Security, privacy, and the boring bits.
This page is maintained by Cooply Solutions Ltd to answer common security and privacy questions about DoseTrend. It describes controls that are enabled today and how we handle customer data. It is not an independent audit or certification.
Sign-in and account controls.
- Email + password with optional TOTP multi-factor authentication.
- SSO (SAML) available on Portfolio tier.
- Role-based access: owner, admin, finance, analyst, viewer.
- Session revocation and password reset via the account settings page.
What we hold, and for how long.
DoseTrend is built on open NHS data (NHSBSA English Prescribing Data, Secondary Care Medicines Data, ODS reference data) under the Open Government Licence v3.0. No patient identifiers are held.
Customer-specific data is limited to account details (name, email, workspace), subscription state, saved views, exports, and audit logs. See our privacy policy for the full list, lawful bases, and retention periods.
Where DoseTrend runs.
DoseTrend is hosted in UK/EU regions. Data at rest is encrypted; data in transit uses TLS 1.2 or higher. Backups are taken daily and retained for 30 days.
Current subprocessors: hosting infrastructure, transactional email, payment processing, error monitoring. The current list is available on request from hello@dosetrend.com.
If something goes wrong.
Email security@dosetrend.com with details of any suspected vulnerability or incident. We aim to acknowledge within one working day.
In the event of a personal data breach affecting customers, we notify affected workspaces without undue delay and, where required, the ICO within 72 hours.
What we can and can't claim.
DoseTrend operates under UK GDPR and the Data Protection Act 2018. Cooply Solutions Ltd is registered with the ICO (ZB137657). We are not currently SOC 2, ISO 27001 or HIPAA certified; if you require a certification for procurement, tell us in your application and we'll be straight about where we're at.
Last reviewed: 10 July 2026.