Built around accountable records

Security and Data Protection

HapMetrix is designed to support a practice’s responsible handling of sensitive case information through access controls, records of activity and documented operational safeguards.

Access registerCase controls

WHO CAN SEE THE CLINICAL RECORDS

Case access

Lead practitionerClinical recording and case work
Authorised
Client contactRelevant case and progress view
Granted
TutorCase access can be revoked
Managed

Access is tied to roles and cases

HapMetrix uses practice memberships, case capabilities and specific access workflows to control what users can view or do. This includes different pathways for practice owners, practitioners, tutors, client contacts and back-office users. Multi-factor authentication is enforced for applicable accounts.

Permissions and access

Role and case capabilities determine access to actions such as clinical recording, billing and practice administration. Client and tutor access can be granted or revoked through the application.

History and audit

Case history and audit records provide oversight of activity. The service includes an audit chain and records for relevant events and access decisions.

Contracts and consent

Contract signing, consent records and case access registers help practices keep the relevant evidence alongside the case—not as a replacement for professional judgement or legal advice.

Protection for service data

Production traffic is protected with HTTPS and TLS. The documented production setup uses encrypted storage for the database and uploaded files. Application-level field encryption is not currently implemented; the service relies on transport encryption, encrypted storage and access-control and audit layers.

HapMetrix supports a practice’s governance and data-protection responsibilities. It does not make a practice automatically compliant with any law, code or professional obligation.

Backups, retention and operational support

Documented backup arrangements use coordinated database and document recovery sets in AWS eu-north-1 (Stockholm, EEA), with encrypted storage and a defined retention cycle. The product also has workflows for data-subject requests, export and erasure or anonymisation. Erased live data may remain in existing backups until the backup-retention cycle expires.

Current service sub-processors documented in the product include AWS for hosting, compute and storage, Resend for transactional email, Sentry for error monitoring, Stripe for payments and Anthropic for AI-assisted support and engineering investigations when a practice asks us to examine an issue. Ask us for the current service privacy and data-processing information relevant to your practice.

Discuss your practice’s requirements

For service privacy, data-processing or security questions, contact the HapMetrix team.

Ask about privacy