← Home

Privacy notice

This notice explains the platform’s current data handling. The organisation that operates this Petrios deployment must complete the deployment-specific fields and confirm its lawful basis, retention schedule, and local rights process.

Last updated: 18 July 2026

Who is responsible

Petrios is open-source teaching-management software. The organisation using a deployment normally decides why and how personal data is processed and is therefore the controller; its hosting and support providers may act as processors.

Controller
We Health Ltd
Postal address
Not declared by this deployment: controller address
Privacy contact
support@petrios.uk

If these details are not declared, contact the organisation that invited you to Petrios before submitting a data-rights request. Repository maintainers do not automatically control data in independently hosted installations.

Information processed

  • Identity and account: name, email, training grade, authentication identifiers, profile, and account status.
  • Membership and authority: organisation, department, role, invitations, and teaching assignments.
  • Teaching activity: sessions created, taught, joined, or attended; private session documents; attendance evidence, roster, corrections, and finalized status; teaching slots and claims.
  • Feedback: first name, last name, email, ratings, answers, and free-text comments. The public feedback form does not require an account, but its submissions are identified, not anonymous.
  • Records and learning: certificates (including recognition route, recipient, teaching-coordinator, and issuer names), Audio Recap listening progress, Recall attempts/answers/completion, personal reflections, portfolio snapshots, and teaching dossiers.
  • Communications: invitation, reminder, notification, newsletter, feedback-release, and delivery status data.
  • Security and technical data: essential authentication cookies, IP/network data available to infrastructure providers, request and error logs, API credentials, audit events, and abuse-prevention signals.

Petrios is not designed for patient records. Users should not enter patient data, clinical secrets, or unnecessary special-category data in session descriptions, feedback, uploaded session documents, reflections, or assistant messages.

Why information is used

Data is used to authenticate users; administer organisations and departments; schedule and deliver teaching; derive attendance from recorded evidence; manage teachers and teaching slots; collect and release feedback; issue and verify certificates; build subject-requested portfolio records; send operational communications; audit access and changes; maintain security; and provide optional AI-assisted teaching operations.

Lawful basis

The deploying controller must identify and record a lawful basis for each purpose. It may rely on public task, contract, legal obligation, legitimate interests, or consent depending on its role and context. Petrios does not choose that basis on the controller’s behalf. Consent should not be described as the basis where people cannot freely refuse or withdraw it.

Feedback, documents, and AI processing

Raw feedback remains identifiable to authorised moderators. Teacher feedback-release emails omit respondent names, email addresses, and raw comments, but may contain aggregate ratings and a moderator-reviewed AI summary from the first response. Reports based on fewer than five responses are labelled as limited, directional evidence; the teacher may still infer who participated. Optional summary paths omit stored identity fields, remove known names where detectable, treat comments as untrusted, and route configured welfare or conduct signals to human review. These controls do not make the source record anonymous. Free text can itself identify a person, so users should avoid unnecessary identifying details.

Optional AI features are currently enabled through OpenAI API. When enabled, a configured AI provider may receive session metadata, assistant messages, purpose-limited feedback content, and private uploaded PDF/DOCX/PPTX learning documents. A deliberate Audio Recap request sends the documents for that session; a deliberate weekly newsletter request sends all available documents for every teaching session in the selected department and completed week. Newsletter generation does not use web search. PDFs may be processed as text and page images; Office files are processed as extracted text. For Audio Recap only, the provider's hosted search may issue queries derived from that learning material to retrieve supporting information from a restricted list of authoritative public clinical and evidence sources. Petrios records the document identifiers and integrity hashes used for recaps and newsletters plus returned recap public-source titles and URLs; it does not copy those public pages. Opening a source link contacts that external website from your browser. The Ops audit log stores model-run hashes and operational metadata rather than raw prompt text or search queries. The provider may retain request and search content under its own terms. OpenAI states that API data is not used to train its models by default, while standard abuse-monitoring logs may be retained for up to 30 days; see its API data controls documentation.

Audio speech synthesis is currently enabled through OpenAI API. When a moderator creates an audio preview, the selected speech provider receives the current draft recap script and request metadata needed to produce the MP3. That separate speech request does not contain the uploaded document files, raw feedback, or hosted-search queries. Re-creating audio makes another provider request and may consume provider credits. The resulting narration is AI-generated and remains unavailable to attendees until the moderator listens to and approves it.

Cookies and tracking

Petrios uses first-party storage needed to sign a user in and maintain the authenticated session. The application does not ship advertising, cross-site behavioural tracking, or analytics cookies. A consent banner is therefore not shown. If an operator adds non-essential analytics, embeds, or tracking, it must update this notice and obtain any consent required before those technologies run.

See Your privacy choices for the platform’s sale/share and Global Privacy Control posture.

Recipients and subprocessors

Authorised users see data according to their role. Infrastructure, email, meeting, and optional AI providers process only the data needed for their service. The current deployment-facing register is published on the subprocessors and external services page. Data may also be disclosed where legally required or necessary to protect people and the service.

Hosting and international transfers

Application host: Render. Data-hosting location: Not declared by this deployment: database and application region(s).

Transfer safeguard: Not declared by this deployment: adequacy decision, UK IDTA/Addendum, or other applicable safeguard. The controller must evaluate every configured provider and onward transfer; “self-hosted” does not by itself prove that all data remains in one country or estate.

Retention and deletion

Petrios does not currently enforce one universal automatic retention schedule. The controller must set and document periods for accounts, membership, attendance evidence, feedback, private session documents, delivery ledgers, communications, audit data, certificates, portfolio records, and provider logs, then implement deletion or anonymisation operations appropriate to those periods. Attendance evidence is append-only in normal application/RLS flows, corrections are new reasoned rows, and public verification or archived document records need separate revocation, deletion, and retention decisions.

Your rights and complaints

Depending on the applicable law, people may have rights to information, access, correction, deletion, restriction, objection, portability, and review of certain automated decisions. Submit a request to the controller named above; it may need to verify identity and may apply lawful exemptions. UK users may also complain to the Information Commissioner’s Office or seek a judicial remedy.

Security and changes

Petrios uses role checks, organisation scoping, Supabase Row Level Security, server-only privileged access, signed capability links, security headers, and automated code, dependency, migration, and secret scanning. No service can promise absolute security. Report vulnerabilities privately using the process in the project’s SECURITY.md.

Material notice changes will update the date above. The controller should tell affected people directly when a change materially affects their processing or choices.