Organisation & Site-Licence Terms
Last updated August 2026. Questions? Email [email protected].
These terms apply where an organisation (a PCN, practice, federation, training hub or other employer, the “Customer”) buys seat licences or a site licence for its staff to use Medicine in Practice (the “Service”), operated by Medicine in Practice. They sit alongside, and where they conflict take precedence over, the consumer Terms for the organisation relationship. The individual named seat-holders remain bound by the consumer Terms and Privacy Policy for their own use.
1. Licence, seats & term
- Licences are annual and per named seat (or, for a site licence, cover the agreed organisation). Access is personal to each named seat-holder and must not be shared or transferred between people.
- The manager dashboard is provided so the Customer can administer its own staff’s seats and see their learning records. The Customer is responsible for who it grants manager access to.
- We invoice the Customer (purchase order and BACS accepted). Licences renew annually; seats can be added or removed at renewal.
- Licensed seats & true-up. The Customer must hold a paid seat licence for every member of staff given access to the Service, up to the licensed seat count (or, for a site licence, within the agreed organisation size band). We may reasonably audit the number of active seats in use against the number licensed. If active usage exceeds the licensed count, we will notify the Customer and invoice the excess seats at the applicable published band rate for the remainder of the current term (pro-rated), and the licensed count will be adjusted at the next renewal. Continued use of the Service confirms the Customer’s acceptance of this audit and true-up right.
- As a business customer, the consumer cancellation rights do not apply; the broader exclusions and the liability cap in clause 7 of the consumer Terms apply to you.
2. Content updates & supervision evidence
During the paid licence period we provide content updates and safety-alert corrections as described in clause 2a of the consumer Terms. The dashboard separates learner-synced formative activity from server-graded assessments and verifiable certificates, and its provenance-labelled learning-activity report can support appraisal, CQC and PCN DES supervision records. It is supporting training evidence, not a warranty or independent determination of any individual’s clinical competence.
Schedule 1: Data Processing Agreement (Art 28 UK GDPR)
This Schedule governs personal data that we process on the Customer’s instructions when we make the Customer’s staff learning records available to the Customer’s managers through the dashboard.
Roles
In respect of the Customer’s instructed processing of its staff’s learning records surfaced on the manager dashboard (staff names, work emails, progress, scores, assessment/certificate records, last-active time and the organisation audit log), the Customer is the controller and we act as processor. Separately, we remain an independent controller for account creation and security, billing/payment records, and our own legitimate-interest processing (service security, fraud prevention and product improvement): this is not a blanket “operator is processor” arrangement.
Scope & purpose of processing
Subject-matter: delivery of training and provision of a manager dashboard. Duration: the licence term (plus any short wind-down/retention period below). Nature/purpose: hosting and displaying learning records to authorised managers of the Customer. Types of data: staff names, work email addresses, learning progress, assessment and certificate records, activity/audit entries. Data subjects: the Customer’s staff who hold seats.
Our obligations as processor
- process this personal data only on the Customer’s documented instructions (these terms and the Customer’s use of the dashboard), unless required by law;
- ensure persons authorised to process it are under confidentiality obligations;
- apply appropriate technical and organisational security measures (encryption in transit, access controls, hashed credentials, audit logging, least-privilege access);
- engage sub-processors only as listed below (or on notice of changes, with a right to object), and impose equivalent data-protection terms on them;
- assist the Customer, taking account of the nature of processing, with data-subject requests and with security, breach-notification and DPIA obligations;
- notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data;
- on the end of the licence, delete or return the Customer’s personal data (and delete existing copies) except where storage is required by law; and
- make available information necessary to demonstrate compliance and allow for reasonable audits.
Sub-processors
We use the following sub-processors to deliver the Service. NHS buyers should note these when completing information-governance (DSPT) checks:
| Sub-processor | Purpose | Notes |
|---|---|---|
| Stripe | Payment processing | Card details are entered on Stripe and are never stored on our servers. |
| Amazon Web Services (AWS) | Application hosting & database | Where account, progress and payment records are stored. Hosted in the UK (London / eu-west-2) region. |
| Anthropic (api.anthropic.com) | AI patient-conversation responses (when the AI-mode Calls lab is used) | Receives the learner’s typed/spoken text for that conversation. Not used where the lab runs in scripted mode. |
| ElevenLabs | Text-to-speech voice for patient calls (when voice mode is used) | Receives the text to be spoken. |
Patients, letters and records in the training are fictional; staff should not enter real patient-identifiable information into any lab, including AI-mode calls.