Privacy Policy
Dose-Response ("we", "us") provides a weekly research bulletin, continuing professional development (CPD) tools, and live educational seminars for clinicians, on the web and in our iOS and Android apps. This policy explains what we collect, why, the lawful basis for it, and your choices. Questions: [email protected].
What we collect
- Your email address, to send the bulletin, sign you in (passwordless one-time codes), and identify your membership.
- Discipline & interests, the taxonomy you choose (discipline, body regions, topics), used to tailor your issues.
- Your CPD content, reflections, critiques, patient cases (which you enter anonymised, with no patient-identifying details), logged external CPD, and generated certificates. This is stored so you can build your portfolio.
- Subscription & payment, if you subscribe, your plan and status. Card details are handled entirely by Stripe; we never see or store your card number.
- Education bookings, if you book a live seminar or journal club, we store your email against that session so we can confirm your place, remind you, and log your attendance to your CPD record. If you apply to join the educator panel, we store what you submit (name, email, role, specialty, links, and your pitch). If you become a panellist, your name, title, bio and photo are shown publicly on the education pages.
- Usage analytics, aggregate analytics (Cloudflare Web Analytics — cookieless) to understand how the product is used. See Cookies & tracking below.
- Crash & error diagnostics, when something goes wrong we record a technical error report (the error type, message and stack trace, the request method and page path without its query string, and an environment tag) to fix it. These reports never include your email, cookies, request headers, or the content you entered. Processed by Sentry.
- Feedback, any feedback you send us, with your email so we can follow up.
How we use it
- To deliver the bulletin and tailor it to your practice.
- To provide the CPD tools and store your portfolio, reflections and cases.
- To manage your membership and process payments.
- To improve the product and respond to your feedback.
We do not sell your personal data, and we do not use your reflections or cases for advertising.
Lawful basis
Under UK GDPR we rely on:
- Contract, to provide your membership, the CPD tools, education bookings and payments (the things you sign up for).
- Legitimate interests, to keep the service secure and working (including crash diagnostics) and to understand aggregate usage, balanced against your rights.
- Consent, for the free bulletin emails (unsubscribe any time). See Cookies & tracking.
- Legal obligation, to keep records we are required to keep, such as payment records.
Cookies & tracking
We use one essential cookie, dr_session, to keep you signed in. It is strictly necessary for the service and needs no consent.
For aggregate usage statistics we use Cloudflare Web Analytics, which is cookieless — it sets no cookies and does not track or fingerprint individuals, so under UK PECR it needs no consent banner. We do not use advertising or cross-site tracking cookies, and we do not sell data.
Who processes your data
We use trusted providers to run the service: Supabase (database), Stripe (payments), Resend (email delivery), Cloudflare (hosting & cookieless web analytics), Sentry (crash & error diagnostics), Zoom (live education sessions), and Buffer (our own social posting, no member data). Each processes data only to provide their service to us.
International transfers
Most of your data is stored in the UK/EU (our database is hosted in the London region). Some providers process data outside the UK, including in the United States (for example Stripe). Where data is transferred internationally, we rely on the provider's safeguards for such transfers, such as the UK International Data Transfer Addendum or Standard Contractual Clauses.
Patient cases
The Cases feature is for anonymised reflective learning. Please do not enter any patient-identifiable information (names, dates of birth, NHS/record numbers, or anything that could identify an individual). You remain responsible for your professional and legal obligations regarding patient confidentiality.
Data retention
We keep your account and CPD data while your account is active so your portfolio persists. You can ask us to delete your data at any time, email [email protected] and we will remove it, subject to any legal record-keeping (e.g. payment records).
Your rights
You can access, correct, export or delete your data, and object to or restrict certain processing. To exercise any of these, email [email protected]; we aim to respond within one month, as UK GDPR requires. You can unsubscribe from emails at any time via the link in any issue, and you have the right to complain to the Information Commissioner's Office (ICO).
Children
Dose-Response is intended for healthcare professionals and is not directed at children under 16.
Changes
We may update this policy; we'll change the date above and, for material changes, tell you by email.
Editorial appraisals are for professional education, not clinical advice, always read the primary source. doseresponse.org