DocMap Logo
← Back to Policies and Terms

DocMap WhatsApp Service (Specialist Triage)

Terms & GDPR Compliance

These policies apply specifically to the DocMap WhatsApp Service. For our broader privacy notice covering both the booking platform and the WhatsApp Service, see the DocMap Privacy Policy.

Section 1

Terms of Service

These terms govern your use of DocMap Specialist Triage (the “DocMap WhatsApp Service”), operated by DocMap Ltd. They are separate from, and additional to, any terms governing the DocMap booking platform.

Last updated: March 2026

1. About the Service

DocMap Specialist Triage (“DocMap”, “the Service”) is a healthcare specialist search and triage tool operated by DocMap Ltd (“DocMap”, “we”, “us”, “our”), a company registered in England and Wales.

The Service helps patients find and connect with trusted women's health specialists for diagnosis, symptom management, and surgical care. It is accessible via:

  • WhatsApp: Our business messaging channel for patient interactions
  • Web dashboard: An operator tool for clinical operations staff

2. Acceptance of terms

By using the Service — whether by sending a message to our WhatsApp number, using the web dashboard, or otherwise interacting with DocMap — you agree to be bound by these Terms of Service and the DocMap WhatsApp Service section of our Privacy Policy.

If you do not agree with these terms, please do not use the Service.

3. Description of the Service

DocMap provides the following:

  • Specialist search: AI-assisted matching of patients with healthcare specialists based on condition, location, insurance, and preferences
  • Triage assistance: Conversational AI that helps classify patient needs and suggest appropriate specialist referrals
  • Case management: Tools for our operators to manage patient conversations and referral workflows
  • WhatsApp messaging: A secure channel for patients to describe their needs and receive specialist recommendations

4. Important medical disclaimers

DocMap is NOT a medical service. Please read the following carefully:

  • We do not provide medical diagnoses, medical advice, or clinical treatment.
  • We do not replace the relationship between you and your healthcare provider.
  • Our AI-generated recommendations are suggestions only and are always reviewed by a human operator before being shared with you.
  • Specialist recommendations are based on publicly available information and do not constitute an endorsement or guarantee of care quality.
  • If you are experiencing a medical emergency, call 999 immediately. Do not use this Service for emergencies.

The Service is a referral facilitation tool — we help connect you with specialists, but all clinical decisions remain between you and your chosen healthcare professional.

5. Eligibility

The Service is available to:

  • Individuals aged 18 or over who are seeking specialist healthcare referrals
  • Healthcare operators and administrators authorised by DocMap to use the dashboard

We reserve the right to refuse or discontinue service to any individual at our discretion.

6. Patient responsibilities

When using the Service, you agree to:

  • Provide accurate and truthful information about your health needs
  • Not use the Service for emergency medical situations (call 999 instead)
  • Not send abusive, threatening, or inappropriate messages
  • Not impersonate another person or send messages on behalf of someone without their explicit consent
  • Not use the Service for any unlawful purpose
  • Understand that our recommendations are informational and do not constitute medical advice

7. How the Service works

7.1 WhatsApp channel

When you message our WhatsApp number for the first time:

  1. You will receive an automated greeting explaining the Service and how we use your information.
  2. You will be asked to agree to processing of your health-related information for triage and referral facilitation.
  3. Our systems may use AI to classify your needs and match specialists; outputs are subject to human review.
  4. A human operator will review AI recommendations before any specialist suggestions are shared with you.
  5. Conversations are stored securely in accordance with our data retention policy.

7.2 AI processing

We use artificial intelligence to:

  • Understand the intent of your messages
  • Search our database of specialist profiles
  • Generate draft recommendations for operator review
  • Summarise conversations for case management

All AI outputs are reviewed by human operators before being communicated to you. We do not use fully automated decision-making that produces legal or similarly significant effects.

7.3 Specialist information

Specialist profiles displayed in the Service are compiled from publicly available sources including:

  • Professional body registrations (GMC, HCPC)
  • Hospital and clinic websites
  • Independent healthcare review platforms
  • Insurance network directories

We make reasonable efforts to keep specialist information accurate and up-to-date, but we do not guarantee the accuracy, completeness, or currency of any specialist profile. Always verify details directly with the specialist or their practice.

8. Data protection

We take data protection seriously, particularly given the sensitive nature of health data. Full details are set out in the DocMap WhatsApp Service section of our Privacy Policy.

Key points:

  • Your health data is special category data under UK GDPR and is processed with your explicit consent
  • Data is stored on encrypted servers in the EU (primarily London, eu-west-2)
  • You can request access to, correction of, or deletion of your data at any time
  • You can withdraw consent at any time by messaging “Withdraw consent” on WhatsApp or emailing admin@docmap.co.uk

9. Intellectual property

All content, software, designs, logos, and trademarks associated with DocMap are the property of DocMap Ltd or its licensors. You may not:

  • Copy, modify, distribute, or reverse-engineer any part of the Service
  • Use the DocMap name, logo, or branding without prior written permission
  • Scrape, crawl, or programmatically access the Service without authorisation

10. Limitation of liability

To the fullest extent permitted by law:

  • The Service is provided “as is” and “as available” without warranties of any kind.
  • We do not warrant that the Service will be uninterrupted, error-free, or free from harmful components.
  • We are not liable for any decisions you make based on specialist recommendations.
  • We are not liable for the quality of care provided by any specialist you choose to consult.
  • Our total liability to you for any claim arising from or related to the Service shall not exceed £100.

Nothing in these terms excludes or limits our liability for:

  • Death or personal injury caused by our negligence
  • Fraud or fraudulent misrepresentation
  • Any other liability that cannot be excluded or limited by law

11. Indemnification

You agree to indemnify and hold harmless DocMap Ltd, its directors, employees, and agents from any claims, damages, losses, or expenses (including legal fees) arising from:

  • Your use of the Service
  • Your breach of these Terms
  • Your violation of any law or the rights of any third party

12. Termination

We may suspend or terminate your access to the Service at any time, with or without cause, and with or without notice.

You may stop using the Service at any time. If you wish to have your data deleted, see the Data Subject Rights section of our Privacy Policy.

Upon termination, provisions relating to intellectual property, limitation of liability, indemnification, and governing law shall survive.

13. Changes to these terms

We may update these Terms of Service from time to time. Material changes will be communicated via:

  • A notice on our website
  • A message on WhatsApp (for active patients)

Continued use of the Service after changes constitutes acceptance of the updated terms.

14. Governing law and jurisdiction

These Terms are governed by the laws of England and Wales. Any disputes arising from or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.

15. Severability

If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

16. Contact us

For questions about these Terms of Service:

General
support@docmap.co.uk
Admin / data protection
admin@docmap.co.uk
Post
DocMap Ltd, 1601 Jasper Walk, London N1 7TW

Section 2

GDPR Compliance Statement

Overview

DocMap Ltd (“we”, “us”) is committed to protecting the privacy and security of personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This statement summarises our GDPR compliance measures for the DocMap WhatsApp Service (Specialist Triage). It complements the DocMap WhatsApp Service section of our Privacy Policy.

1. Data Controller

Organisation
DocMap Ltd
Role
Data Controller
Privacy / data protection contact
admin@docmap.co.uk
Supervisory authority
Information Commissioner's Office (ICO)

2. Lawful Basis for Processing

WhatsApp triage: messages, AI classification, specialist matching, conversation history

Data type: Health data

Lawful basis: Consent (Art. 6(1)(a)); explicit consent (Art. 9(2)(a))

Internal operator notifications (e.g. new conversation alerts)

Data type: Contact / identifiers

Lawful basis: Legitimate interests (Art. 6(1)(f)) — not for unrelated marketing

Legal compliance and record-keeping

Data type: All categories

Lawful basis: Legal obligation (Art. 6(1)(c)) where applicable

Health data is not processed using Article 9(2)(h) for the core triage service (see the “Special category data” section of the WhatsApp Service privacy notice). Observability traces may contain message content: they are pseudonymised where technically possible and are subject to retention limits.

3. Data Processing Activities

3.1 Patient data (via WhatsApp)

Collection:
Patients initiate contact by messaging our WhatsApp Business number. They receive an automated notice explaining processing. A recorded affirmative consent step for automated health-data processing is implemented.
Processing:
Messages may be classified by AI to understand patient needs. Specialists are matched using vector search against a database of publicly available specialist profiles.
Storage:
Messages and case records are stored in encrypted databases (AWS DynamoDB, eu-west-2). Temporary cache data is stored in encrypted Redis (Upstash, EU).
Retention:
Active conversation data is retained for 12 months. Session data expires within 24 hours to 7 days.
Deletion:
Automated deletion after retention period. Manual deletion available on request.

3.2 Operator data (dashboard users)

Collection:
Username and authentication credentials for authorised operators.
Processing:
Session management for dashboard access.
Storage:
Credentials are stored in environment configuration (not in the database).
Retention:
Active while the operator account exists.

4. Data Subject Rights

We facilitate the following rights for all data subjects:

Access (Art. 15)

How to exercise: Email admin@docmap.co.uk or message "Access my data" on WhatsApp

Response time: 30 days

Rectification (Art. 16)

How to exercise: Email admin@docmap.co.uk with correction details

Response time: 30 days

Erasure (Art. 17)

How to exercise: Email admin@docmap.co.uk or message "Delete my data" on WhatsApp

Response time: 30 days

Restrict processing (Art. 18)

How to exercise: Email admin@docmap.co.uk

Response time: 30 days

Data portability (Art. 20)

How to exercise: Email admin@docmap.co.uk requesting JSON export

Response time: 30 days

Object (Art. 21)

How to exercise: Email admin@docmap.co.uk

Response time: 30 days

Withdraw consent

How to exercise: Message "Withdraw consent" on WhatsApp or email admin@docmap.co.uk

Response time: Without undue delay

Erasure requests trigger deletion from live systems including:

  • DynamoDB (patient records, message archives, case data)
  • Redis (conversation cache, session data, greeting flags)
  • Observability traces where they contain identifiable or re-identifiable content

Backups may retain data for a limited period after live deletion — see Section 8 of the WhatsApp Service privacy notice.

5. Data Processors and International Transfers

Amazon Web Services

Role: Infrastructure (DynamoDB, SES)

Location: EU (London)

Transfer safeguard: UK Adequacy; AWS DPA

Upstash

Role: Redis cache

Location: EU

Transfer safeguard: DPA; EU hosting

Meta Platforms

Role: WhatsApp Business API

Location: EU/US

Transfer safeguard: Meta DPA; EU–US Data Privacy Framework

OpenRouter

Role: LLM inference

Location: US

Transfer safeguard: DPA; Standard Contractual Clauses

Pinecone

Role: Vector search (specialist profiles only)

Location: US

Transfer safeguard: DPA; SCCs; configuration-dependent

Langfuse (or equivalent)

Role: LLM observability / traces

Location: Per provider

Transfer safeguard: DPA; may include US transfers

All processors are bound by Data Processing Agreements (DPAs) that require:

  • Processing only on our documented instructions
  • Appropriate technical and organisational security measures
  • Notification of personal data breaches without undue delay
  • Deletion or return of data upon termination of the agreement

6. Technical and Organisational Measures

Security

  • Encryption at rest: AES-256 for all databases (DynamoDB SSE, Upstash encryption)
  • Encryption in transit: TLS 1.2+ for all API communications and data transfers
  • Authentication: Operator access requires authenticated sessions; webhook payloads are verified using HMAC-SHA256
  • Access control: Principle of least privilege applied to service credentials (IAM policies)
  • Input validation: All incoming data is validated and sanitised

Privacy by design

  • Phone numbers are masked in internal notifications (last 4 digits only)
  • AI observability traces use pseudonymised session identifiers where possible
  • Specialist search queries are transient — patient text is not stored in the search index
  • Data minimisation: we collect only what is necessary for the triage service

Breach notification

In the event of a personal data breach:

  • We will notify the ICO within 72 hours of becoming aware of a breach that is likely to result in a risk to individuals' rights and freedoms
  • We will notify affected data subjects without undue delay where the breach is likely to result in a high risk
  • We maintain a breach register documenting all incidents, their effects, and remedial actions

7. Data Protection Impact Assessment (DPIA)

Given that we process health data (special category) at scale using AI systems, we have conducted a Data Protection Impact Assessment in accordance with Article 35 of UK GDPR. Key findings and mitigations are documented internally and reviewed quarterly.

8. Records of Processing Activities (ROPA)

We maintain Records of Processing Activities as required by Article 30 of UK GDPR. These records document:

  • Categories of data subjects and personal data
  • Purposes of processing
  • Categories of recipients
  • International transfers and safeguards
  • Retention periods
  • Technical and organisational security measures

These records are available to the ICO upon request.

9. Data Protection Officer

For organisations of our size, appointing a formal DPO is not mandatory under UK GDPR. However, all data protection enquiries are handled by our designated privacy lead:

Email: admin@docmap.co.uk

10. Complaints

If you believe we have not handled your data appropriately, you may:

  1. Contact us at admin@docmap.co.uk — we will investigate and respond within 30 days
  2. Lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk

11. Review

This GDPR Compliance Statement is reviewed and updated at least annually, or whenever there are material changes to our data processing activities.