Skip to content
Trust

Data Governance

Clinical data is a privilege, not an entitlement. These are the principles that govern how we handle it, written to satisfy your legal, privacy, and security teams.

Last updated: 11 July 2026

Governance is built into how the platform works, not bolted on afterward. The commitments below apply to any clinical data handled through a partnership. They are summarized here and made binding in the specific agreement we sign with each institution.

Institutional ownership

Data contributed by a partner remains the property of that institution and its patients. We act only within the scope you define. You may audit, restrict, or end our use in line with our agreement, and we return or delete data on request.

Privacy by design

The platform is built to operate without holding on to patient-identifying information, and patient videos are not permanently stored as part of routine product operation. Privacy is a design requirement, not an afterthought.

Consent and lawful basis

We only work with data that has an appropriate lawful basis and, where required, the necessary approvals. We support your consent framework and will not use data beyond the purposes you have authorized.

Data minimization and purpose limitation

We use only what a project needs, only for the agreed purpose, and avoid retaining anything we do not require. Scope is defined for each engagement.

Governed improvement

Our AI improves through careful, validated development. Improvement never depends on quietly retaining or repurposing customer data, and we do not use one partner’s data to serve another without explicit, written agreement.

Access control and isolation

Access is least-privilege and role-based, and access is logged. Data from different institutions is kept separate and isolated.

Retention and deletion

We retain data only for the duration and purpose set out in our agreement. On expiry or request, we delete or return it and can provide confirmation.

Service providers

Where we rely on infrastructure providers, they are bound by data-protection terms consistent with these commitments. We can share our current list with partners under agreement.

Incident response

We maintain an incident-response process and will notify affected partners without undue delay in the event of a data incident, consistent with our contractual and legal obligations. See our Security page.

To discuss a data-governance framework for your institution, contact security@trigone.net.

Questions about this document? Contact contact@trigone.net. For related policies, see our Privacy, Security, and Data Governance pages.