Privacy Notice - BetterLetter Software

Privacy Notice – Use of BetterLetter at Chiddingfold Surgery

Version: 1.0
Date: 18th June 2026
Review Date: 18th June 2028

 Introduction

This privacy notice explains how Chiddingfold Surgery uses the BetterLetter system to support the processing of clinical correspondence and the maintenance of patient records.

We are committed to protecting the confidentiality, integrity, and security of your personal information and to complying with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Common Law Duty of Confidentiality, and NHS information governance requirements.

 Data Controller

Chiddingfold Surgery is the Data Controller for the personal information processed through BetterLetter.

Contact Details:

Practice Manager: Amanda Howell
Address: Ridgley Road, Chiddingfold, Godalming, Surrey GU8 4QP
Telephone: 01428 683174
Email: contacts.chiddingfold@nhs.net

 Data Protection Officer (DPO)

  • Name: Dan Clement
  • Role: Associate Director ICS Information Governance / Data Protection Officer (NHS Kent & Medway Integrated Care Board)
  • Email address: kmicb.ig@nhs.net
  • Telephone: 01634 335095
  • Postal Adress: NHS Kent and Medway, 2nd floor, Gail House, Lower Stone Street, Maidstone, ME15 6NB

 What is BetterLetter?

BetterLetter is a clinical correspondence management system used by the practice to assist in the processing of letters and documents received from hospitals, community providers, and other healthcare organisations.

 The system uses artificial intelligence and automation technologies to:

  • Process incoming clinical correspondence.
  • Identify clinically relevant information.
  • Suggest clinical coding.
  • Support workflow management.
  • Assist staff in updating patient records efficiently and accurately.

BetterLetter does not make clinical decisions. All suggested actions, coding, and updates are reviewed and authorised by appropriately trained healthcare professionals or authorised practice staff before being added to a patient's record.

Why We Use BetterLetter

We use BetterLetter to:

  • Improve the speed and accuracy of processing clinical correspondence.
  • Reduce administrative burden.
  • Improve patient safety.
  • Ensure important clinical information is recorded promptly.
  • Support continuity of care.
  • Improve data quality within patient records.

 Categories of Personal Information Processed

The information processed may include:

 Personal Information

  • Name
  • Address
  • Date of birth
  • NHS number
  • Contact details
  • Gender

Special Category Information

  • Medical history
  • Diagnoses
  • Clinical observations
  • Test results
  • Treatment plans
  • Prescriptions and medication information
  • Referral information
  • Hospital correspondence
  • Other health-related information contained within clinical letters

Source of Information

Information processed through BetterLetter is received from:

  • NHS hospitals
  • Community healthcare providers
  • Mental health services
  • Diagnostic services
  • Other GP practices
  • Independent healthcare providers involved in your care
  • Healthcare professionals involved in your treatment
  •  

Lawful Basis for Processing

Under UK GDPR, the lawful basis for processing personal information is:

Article 6(1)(e) – Public Task

 Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the practice.

Article 9(2)(h) – Health or Social Care

 Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care, or the management of health or social care systems.

 The processing is also supported by Schedule 1, Part 1 of the Data Protection Act 2018.

 Automated Processing and AI

BetterLetter uses artificial intelligence and machine learning technologies to assist with document processing and coding suggestions.

 The system:

  • Does not make automated clinical decisions about patients.
  • Does not determine treatment plans.
  • Does not replace clinical judgement.
  • Operates only as a decision-support tool.

All outputs generated by BetterLetter are reviewed by authorised practice staff before any information is accepted into the patient record.

 The practice does not rely solely on automated decision-making that produces legal or similarly significant effects on patients.

 Data Sharing

Information may be shared where necessary with:

  • NHS England
  • Integrated Care Boards (ICBs)
  • Hospitals and specialist providers
  • Community healthcare services
  • Other organisations involved in your direct care
  • Regulatory bodies where legally required

 Information is shared only where there is a lawful basis to do so and in accordance with NHS confidentiality requirements.

BetterLetter as Data Processor

BetterLetter acts as a Data Processor on behalf of the practice.

 A written Data Processing Agreement is in place to ensure that:

  • Information is processed only on documented instructions from the practice.
  • Appropriate security measures are maintained.
  • Confidentiality obligations apply to all personnel.
  • Data is protected against unauthorised access, loss, alteration, or disclosure.
  •  

International Transfers

Patient information processed through BetterLetter is not routinely transferred outside the United Kingdom.

 Where any international processing occurs, appropriate safeguards required by UK GDPR will be implemented.

 Data Security

The practice and BetterLetter implement appropriate technical and organisational security measures including:

  • Encryption of data in transit and at rest.
  • Access controls and authentication measures.
  • Audit logging and monitoring.
  • Staff confidentiality training.
  • Regular security reviews.
  • NHS information governance compliance requirements.

Retention of Information

Patient information remains part of the GP medical record and is retained in accordance with:

  • NHS Records Management Code of Practice.
  • Applicable legal and regulatory requirements.

 Records are not retained for longer than necessary.

Your Rights

Under UK GDPR, you have the right to:

Be informed about how your information is used.

  • Access your personal information.
  • Request correction of inaccurate information.
  • Request restriction of processing in certain circumstances.
  • Object to processing where applicable.
  • Request data portability where applicable.
  • Lodge a complaint regarding the use of your information.

Some rights may be limited where information is processed for healthcare purposes or where exemptions apply under law.

 Accessing Your Information

You may request access to your personal information by contacting the practice.

Requests should be made to:

 Chiddingfold Surgery

Ridgley Road

Chiddingfold

Godalming

Surrey

GU8 4QP

 Email: contacts.chiddingfold@nhs.net

Complaints

If you have concerns about how your information is handled, please contact the Office Manager or Data Protection Officer in the first instance.

 You also have the right to complain to:

 Information Commissioner's Office (ICO)

Information Commissioner's Office (ICO)

Telephone: 0303 123 1113

 Changes to This Privacy Notice

We may update this privacy notice from time to time to reflect changes in legislation, guidance, or our processing activities. The latest version will always be available from the practice website and reception.

Approved by: Amanda Howell - Practice Manager
Document Owner: Amanda Howell

Version: 1.0
Review Date: 18th June 2025

Date Published: 18th June, 2026
Date Last Updated: 18th June, 2026