Tempo GP

Security summary

Studystreaks Ltd · Tempo GP · last updated August 2026

A single page a practice manager can hand straight to their eHealth or IT lead. For the full processor agreement, see data governance & DPA.

Whitelist request letter

Zero patient data

Tempo GP never requests, collects, stores or processes patient identifiable data. Do not enter patient names, dates of birth, CHI or NHS numbers, or identifiable clinical detail into any free-text field, note or friction tag.

Controls at a glance

Patient data
Tempo GP never requests, collects, stores or processes patient identifiable data. Do not enter patient names, dates of birth, CHI or NHS numbers, or identifiable clinical detail into any free-text field, note or friction tag.
Encryption in transit
TLS 1.3 (HTTPS), with HSTS enforced
Encryption at rest
AES-256 at rest, including database backups
Hosting
UK / EU data centres, served through Cloudflare's edge network
Authentication
Email and password or Google sign-in, with hashed credentials handled by the managed auth provider
Access control
Per-row database authorisation (Row Level Security) scoped to the signed-in clinician. Team views are aggregated, and any view that could identify one clinician is suppressed until at least three have contributed.
Session timeout
Signed-in sessions end automatically after 45 minutes without interaction, with a warning first — so a session left open on a shared consulting room computer closes itself.
Rate limiting
Sign-in and password reset are rate limited by the authentication provider. Sheet reading is capped per user per hour, with edge rate limiting in front of the site.
Retention and deletion
Full access while subscribed; 30 days to download everything after a subscription ends; permanent secure deletion at day 90.
Breach notification
The controller is notified without undue delay and within 48 hours of Studystreaks Ltd becoming aware of a personal data breach.
Network requirements
Outbound HTTPS (TCP 443) only. No inbound connections, no local install, no browser plug-in, no smartcard integration.
Reporting a vulnerability
Email hello@studystreaks.co.uk with the details. We acknowledge reports within two working days and will not pursue researchers acting in good faith.

Security response headers

Sent on every page, so they can be checked with any header inspection tool.

Sub-processors

Studystreaks Ltd, company no. SC865254, Studystreaks Ltd, c/o Smith & Wallace & Co., 1 Simonsburn Rd, Kilmarnock, Scotland, KA1 5LA.

ICO registration: application in progress

Security contact: hello@studystreaks.co.uk