Who is responsible for your information?
For patient, clinician and clinic-administrator accounts, the organisation that created or manages the account normally decides why and how the information is used. It is usually the data controller, and Strange Duck Labs acts as its technology provider and data processor.
For information collected directly through the public NeuroLog website, such as essential security logs or a direct support enquiry, Strange Duck Labs may act as the data controller.
Information NeuroLog may hold
- Account details, such as your name, email address, preferred name, role and organisation.
- Daily check-ins and journal information you choose to record, including treatment, sleep, wellbeing, focus, mood, energy, appetite, side effects and personal notes.
- Clinician-access requests, approvals, revocations and related audit records.
- Technical and security information, such as sign-in activity, timestamps, device or browser details and error logs.
- Support communications and information you provide when asking for help.
Some information entered into NeuroLog may be health data and therefore receives additional protection under UK data-protection law.
Why the information is used
- To provide and secure your NeuroLog account.
- To preserve the entries you choose to record and present them back to you.
- To let you grant, review and withdraw clinician access.
- To produce summaries and reports you or an authorised clinician request.
- To maintain reliability, investigate faults, prevent misuse and meet legal obligations.
The controller for your account is responsible for identifying the appropriate lawful basis under the UK GDPR and, where health information is involved, the relevant additional condition for processing. NeuroLog does not sell personal information or use treatment entries for advertising.
Who can see or receive it?
Your entries are available to you and to clinicians you have authorised, subject to the permissions and controls used by your organisation. Authorised clinic administrators may access account and operational information where their role requires it.
Information may also be handled by carefully selected hosting, email, backup, security or technical-support providers acting under contract. It may be disclosed where required by law, to protect people from serious harm, or to establish or defend legal rights.
Retention and security
Your organisation determines how long account and clinical information must be retained. Technical logs and backups may be kept for shorter operational periods or for as long as reasonably required for security, recovery and legal obligations.
NeuroLog uses access controls, tenant separation, audit records, secure sessions and other organisational and technical safeguards. No online service can promise absolute security, but the platform is designed to restrict information to authorised people and uses continuous security review as it develops.
Your rights
Depending on the circumstances and the lawful basis being used, you may have rights to be informed, access your information, correct it, erase it, restrict or object to processing, receive portable data, and complain about how it is handled.
Start by contacting the clinic or organisation that provided your account. It can identify the controller and handle your request. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
Emergency and medical information
NeuroLog is not an emergency service and is not monitored for urgent messages. It does not provide medical advice, diagnosis or treatment recommendations. If you need urgent medical help, use the appropriate NHS or emergency service rather than entering the information into NeuroLog and waiting for a response.
Changes to this notice
This notice may be updated when NeuroLog’s features, providers or legal obligations change. The date at the top of the page shows the latest published version. Material changes will be communicated through the service or by the organisation responsible for your account where appropriate.