Applies to: Blippit Meds v3 and the blippitmeds.com website
Last updated: 27 July 2026
Version: 2.0
Blippit Meds is provided by Get Logged In Ltd, trading as Blippit. We are registered with the Information Commissioner's Office and our entry is publicly available on the data protection register.
Get Logged In Ltd
Registered in England and Wales, company number 07309781
ICO registration: ZB082813
Contact for all data protection matters: support@blippit.co.uk, or call 01772 657100. Our registered office address is recorded on the Companies House public register under the company number above.
We have not appointed a statutory Data Protection Officer, as we are not required to do so under UK GDPR Article 37. Data protection responsibility rests with John Bidder, Director. Where Blippit Meds is deployed in an NHS Trust, that Trust will have its own Data Protection Officer, and questions about the processing of your data as a member of Trust staff should normally go to them first. See section 8.
Blippit Meds is a web-based clinical decision support tool for intravenous fluid prescribing, used by clinical staff within NHS Trusts. It restructures NICE Clinical Guideline CG174 into a set of calculators and supporting guidance.
Blippit Meds v3 is software intended for use as a Class I medical device under the UK Medical Devices Regulations 2002 (as amended). It supports clinical decision making. It does not make clinical decisions, and it does not administer or control the administration of any fluid or medicine.
Registration with the Medicines and Healthcare products Regulatory Agency is in progress. Blippit Meds v3 is not yet placed on the UK market and is currently in controlled evaluation with a partner NHS Trust.
Blippit Meds holds no patient data. No patient names, NHS numbers, dates of birth, diagnoses, ward locations or any other patient identifiers are entered into, stored by, or transmitted by the system. The system is designed so that patient identifiers cannot be entered, even inadvertently.
This distinction matters, so we state it plainly.
For personal data relating to the staff of a deploying NHS Trust, the Trust is the data controller and Get Logged In Ltd is the data processor. The Trust decides who may use Blippit Meds and for what purpose. We process staff personal data only on the Trust's documented instructions, under a Data Processing Agreement signed with that Trust.
For the blippitmeds.com website, and for our own business records such as billing and correspondence with a Trust's nominated contact, Get Logged In Ltd is the controller.
| What we process | Who it relates to | Why | Lawful basis | How long we keep it |
|---|---|---|---|---|
| Your work email address, used to send a single-use sign-in link | Clinical staff of a deploying Trust | To provide secure, password-free access to an authorised clinical tool | Legitimate interests of the Trust in providing secure access to a clinical tool | Held in the authentication service until your account is deleted, or until the Trust ends its licence |
| Access log entry: your email address, a timestamp, and whether the sign-in link was used | Clinical staff and Trust administrators | Security monitoring and access audit, so the Trust can meet its own information governance obligations | Legitimate interests of the Trust in security monitoring and access audit | 29 days. Deleted automatically by a native Firestore retention policy, not by manual housekeeping. |
| Trust administrator email address | Trust administrators, typically one to three per Trust | To provide the administration console and let the Trust manage its own team | Performance of the licence contract with the Trust | For the duration of the Trust's licence, then deleted on offboarding or on request |
| Domain change audit record: the email address and user identifier of the Get Logged In Ltd staff member who changed a Trust's approved email domains, with a timestamp and the before and after values | Get Logged In Ltd staff only | Security accountability for changes that control who can access the clinical tool | Our legitimate interests in security and accountability | Retained for the life of the Trust record as a security audit trail |
We collect no names, job titles, ward locations, professional registration numbers or any other personal attributes from clinical users. Your email address is the only personal data we hold about you as a clinical user.
Blippit Meds records anonymous data about how the calculators are used, to support the Fluid Stewardship comparison feature that Trusts use to review their own fluid prescribing patterns. Each record contains only the calculator type, a volume band, the fluid name, a count of IV medicines, and a timestamp.
These records contain no identifier of any kind, for either patient or clinician. They cannot be traced back to you. They are not personal data, and data protection law does not apply to them. They are held for 90 days by default.
There is no self-registration in Blippit Meds v3, and there is no password.
A Trust nominates one or more administrators, whom we add to the Trust's account. The Trust supplies the email domain or domains used by its clinical staff. When you enter your work email address, the system checks it server side against that Trust's approved domains. If it matches, you are sent a single-use sign-in link by email. If it does not match, no access is granted.
Sign-in links are single use and expire after 15 minutes. There is no password to create, store, forget or reset.
Signing in on a second device does not sign you out of the first. If you use a shared device, sign out when you have finished.
All data is held in Google Firebase, within Europe.
| Service | Purpose | Location |
|---|---|---|
| Firebase Authentication | Sign-in identity | eur3, Europe multi-region |
| Cloud Firestore | Access logs, Trust administrator records, Trust configuration, anonymous usage data, domain change audit | eur3, Europe multi-region |
| Firebase Hosting | Serving the application | Europe |
| Cloud Functions | Server-side access checks and administrative operations | europe-west1, Belgium |
No personal data is transferred outside the United Kingdom or the European Economic Area in normal operation. Transfers between the UK and the EEA are covered by the UK adequacy regulations for the EEA.
Data is encrypted in transit using TLS and encrypted at rest by Google Cloud. Access to the underlying Firebase console is restricted to Get Logged In Ltd and protected by strong authentication.
Access to data within the application is enforced server side by Firestore security rules, not by the browser, so the restrictions below cannot be bypassed by a user:
Blippit Meds uses algorithms. It calculates fluid volumes and rates from clinical values that the user enters, and it displays guidance based on those values. This is the core function of the product.
None of this constitutes automated decision making about you under UK GDPR Article 22. The calculations concern a patient's fluid requirements, not the user, and they produce a recommendation for a qualified clinician to accept, adjust or reject using their own judgement. No decision about any individual is made solely by automated means, and no decision produces a legal effect or similarly significant effect on any data subject whose personal data we process.
We do not profile users. We do not analyse individual usage patterns, and we do not use your data to make any assessment about you.
You have the following rights over your personal data: access, rectification, erasure, restriction of processing, objection to processing, and data portability. Where processing relies on consent, you have the right to withdraw it, although we note that none of the processing described in section 4 relies on consent.
You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As set out in section 7, no such decision is made.
How to exercise them. If you are a member of staff at a Trust using Blippit Meds, the Trust is the controller of your data, so please contact your Trust's Data Protection Officer or Information Governance team in the first instance. We will support the Trust in responding.
You may also contact us directly at support@blippit.co.uk and we will pass your request to the relevant Trust and assist with it.
We and the Trust will respond within one month of receiving your request. If a request is complex we may extend this by up to two further months, and we will tell you if that happens.
Erasure has a practical consequence worth stating: your email address is how the system knows you are authorised. If it is erased, your access to Blippit Meds ends.
Some limited business records, such as invoicing records naming a Trust's contact, must be kept for six years to meet UK tax and company law obligations, and cannot be erased on request.
We use one sub-processor in the delivery of Blippit Meds. A data processing agreement is in place.
| Sub-processor | What it does | Data involved | Location |
|---|---|---|---|
| Google Ireland Limited (Firebase: Authentication, Firestore, Hosting, Cloud Functions) | Authentication, data storage, hosting, server-side processing | Work email addresses, access logs, Trust administrator emails, anonymous usage data, domain change audit records | Europe (eur3 and europe-west1) |
We will tell affected Trusts before adding or replacing a sub-processor.
We do not sell personal data. We do not share personal data with third parties for marketing purposes. We do not share it with anyone other than the sub-processor above and the deploying Trust itself.
Zero tracking. blippitmeds.com does not use Google Analytics, advertising cookies, or any other analytics or advertising tag. As we do not currently have traffic expectations for this site, we have not deployed a tracking solution. The site sets only cookies that are strictly necessary for it to function, if any. If this changes, this section will be updated to name the tool and describe the cookies it sets.
This policy does not apply once you follow a link from our website or from within Blippit Meds to a third party site. If a Trust embeds a help video hosted elsewhere, for example, that provider's own privacy policy applies to your use of it.
Blippit Meds is a professional tool for clinical staff. It is not intended for, marketed to, or accessible by children. We do not knowingly process the personal data of anyone under 18. If you believe we hold data relating to a child, contact support@blippit.co.uk and we will investigate and delete it.
We maintain a process for identifying, containing and assessing personal data breaches. Where a breach affects Trust staff data, we will notify the affected Trust without undue delay so that the Trust, as controller, can meet its own obligation to notify the Information Commissioner's Office within 72 hours where required.
If you have a question or a complaint about how your data has been handled, contact support@blippit.co.uk and we will investigate.
If you are not satisfied with our response, or you believe your data is being processed unlawfully, you can complain to the Information Commissioner's Office at ico.org.uk/concerns or by calling 0303 123 1113.
We review this policy annually, and whenever we make a material change to how Blippit Meds processes data. The date at the top of the page shows when it was last updated. Where a change materially affects how Trust staff data is processed, we will notify deploying Trusts directly rather than relying on you noticing the change here.
Blippit Meds is a product of Get Logged In Ltd, trading as Blippit. This policy sits alongside the Blippit Meds Data Protection Impact Assessment (BMv3-DOC-007) and the Data Processing Agreement held with each deploying Trust, both of which are available to Trust Information Governance teams on request.