Privacy notice
How the PCRA SOP Maker handles your organisation's data. This notice is in plain English; the formal assessment is in PCRA's DPIA, which your organisation may rely on (see the green box below).
Last updated: 5 July 2026 · Controller: Primary Care Research Alliance, Middleton House, PO22 6DU · Contact: daphne@pcralliance.uk
SOPMaker processes only professional staff details (no patient data), makes no automated decisions about individuals, and deletes everything within 24 hours. PCRA has completed a full DPIA and assessed the processing as low risk — in PCRA's assessment, using SOPMaker does not itself introduce processing that meets the UK GDPR Article 35 "high-risk" threshold. Whether your organisation needs its own DPIA is always your organisation's judgement: take PCRA's DPIA to your data-protection lead or DPO per your own policy — for most organisations the screening it enables is brief, because the substantive analysis is already done. Keep a copy on file as your due-diligence record. You remain responsible for telling your named staff their details appear on your SOPs, reviewing every SOP before use, and not entering patient data. See also our Terms of Use & AI notice and Complaints procedure.
What this tool does
PCRA SOP Maker drafts a bespoke set of clinical-trial Standard Operating Procedures for your organisation based on a short intake form. Every SOP is rendered from PCRA's reviewed, version-controlled templates — the same answers always produce the same document. An AI model drafts the accompanying extras (the one-page quick-reference cards, a cross-document coherence review, and optional pack-scope suggestions you confirm). The output is a Microsoft Word zip file you download, review, sign and file. The tool does not store your data after generation completes.
What data we collect
We collect what you type into the wizard. That is, in summary:
- Practice information — practice name, address, ICB, list size, practice type.
- Named research roles — the names and professional registration numbers (GMC, NMC) of your Principal Investigator, Research Lead, and Practice Manager.
- Operational details — clinical system, equipment, archiving arrangement, ISF format, emergency arrangements, nearest A&E.
- SOP scope — whether you've chosen the Core or Comprehensive pack.
We do not collect:
- Patient data of any kind.
- Trial-participant data.
- Your personal email address, NHS account, or any identifier of the person filling in the form.
- Payment data.
Voluntary feedback for our funder. After your pack is generated we may invite you to answer a few optional questions — your NIHR Research Delivery Network region, whether you would recommend the tool, and free-text comments — used in aggregate to report the tool's reach and reception to our funder (NIHR). This is entirely voluntary and does not affect your access or your pack. Your organisation's name is included in that reporting only if you tick the box saying so. We ask you not to include personal details in comments; if any are included we will remove them before reporting. To have a feedback entry corrected or deleted, contact info@pcralliance.uk.
Lawful basis
We process this data under Article 6(1)(f) UK GDPR — legitimate interests. Our legitimate interest is helping NHS research organisations (GP practices, pharmacies, care providers and research-nursing services) comply with the Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025 and ICH GCP E6(R3). We do not process special-category (Article 9) data.
The named individuals' data items (names, GMC/NMC numbers) are about NHS staff acting in their professional capacity. Most are already in the public domain via the GMC/NMC online registers. We've assessed that the legitimate interests test is met because the processing is proportionate, expected by trial-active practices, and necessary to produce SOPs that name the responsible roles.
Where your data goes
- From your browser to the SOP Maker server over HTTPS.
- The server holds the data in process memory while building your pack. The SOPs themselves are rendered locally from PCRA's templates — no AI is involved in the SOP text.
- For the AI-drafted extras (each one-page quick-reference card and the pack coherence review — and scope suggestions, if you typed study context), the server sends the relevant SOP text and your intake to Anthropic's API (Claude). Anthropic processes the request on US infrastructure.
- Anthropic returns the drafted text. The server bundles the pack into a single zip on its local disk.
- You download the zip. The server schedules the zip and the in-memory data for automatic deletion within 24 hours.
Cross-border transfer
The transfer to Anthropic is to the United States and is safeguarded by the Standard Contractual Clauses together with the UK International Data Transfer Addendum, incorporated in Anthropic's Data Processing Addendum — binding contractual safeguards under Article 46 UK GDPR that do not depend on any US self-certification register.
Anthropic's Commercial Terms state that "Anthropic may not train models on Customer Content from Services". API logs are retained for up to 30 days by default, per Anthropic's terms.
How long we keep your data
| Where | What | How long |
|---|---|---|
| SOP Maker server (memory) | Your intake and the SOPs while they're being drafted | Up to 24 hours after generation; deleted automatically |
| SOP Maker server (disk) | The final zip ready for you to download | Up to 24 hours from creation; deleted automatically |
| Anthropic API | The prompts and responses | Up to 30 days, per Anthropic's commercial terms |
| Your computer | The downloaded zip and extracted SOPs | You decide; the SOPs themselves carry a 25-year retention obligation under CTIMP regulations once signed |
| Hosting platform request log | HTTP method, path, status code, IP — your intake content is NOT logged | Per the platform's standard log retention (typically 7-30 days) |
Your rights
Under UK GDPR you have the right to:
- Access a copy of the data we hold about your practice.
- Rectify data that's wrong.
- Erase your data. The 24-hour auto-purge handles this routinely. If you need it deleted sooner, email us with the date and time you used the tool and we'll purge the specific session.
- Object to processing. You can decline to use the tool — manual SOP drafting is the alternative.
- Data portability — the zip download is the portable copy.
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you think we have processed your data unlawfully.
Automated decision-making
SOP Maker uses an AI model (Anthropic's Claude) to draft documents, but the tool does not make decisions about individuals. Article 22 UK GDPR (right not to be subject to automated decisions with legal/similar effect) does not apply because the tool produces a draft document that you, the practice, then review, edit, sign and approve.
Security
- All traffic is over HTTPS (TLS 1.2 or higher).
- Access is by a per-organisation access code issued by PCRA. The stored record is only the organisation label, a use-quota and a count — no individual user accounts, names or email addresses are collected or stored.
- The application code does not log your intake fields, prompts, or responses.
- Login attempts and generation requests are rate-limited to deter abuse.
- Server-side session cookies are
HttpOnlyand expire after 8 hours of inactivity.
Requesting access yourself (self-service)
Where the self-service route is switched on, an NHS practice in the NIHR Kent Surrey Sussex region can request its own access code. You give us your practice name, county and NHS (or NIHR) email address; we run automated checks (email domain, region, and an AI check that the practice details are plausible), send a one-time code to that address, and — once you enter it — issue your practice's access code and sign you in. Your email address is used only to deliver those messages and is not stored: the pending request exists only as a signed token in your own browser, and what we keep afterwards is the same as for any organisation — the practice name as a label, the code, and its use-count. A transactional-email provider delivers the messages and processes the address transiently for that purpose. Requests our checks cannot confirm are passed to PCRA by email for a quick manual review.
Contact
For any privacy question, data subject request, or to report a concern:
Email: daphne@pcralliance.uk
Subject line: "SOP Maker — privacy"
If you do not receive a response within 5 working days, escalate to PCRA's data protection lead at info@pcralliance.uk. See also our Complaints procedure.
Changes to this notice
We will update this notice when the tool changes meaningfully (new fields collected, new processors involved, new retention periods, new security controls). The date at the top of the notice indicates the last revision. The technical evidence in docs/dpia/ is updated alongside.
PCRA is the data controller for the tool's processing and is responsible for keeping this notice and the underlying DPIA accurate. PCRA's completed DPIA is designed to make a user organisation's own screening quick — take it to your data-protection lead or DPO per your own policy (see the green box above).