TopMD Precision Medicine Ltd  ·  Last updated: 27 March 2026  ·  Effective: 27 March 2026
Summary: TopMD Precision Medicine Ltd is the data controller for personal data collected through this website and the TopMD platform (app.topmd.co.uk). We process the minimum personal data necessary to operate our service. We do not sell your data. Research datasets you upload to the platform are processed solely to deliver your analysis results and are not used for any other purpose.
1

Who we are

TopMD Precision Medicine Ltd is a company registered in England and Wales. We develop and operate a cloud-based precision medicine analytics platform that enables research scientists, clinical researchers, and pharmaceutical organisations to perform advanced genomic and transcriptomic analysis.

For the purposes of UK data protection law, TopMD Precision Medicine Ltd is the data controller in respect of personal data collected through our website (topmd.co.uk) and platform (app.topmd.co.uk).

This Privacy Notice explains what personal data we collect about you, why we collect it, how we use it, and what your rights are. It applies to visitors to our website, registered platform users, and contacts at organisations we work with.

We are committed to processing personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2

What personal data we collect

Account and identity data

When you register for or use the TopMD platform, we collect:

  • Name and job title
  • Institutional or professional email address
  • Organisation name and type (e.g. academic institution, pharmaceutical company, NHS trust)
  • Account credentials (password stored in hashed form only; we never store plaintext passwords)

Usage and platform data

When you use the platform we automatically collect:

  • Log data: IP address, browser type, operating system, pages visited, time and date of access
  • Platform activity: jobs submitted, tools used, files uploaded (filenames and sizes only — not file contents), and results retrieved
  • Session identifiers generated by AWS Cognito (our authentication service)

Communications data

If you contact us by email, submit an enquiry, or correspond with us regarding licensing or support, we retain records of that correspondence including your name, email address, and the content of messages.

Licence and billing data

For organisational licence holders, we retain records of the licence type, issue date, and the contact details of the designated licence administrator at your organisation. Payment processing (where applicable) is handled by a third-party payment processor; we do not store full payment card details.

3

How and why we use your data

PurposeData usedLegal basis
Create and manage your platform accountAccount and identity dataContract
Deliver analysis jobs and return resultsAccount data, uploaded research files, job configurationContract
Authenticate users and enforce access controlsAccount credentials, session identifiersContract / Legitimate interests
Manage organisational licencesAccount data, licence recordsContract / Legal obligation
Respond to support and licence enquiriesCommunications dataLegitimate interests
Monitor platform performance and diagnose errorsUsage data, log dataLegitimate interests
Improve our platform and servicesAggregated, anonymised usage statisticsLegitimate interests
Comply with legal and regulatory obligationsAny relevant personal dataLegal obligation
Prevent fraud and protect platform securityUsage data, log data, account dataLegitimate interests

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

5

Research and genomic data you upload

Important: You are responsible for ensuring that any research data you upload to the TopMD platform has been appropriately consented, anonymised, or de-identified in accordance with your institution's ethics approval and applicable law before upload. TopMD Precision Medicine Ltd processes uploaded data solely to deliver your requested analysis and does not independently verify the provenance of uploaded datasets.

How we handle uploaded datasets

Files you upload to the platform (such as FASTQ files, gene expression matrices, or clinical metadata) are:

  • Stored in encrypted form in AWS S3 (eu-west-2, London region) using AES-256 server-side encryption
  • Processed only to execute the analytical job you have submitted
  • Not accessed by TopMD staff except where required to diagnose a technical fault you have reported, and only with your knowledge
  • Not used to train models, shared with third parties, or used for any purpose other than delivering your analysis results
  • Retained for a limited period to allow you to retrieve your results (see Section 8)

Where uploaded data may contain personal data

If your uploaded datasets contain personal data (for example, sample IDs that could be linked back to individual research participants), TopMD Precision Medicine Ltd acts as a data processor on your behalf in respect of that data, and you remain the data controller. If you require a data processing agreement, please contact us at privacy@topmd.co.uk.

6

Who we share your data with

We do not sell your personal data to any third party. We share data only with the following categories of service providers, strictly for the purposes of delivering our platform:

RecipientPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure: compute, storage (S3), database (DynamoDB), authentication (Cognito), job execution (Batch). AWS acts as a data processor under a Data Processing Addendum.UK (eu-west-2 London, primary)
AnthropicWhere you request AI-assisted interpretation of analysis results, anonymised result summaries may be sent to Anthropic's API. No uploaded research data or personally identifiable information is transmitted.United States (with appropriate safeguards)
Email service providerTransactional email (account verification, notifications). Limited to email address and message content.EU / UK

We may also disclose personal data if required to do so by law, court order, or in response to a lawful request from a regulatory or law enforcement authority.

7

International transfers

Our primary infrastructure runs in AWS eu-west-2 (London) and your data is stored and processed in the UK by default.

Where data is transferred outside the UK — for example, to Anthropic's API for AI interpretation features — we ensure that appropriate safeguards are in place in accordance with UK GDPR, including the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses approved by the ICO.

You can request details of the specific safeguards in place for any transfer by contacting us at privacy@topmd.co.uk.

8

How long we keep your data

Data categoryRetention periodReason
Account data (active users)Duration of account plus 12 months after closureService delivery; reasonable run-off period
Uploaded research files (FASTQs, matrices)90 days from upload, then automatically deletedResults retrieval window; minimisation principle
Analysis results and job records12 months from job completionResults access; audit trail
Licence records7 years from licence expiryLegal and contractual obligation
Platform logs (access, error)90 daysSecurity monitoring; fault diagnosis
Support and communications records3 years from last contactContinuity of support; legitimate interests
9

Your rights

Under UK GDPR you have the following rights in relation to your personal data:

Right of access

Request a copy of the personal data we hold about you (Subject Access Request).

Right to rectification

Ask us to correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your personal data where there is no legitimate reason for us to continue processing it.

Right to restrict processing

Ask us to suspend processing of your data in certain circumstances.

Right to data portability

Request a copy of data you have provided to us in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interests.

Automated decisions

We do not carry out solely automated decision-making with legal or significant effects.

Right to withdraw consent

Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, contact us at privacy@topmd.co.uk. We will respond within one calendar month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk  ·  0303 123 1113. We would welcome the opportunity to address any concern before you contact the ICO.

10

Cookies

Strictly necessary cookies

These cookies are essential for the website and platform to function and cannot be disabled. They include session authentication tokens issued by AWS Cognito and CSRF protection tokens.

Analytics cookies

With your consent, we use analytics cookies to understand how visitors use our website. These help us improve our content and user experience. Analytics data is aggregated and does not identify individuals.

Managing cookies

You can manage cookie preferences through the cookie banner on your first visit, or by adjusting your browser settings. Note that disabling strictly necessary cookies will prevent the platform from functioning correctly.

11

Changes to this notice

We review this Privacy Notice periodically and will update it when our practices change or when required by law. The date at the top of this page shows when it was last updated.

For significant changes that affect how we use your personal data, we will notify registered users by email before the change takes effect and, where required, seek fresh consent. Previous versions of this notice are available on request.

Contact us

For any questions about this Privacy Notice, to exercise your data rights, or to request a data processing agreement:

CompanyTopMD Precision Medicine Ltd
PostTopMD Precision Medicine Ltd, Southampton, United Kingdom
ICOico.org.uk  ·  0303 123 1113