Healing Process policy suite
Individual, Patient and Carer App Terms
1. Purpose
To define the conditions under which an individual, patient or authorised carer may use Healing Process, including the distinction between private personal record mode and a provider-linked care pathway.
2. Scope and status
These draft terms apply to the authenticated individual app. Deployment-specific information must identify the provider, controller, service hours, support, urgent route, jurisdiction, eligibility, app-store terms and any charges before acceptance.
Deployment-specific policy framework
3. Policy principles
- The app is supplementary. It does not diagnose, prescribe treatment, guarantee healing, provide emergency care or replace examination and professional judgement.
- Private mode is not monitored. Linked mode exists only where the app names the participating service and its operating arrangements.
- The user must seek urgent help independently when needed and must not wait for an app indicator or message.
- The original photograph is retained; any aligned or analysed view can be inaccurate and is not a clinical conclusion.
4. Mandatory requirements
- The user provides accurate account and episode information, protects credentials, confirms the correct wound/skin area and follows capture instructions without disturbing care unsafely.
- A carer uses an authorised carer account, acts within authority, respects the person’s wishes and privacy and does not impersonate them.
- The user follows the care plan and does not change dressings, medicines or treatment because of app content alone.
- Messaging is used only for the purpose and hours shown. Submitted does not mean reviewed; urgent alternatives remain available.
- Users do not upload unrelated people, unlawful content, external filters, malicious code or images obtained without authority.
- Access may be restricted for safety, security, misuse, expired provider enrolment or contract end, with an appropriate route to obtain records and continue care.
- Privacy information explains controller roles, data use, sharing, retention and rights. Separate permission is needed for unrelated research or AI training where applicable.
- Service availability depends on networks and providers; downtime status and alternative routes are part of the service information.
- These terms do not remove legal rights or the provider’s clinical responsibilities and should be reviewed by UK counsel before production use.
5. Procedure and escalation
- Acceptance records the term version, role, date/time and linked provider where applicable.
- A material change affecting care, data or responsibility is presented clearly and, where necessary, requires renewed acceptance or provider agreement.
- Account closure follows provider and records rules; clinically required records may remain even when ordinary access ends.
- Complaints, privacy requests, safety concerns and urgent medical needs use separate, clearly labelled routes.
6. Roles and responsibilities
User/carer
uses the app honestly, safely and within authority.
Provider
owns linked-pathway care, monitoring, staffing, response and local information.
Product operator
supplies and supports the product within approved scope.
App stores/device providers
may apply separate platform terms.
Legal/Clinical leads
keep wording aligned with service and evidence.
7. Records, confidentiality and retention
Keep acceptance, role/authority, provider linkage, terms versions, notices, account actions, misuse, complaints and exit records according to applicable schedules.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review before every live deployment and after material product, provider, legal, privacy or regulatory change. Test comprehension with intended users and accessible formats.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
- Consent and Proxy Access Policy
- Acceptable Use Policy
- Data Protection Policy
- Safety and Urgent Action page
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
