Documentation
Policies & Governance
How GP Widget is built, governed and kept safe — written to be read by the people who rely on it. These pages cover our AI governance, security and data protection, clinical safety, and trust and legal documentation.
Governance
AI Model Governance & Change Control
How Widgi AI updates are managed, approved by our Clinical Safety Officer, and communicated to your organisation.
Patient Data Protection in AI
How Widgi AI scans prompts for patient-identifiable information and blocks it before it reaches the model.
Patient Data Protection — Demonstration
A short recorded demonstration showing a patient-identifiable prompt being detected and blocked before it reaches the AI.
Data Destruction & Retention
How long data is kept, how it is automatically deleted at end of life, and how it is rendered permanently unrecoverable.
Audit Logging & Integrity
How audit logs are kept append-only, made immutable and tamper-evident, and support forensic investigation.
Security & Data Protection
Data Hosting & UK Data Residency
Where your data lives: all hosting, storage, AI processing and backups run in the AWS UK (London) region.
Subprocessors & International Transfers
The suppliers we rely on to run GPWidget, and how international data transfers are minimised and safeguarded.
Access Control, MFA & Encryption
Role-based least-privilege access, multi-factor authentication, and encryption in transit (TLS 1.2+) and at rest (AES-256).
Incident Management & Breach Notification
How we detect and respond to incidents, and how confirmed breaches are reported to your organisation within 24 hours.