Patient Compass Carebit Connector privacy notice
Last updated:
Scope and responsibilities
GGO Systems Limited publishes the Patient Compass Carebit browser extension. It is a staff tool used with a separately installed, practice-operated local connector. The practice controls access to its Carebit account and is responsible for its patient records, staff authorisation and local document retention.
This notice covers the browser extension and the Windows local connector, including the 0.2.0 beta. Carebit and The Helm are separate services with their own applicable privacy notices.
Information used by the connector
When a staff member starts a handoff, the extension reads the selected Carebit record’s identifier from its URL. It does not read the patient’s name, notes or clinical record body from the page. It keeps the record identifier, relevant tab references and workflow status in browser session storage to bind the letter to the intended record.
The extension receives the reviewed guide letter from The Helm and passes it to the local connector. The letter may include guide links, a QR code and an access code. The connector renders a PDF locally and stores it with the recipient association and upload-reconciliation records. These materials must be treated as confidential practice records. The extension does not send the Carebit record identifier or generated PDF back to The Helm.
Where information goes
After a staff member reviews the PDF and confirms the original recipient, the local connector sends the PDF and recipient association to the practice’s Carebit service to create a draft. It does not enable sharing or notifications. Staff review and any subsequent sending take place separately in Carebit.
The connector does not send operational records to a publisher analytics or telemetry service. It contains no advertising or profiling and does not sell user data. Information is used for document preparation and the associated confirmation and reconciliation workflow, not for unrelated purposes, creditworthiness or lending decisions.
Browser-store installation and update services, and any PDF viewer used by the practice, are separate products with their own applicable privacy notices.
Credentials and storage
The Windows connector stores practice API credentials encrypted for the current Windows user using Windows Data Protection. The browser extension and The Helm do not receive these credentials. The local connector decrypts them in memory when authenticating to Carebit.
Browser handoff context is held in session storage. Local PDFs, recipient associations and reconciliation records persist after the browser closes. Disconnecting the connector does not delete those records or credentials. This beta does not perform automatic retention-based deletion. The practice must specify and implement its retention and secure-disposal procedure, including reconciliation of uncertain uploads before removing relevant records.
The Windows connector restricts its data folder to the current user and system or administrator access. This does not replace the practice’s device security, account access and backup controls.
Changes and patient-record enquiries
This notice will be reviewed when the connector’s data handling changes. Direct patient-record access, correction or deletion requests, and questions about a letter, to the responsible practice.
Do not send patient records, access codes, documents or credentials to the publisher for support.
Publisher contact
For questions about the extension, contact GGO Systems Limited:
info@ggo-systems.comRegistered in England & Wales, company number 17268411. Registered office: 68 Ambergate Street, London, SE17 3RX, United Kingdom.