Privacy notice
Last updated August 2026
Who we are
SoliWard is operated by Alejandra Torres, trading as SoliWard, of [POSTAL ADDRESS TO BE CONFIRMED]. Alejandra Torres is the data controller for the personal data described in this notice and decides how and why it is processed.
ICO registration: The controller is assessing its data protection fee obligations with the Information Commissioner's Office. No ICO registration number is currently provided in this notice.
The short version
Your reflections belong to you. They are stored against your account only, protected by row-level security so that no other user can read them, and you can export or permanently delete them at any time from Settings.
What we collect, why, and our legal basis
- Account data — email, and optionally display name, university, cohort year and field of practice. Used to create and secure your account. Legal basis: performance of our contract with you.
- Placement details — placement name, setting, dates, shift pattern and supervisor's first name. Used to provide the service. Legal basis: performance of our contract.
- Your content — shift logs, reflections, wins, check-ins and voice recordings you create. Used to provide the features you request. Legal basis: performance of our contract.
- Wellbeing and recovery entries — mood, support, confidence, demand and free-text wellbeing information you choose to enter. Used to provide the wellbeing features you request. Legal basis: performance of our contract. [LEGAL REVIEW: Some wellbeing or recovery information may constitute special category data concerning health under UK GDPR. The controller must confirm and document the applicable Article 9 condition, and any required DPA 2018 Schedule 1 condition, before relying on that processing.]
- Money Hub data — if you save a Money Hub calculation, payslip-derived figures such as gross/net pay, tax, NI, pension and student-loan amounts may be stored. The original payslip file is processed and redacted in your browser and is not uploaded. Legal basis: performance of our contract.
- Technical and usage data — approximate country derived from request headers, browser type, and basic usage/telemetry. We do not store raw IP addresses or persistent device identifiers. Used for security, fraud prevention and improving the product. Legal basis: our legitimate interests in running a secure, working service.
- Support messages — anything you send us. Legal basis: legitimate interests in responding to you.
- Subscription data — your plan status, subscription identifiers for SoliWard Plus, and any complimentary/internal Plus access granted separately from Paddle. Legal basis: performance of our contract and compliance with legal (tax and accounting) obligations.
Patient information
Do not enter patient-identifiable information. SoliWard is intended for de-identified reflective writing only. Before you save, and again before any text is sent to an AI feature, we run an automated pattern-based check in your browser that flags anything that looks identifiable — names, initials, NHS numbers, dates of birth, addresses or rare diagnoses — and offers a de-identified rewrite. Text the check flags is blocked from being sent to our AI provider until you change it. These checks are best effort: they reduce risk but are not a guarantee of anonymity, and someone with contextual knowledge of a placement, setting or event may still be able to identify a person indirectly. You remain responsible for what you write, under the NMC Code and your university's policies.
Voice recordings and AI
Voice transcription is optional. If you use it, the audio you record is held in your browser only for as long as it takes to send it to our external AI transcription service; we do not store audio files. The audio is sent as recorded — it is not screened, redacted or anonymised before transmission, and our PII check only runs on the transcript that comes back, after which the existing warning and review behaviour applies. Before recording you are asked to acknowledge a warning not to speak identifying information.
SoliWard uses the Lovable AI Gateway. Text you submit for transcription, tidying, follow-up questions or drafting is sent through that gateway and may be routed to third-party AI model providers to return the result. We do not use your reflections to train models. Our providers' own retention, logging, training and processing locations are governed by their applicable terms and are not something SoliWard represents as guaranteed — see the relevant provider privacy information. AI output is always a draft for you to review and edit, and reflections created with AI help are marked as AI-assisted in the app and in exports.
[OWNER/LEGAL CONFIRMATION REQUIRED: confirm the applicable international data-transfer safeguard and any provider data-processing agreement or addendum arrangements before publication. Do not publish without verifying these arrangements.]
Who we share data with
- Service providers (subprocessors) — our managed cloud hosting and database provider, our AI gateway and underlying model providers for the processing described above, and our error-reporting/capture service for limited technical diagnostics.
- Paddle.com — our Merchant of Record and payment processor for SoliWard Plus. Paddle handles checkout, subscription management, payments, tax compliance, invoicing and refunds, and processes your name, email, billing and payment details as its own controller for those purposes.
- Professional advisers — legal and accounting advisers where necessary.
- Authorities — where we are required to disclose by law.
We do not sell your data and we do not use your reflections to train AI models. Our primary database is hosted in Ireland (AWS eu-west-1) and the application is served through Cloudflare's edge network. Processing locations for our AI gateway and its underlying providers are governed by those providers' terms and are not something SoliWard can independently confirm; some processing may therefore take place outside the UK/EEA. SoliWard does not control where a provider routes or stores data beyond the options its service offers.
Storage, security and retention
Data is stored in our managed cloud database and is sent over encrypted network connections (HTTPS). Access is controlled by row-level security policies tied to your authenticated user ID. Storage-level encryption at rest depends on our hosting provider's own configuration rather than on anything SoliWard implements. Work you create while offline is encrypted in your browser with AES-GCM using a non-extractable key held by your browser until it syncs, and you can clear that queue yourself from Settings. Payslips you upload to the Money Hub are converted and redacted in your browser first: only the redacted image you have reviewed is sent for AI extraction, the original payslip file is processed locally and is not uploaded, and our server rejects raw or unsupported document formats. If you save a Money Hub calculation, the extracted payslip figures (such as gross/net pay, tax, NI, pension and student-loan amounts) are stored in your account. Automated redaction is best effort and you can review it before anything is sent.
- Account, placement and reflective content: kept while your account is active.
- Account deletion: all records associated with your account are removed from the application database through our account-erasure process, including reflections, shift logs, placements, wellbeing and recovery entries, Money Hub calculations, wins, mentor meetings, competencies, milestones, revalidation/CPD records, feedback and other application records. Locally stored data is purged from your browser. Copies may persist in our providers' routine backups, infrastructure logs or third-party systems until they age out under those providers' own retention schedules, which SoliWard does not control.
- Voice audio: sent for transcription and then discarded; we do not store audio files.
- Inactive accounts: handled in line with our published retention policy. We do not currently operate an automated deletion schedule for inactive accounts.
- Subscription and transaction records: retained by Paddle and by us for [OWNER/LEGAL CONFIRMATION REQUIRED: confirm the retention period required to meet UK tax and accounting obligations before publication.] Complimentary or internal Plus access is recorded separately and does not create a Paddle subscription.
- Security and technical logs: kept for [OWNER/LEGAL CONFIRMATION REQUIRED: confirm the retention period for security and technical logs before publication.]
Cookies
Necessary cookies and local storage keep you signed in, remember your accessibility preferences and support offline use. SoliWard currently does not run optional advertising or analytics pixels. If optional analytics or advertising cookies are enabled in future, they will be switched off until you accept them: nothing will be loaded or sent to an advertising provider before that, and you will be able to change or withdraw your choice at any time in Settings. Withdrawing stops future optional events; data already sent to a third party cannot be recalled. Optional analytics never include your reflections, shift notes, clinical details, email or user ID. Paddle sets its own cookies during checkout to process your order. You can clear cookies and site data in your browser at any time, though this will sign you out.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent where processing is based on it. Export any reflection as a PDF from your history at any time, and delete your account from Settings. We respond to requests within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data.
Professional use guidance
Read our professional use guidance for how to use SoliWard, and its AI features, responsibly and in line with confidentiality expectations.
Contact
For any privacy question or request, email hello@soliward.co.uk. We aim to respond within one month.