On your data
How we handle your data
Before work starts, we agree the scope in writing with your firm: the systems we work in and the kinds of data involved. These are the rules we follow.
| Access | Only what the build needs. The statement of work lists the systems and kinds of data involved, and we ask for named accounts with the least access the build needs. |
| Data-flow records | Every build has a written record before it goes live: each system it touches, the kinds of data, why, the vendor, how long the data is kept and who can reach it. You can read and print it in the Corwen dashboard. A build cannot be marked live without one. |
| Language models | Where a build sends your data to a language model, it goes through commercial API access, not a consumer chatbot subscription, and the data-flow record names the provider and how long it keeps the data. |
| Health information | No patient health information in any Corwen system until business associate agreements (BAAs) are in place with your practice and with every vendor involved. |
| Tax returns | We use tax return information only to do the work your firm asked for. Never for our own purposes, for marketing or to train a model. |
| Legal work | We work at your direction and under your supervision, keep what you share confidential and treat privileged material as privileged. |
For this site and the Corwen dashboard, see the privacy policy.