SOP Maker Privacy notice
← Back to SOP Maker

Privacy notice

How the PCRA SOP Maker handles your organisation's data. This notice is in plain English; the formal assessment is in PCRA's DPIA, which your organisation may rely on (see the green box below).

Last updated: 5 July 2026 · Controller: Primary Care Research Alliance, Middleton House, PO22 6DU · Contact: daphne@pcralliance.uk

Do you need your own DPIA to use this tool? PCRA's completed DPIA makes that decision quick.

SOPMaker processes only professional staff details (no patient data), makes no automated decisions about individuals, and deletes everything within 24 hours. PCRA has completed a full DPIA and assessed the processing as low risk — in PCRA's assessment, using SOPMaker does not itself introduce processing that meets the UK GDPR Article 35 "high-risk" threshold. Whether your organisation needs its own DPIA is always your organisation's judgement: take PCRA's DPIA to your data-protection lead or DPO per your own policy — for most organisations the screening it enables is brief, because the substantive analysis is already done. Keep a copy on file as your due-diligence record. You remain responsible for telling your named staff their details appear on your SOPs, reviewing every SOP before use, and not entering patient data. See also our Terms of Use & AI notice and Complaints procedure.

What this tool does

PCRA SOP Maker drafts a bespoke set of clinical-trial Standard Operating Procedures for your organisation based on a short intake form. Every SOP is rendered from PCRA's reviewed, version-controlled templates — the same answers always produce the same document. An AI model drafts the accompanying extras (the one-page quick-reference cards, a cross-document coherence review, and optional pack-scope suggestions you confirm). The output is a Microsoft Word zip file you download, review, sign and file. The tool does not store your data after generation completes.

What data we collect

We collect what you type into the wizard. That is, in summary:

We do not collect:

Voluntary feedback for our funder. After your pack is generated we may invite you to answer a few optional questions — your NIHR Research Delivery Network region, whether you would recommend the tool, and free-text comments — used in aggregate to report the tool's reach and reception to our funder (NIHR). This is entirely voluntary and does not affect your access or your pack. Your organisation's name is included in that reporting only if you tick the box saying so. We ask you not to include personal details in comments; if any are included we will remove them before reporting. To have a feedback entry corrected or deleted, contact info@pcralliance.uk.

Lawful basis

We process this data under Article 6(1)(f) UK GDPR — legitimate interests. Our legitimate interest is helping NHS research organisations (GP practices, pharmacies, care providers and research-nursing services) comply with the Medicines for Human Use (Clinical Trials) (Amendment) Regulations 2025 and ICH GCP E6(R3). We do not process special-category (Article 9) data.

The named individuals' data items (names, GMC/NMC numbers) are about NHS staff acting in their professional capacity. Most are already in the public domain via the GMC/NMC online registers. We've assessed that the legitimate interests test is met because the processing is proportionate, expected by trial-active practices, and necessary to produce SOPs that name the responsible roles.

Where your data goes

  1. From your browser to the SOP Maker server over HTTPS.
  2. The server holds the data in process memory while building your pack. The SOPs themselves are rendered locally from PCRA's templates — no AI is involved in the SOP text.
  3. For the AI-drafted extras (each one-page quick-reference card and the pack coherence review — and scope suggestions, if you typed study context), the server sends the relevant SOP text and your intake to Anthropic's API (Claude). Anthropic processes the request on US infrastructure.
  4. Anthropic returns the drafted text. The server bundles the pack into a single zip on its local disk.
  5. You download the zip. The server schedules the zip and the in-memory data for automatic deletion within 24 hours.

Cross-border transfer

The transfer to Anthropic is to the United States and is safeguarded by the Standard Contractual Clauses together with the UK International Data Transfer Addendum, incorporated in Anthropic's Data Processing Addendum — binding contractual safeguards under Article 46 UK GDPR that do not depend on any US self-certification register.

Anthropic's Commercial Terms state that "Anthropic may not train models on Customer Content from Services". API logs are retained for up to 30 days by default, per Anthropic's terms.

How long we keep your data

WhereWhatHow long
SOP Maker server (memory)Your intake and the SOPs while they're being draftedUp to 24 hours after generation; deleted automatically
SOP Maker server (disk)The final zip ready for you to downloadUp to 24 hours from creation; deleted automatically
Anthropic APIThe prompts and responsesUp to 30 days, per Anthropic's commercial terms
Your computerThe downloaded zip and extracted SOPsYou decide; the SOPs themselves carry a 25-year retention obligation under CTIMP regulations once signed
Hosting platform request logHTTP method, path, status code, IP — your intake content is NOT loggedPer the platform's standard log retention (typically 7-30 days)

Your rights

Under UK GDPR you have the right to:

Automated decision-making

SOP Maker uses an AI model (Anthropic's Claude) to draft documents, but the tool does not make decisions about individuals. Article 22 UK GDPR (right not to be subject to automated decisions with legal/similar effect) does not apply because the tool produces a draft document that you, the practice, then review, edit, sign and approve.

Security

Requesting access yourself (self-service)

Where the self-service route is switched on, an NHS practice in the NIHR Kent Surrey Sussex region can request its own access code. You give us your practice name, county and NHS (or NIHR) email address; we run automated checks (email domain, region, and an AI check that the practice details are plausible), send a one-time code to that address, and — once you enter it — issue your practice's access code and sign you in. Your email address is used only to deliver those messages and is not stored: the pending request exists only as a signed token in your own browser, and what we keep afterwards is the same as for any organisation — the practice name as a label, the code, and its use-count. A transactional-email provider delivers the messages and processes the address transiently for that purpose. Requests our checks cannot confirm are passed to PCRA by email for a quick manual review.

Contact

For any privacy question, data subject request, or to report a concern:

Email: daphne@pcralliance.uk
Subject line: "SOP Maker — privacy"

If you do not receive a response within 5 working days, escalate to PCRA's data protection lead at info@pcralliance.uk. See also our Complaints procedure.

Changes to this notice

We will update this notice when the tool changes meaningfully (new fields collected, new processors involved, new retention periods, new security controls). The date at the top of the notice indicates the last revision. The technical evidence in docs/dpia/ is updated alongside.

PCRA is the data controller for the tool's processing and is responsible for keeping this notice and the underlying DPIA accurate. PCRA's completed DPIA is designed to make a user organisation's own screening quick — take it to your data-protection lead or DPO per your own policy (see the green box above).