Education and archived tools privacy notice
What we collect, and why.
Effective 7 September 2026 · version 14
Who is responsible
The controller is Samad Salam, trading as Doctor Tax Check, for the Doctor’s Passport website, saved free Passport and interest registrations. Questions or privacy requests can be sent to privacy@doctorspassport.co.uk. The service address is 101 Queens Drive, Liverpool, L15 7ND, United Kingdom.
Education learning lists on this device
Chapter quizzes and the Cardiology check save up to 20 active drafts (question/content versions, answers, flags, position and paused timer state) and 50 completed result snapshots in this browser. Clear those drafts and results using Practice history on My Dashboard. The progressive question preview stores its answers and history separately; use Clear practice data inside that preview to remove them. They do not sync to an account, and anyone using this browser profile can see them. Results remain snapshots when content changes; old draft versions start afresh. The optional timer pauses when the page is hidden. The tutorial remembers its choices for the current browser visit and does not add them to practice results. The homepage stays visible until you choose a feature or information page. During the current test, those homepage links open the four-question tutorial for signed-in and signed-out visitors, remembering the page you chose for afterwards. Privacy, clinical information and account actions remain directly accessible. Loading or refreshing the homepage does not automatically start the tutorial. Replay learning demo opens it when selected. Sign-in status is used to show the appropriate continue or login link. Education progress still stays on this device.
When you open a textbook chapter, its title, system, link and visit time are stored in this browser to show up to eight recently opened topics. Choosing Save topic or Review later stores that topic in a list on the same device, up to 100 topics per list. This learning data is not sent to an account, does not sync across devices and is not a measure of mastery. It remains until you remove it, use Clear learning lists in My Dashboard, or clear your browser data. Other people using the same browser profile can see these lists.
The flashcard pilot stores each reviewed card’s identifier, your chosen interval, review time and next due time in this browser. Its schedule is separate from your topic lists and remains until you clear your browser data. It does not send reminders or sync to an account.
Focus mode and text size adjust the reading display. The privacy rules below still apply to website events and the archived portfolio and pay checker. Archiving those tools does not delete existing records or change access controls.
Information we collect
If you request updates about a planned paid product, we collect the option you selected, your email address, request confirmation, current medical role, broad UK region, the first outcome you would use the Passport for, your response to the displayed price options and when you would realistically want access. We also record the page and non-personal campaign label you joined from and the version of this notice. The live form records this only as a pending, unverified contact request. It is not marketing consent, is not added to a mailing list and is not counted as a verified lead. We will not send marketing until a separate double-opt-in confirmation process is available and completed. Do not include patient, colleague, employer, rota, health or other confidential details. Pending email requests are stored separately from product-response fields.
If you sign in to the free Passport, the sign-in service provides your email address and may provide your name. We store the non-confidential fields you choose to save: preferred name, career stage, specialty, UK nation, current organisation, a current rotation or post with dates, rotation-closeout checks, a weekly-review timestamp, up to twelve saved professional goals including completed or archived history, up to 150 career-index records and up to 100 planner actions under the current fair-use limits. Career records may include a type, concise title, organisation, dates, status, a non-confidential summary, tags and a plain-text reference to where evidence is held. Planner actions may include a title, date, priority, completion time and a link to one of those records. A saved goal may include its title, type, deadline, confirmed next step, researched draft actions, suggested dates, source links and the date those sources were checked. Do not enter patient information, clinical notes, colleague details, health information or confidential organisational information. You can clear these saved fields from the Passport page. Saves use one versioned snapshot for the current Passport: each accepted change advances its revision, and an out-of-date tab must reload rather than silently replace newer information. This is concurrency protection, not a historical backup or permanent audit archive.
The public demos do not ask for or save payslips, payroll numbers, payment details, patient information or health information. Signed-in assessment drafting also runs locally in your browser: its notes and editable draft are not saved with the Passport or transmitted. Only a separate career-index pointer you deliberately create is saved. The one-free-case Money Check requires sign-in, then reads an XLSX or CSV timetable, iCalendar file and one payslip PDF in your browser. For an older rota, you may also open a PNG, JPG or WebP screenshot as a browser-local manual reference; it is displayed but not automatically extracted. You select one payslip month; only rota entries dated within that month enter the editable calendar. Every import remains an unverified draft. Teaching, Rest/off, leave, sickness and bank-holiday entries can be retained, and every date and week must be confirmed. If an imported entry is marked as sick, the checker asks for the hours and type of shift you were originally due to work; it does not ask for a diagnosis or reason for sickness. Those uploaded files, extracted text, calendar edits, sick-entry details, confirmed figures and the result are not transmitted to or stored by Doctor’s Passport. To enforce one free payslip month per signed-in account, we store a pseudonymous keyed-HMAC account key, the selected payslip month and activation timestamp. We do not store the email again in this entitlement record. Password-protected, scanned and image-only payslip PDFs are not supported.
For the current or immediately preceding month, if you paste a supported Loop Personal Roster link, your browser checks its provider and sends only the supported provider label and opaque access token to Doctor’s Passport. The server reconstructs the approved Employee Online address, retrieves that calendar once and returns it to your browser for the same local check. A provider feed may contain dates outside your selected payslip month. The response exists transiently for parsing, only entries in the selected month enter the editable calendar, and other entries are discarded from the check. The link, token, raw calendar, extracted rota fields, calendar edits and result are not written to the database, object storage or analytics, and the calendar is not refreshed automatically. The request and response exist transiently while the import is completed through the site host. Treat a Personal Roster link like a password: anyone who has it may be able to view the rota it exposes. Older payslip months use a saved timetable file, local screenshot reference or manual reconstruction because a rolling feed may no longer contain the complete month.
Goal research is optional. The source-led fallback does not send goal context to OpenAI. When live source research is available and you ask for it, Doctor’s Passport sends only the non-confidential goal context needed to prepare the response—such as goal title and type, target date, career stage, specialty and UK nation—to OpenAI. It does not send your email address, name, organisation, rota, payslip or uploaded file. OpenAI returns draft actions, dates and sources for you to review; it does not receive authority to make decisions or submit anything for you.
Basic website-action records contain an allowlisted event name, page, short-lived page-view identifier, time and non-personal campaign labels from the link used to open the page. These labels can record that a free check, free Passport or Doctor’s Brief page was opened or completed, but not the fields entered or an article-reading profile. They identify a channel or campaign, not an individual. Loop access tokens and calendar contents are excluded. Public event, interest and one-time calendar endpoints use short-lived keyed-HMAC rate buckets derived from the network address supplied by the hosting edge. The raw address and browser user-agent are not written to those buckets; the pseudonymous bucket values expire and are used only to limit abuse, not for analytics or recognition across services. We do not add advertising identifiers, cross-site fingerprints or session replay.
How we use it and our lawful bases
We use pending requests to understand unverified interest in one-off checks and Money Monitor. A request alone is not permission to email you. Marketing would rely on consent only after a separate double-opt-in confirmation step is available and completed. We rely on our legitimate interests to understand aggregated demand, compare non-personal acquisition channels, prevent duplicate requests and count a limited set of first-party interactions needed to improve the site. Those interests are balanced against the small amount of data collected and your right to object. Registering interest does not create an account, start a subscription or authorise any payment. We use the signed-in identity and saved free-Passport fields to provide the persistent record you ask us to maintain. When you actively request goal research, we process the bounded goal context to provide that requested feature. We use legitimate interests to retain the minimal pseudonymous free-check marker needed to operate and prevent repeated free-case claims. Signing in does not give marketing consent or authorise payment, and goal suggestions do not determine eligibility or official completion.
Retention
An unverified contact request expires after 30 days and is deleted on the next retention cleanup. Confirmed interest and consent records, once a double-opt-in process exists, expire after 12 months and are deleted on the next cleanup, or earlier where appropriate after consent is withdrawn. Basic website-action records are deleted within 90 days. Free-Passport fields are kept while you use the feature and are deleted from the active record when you use “Clear saved Passport” or request deletion. Unused records are reviewed periodically so they are not kept longer than needed. A minimal suppression record may be retained when needed to respect an unsubscribe. The pseudonymous free-check entitlement marker is retained while the offer operates so the one-case limit can be honoured consistently; you may ask us to erase it, in which case we may accept that the account can claim again unless a lawful suppression need applies.
Doctor’s Passport does not retain uploaded rota or payslip files, locally displayed rota screenshots, selected-month calendar entries, edits, sick-entry details, figures or free-check results. The pseudonymous account key, selected month and activation timestamp are the only free-check entitlement metadata retained. Browser-local check data is cleared when you refresh or leave the page; a Loop request and response exist only transiently while that one-time import is completed.
Storage and sharing
The site and database are hosted through ChatGPT Sites using Cloudflare infrastructure. ChatGPT sign-in identifies the user of a saved free Passport. When live source research is available, OpenAI processes the bounded non-confidential goal context only when that research is requested. The owner-only results page is restricted to the project owner; it shows only an aggregate pending-request count, not pending contact addresses. IONOS hosts the branded project mailbox and processes recipient details and message content when an email is sent. These providers act as processors or supporting service providers. Some processing may occur outside the UK; where UK data-protection law requires a transfer safeguard, the relevant provider arrangement must use an applicable adequacy decision or approved contractual safeguard. You can request further information about applicable safeguards. We do not sell this information or use it for advertising.
Your choices and rights
You can ask for access, correction, deletion, restriction or portability where applicable; object to processing based on legitimate interests; or withdraw email consent at any time by contacting us. Neither the interest list nor goal research makes decisions about eligibility, progression, employment or payment. You may complain to the UK Information Commissioner’s Office at ico.org.uk.