Skip to Content
Legal

Data processing

Last updated: 2 October 2026

A summary of how Al Jawad Software House, which provides Ventrecs, processes personal data, including patient data, on behalf of healthcare providers that use the products. The signed data processing agreement is provided to customers during procurement.

Roles

The healthcare provider is the controller of the personal data it puts into a Ventrecs product. Al Jawad Software House acts as processor and handles that data only to provide the service and on the provider’s documented instructions.

Confidentiality

Everyone at Al Jawad who can access customer data is bound by a duty of confidentiality.

Security

Access is role-based and limited to the facility the user is authorised for, enforced on the server.

Patient sensitivity levels restrict access to sensitive records.

Every access, update and clinical action is recorded in an audit trail.

Safety-critical actions need the right role and, in some cases, a second person.

More detail is on the Security & Delivery page.

Where data is hosted

The hosting location and model are agreed with each customer for its deployment, and written into the contract.

Subprocessors

We use subprocessors only where needed to deliver the service and we are responsible for them. The list is on the Subprocessors page, and customers are told in advance of changes that affect their deployment.

Requests and incidents

We help customers respond to requests from the people the data is about.

If we become aware of a personal-data breach affecting customer data, we tell the customer without undue delay.

End of service

When a contract ends, we return or delete customer data as the customer chooses, unless the law requires us to keep it.

Questions and the signed agreement

Write to [email protected] and we will send the data processing agreement for your review.