Privacy Notice

Last updated: 24 August 2026 · Breakthrough Medical Solutions Ltd

This privacy notice explains how Breakthrough Medical Solutions Ltd ("Breakthrough", "we", "us" or "our") collects, uses, stores and shares personal information when you use our website, learning platform or related services, contact us, or interact with us as a student, educator, institutional customer, supplier or business contact.

Some categories below apply only where the relevant feature is enabled. For example, payment information, profile photographs, session recordings or reasonable-adjustment information are only processed where those functions are used. We review this notice when our processing changes materially.

1. Contact details

Organisation: Breakthrough Medical Solutions Ltd

Email: info@breakthrough-med.com

Website: https://breakthrough-med.com

Postal contact: You may also write to our registered office address as recorded at Companies House.

2. Our role as controller and processor

Breakthrough can act as both a data controller and a data processor, depending on the processing activity. We are not both for the same processing activity.

  • Controller: we act as controller where we decide why and how personal information is used, for example for our website, direct customer relationships, account administration where we determine the purpose, payments and billing, security, business development and marketing, support and complaints, legal compliance, and product/service improvement carried out for our own purposes.
  • Processor: where a university, medical school or other educational organisation determines the purposes and essential means of processing student or educator information through Breakthrough, we may process that information on the organisation’s documented instructions. In those circumstances, the educational organisation is the controller and its privacy notice and our data-processing agreement with it also apply.

If you are using Breakthrough through an educational organisation, you may contact either us or that organisation about your data. Where we are acting only as processor, we may need to pass your request to the relevant controller and assist it in responding.

3. What personal information we collect and use

Depending on your relationship with us and the features enabled, we may collect or use:

Service, account and customer information

  • Names and contact details, including email address and telephone number where provided.
  • Postal or billing addresses.
  • Organisation or university affiliation, professional role, course and year of study where applicable.
  • Account and registration information, authentication information and information used for security purposes.
  • Purchase, subscription, licence, account and service history.
  • Payment and financial transaction information. Where a specialist payment provider is used, it may process full card or bank details directly and we may receive only limited billing details and payment status.
  • Marketing preferences and records of consent or opt-out.
  • Records of meetings, decisions, correspondence, compliments, complaints and support interactions.

Learning-platform and technical information

  • Educational activity and performance information, including case responses, decisions, scores, progress, team activity, facilitator interactions and other interactions with the learning platform.
  • Website and app user-journey information, IP addresses, browser/device information, logs, diagnostics and cookie/analytics information where applicable.
  • Profile photographs or other images uploaded to the service where that feature is used.
  • Session, video or call recordings and screenshots where recording or troubleshooting features are enabled.
  • AI interactions and related prompts/outputs where an AI-enabled feature is used. Breakthrough is not intended for patient-identifiable information and users should not enter patient-identifiable or unnecessary sensitive personal information into AI features.

Reasonable adjustments and health information

Where a user requests a reasonable adjustment or accessibility support, we may process information about the adjustment required and, only where necessary, information about a disability, learning difficulty or health condition. Where possible, we ask for the adjustment needed rather than a diagnosis.

Health information is special category data and receives additional protection. Where Breakthrough determines this processing itself, we normally rely on your explicit consent under Article 9(2)(a) UK GDPR. You may withdraw that consent at any time, although this does not affect processing already carried out lawfully. Where we process reasonable-adjustment information solely on behalf of an educational organisation, that organisation determines the relevant lawful basis and special-category condition and we process the information on its instructions.

If health information becomes relevant to a complaint or legal dispute, we may also process it where necessary for the establishment, exercise or defence of legal claims.

4. Why we use personal information and our lawful bases

PurposeLawful basis
Provide and administer the Breakthrough service, licences, payments and customer relationshipsContract where processing is necessary to enter into or perform a contract with you; legitimate interests where users access the service through an organisation or where proportionate administration is not strictly contractual.
Create, administer and secure accounts; authenticate users; prevent misuse; maintain service reliabilityContract and legitimate interests in operating a secure and reliable service.
Operate the learning platform, understand usage, evaluate and improve the service, and provide authorised educators/organisations with relevant activity and performance informationLegitimate interests where Breakthrough determines this processing. Where we act as processor, we process on the educational organisation’s documented instructions and the organisation determines the lawful basis.
Respond to queries, troubleshoot technical issues, investigate complaints and resolve disputesContract where relevant to the service relationship; legitimate interests in providing support, correcting issues, resolving disputes and protecting the rights and interests of users, customers and Breakthrough.
Comply with tax, accounting, regulatory, data-protection and other legal requirementsLegal obligation.
Send service communications and important operational updatesContract and/or legitimate interests, depending on the communication.
Business development and direct marketing to existing or prospective institutional customers and professional contactsLegitimate interests for proportionate B2B marketing where permitted; consent where required or where you have opted in. You can opt out of direct marketing at any time.
Process reasonable-adjustment or health information where Breakthrough is controllerAn applicable Article 6 basis above plus Article 9(2)(a) explicit consent. For legal claims, Article 9(2)(f) may apply where necessary.

Our legitimate interests include operating, maintaining, securing and improving Breakthrough; administering access; supporting users and organisations; understanding proportionate platform usage; preventing misuse; resolving disputes; and communicating with relevant institutional customers and professional contacts. We balance these interests against individuals’ rights and expectations, minimise the information used, and do not rely on legitimate interests where those interests are overridden by the rights and freedoms of the individual.

5. Users under 18

Breakthrough is designed primarily for higher-education learners and educators, but some university students may be under 18, including 17-year-old students. We therefore treat the service as potentially accessible to children for data-protection purposes and consider the ICO Children’s Code when designing relevant online features.

  • We aim to provide privacy information in clear, concise language that older teenage users can understand.
  • We use data minimisation and high-privacy defaults for under-18 users where appropriate.
  • We do not use personal information of users we know are under 18 for targeted direct marketing.
  • We do not require users to disclose more health or disability information than is reasonably necessary to provide an adjustment.
  • We assess new features that may materially affect under-18 users against the privacy and best-interest principles in the Children’s Code.

6. Where we get personal information from

  • Directly from you, including through account registration, platform use, support requests, forms and communications.
  • Universities, medical schools, colleges and other educational organisations that provision or administer access to Breakthrough.
  • Publicly available sources, such as university websites, professional directories, publications, conference information and professional networking platforms, particularly for B2B business development.
  • Suppliers and service providers, for example authentication, payment, hosting, analytics, communications or security providers where they return information necessary to provide or protect the service.

7. How long we keep personal information

We do not keep personal information indefinitely simply in case it becomes useful. We use a general maximum retention framework, with shorter periods for information that does not need to be kept as long. We review information and delete or anonymise it earlier where there is no continuing purpose to retain it. Where data is anonymised so that individuals can no longer be identified, it is no longer personal data and may be retained for longer for statistical, educational or product-improvement purposes.

InformationTypical retention
Most account, profile, customer, service and educational activity recordsFor the active relationship and generally up to 6 years after the account, licence or institutional relationship ends, where needed for contractual, audit, dispute, institutional-record or service-administration purposes. Data may be deleted or anonymised sooner when no longer necessary.
Contracts, invoices, payments and financial/tax recordsGenerally 6 years, or longer where a legal or regulatory requirement applies.
Marketing and business-development contactsUntil you opt out, or generally up to 3 years after the last meaningful interaction. We may retain a minimal suppression record for longer so that we can respect an opt-out.
Technical/security logs, IP addresses and diagnostic informationGenerally up to 24 months, unless needed for a security incident, investigation or legal claim.
Session/call/video recordings and troubleshooting screenshotsGenerally up to 12 months. Relevant material may be kept longer if needed for an unresolved support issue, complaint, dispute or legal claim.
Reasonable-adjustment and health informationOnly for as long as necessary to provide the adjustment and generally no longer than 12 months after the relevant account/course/institutional relationship ends, unless a longer period is required for an active complaint, legal claim or controller instruction.
Complaints, claims and dispute recordsGenerally up to 6 years after closure, and longer where a claim or legal requirement remains active.
Consent and opt-out recordsGenerally up to 6 years after the consent is withdrawn or we last relied on it, where needed to demonstrate compliance.
Data processed by us solely as processor for an educational organisationFor the period instructed by the controller and set out in the relevant contract/data-processing agreement. At the end of the service, we delete or return the data as required, subject to any legal obligation to retain it.

8. Who we share personal information with

We share personal information only where necessary for the purposes described in this notice. Recipients may include:

  • Authorised universities, educational institutions and educators, including access to relevant student activity, progress and performance information where necessary to provide the service.
  • Cloud hosting, database, storage, authentication and infrastructure providers.
  • AI service providers where AI-enabled functionality is used.
  • Payment and billing providers where payment functionality is used.
  • Email, communications, analytics, security, monitoring and error-reporting providers where relevant.
  • Professional advisers and consultants, such as legal and accounting advisers, where they need the information to provide services to us.
  • Relevant regulatory, tax, law-enforcement or other authorities, and other organisations we are legally required to share information with.

Development tools that do not access, store or process production personal information are not treated as processors for this notice. If a development or support tool is later given access to production personal information, we will assess it as a processor or other recipient and put the required safeguards in place.

9. International transfers

Some of our service providers process or make personal information accessible outside the UK. We may also provide the service to educational organisations outside the UK. Where a restricted international transfer occurs, we use an appropriate transfer mechanism where required, such as UK adequacy regulations/data bridges, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with any required transfer-risk assessment.

Organisation / categoryLocation and safeguard
Vercel Inc. — Cloud hosting and web infrastructureUnited States. UK Addendum to the EU Standard Contractual Clauses, as applicable under Vercel’s data-processing terms.
OpenAI OpCo, LLC — Artificial intelligence/API services where enabledUnited States. UK Addendum to the EU Standard Contractual Clauses, as applicable under OpenAI’s data-processing terms.
Google LLC and authorised Google subprocessors — Cloud productivity, email, file storage and communicationsUnited States and other locations used by Google/subprocessors. Applicable Google data-processing terms and UK transfer safeguards, including contractual clauses where required.

Where an overseas university or educational organisation becomes a customer and receives or accesses personal information, we will assess the transfer mechanism that applies to that specific organisation and country before the transfer takes place.

10. How we protect personal information

We use appropriate technical and organisational measures proportionate to the nature of the information and our services. These may include access controls, authentication, encryption in transit, secure hosting, logging and monitoring, role-based access, data minimisation, contractual controls with processors, and procedures for responding to security incidents. Access to production personal information is limited to people and providers who need it for an authorised purpose.

11. Your data-protection rights

Depending on the circumstances and lawful basis, you may have rights to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase personal information in certain circumstances;
  • ask us to restrict how we use personal information;
  • object to processing based on legitimate interests and object to direct marketing at any time;
  • receive or transfer certain information in a portable format where the right applies; and
  • withdraw consent at any time where we rely on consent.

We normally respond to valid data-protection requests without undue delay and within the applicable statutory period. If the information is processed by us solely as a processor for an educational organisation, we may refer the request to that organisation and assist it in responding.

12. Cookies and similar technologies

Our website and platform may use cookies or similar technologies for essential functionality, security and, where enabled, analytics. Where consent is required for non-essential cookies or similar technologies, we will ask for it before using them.

Further information is provided in our Cookie Policy, or you can manage your preferences at any time via .

13. How to complain

If you have concerns about how we use your personal information, please contact us first:

Email: info@breakthrough-med.com

Post: Our registered office address as recorded at Companies House.

If you remain unhappy, you can complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Telephone: 0303 123 1113

ICO complaints website

14. Changes to this privacy notice

We may update this privacy notice when our services, data uses, suppliers or legal obligations change. Where a change is material, we will take reasonable steps to bring it to the attention of affected users. The "Last updated" date at the top shows when this notice was most recently revised.