This is the area we go deepest in. Fifteen years building software that handles health data, with a specific track record in oncology and precision medicine — including leading engineering at Sonrai Analytics on a multi-omics analytics platform for cancer research, taken from research tool towards commercial product.
Health data is special-category data under UK GDPR Article 9. That is not a compliance checkbox bolted on at the end — it changes the architecture. Access decisions have to be audited, including the denials, because a refusal that leaves no trace cannot be reviewed. Erasure has to be evidenced rather than asserted. Data minimisation has to be a constraint applied before a field is added, not a clean-up afterwards.
Where we help
- Clinical and health-data platform architecture, from proof-of-concept to production
- Precision-medicine and multi-omics data pipelines at scale
- Applied AI and machine learning on clinical data, including the governance around it
- UK GDPR Article 9 handling — audited access, evidenced erasure, data minimisation by design
- Connected-care and remote-monitoring systems spanning web, mobile and devices
- Security and information-governance work that survives procurement scrutiny
Why it matters who builds it
What this experience buys a client is not a slide about compliance. It is people who have already made — and then lived with — the architectural decisions a regulated, clinically-adjacent system forces on you. The cost of getting those wrong is not a bug report; it is a system that cannot be signed off, or one that quietly mishandles the most sensitive data a person has.
Recent work in this area includes Halo Connected Health, a connected-care platform for health and social care, and Kintsugi, a wellbeing and recovery app handling Article 9 data with EU-resident hosting.