Merentra Privacy Notice
How Merentra handles account, professional, Training, Opportunities, connected-source and service information.
Last updated: 11 August 2026
1. Who this notice applies to
This notice applies to people who visit the Merentra website, create a Merentra account, use the secure Merentra App, connect a source, pair a device or communicate with us about the service. Merentra acts as controller for the personal information it determines how and why to process. An organisation may have separate responsibilities for information it provides or receives under an agreed service.
2. Information we process
Depending on how you use Merentra, this may include account and contact details; profession, career stage and membership choices; manual Professional Record items, categories, tags, dates, reminders, revision history and encrypted evidence attachments; Practice periods, whole-scope context, supporting information, PDP goals, declarations, Record links and preparation exports; Training programmes, rotations, capabilities, assessments, procedures, milestones, supervisors, reviews, evidence links and Training exports; feedback campaign settings, invitation delivery details, encrypted responses and thresholded aggregate reports; Opportunities you add, save or dismiss; preferences; application tasks; evidence links; revisions; source provenance; encrypted trusted-feed URLs and bounded feed results; relevance explanations; private Work profiles, job plans, rotas, imports, connected-source records, planning assumptions, actuals and additional-work records; source provenance and audit history; device and security information; support communications; subscription and payment-status information; and bounded service-health events.
3. Information Merentra is not designed to receive
Do not upload patient-identifiable information, clinical records, patient lists or information you are not authorised to use. Training assessments and feedback must not contain identifiable patient details. Do not enter employer-system passwords. Merentra’s Work imports and connections are intended for professional scheduling and career information, not clinical care records.
4. Why we use information
We use information to create and secure accounts; provide manual Record, evidence, revision, reminder and member-controlled export features; provide Practice preparation, readiness guidance, PDP and member-controlled appraisal or revalidation outputs; organise Training programmes, progression evidence, assessments, logbooks, milestones, reviews and member-controlled exports; issue purpose-limited assessment or feedback links; encrypt responses and generate reports only after closure and configured response thresholds; provide an Opportunities workspace, trusted read-only feed synchronisation, source freshness, explainable relevance and member-controlled application planning; provide Work features; import, compare and reconcile sources; calculate member-configured planning estimates; maintain connected sources; create privacy-controlled mobile snapshots; provide support; administer subscriptions; prevent abuse; meet legal obligations; and improve reliability and usability.
5. Lawful bases
We rely on performance of a contract where processing is needed to provide the service you request; legitimate interests for security, service improvement and proportionate business administration; consent where a specific optional activity requires it; and legal obligation where applicable. Special-category information should not be added unless the relevant Merentra workflow expressly supports it and a valid lawful condition has been established.
6. Connected sources
When you authorise Google, Microsoft, Google Sheets, an HTTPS calendar feed or a trusted HTTPS opportunity feed, Merentra uses the selected permission or encrypted secret to retrieve bounded source information. Credentials and feed URLs stay in the private application domain and are not sent to Business OS. Calendar changes enter protected review before timetable publication. Opportunity feeds remain read only, preserve provenance and may mark items stale or withdrawn. You can pause, remove or revoke a source.
7. Mobile devices
A paired device receives a bounded Work snapshot rather than the complete professional record. You choose generic, discreet or detailed disclosure and separately control lock-screen detail. Device access can be revoked from the Merentra App.
8. Sharing and processors
We may use carefully selected hosting, email, payment, analytics, security and support providers acting under appropriate terms. We do not sell the private professional record. We may disclose information where required by law, to protect the service or its users, or as part of a properly governed business transfer.
Opportunity matching uses member-selected preferences and bounded, approved Work, Record, Practice and Training context to calculate relevance and explain contributing signals. It does not make a solely automated decision with legal or similarly significant effect, does not verify eligibility and does not submit an application. Trusted-feed publishers do not receive the member’s shortlist, preferences, evidence links or Mara drafts through the read-only feed.
Private assessment and named feedback links are purpose limited, expire and may be single use. Possession of a private assessment link does not independently verify responder identity, so an official authenticated programme route may still be required. A member may also enable a reusable campaign website link and QR code. That campaign credential cannot submit feedback directly; it creates a separate short-lived, one-use response session for each respondent.
QR respondents do not need a Merentra account or email address. Merentra does not intentionally store a raw IP address, raw user-agent string or device fingerprint in the feedback records. It stores encrypted response content, one-way token hashes, bounded campaign settings and aggregate collection counts. Ordinary hosting, CDN, web-application-firewall or security logs may still be produced under the infrastructure provider’s policy.
The member does not receive an individual QR-session list, respondent identities or individual rating sets. Feedback reports remain unavailable until collection is closed and the minimum number of valid responses is reached. Small role groups and low-volume comment categories are suppressed. Eligible comments may be reproduced without identity and can still identify a person through their wording.
9. Organisation pilots, consent and credentials
Joining an organisation creates a bounded relationship and does not automatically disclose your private professional workspace. An organisation may hold organisation-owned records such as its tenant profile, roles, seats, programmes, cohorts, placements, invitations, audit history and credentials it issues. Access to a member-owned summary requires a specific purpose, allowlisted scope and expiry, and may be granted, declined or revoked by the member. Individual feedback responses, private notes, Mara prompts, connected-source secrets and unrelated portfolio content are not shared through the organisation consent summary. Public credential verification exposes only bounded issuer claims and current status, not the member’s identity or portfolio.
For approved pilots, a separate Merentra Data Service may receive a deterministic, pseudonymous organisation snapshot over signed requests. The snapshot excludes raw WordPress user identifiers, invitation email addresses, evidence files, individual feedback responses and provider credentials. Local pilot data is retained until migration, reconciliation, restore and deletion controls have been separately approved.
10. International transfers
Where a provider processes information outside the United Kingdom, we use an appropriate transfer mechanism and proportionate safeguards where required.
11. Retention
We retain information for as long as needed to provide the account, meet legal and security requirements, resolve disputes and maintain necessary audit history. Connection secrets are removed on revocation. Retention periods may differ by data category and organisation agreement.
12. Your rights
Subject to applicable law, you may have rights of access, correction, erasure, restriction, objection, portability and withdrawal of consent. The secure App includes account-session, device, export and application-profile erasure controls covering Record, Practice, Training, Opportunities and Work. You may also complain to the UK Information Commissioner’s Office.
13. Security
Merentra uses access controls, encryption, provenance, transactional updates, audit history, rate limiting and data-boundary controls. No online service can promise absolute security; report suspected misuse promptly.
14. Cookies
The website may use essential cookies for security, session and account functions. Optional analytics or marketing cookies should be used only in line with the choices presented by the cookie controls.
15. Contact
Use the privacy contact details shown in your Merentra account or the contact route published on this website. Please do not include patient-identifiable or unnecessary sensitive information in a privacy enquiry.
16. Changes to this notice
We may update this notice as the service, providers or legal requirements change. The current version and update date will be published here.
New accounts open only while evidence, capacity and support are current.
Merentra now uses one server-enforced gate for free registration, paid access and launch-stage promotion. Existing members keep access when the cohort is paused; new accounts reopen only after the live-acceptance run, named ownership and capacity controls allow it.