🔥 SUMMER SALE: Save 20% on ALL Plans & Credits with codeSUMMER20
SCA Prep

Privacy Policy

Last updated: 26/07/2025

1. Introduction

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SCA (Structured Clinical Assessment) Prep Medical Education Platform. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

The data controller responsible for your personal information is SCA Prep.

Email: hello@scaprep.co.uk

3. Information We Collect

3.1 Personal Information

  • Account Information: Email address, password (encrypted), name
  • Usage Data: Chat conversations, generated medical scenarios, case studies
  • Payment Information: Billing details processed through Stripe (we do not store card details)
  • Technical Data: IP address, browser type, device information, session data

3.2 Automatically Collected Information

  • Log files and server data
  • Cookies and similar tracking technologies
  • Analytics data for service improvement

4. How We Use Your Information

We process your personal data for the following purposes under these lawful bases:

Contractual Performance

  • Provide medical education services and AI-generated content
  • Manage your account and subscriptions
  • Process payments and billing

Legitimate Interests

  • Improve our services and develop new features
  • Conduct analytics and research
  • Prevent fraud and ensure security

Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal requests and court orders

5. Third-Party Services

We may share your information with the following third-party services:

  • OpenAI: For AI-powered content generation (subject to OpenAI's privacy policy)
  • Stripe: For payment processing (subject to Stripe's privacy policy)
  • Vercel: For hosting and infrastructure services
  • Resend: For email communications
  • Vercel Analytics: For website analytics

These third parties are contractually obligated to protect your information and use it only for specified purposes.

6. Data Retention

We retain your personal information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements

Retention Periods:

  • Account Data: Until account deletion + 30 days
  • Chat History: Until manually deleted by user or account closure
  • Payment Records: 7 years (UK tax law requirement)
  • Analytics Data: 26 months

7. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

Right of Access: Request copies of your personal data
Right of Rectification: Request correction of inaccurate data
Right of Erasure: Request deletion of your personal data
Right to Data Portability: Request transfer of your data
Right to Object: Object to processing of your personal data
Right to Restrict Processing: Request limitation of processing

To exercise these rights, please contact us at hello@scaprep.co.uk. We will respond within one month of receiving your request.

8. Cookies and Tracking

We use cookies and similar technologies to:

  • Maintain your login session
  • Remember your preferences
  • Analyze website usage
  • Improve our services

You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our service.

9. Security Measures

We implement appropriate technical and organizational security measures to protect your personal data:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Regular security assessments
  • Employee training on data protection
  • Incident response procedures

10. International Data Transfers

Some of our service providers may be located outside the UK/EEA. In such cases, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the UK Government
  • Appropriate certifications and codes of conduct

11. Medical Education Content Disclaimer

Important Notice:

Our platform generates educational medical content using artificial intelligence. This content is for educational purposes only and should not be used for actual patient diagnosis or treatment. Always consult qualified medical professionals for clinical decisions.

12. Children's Privacy

Our service is not directed to children under 16 years of age. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us immediately.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. Continued use of our service after changes constitutes acceptance of the updated policy.

14. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: hello@scaprep.co.uk