Skip to main content
Governance

Data Protection & Information Governance

Governance statement and operating framework for the Lazomis QI service.

Core position

Flux Medical Limited protects personal and confidential information through privacy by design, proportionate security and accountable governance. Customers normally control their project data; Flux Medical normally processes it on their documented instructions. Lazomis QI is not an electronic patient record, and projects should avoid direct patient identifiers wherever possible.

Document control

Document control details
OrganisationFlux Medical Limited, trading as Lazomis QI
Company number16158150
Registered officeUnit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG
Contactprivacy@lazomis.co.uk
Version2.0
Effective date15 August 2026
Review cycleAt least annually and after material legal, service or risk changes

1. Purpose and scope

This statement describes the data-protection and information-governance framework applied by Flux Medical Limited to the Lazomis QI website, platform, project tools, organisational workspaces, demonstrations, support, billing, communications, integrations and related services. It covers personal data, special-category data, confidential patient information and other sensitive business or organisational information.

It is a public governance statement, not a substitute for the Privacy Policy, Data Processing Agreement, customer contract, local clinical-governance approval or a project-specific data protection impact assessment. The facts of each processing activity determine the applicable legal roles and requirements.

2. Organisation and accountability

Lazomis QI is operated by Flux Medical Limited, registered in England and Wales under company number 16158150. Senior management remains accountable for establishing proportionate privacy, security and information-governance controls, assigning responsibilities, reviewing risk and retaining evidence of decisions.

  • Maintain approved policies, procedures and defined owners.
  • Keep records of processing, systems, suppliers, risks, incidents, training and assurance.
  • Embed data protection by design and default in product and operational change.
  • Review governance controls at planned intervals and after material change or incident.
  • Provide a route for users, customers and individuals to raise privacy or governance concerns.

Accountability means evidence

Compliance is not established by publishing this statement alone. Flux Medical must be able to demonstrate that controls operate in practice.

4. Data-protection principles

Data-protection principles and how they are applied
PrincipleHow it is applied
Lawfulness, fairness and transparencyDefine purposes and roles; identify lawful bases; provide clear notices; avoid unexpected reuse.
Purpose limitationUse information only for defined, compatible and authorised purposes.
Data minimisationCollect only fields necessary for the audit, QI, service or business purpose.
AccuracySupport correction, validation and appropriate review of records and outputs.
Storage limitationApply documented retention, contract-end and deletion arrangements.
Integrity and confidentialityUse risk-based technical and organisational security controls.
AccountabilityRecord decisions, risks, contracts, training, incidents and assurance activity.

5. Controller and processor roles

5.1 Flux Medical as controller

Flux Medical normally acts as controller for its website, individual accounts, billing, enquiries, support, complaints, marketing preferences, security, service administration, supplier management and its own corporate and legal records.

5.2 Customer as controller; Flux Medical as processor

Where a healthcare organisation determines the purpose, dataset, participants, access and use of a clinical audit, quality-improvement or service-evaluation project, that organisation will normally be controller. Flux Medical will normally act as processor, handling project data under documented instructions and the applicable Data Processing Agreement.

5.3 Individual users

An individual professional may be controller for genuinely independent activity, but employment, honorary-contract, training and local-governance arrangements often mean the relevant healthcare organisation controls the work. Users must not assume that purchasing an individual Project Credit authorises processing of organisational or patient information.

Role test

Contract labels help, but legal roles follow who actually decides the purposes and essential means of processing.

6. Information assets and processing records

Flux Medical maintains proportionate records of processing activities and an information-asset view covering systems, datasets, purposes, categories of people and data, recipients, processors, locations, retention, security, lawful bases and risk owners. New or materially changed processing must be recorded before or promptly after implementation.

  • Account, authentication and professional-profile data.
  • Organisation membership, permissions, invitations and audit trails.
  • Project configuration, submitted records, comments, attachments, analysis and exports.
  • Support, complaint, billing, transaction and communication records.
  • Security, access, performance, error and consent logs.
  • Supplier, employee, contractor and corporate-governance information.

7. Clinical audit and QI governance

Lazomis QI supports clinical audit, quality improvement and service evaluation. It is not the authoritative patient record. The responsible user and organisation must classify the activity, identify its sponsor or owner, approve the dataset, confirm legal and confidentiality requirements, define access, and determine whether research ethics, consent or another approval is required.

  • Use the minimum dataset necessary for the stated objective.
  • Document standards, inclusion and exclusion rules, denominator logic and planned outputs.
  • Maintain the authoritative clinical record and statutory or local records elsewhere.
  • Do not use project outputs as the sole basis for individual care or high-impact decisions.
  • Review external sharing, publication and benchmarking for confidentiality and re-identification risk.
  • Ensure contributors understand their role and report concerns through the appropriate route.

8. Data minimisation and custom fields

Default rule

Use anonymous data where the purpose can be achieved without personal data. Where personal data is necessary, prefer appropriately pseudonymised identifiers and keep the re-identification key separately under the controller's control.

Direct identifiers such as names, NHS numbers, full addresses, identifiable images and unnecessary narrative should not be entered merely because a field permits text. Pseudonymised information remains personal data. Small numbers, dates, rare conditions and combinations of indirect identifiers may also create re-identification risk.

Custom fields and attachments must not be used to circumvent platform safeguards, the approved dataset, local governance, confidentiality duties or the customer's Data Processing Agreement. Customers should review custom fields before data collection and remove unnecessary fields.

9. Lawful basis, confidentiality and transparency

For each controller activity, the responsible controller must identify and record an appropriate UK GDPR Article 6 lawful basis and, where special-category data is processed, an Article 9 condition. Criminal-offence data requires an applicable legal condition and safeguards. Consent is not automatically the correct basis for clinical audit or employment-related processing.

A data-protection lawful basis does not by itself satisfy the common-law duty of confidentiality. Controllers must separately consider consent, direct-care expectations, statutory authority, section 251 support or another lawful route where confidential patient information is used beyond direct care.

People must receive clear, accessible privacy information unless a lawful exemption applies. Flux Medical's Privacy Policy covers its controller activities; customer controllers remain responsible for privacy information about their projects and services.

10. National data opt-out

The national data opt-out applies in England to specified uses and disclosures of confidential patient information for research and planning. It does not apply to genuinely anonymous information, individual care, uses with the person's consent, legal requirements and certain approved exceptions.

Customer controllers must assess whether a project or disclosure is in scope and apply the required checking process before an in-scope use. Where Flux Medical acts as processor, it follows the customer's documented instruction and supports agreed controls. New and materially changed uses are screened for national data opt-out relevance.

  • Record the assessment and its rationale.
  • Identify whether the data remains confidential patient information at the point of use or disclosure.
  • Apply opt-outs before the in-scope processing, using the approved service or workflow.
  • Keep evidence of the check and manage later updates where required.
  • Do not describe pseudonymised data as automatically outside the policy.

11. Privacy by design and DPIAs

Data protection is considered through design, procurement, change and retirement. A data protection impact assessment (DPIA) is completed before processing likely to result in high risk to people. Screening is recorded even where a full DPIA is not required.

  • New uses of health or other special-category data at scale.
  • Systematic monitoring, profiling or innovative technology with material privacy impact.
  • AI features using sensitive data or producing outputs about individuals.
  • New integrations, international transfers or significant supplier changes.
  • Linkage, benchmarking, publication or research uses with re-identification risk.
  • Material expansion of custom fields, data sources, recipients or retention.

A DPIA describes the purpose and necessity, people and data affected, information flows, lawful basis, consultation, risks, controls, residual risk, approvals and review date. High residual risk is escalated and, where required, the ICO is consulted before processing begins.

12. Access control and user responsibilities

Access is based on role, least privilege and need to know. Authentication, permission changes and significant activity should be logged and reviewable. Organisation administrators are responsible for approving members, assigning roles, reviewing access and removing access promptly when authority ends.

  • Use an individual account and protect credentials and devices.
  • Do not share accounts, export data to unauthorised locations or invite unauthorised users.
  • Verify recipients and permissions before sharing or downloading.
  • Report suspected compromise, misdirected disclosure or inappropriate access promptly.
  • Use approved secure channels and comply with local policy.

13. Information security

Flux Medical applies risk-based technical and organisational measures designed to protect confidentiality, integrity, availability and resilience. The exact controls evolve with the service and risk profile.

Security control areas and expected safeguards
Control areaExpected safeguards
Identity and accessAuthentication safeguards, role-based access, least privilege, access review and prompt revocation.
Data protectionEncryption in transit; encryption at rest where supported; secrets management; secure backup and deletion.
Application securitySecure development, change control, dependency and vulnerability management, testing and separation of environments.
MonitoringSecurity and audit logging, alerting, investigation and preservation of relevant evidence.
InfrastructureSecure configuration, provider assurance, availability controls, backup and recovery.
People and processConfidentiality duties, training, incident response, supplier governance and documented procedures.

No online service can guarantee absolute security. Controls are reviewed against foreseeable threats, the sensitivity and volume of data, technology, implementation cost and potential harm.

14. AI and automated processing

AI-enabled features may assist drafting, mapping, summarising or analysing QI work. Outputs require competent human review. Lazomis QI does not use AI to make autonomous diagnostic, treatment or other legally or similarly significant decisions about people.

  • Send only the minimum information necessary to an approved AI service.
  • Exclude sensitive project fields unless the use has been assessed, approved and configured.
  • Record suppliers, purposes, data flows, retention and transfer safeguards.
  • Test for accuracy, bias, security and foreseeable misuse appropriate to the feature.
  • Provide transparency and meaningful human oversight.
  • Do not use customer project content to train general-purpose models unless separately assessed, transparently explained and lawfully agreed.

The Artificial Intelligence Policy provides further governance requirements and should be read with this statement.

15. Suppliers and international transfers

Suppliers that process personal data are selected through proportionate due diligence covering security, privacy, resilience, location, subcontracting, incident handling, deletion and audit evidence. Written terms must include the requirements applicable to processor contracts. Material supplier risk is recorded and reviewed.

Where personal data is transferred outside the United Kingdom, Flux Medical uses an applicable lawful safeguard, such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum or another permitted mechanism. Transfer risk and supplementary measures are assessed where required. Customers are informed of subprocessors through the applicable contract or governance documentation.

16. Data sharing, exports and disclosures

Personal or confidential information is shared only for a defined, lawful and necessary purpose, with appropriate authority, minimum data, secure transfer and a recorded recipient. Routine sharing requires an appropriate agreement or documented arrangement. Emergency or legally compelled disclosures are recorded and reviewed.

  • Verify the identity, authority and secure contact details of the recipient.
  • Use anonymous or aggregated information where possible.
  • Check small numbers, rare characteristics and linkage risk before publication.
  • Apply national data opt-out requirements where relevant.
  • Protect exported files after download; platform controls cannot govern unauthorised copies outside the Service.
  • Escalate law-enforcement, court, regulator or safeguarding requests through the appropriate governance route.

17. Records management and retention

Information is retained only for as long as needed for its purpose, customer instructions, legal or regulatory obligations, security, dispute resolution and claims. Flux Medical maintains an internal retention schedule and contract-end process. Customer-controlled project data follows the applicable agreement and documented controller instructions.

Record classes and governance approach
Record classGovernance approach
Account and profileRetain during active use and a limited closure period for administration, recovery and disputes.
Customer project dataRetain, return, export or delete under the customer agreement and instructions.
Transactions and invoicesRetain for applicable accounting, tax and company-law periods.
Security and audit logsRetain for a proportionate period based on threat, investigation and assurance needs.
Incidents, complaints and legal recordsRetain long enough to manage the matter, obligations and claims.
BackupsProtect from ordinary use and remove through documented rotation unless a legal hold applies.
Anonymous statisticsMay be retained where re-identification is not reasonably likely and anonymity is maintained.

Deletion from live systems may not immediately remove protected backup copies. Backups are isolated from ordinary use and expire through the established rotation process. Legal holds are documented, authorised and reviewed.

18. Individual rights

Depending on the circumstances, individuals may have rights to information, access, correction, erasure, restriction, objection, portability, withdrawal of consent and safeguards relating to automated decision-making. Requests are handled without undue delay and normally within one month, subject to lawful extension or exemption.

Flux Medical verifies identity proportionately, records requests and responses, searches relevant systems, protects third-party information and communicates reasons where a request cannot be met in full. Where Flux Medical acts only as processor, it refers the request to the customer controller and provides contractual assistance.

19. Incidents and personal-data breaches

Users and staff must report suspected loss, unauthorised access, disclosure, alteration, unavailability, malware, misdirected communications or inappropriate processing promptly. Reports are triaged, contained, investigated and documented. Evidence is preserved and lessons are tracked.

  • Record all personal-data breaches, including those not reported externally.
  • Assess affected data, people, likely consequences, containment and residual risk.
  • Notify the relevant controller without undue delay where Flux Medical acts as processor.
  • Where Flux Medical is controller, notify the ICO within 72 hours of awareness when the legal threshold is met, or document why notification is not required.
  • Notify affected people without undue delay where the law requires it.
  • Complete corrective actions, review control failures and update risk assessments.

Do not include patient details in ordinary email

Use privacy@lazomis.co.uk to initiate a report, but agree a secure route before transmitting sensitive incident material.

20. Business continuity and resilience

Continuity and recovery arrangements address loss of availability, integrity and access to critical services. Measures include proportionate backups, recovery procedures, dependency review, incident communications and testing. Recovery priorities consider contractual commitments, security and the risk to users and customers.

Customers remain responsible for their own continuity arrangements, approved copies and authoritative records. Lazomis QI must not be the sole repository for information required for immediate patient care or emergency response.

21. Training and assurance

People with access to personal or confidential information receive appropriate induction and refresher training covering confidentiality, phishing, secure handling, incidents, individual rights and their specific role. Enhanced training is provided where responsibilities require it.

Assurance may include policy review, access review, vulnerability and recovery testing, supplier review, DPIA review, incident exercises, internal checks, independent assessment and customer evidence. Findings are risk-rated, assigned, tracked and reported to management.

22. Governance status statements

Public claims about assurance must be accurate, current and supported by evidence. ICO registration is an administrative requirement and is not a certification of compliance. A Data Security and Protection Toolkit status should be described using the precise organisation name, scope, standard year and published status shown in the current toolkit record.

23. Contact, complaints and related documents

Contact and complaint routes
PurposeRoute
Privacy and information governanceprivacy@lazomis.co.uk
Postal contactFlux Medical Limited, Unit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG
Service complaintshttps://lazomis-qi.co.uk/complaints
ICO complainthttps://ico.org.uk/make-a-complaint/data-protection-complaints/

We encourage people to contact us first so that we can investigate. This does not affect the right to complain to the Information Commissioner's Office or seek another remedy. Related documents include the Privacy Policy, Terms of Use, Cookie Policy, Artificial Intelligence Policy, Contributor Participation, Data Sharing and Consent Policy, Data Processing Agreement, retention schedule, incident procedure and supplier/subprocessor information.

Appendix A: Responsibility matrix

Responsibilities of Flux Medical and the customer or user
ActivityFlux MedicalCustomer / user
Flux controller processingDefine purpose, lawful basis, notice, rights and retention.Provide accurate information and use authorised routes.
Customer project processingProcess under documented instructions; provide agreed security and assistance.Act as controller; approve purpose, fields, lawful basis, confidentiality, access and retention.
Custom fields and attachmentsProvide controls and guidance; address reported misuse.Review necessity and prohibit unauthorised identifiers or narratives.
National data opt-outAssess own controller uses; follow controller instructions as processor.Assess project scope and apply checks before in-scope processing.
AI featuresAssess feature, supplier, minimisation, security and human-oversight controls.Avoid unauthorised sensitive data and review outputs.
AccessOperate platform authentication and permissions.Approve users, assign least privilege and revoke promptly.
IncidentDetect, contain, investigate and notify as required by role.Report promptly and support containment and facts.
ExportsProvide authorised export capability.Verify recipient, secure downloaded files and manage onward use.