’s DPA for their data residency commitments. Transcript data stored in Firebase is in asia-south1 (Mumbai).
SheldonDx uses Google Gemini (via Google Cloud) to power the automated clinical-reasoning support workflow. This is a clinical decision support tool — it does not make diagnoses. All outputs must be reviewed by the responsible clinician.
What is sent to Gemini
- Synthesised clinical evidence items (domain, criterion, evidence text, strength)
- Patient demographics (age group, assessment type)
- Prior screening scores (ASRS, CAT-Q, ADI-R totals)
- Lowercase transcript signal keywords (not verbatim transcript text)
- Session context (ADOS-2 module, CSS band, coding state)
What is NOT sent
Patient names, email addresses, phone numbers, dates of birth, and verbatim transcript text are not included in Gemini API calls.
Retention of reasoning-support outputs
Clinical reasoning-support outputs (formulations, evidence summaries, differential weights) are stored in Firestore as part of the clinical record for 8 years (adult patients) or 25 years (child patients).
Google processes data under the Google Cloud Data Processing Addendum (DPA), which includes Standard Contractual Clauses for international transfers.
The following sub-processors receive personal or clinical data as part of delivering SheldonDx services:
| Processor | Data received | Purpose | Policy |
|---|---|---|---|
| Recall.ai | Meeting URL, referral metadata, audio/video stream | Session recording & transcription | recall.ai/privacy |
| Deepgram | Audio via Recall.ai; clinician microphone (dictation) | Speech-to-text (nova-3-medical) | deepgram.com/privacy |
| Zoom | Meeting topic, duration, OAuth token | Video call creation | zoom.us/privacy |
| Google (Calendar) | OAuth token, connected email | Calendar integration | policies.google.com |
| Google Gemini | Clinical evidence, demographics, transcript signals (Presidio-redacted) | MDT AI analysis | cloud.google.com/terms/data-processing |
| Razorpay | Order amount, payment reference | Payment processing (INR) | razorpay.com/privacy |
| WhatsApp / Meta | Clinician notifications — no patient PHI (deep-link only) | LEADS onboarding & intake notifications | whatsapp.com/legal/privacy-policy |
| mem0 | Anonymised conversation context (linked-account users) | Personalised response memory | mem0.ai/privacy |
| Brevo | Clinician email address | Transactional email delivery | brevo.com/legal/privacypolicy |
| Firebase (Google) | All Firestore data | Database, auth, hosting | cloud.google.com/terms/data-processing |
Clinical records
8 years (adult) / 25 years (child)
UK NHS standards + Indian Medical Council guidelines
Non-clinical data
30 days
Chat history, screening scores outside formal assessment
OAuth credentials
Until disconnected
Clinician controls via Settings → Integrations
Payment records
7 years
Statutory requirement (India Companies Act)
If you request deletion of an account whose clinical records are within the statutory retention period, we will deactivate your account and anonymise identifiers where possible, but the clinical record itself will be retained for the full statutory period. We will notify you of what is retained and why.
Under GDPR / UK GDPR (EU/UK clinicians)
- Access — request a copy of personal data we hold
- Rectification — correct inaccurate data
- Erasure — request deletion (subject to clinical retention obligations)
- Portability — receive your data in JSON or PDF format
- Restriction — pause processing while a dispute is resolved
- Object — object to processing based on legitimate interests
- Lodge a complaint — with the UK ICO at ico.org.uk
Under India DPDP Act 2023
- Access — summary of personal data processed and processing activities
- Correction & erasure — rectify inaccurate or misleading data; request erasure on withdrawal of consent
- Grievance redress — raise a complaint with our Grievance Officer (see §16)
- Nomination — nominate a person to exercise rights on death or incapacity
All rights requests: info@sheldondx.com. We respond within 30 days.
The Digital Personal Data Protection Act 2023 is our primary statutory compliance obligation. SheldonDx is the Data Fiduciary for clinician data; registered clinicians are independent Data Fiduciaries for their patients’ data.
consentGranted flag recorded in Firestore with timestamp)Current status: We have completed an initial Data Protection Impact Assessment (DPIA) for session recording and MDT AI analysis. Article 30 records of processing are maintained. We are working toward formal GDPR certification (ISO 27701) — target Q3 2026.
SheldonDx is not currently HIPAA-certified.
We do not currently have a signed Business Associate Agreement (BAA) with all sub-processors (Recall.ai, Deepgram). US-based clinicians: do not use SheldonDx with US patients until HIPAA certification is complete and a BAA is in place.
What we are doing
- Implementing HIPAA Security Rule technical safeguards (access controls, encryption, audit logs)
- Drafting BAA templates for Recall.ai, Deepgram, and Google Cloud
- Conducting a HIPAA risk analysis
- Training all staff on HIPAA Privacy Rule obligations
Timeline
Target HIPAA readiness: Q4 2026. We will update this page when certification is complete. Subscribe to our changelog at sheldondx.com/changelog for updates.
- Data encrypted in transit (TLS 1.3 minimum)
- Data encrypted at rest (AES-256 via Firebase / Google Cloud)
- Firestore security rules enforce per-clinician data access (clinicians cannot access other clinicians’ patient data)
- OAuth tokens stored in a restricted Firestore sub-collection inaccessible to client-side code
- Firebase Authentication enforces email/password with rate limiting
- API endpoints authenticated via Firebase ID tokens (server-side verification)
- Recall.ai webhook verified by signature (HMAC-SHA256)
- Razorpay webhook verified by signature (HMAC-SHA256)
In the event of a personal data breach that poses a risk to individuals:
- We will notify the relevant supervisory authority (UK ICO / India DPBOARD) within 72 hours of becoming aware
- We will notify affected clinicians without undue delay if there is a high risk to their rights or their patients’ rights
- Notification will include: nature of breach, data categories affected, likely consequences, and measures taken/proposed
To report a suspected breach: info@sheldondx.com
Subscription and per-assessment payments are processed by Razorpay. Card numbers, bank account details, and UPI IDs are handled entirely by Razorpay and never pass through or are stored on SheldonDx servers. Razorpay is PCI DSS Level 1 certified.
SheldonDx retains: order reference, payment status, amount (INR), and Razorpay transaction IDs for billing and dispute resolution purposes. Payment records are retained for 7 years.
We will notify you of material changes to this policy by email (to your registered clinician account email) at least 30 days before changes take effect. Continued use of SheldonDx after the effective date constitutes acceptance.
Contact
General privacy: info@sheldondx.com
DPO (GDPR): info@sheldondx.com
DPDP Grievance Officer: grievance@sheldondx.com
Security incidents: info@sheldondx.com
© 2026 ZEBRA HEALTH LTD · sheldondx.com