Supplier/business dataInvoices, stock, rooms and business contacts.
No patient recordsClinical information is outside scope.
Private storageFiles and operational records are not published on the public website.
Human reviewAI does not silently become the final decision-maker.
1. The short version
DBX ONE needs supplier and operational stock information to provide INSIGHTS and STOCKROOM. We do not need patient records. Supplier files are stored privately, access is restricted, and the current AI-processing route depends on which DBX ONE product you use.
2. STOCKROOM: automated invoice processing
Supplier emails or manually uploaded invoices can be stored in private Cloudflare R2 storage. A Cloudflare Queue can process the invoice in the background. The automated extractor can use Cloudflare AI services first. Under the configured fallback rules, low-confidence or failed extraction may be sent to the OpenAI API for another attempt. The result is validated by ordinary code before it becomes an expected delivery; AI does not directly add physical stock.
Physical stock only changes after a real workflow event. A supplier invoice creates an expected delivery. Staff confirm what arrived before central stock increases.
3. INSIGHTS: current trial/manual route
Files submitted through the INSIGHTS trial form are stored privately in Cloudflare R2. The current manual AI-assisted INSIGHTS workflow may use DBX ONE's individual ChatGPT consumer account with "Improve the model for everyone" switched off. This is a different route from STOCKROOM's automated API workflow and is not represented as ChatGPT Business, Enterprise or the OpenAI API.
If the INSIGHTS processing route changes materially, these pages and the acceptance wording should be updated before the new route is used for live client data.
4. What we ask you not to send
- Patient records, clinical notes, prescriptions or medical history.
- Payroll files, staff health records or unrelated special-category data.
- Passwords, security answers or online-banking credentials.
- Documents unrelated to the agreed supplier/stock workflow.
Ordinary supplier invoices can contain names, business contact details, addresses, signatures, account references or bank details. Those are treated as confidential business information.
5. Storage and service providers
If a STOCKROOM user enables app notifications, the service stores the push subscription created by that browser/device and uses the browser or operating-system push service to deliver the alert. App notifications are optional and can be disabled by the user.
| Provider | Purpose |
|---|
| Cloudflare | Public site delivery, Workers, D1 database, private R2 file storage, Queues, Turnstile and configured AI/infrastructure services. |
| OpenAI | STOCKROOM API fallback where configured; current INSIGHTS manual ChatGPT route as separately disclosed. |
| Resend | Transactional email, account invitations, notifications and support delivery. |
| Browser / operating-system push service | Delivery of opt-in STOCKROOM app notifications on supported devices/browsers. |
| Zoho | DBX ONE business and support mailbox. |
| Stripe | Hosted payment processing where a paid INSIGHTS route uses Stripe. |
6. OpenAI data controls
OpenAI states that API inputs and outputs are not used to train its models by default unless an API organisation explicitly opts in. OpenAI also documents default abuse-monitoring retention for API usage. For the separate individual ChatGPT consumer route used by the current INSIGHTS workflow, model improvement is switched off so new conversations are not used to improve models under OpenAI's current consumer data controls.
7. Access and security
- Website traffic uses HTTPS.
- STOCKROOM uses authenticated accounts and role-based access.
- Private files are stored in non-public object storage.
- Important stock movements and administrative actions generate audit records.
- Support and security issues can be escalated through the service or by email.
No system is risk-free. DBX ONE does not claim security certifications it has not obtained.
8. Retention
STOCKROOM operational data is normally retained while the organisation uses the service. Free INSIGHTS trial material may be kept during the trial and decision period, normally up to 90 days after delivery unless deleted earlier or the practice continues. Audit, security and provider logs can have separate limited retention periods.
9. Deletion
A practice can request deletion or terminate its STOCKROOM organisation. DBX ONE deletes service-controlled client data according to the applicable workflow and DPA. Third-party providers may retain limited backups, API abuse-monitoring logs or security records for their documented periods or where law requires.
10. Questions before sending anything
If the practice has an information-governance lead, DPO or other internal approval process, review these pages before submitting live supplier data. Questions can be sent to [email protected].
Read the DPA · Read the Privacy Notice · Read the Terms