How SimplyWayfinding handles information
SimplyWayfinding is a digital wayfinding service that helps people find their way around hospital sites using QR codes, searchable start points and destinations, and route guidance.
SimplyWayfinding is currently operated by Allen Gibson. For personal information processed directly through SimplyWayfinding as described in this notice, Allen Gibson is the data controller. The privacy contact is info@simplywayfinding.com.
Where information is separately shared with a participating NHS organisation, that organisation may have its own responsibilities for how it handles that information.
Last updated: 10 September 2026
SimplyWayfinding has been designed to minimise the personal information needed to provide wayfinding.
When using the normal wayfinding service:
Additional information is processed only where needed for website hosting, security, aggregate Web Analytics and optional feedback, as explained below.
SimplyWayfinding calculates routes within your browser.
Once the application has loaded, selecting or changing a normal start point, destination or route does not intentionally send that selection to a SimplyWayfinding database.
The application may temporarily save the active journey in your own browser so that it can recover after a reload. This local information is described further under Cookies, storage and offline caching below.
QR codes installed at a hospital may contain a SimplyWayfinding starting location. This allows the application to know where the QR code is physically positioned without using GPS or live location tracking.
The QR code does not identify the person scanning it.
Testing of the current Netlify Web Analytics configuration has not shown these fixed QR start-location values in the analytics information available to SimplyWayfinding. The analytics view records use of the relevant site or page rather than presenting the QR starting location as location-level analytics.
Netlify still handles the web request needed to deliver the application and may process request and technical information as part of its underlying hosting, security and service operation.
SimplyWayfinding does not use QR-code information to identify an individual or infer their health, medical condition, treatment or reason for visiting a hospital.
A deliberately shared journey link or a journey QR code created by a member of staff may contain additional route information such as a start point, destination or stair-free preference so that the journey can be opened on another device.
These route parameters are used by the browser to initialise the requested journey.
SimplyWayfinding does not use information contained in these links to profile users or infer health information.
Once the journey has loaded, subsequent route calculations continue to take place within the browser unless you deliberately submit a relevant issue report. Depending on the issue selected, that report may include limited route identifiers needed to investigate it.
Feedback is optional and is collected using Netlify Forms.
The feedback form uses predefined choices. It does not provide a comments box or any other free-text field and does not ask for your name, contact details or a file upload. You cannot request or receive an individual reply through this form.
Email and other correspondence are separate contact channels, not part of the structured feedback form. They may contain free text and must be handled under their own access, retention and information-governance arrangements. Please do not include NHS numbers, appointment details, medical records or other unnecessary confidential information.
Depending on what you choose to report, the form may collect:
Limited route context is included only when it is relevant to the selected issue. A directions report may include stable identifiers for the start and destination, the current floor and route step, and the stair-free setting. A location report may include only the relevant start or destination identifier and current floor. Map, signage and obstruction reports may include the current floor and route step, but not both journey endpoints. Only accessibility issues concerning route instructions, a stair-free route or the map alternative may include the fuller route context. A relevant lift report may also include the lift identifier and reroute outcome.
Experience ratings and non-route accessibility reports do not include route identifiers. The form does not submit a written route summary.
SimplyWayfinding does not ask you to provide medical information. However, an accessibility choice or route identifier may reveal or suggest information about disability, health or the reason for visiting a particular part of a hospital.
The absence of name and contact fields reduces identification risk, but a submission should not be treated as guaranteed anonymous. Route context may be distinctive, and Netlify may process an IP address and other request metadata when receiving the form.
Redacted or aggregated feedback may be shared with participating NHS organisations during testing and pilot evaluation.
Individual submissions are not routinely shared. Where information from a submission is needed to investigate a specific problem, only the minimum relevant information will be shared under an appropriate governance arrangement or where disclosure is required by law.
SimplyWayfinding is hosted using Netlify.
Netlify currently provides:
As part of delivering, protecting and administering the website, Netlify processes technical information associated with web requests. This may include information such as IP address, browser or device information, requested page or request information, date and time, and server or security logs.
The public SimplyWayfinding application does not currently include an advertising tracker or third-party client-side analytics script.
Netlify Real User Monitoring (RUM) is not enabled.
Netlify states that personal information processed through its services may be processed internationally and that it uses appropriate legal mechanisms for relevant international transfers. Further information is available in Netlify's privacy information and Data Processing Agreement.
Feedback submitted using Netlify Forms includes the information submitted through the form. Netlify may also process IP address and other request metadata as part of providing and securing the Forms service.
SimplyWayfinding currently uses Netlify Web Analytics. The information available to SimplyWayfinding is very limited and is used only as a high-level indicator that the website is receiving traffic.
It is used to:
Netlify Web Analytics is generated on the server side from requests handled by Netlify. SimplyWayfinding does not add a client-side analytics tracking script for this purpose and Netlify Web Analytics does not require an analytics cookie.
Netlify uses technical request information, including IP addresses, when producing some aggregate statistics such as approximate unique visitor numbers.
The analytics information available to SimplyWayfinding may include page views, approximate unique visitor counts, popular pages, referral sources and broad geographic or technical information.
Testing of the current SimplyWayfinding implementation has not shown the starting-location value contained in fixed-location QR codes within the Netlify Web Analytics information available to SimplyWayfinding.
SimplyWayfinding does not use Web Analytics to:
If the analytics configuration changes so that route, QR-location or destination-level analysis becomes available or is proposed for use, the privacy implications will be reviewed before that functionality is used.
Netlify Web Analytics does not use analytics cookies.
Netlify Real User Monitoring is not enabled.
SimplyWayfinding does not currently use non-essential cookies for advertising or behavioural tracking.
The application does use functional browser storage and caching to operate the wayfinding service.
Local browser storage may keep:
This information remains within that browser and is not itself an analytics record.
Using Reset journey, clearing the start or destination, or clearing SimplyWayfinding site data in the browser removes the saved journey information.
Session storage keeps the active journey state and some temporary interface information during the current browser session.
Session information normally clears when the relevant browser session or tab is closed.
SimplyWayfinding uses a Progressive Web App service worker and browser Cache Storage to retain essential website, map and application files.
This improves performance and allows some parts of the service to continue working when connectivity is limited.
Cached website files do not by themselves tell SimplyWayfinding which route an individual planned.
Stored SimplyWayfinding information can also be removed by clearing the site's data through your browser settings.
SimplyWayfinding uses information only where it is needed to:
| Purpose | Lawful basis |
|---|---|
| Delivering, maintaining and securing SimplyWayfinding | Legitimate interests |
| Receiving, triaging and investigating structured feedback | Legitimate interests |
| Diagnosing route, map, accessibility and technical issues | Legitimate interests |
| Aggregate Web Analytics traffic indication | Legitimate interests |
| Processing or disclosure required by law | Legal obligation |
The legitimate interest supporting Web Analytics is understanding at a high level whether the website is receiving traffic and establishing a broad traffic baseline during testing.
Safeguards include:
These arrangements will be reviewed with participating organisations as SimplyWayfinding develops.
Structured feedback submissions and related operational copies held through Netlify Forms or feedback-notification email will be retained for no longer than 12 months from submission.
They will be deleted earlier where they are no longer required to triage or investigate the feedback.
Feedback may be de-identified or aggregated for service evaluation and improvement. Findings may be retained for longer only where they have been properly anonymised so that people are no longer identifiable.
Feedback records are reviewed and deleted manually.
Web Analytics information is currently available to SimplyWayfinding through Netlify for no longer than 30 days. The exact period may be shorter depending on the Netlify service in use.
Netlify may separately retain underlying hosting, security and technical-service information in accordance with its own data-processing arrangements.
Aggregate analytics summaries may be retained for longer where they do not identify individual visitors.
SimplyWayfinding does not deliberately export or retain individual route, destination or QR-location information for analytics purposes.
The retention arrangements will be reviewed before any change that would materially increase the amount or duration of personal information retained.
UK data-protection law may give you rights, where applicable, to request:
Where processing genuinely relies on consent, you may withdraw that consent.
Because SimplyWayfinding does not require user accounts and its Web Analytics is intended to provide aggregate usage information rather than identify individuals, it may not be possible to associate an analytics statistic with a particular person.
The feedback form does not collect a name, contact details or an account identifier. This may make it difficult or impossible to locate a particular submission in response to a rights request. If you contact us about a submission, we will use only the minimum information reasonably needed to try to locate it.
To make a privacy request, email info@simplywayfinding.com.
You may also complain to the UK Information Commissioner's Office.
This notice will be reviewed when SimplyWayfinding changes in a way that may affect privacy.
Examples include introducing:
The page will always show the date it was last updated.
Where a change materially affects how personal information is collected, used or shared, the change will also be highlighted within the service or at the relevant point of interaction where reasonably practicable.