DrToye
DrToye
Health Management System

Privacy Policy

Effective date: 1 April 2026  |  Last updated: 13 April 2026

1. Who We Are

DrToye HMS is operated by Neural Signal Corporation Limited ("we", "us", "our"), registered in England and Wales. We act as a data processor on behalf of healthcare providers (Hospitals) that use our platform, and as a data controller for account and platform-related data.

Data Protection Officer contact: support@drtoye.com

2. Data We Collect

CategoryExamplesLawful Basis
Identity DataFull name, date of birth, gender, profile photoContract performance
Contact DataEmail address, phone number, home addressContract performance, consent (SMS/calls)
Health DataMedical history, diagnoses, lab results, prescriptions, vital signs, allergiesProvision of healthcare (Article 9(2)(h) UK GDPR)
Appointment DataBooking details, doctor assignments, scheduling historyContract performance
Financial DataBilling records, payment method (via Stripe — we do not store full card numbers)Contract performance, legal obligation
Technical DataIP address, device type, app version, push notification tokensLegitimate interest (security & service improvement)
Communication DataIn-app chat messages, email correspondenceContract performance

3. How We Use Your Data

4. Third-Party Processors

We use the following third-party services to deliver the Platform. All are bound by data processing agreements:

ServicePurposeData Shared
TwilioSMS text messages & automated voice callsPhone number, message content
StripePayment processingPayment details (tokenised)
MongoDB AtlasDatabase hostingAll platform data (encrypted)
ElevenLabsAI voice synthesis for automated callsPatient name, appointment details (in call script)
SMTP providerEmail deliveryEmail address, message content
Firebase (FCM)Push notificationsDevice token, notification content
AgoraVideo call infrastructureAudio/video stream (not recorded)

We do not sell, rent, or share your personal data with any third party for marketing purposes.

5. SMS & Voice Call Communications

By providing your phone number during registration, you consent to receive transactional SMS and automated voice calls related to your healthcare. These include:

Opt out: Reply STOP to any SMS, update preferences in the app, or contact support@drtoye.com.

No marketing or promotional messages are sent. Standard carrier message and data rates may apply.

6. Data Security

7. Data Retention

8. Your Rights (UK GDPR)

Under UK data protection law, you have the right to:

To exercise any of these rights, contact support@drtoye.com. We will respond within 30 days.

9. Cookies & Analytics

The DrToye web portal may use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies. The mobile app does not use cookies.

10. Children's Privacy

The Service is not intended for children under 16. We do not knowingly collect data from children under 16 without parental consent. Minors' accounts are created and managed by a parent, guardian, or Healthcare Provider.

11. International Transfers

Your data is primarily stored in the UK/EEA. Where data is processed by third-party services outside the UK (e.g., MongoDB Atlas, Twilio), appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and UK International Data Transfer Agreements (IDTAs).

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top of this page indicates when the latest revision was made.

13. Contact & Complaints

If you have questions or complaints about this Privacy Policy or how we handle your data:

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk