Legal

Data protection

A plain-English summary of the data RTT Insight uses, how it is protected, and the responsibilities we each hold. This page is maintained by VUIT Data Labs Ltd and is not an independent certification.

Last updated: August 2026

The data behind the platform

  • RTT Insight is built on Referral-to-Treatment statistics published openly by NHS England, covering acute trusts in England across all treatment functions.
  • The figures are aggregate counts and waiting-time distributions. No patient-level records, identifiers or clinical detail are held.
  • Published data is loaded into a managed Tableau Cloud dataset and queried on demand. Users never receive raw extracts of anything beyond the published statistics.

Roles under UK GDPR

  • VUIT Data Labs Ltd is the controller for account, billing and enquiry data described in our privacy notice.
  • Where an organisation subscribes on behalf of its staff, that organisation controls who holds a seat; we process seat data on their instructions.
  • Because the analytics contain no personal data, no data processing agreement covering patient or clinical data is required. If your organisation requires a signed DPA for account data, contact us and we will provide one.

Subprocessors

  • Application and database hosting — runs the web application, authentication and database.
  • Tableau Cloud (Salesforce) — hosts the published RTT dataset the platform queries.
  • OpenAI — generates chat answers and report narrative from the questions and briefs you submit.
  • Stripe — subscription billing, invoicing and payment processing.
  • Transactional email provider — delivers account, billing and enquiry emails.

We review subprocessors before engagement and contract them to equivalent data protection obligations. We will tell account holders before adding a subprocessor that handles personal data.

Security controls in place

  • Accounts require email verification and a password; sessions are token-based and expire.
  • Database access is governed by row-level security so each account can only reach its own records.
  • Administrative functions are gated behind a separate role that is granted manually.
  • Traffic is encrypted in transit with TLS.
  • Payment card data is handled entirely by Stripe and never stored by us.
  • Credentials for the data platform are held server-side only and are never exposed to the browser.

These are the controls currently enabled in the product. They are not a claim of certification against SOC 2, ISO 27001 or any other standard.

AI and chat content

The analyst chat sends your question, the current dashboard filters and the aggregate figures needed to answer it to our AI provider. Do not paste patient-identifiable or otherwise confidential information into the chat. Chat content is not used to train third-party models.

Making a request

Data protection requests, DPA requests, security questionnaires and vulnerability reports should go to contact@rtt.vuit.online. We acknowledge within five working days and respond to rights requests within one month.