The Wellness and wai

Trust Centre

Nothing here is behind a form, anything marked on request is sent within 24 hours, and a credential we do not hold says so with the month it is expected.

10

on this site

9

sent within 24 hours

13

not held yet, each with a month

The clinic

The London Wellness Clinic Ltd, incorporated in England and Wales, trading as The Wellness. The company is the data controller for personal data processed on this site and in the clinic, and the manufacturer of wai.

The privacy policy

Every doctor who sees your people is registered with the General Medical Council. Each is named on this site with their training and qualifications, and the register itself is where a number is checked.

Our clinicians, with training and registration

The Wellness coordinates care. Regulated clinical services are delivered through registered partner clinics, UKAS accredited laboratories and registered pharmacies. The regulator each partner is registered with, and its registration details, are sent with the documents for the service you are buying.

Medical indemnity for every clinician and public liability for the clinic. Current certificates carry the insurer, the cover and the renewal date on the face of each.

The data controller is registered with the Information Commissioner’s Office. The certificate is sent rather than quoted here, so the number you rely on is the one on the document.

Clinical safety

DCB0129 and DCB0160 each require a Clinical Safety Officer, a registered healthcare professional, to approve the clinical risk management plan, every version of the hazard log and every clinical safety case report. None is appointed. Until one is, every score in the hazard log is a proposal, and this is the single gate that blocks an NHS conversation.

Version 0.1, dated 6 September 2026. 71 hazards across 156 agent actions, each scored for severity and likelihood against the criteria in the clinical risk management plan. Not approved, because no Clinical Safety Officer is appointed, so every score in it is a proposal. The document goes to a named clinical safety or security team rather than onto the open web, because it maps where the controls are thin.

A structured argument under DCB0129 3.4.1 and DCB0160 3.4.1 with the risk management plan that sets the scoring criteria, both version 0.1, dated 6 September 2026. Neither can be approved until a Clinical Safety Officer signs it, and both are sent as they stand rather than after a tidy up.

Every place in wai where a model acts or proposes, read out of the source rather than inferred from a filename. 156 actions, of which 33 reach a patient or the clinical record with nobody accepting them. That second number is the reason the hazard log exists, and we state it before anyone asks.

We are the manufacturer under DCB0129 and, in our own clinic, the deploying organisation under DCB0160. A buyer deploying wai makes their own DCB0160 case, and the hazard log, the safety case and the inventory go across at the start so they are not writing from a blank page.

MHRA guidance of 29 July 2026 says a product used only to transcribe, summarise, draft correspondence or suggest clinical codes for a clinician to review is not a medical device, and that diagnostic suggestion, treatment recommendation or autonomous action makes it one. wai does more than the exempt list, so we are seeking a written opinion rather than asserting a position.

NHS England runs a self certified supplier registry for ambient voice technology, opened in January 2026, with applications open. It asks for a Clinical Safety Officer, DTAC and the device position above, so our application follows those three.

Data protection

Every third party that processes data on our behalf, named with what it does. Read out of the code rather than kept as a list somebody has to remember to update.

The sub processors, named

A draft on our paper, written to UK GDPR, ready for your legal team to mark up. Where your standard terms are preferred, we read them.

What we hold about a person, who processes it, where it is held, how long it is kept and how it leaves. One diagram and one page. An employer sees use in aggregate only, never who and never why.

The self assessment any supplier touching NHS identifiable data completes, built on the ten National Data Guardian data security standards and now aligned to the NCSC Cyber Assessment Framework. Not submitted. The work is the assessment itself, not new controls, because the controls are already documented.

The policy that governs personal data on this site and in the clinic, and the terms under which services are provided.

The terms

Security

How access is controlled, how records are encrypted at rest and in transit, how staff are vetted, how a breach would be reported and who to call. Written so most of a security questionnaire is answered before it arrives.

The security statement

Write to team@thewellnesslondon.com. We acknowledge a security report within 24 hours. We will not pursue anyone who reports a fault in good faith and does not access another person’s data while finding it.

How to report one

Mandatory across every G-Cloud lot and asked for by every public body, and Plus for the cloud lots. Not held. Certification is against controls we already run, so the work is the audit rather than the build.

Asked for by enterprise security teams, and accepted as underway where the certificate has not yet been issued. Not held, and started rather than claimed.

Required by the second version of the digital technology assessment criteria on every administrative and remote account. Enforced on the admin surfaces and being extended to every remote path before that assessment is submitted.

Public procurement

Under the Procurement Act 2023 a supplier registers once on the Central Digital Platform, enters its core and exclusion grounds data, and issues a share code to each buying authority. Nothing public can be bid without it. Free, and one afternoon of work.

Awarded on 6 August 2026 and the first G-Cloud to run as an open framework under the Procurement Act 2023, so it reopens to new suppliers rather than closing for four years. We are not on it. Cyber Essentials is mandatory across every lot, so the application follows that certificate.

Five areas, clinical safety, data protection, technical assurance, interoperability, and usability and accessibility. The second version of the form was published in February 2026 and the previous one retired on 6 April 2026. Not submitted, because its clinical safety section asks for a Clinical Safety Officer we have not yet appointed.

Procurement policy note 002 sets a minimum weighting of 10% of the total score on social value for procurements started under the Procurement Act 2023 from 1 October 2025. Our statement names what we actually do rather than what scores well.

The social value statement

Procurement policy note 06/21 requires a carbon reduction plan committing to net zero by 2050 for central government contracts above £5m a year. No contract of ours is near that threshold, so the plan is written when a bid needs it rather than published to look prepared.

A statement to the shape the public sector accessibility regulations set, naming compliance status, the content that is not accessible and why, how to ask for an alternative and how to complain. Measured against WCAG 2.2 AA.

The accessibility statement

Our own harnesses measure contrast, target size, overflow and reduced motion on every new surface at 390 and 1280 pixels wide, and the main journeys are walked by keyboard and by screen reader. Nobody outside this company has audited it, and the statement says so rather than implying otherwise.

Time to first appointment, the proportion seen the same day and the proportion of results returned within 24 hours. Nobody else can quote a number only we hold, which makes this the strongest thing we could publish and the one thing on this page that is entirely within our control. Not published yet.

Section 54 of the Modern Slavery Act 2015 applies above £36m of turnover. We are well below it, so our statement is published voluntarily and is written to the six areas the guidance names rather than to the threshold.

The modern slavery statement

wai runs the clinic it was built in. Every clinician, every round, every letter and every payment at The Wellness goes through it, which makes the reference a working site rather than a pilot that ended.

The clinicians who use it

Who else processes the data

  • AnthropicLanguage models behind clinical drafting and the agent surfaces
  • CalendlyBooking a call from a business page
  • DeepgramSpeech to text for calls and dictation
  • Google, including FirebaseAuthentication, the earlier record store and calendar integration
  • OpenAILanguage and embedding models behind search and drafting
  • PineconeVector search across guidelines and clinical knowledge
  • ResendTransactional email on the newer paths
  • SendGridTransactional and clinical email
  • SentryApplication error reporting
  • SlackInternal notification of enquiries and agent work
  • StripeCard payments and checkout
  • SupabaseThe primary database and file storage
  • TwilioVoice calling and messaging
  • VercelApplication hosting and delivery

Read from the source on 8 September 2026, from the services the running code calls rather than from a list held by hand. Where each one holds data is confirmed in the data processing agreement. Call recordings are held in an S3 compatible object store whose provider is set per deployment and named in the data processing agreement.

Ask for the rest

Documents

Anything marked on request is sent within 24 hours, with no form and no agreement to sign first.

Ask for the documents

Security

A vulnerability report goes to team@thewellnesslondon.com. A procurement question goes to 020 3951 3429. If it is a fit, you hear from us within 24 hours.

020 3951 3429Book a demo