Privacy Notice
Our Vision
This privacy notice explains what happens to any personal data you give us or that we may collect from or about you. It applies to all products, services, and instances where we collect your personal data.
This notice:
- Let you know what we do with your personal data and what we do to keep it secure. It also explains where and how we collect your personal data, as well as outlines your rights over any personal data We hold about you; and
- It applies to all products, services, and instances where we collect your personal data (for example, if you use any of our websites or services, use any of our mobile apps, or interact with us on social media). However, please note that certain of our sites and products will have their own specific privacy notices or policies that will apply in place of this notice.
This privacy notice has been adopted by Umedeor Ltd (company number 11067577) and its subsidiary Cohort Science (company number 13780369) in line with UK GDPR and the Data Protection Act 2018.
The contact address for all the companies referred to above is: 8 Warner Yard, London, EC1R 5EY
1.Scope of this privacy notice
This notice sets out the basis on which any personal data we collect from you or that you provide to us will be processed by us. ‘Processing,’ for the purpose of this notice, covers a very broad range of activities including using, transferring, storing and even deleting.
Please read the following terms carefully to understand our views and practices regarding your personal data and how we will treat it. For the avoidance of doubt, by registering with or using our websites, apps, services, or otherwise interacting with us, you consent to the collection, use and transfer of the relevant data and your information under the terms of this privacy notice (save that, as noted above, certain of our sites and products will have their own specific privacy notices or policies which will apply in place of this notice).
2. What information about you might we process and where do we get it from?
We may collect and process the following information about you:
Information you give us:
- You may give us information about yourself by filling in forms on our websites, using our services, or corresponding with us (for example, by e-mail or via social media). The information you give us may include your name, address, email address, phone number, and feedback you might provide.
- If you contact us, we may keep a record of that correspondence.
- Information is provided when submitting or updating a request for support or contacting our support teams.
- Information provided when creating a user account within our clinical systems (including usernames and password information).
- Information is collected as a result of any monitoring that may take place. We may monitor (including recording) certain interactions between us to comply with any legal obligations, detect fraud or criminal activity, and for training purposes.
- Information about any device that you use to visit our websites or access our services (such as the type of device used, operating system, browser type, IP
address, and screen resolution. - Details of the resources you access through our websites or services.
3. What uses do we make of the information?
The information We collect may be used in the following ways:
- To manage your account and for our own internal administrative purposes.
- To provide you with information, products, or services you request from us.
- To contact you about our services (see below for more information regarding our marketing activities).
- To conduct market research and statistical analysis, either ourselves or through an agency.
- To help us understand you better as a user of our websites and/or a recipient of our services, we can improve our sites and services and better deliver them to you.
- To perform any contracts entered between you and us.
- For security and safety purposes.
- To assist you with using our websites and services and to respond to any comments or queries you may have raised.
- To allow you to participate in interactive features of our websites or services when you choose.
- To notify you about changes to, or any issues with, our services.
- To ensure that We present the correct version of our websites and services for your device; and
- To monitor visitor interests and behaviour and understand general usage of our websites and services, which will help us improve our sites and services. Please note that our websites are not intended for children, and (save as may be expressly provided for) we do not knowingly collect data relating to children via our websites.
We will only use your personal data for the purposes we collected it unless we consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis.
4. What are the grounds used to justify our processing of your personal data?
Like most businesses we may rely on a range of legal bases to ensure that our use of your personal data is lawful, including:
- Where it is needed to provide you with our products or services, such as:
- Updating your records and contacting you about the relevant product or service (where appropriate).
- Sharing your personal data with service providers to deliver the relevant product or service.
- Activities relevant to managing the relevant product or service including any enquiries you may make regarding the product or service, your application to receive the relevant product or service, and the administration and management of accounts.
- Where it is in our legitimate interests to do so (provided this is not overridden by considerations regarding your rights and interests), such as:
- Managing your products and services relating to that, updating your records, and contacting you about the relevant product or service (where appropriate).
- Performing and/or testing the performance of our products, services and internal processes.
- The following guidance and recommended best practices of government and regulatory bodies.
- Managing and auditing our business operations including accounting and finance functions.
- Monitoring and keeping records of our communications with you.
- Administering our governance requirements, such as internal reporting and compliance obligations.
- Undertaking market research analysis and developing statistics.
- For direct marketing communication purposes to help us offer you relevant products and services; and/or
- Complying with any relevant legal and/or regulatory obligations.
- To comply with our legal obligations; and/or
- With your (explicit) consent (though except for some direct marketing communications, it is not likely that we would rely on this ground).
5. Cookies
We use cookies to distinguish you from other users. This helps us provide you with a good browsing experience and allows us to improve our website.
To each of your visits to our website, the information we collect about you includes:
- Technical information, including the internet protocol (IP) address used to connect your computer to the internet.
- Internet browser type and version
- Login information, time zone setting and location.
- Browser plug-in types and versions.
- Operating system and platform.
- Other technology used to access our website
- Complete Uniform Resource Locators (URL) clickstreams to, on and from our websites, products/services you viewed or searched for.
- Page response times, download errors, and length of visits to certain pages.
- Page interaction information (such as scrolling, clicks and mouse-overs).
- Methods used to browse away from the page
Please refer to our Cookie Policy for detailed information on our cookies and their purposes.
6. Disclosure of the information
We may disclose your information to other organisations in certain situations. For example, we may disclose information:
- Within uMed for our internal business purposes and to the extent necessary for us to deliver any relevant services to you approved and on behalf of your GP.
- To third-party partners and suppliers where we need them to process your personal data on our behalf and as approved by your GP, so that we can deliver our services to you. Of course, we remain responsible for those third parties, and it is our responsibility to ensure that they use any personal data that we make available to them correctly and in accordance with our instructions and the law.
- In order to:
- enforce or apply our terms of use in respect of our websites, services and/or other agreements or to investigate potential breaches; or
- protect our rights, property and safety (and that of our customers or others).
- If we are obliged to disclose or share your personal data to comply with any legal or regulatory obligation or request.
- We may share information with prospective purchasers in connection with a potential sale or transfer of part or all of our business.
7. Information storage and information retention
The information we collect from you will be processed (which may include, where relevant, storing it) in accordance with our obligations under the relevant laws, which set out our obligations as someone with personal data within our possession and control.
We will retain a record of your personal data in accordance with relevant law and based on the following criteria:
- Where we have a reasonable business need to do so, for example, to manage our relationship with you;
- Where we are providing products and/or services to you and then for as long as someone could bring a claim against us in respect of those products or services; and/or
- In line with any legal and regulatory requirements or guidance regarding retention periods.
We use strict procedures and security features designed to prevent any unauthorised or unlawful access to the personal data we control. All information you provide to us is stored securely at our offices and (where relevant) at the offices of third-party agencies, service providers, representatives, and agents, as described above. We also hold your personal data in secure data centres in the UK.
Where we have given you (or where you have chosen) a password that enables you to access certain parts of our website(s) or services, you are responsible for keeping this password confidential. We ask you not to share your password information with anyone.
8. Transfers of personal data overseas
We are primarily a UK-based business; where possible, we use third-party vendors in the UK or EU. However, occasionally, where that is not possible, uMed will ensure that the third-party has adequacy regulations that meet the requirements of the GDPR as recommended by the ICO.
9. Third-party sites and links
Our websites may, from time to time, contain links to and from the websites of our partner networks (from certain of our sites), advertisers, or other third parties (for example, we include links below to the site of the Information Commissioner’s Office).
If you follow a link to any of these websites, please note that these websites and any services that may be accessible through them have their own privacy notices and policies and that we do not accept any responsibility or liability for these notices or policies (and how they may be applied) or for any personal data that may be collected through those third-party websites or services, such as contact and location data. Please check the relevant third-party policies before providing personal data to those websites or using their services.
10. Marketing – Letting you know about our products and services
From time to time, we would like to tell you about the products and services available from uMed.
If you have agreed to receive marketing materials from us, we may contact you by post, email, text message, online, social media, or any other electronic means.
In addition, as noted above, we have a legitimate interest in using the personal data we hold about individuals to inform them about our products and services. This ground will not apply if you interact with us in a personal capacity.
You have the right to ask us not to process your personal data for marketing purposes at any time. You can exercise your right to limit or prevent such processing by contacting us (see below) or selecting an option to unsubscribe in any relevant electronic communication.
11. Your rights
You have several important legal rights regarding how personal data relating to you is used. You can find more information about your rights on the Information Commissioner’s Office website – please see https://ico.org.uk/for-the-public/
Below, We have outlined the key rights that may be relevant to your use of our websites and services.If you want to exercise these rights, please contact us using the information below. Please note that You may be asked to provide us with reasonable proof of your identity so that we can be sure that we are discussing your information with you (or if someone is making a request on your behalf, they have the authority to do so).
Please note that if you have a query regarding any medical record or similar that we hold on behalf of a GP practice or hospital, then we will most likely need to refer your query to the relevant third party as they are responsible for that information (i.e., they are the ‘data controller’) and will need to determine how to respond to your query.
12. Right of access to information
You have the right to access certain information held about you so that you can be aware of, and verify the lawfulness of the processing we undertake.
You can exercise your right of access by making a ‘subject access request.’
We will review each request that we receive, and if we agree that we are obliged to provide personal data to you, then we will (subject to certain limited exceptions provided under the relevant law) amongst other things: (i) describe it to you; (ii) tell you why we are holding it; (iii) tell you who it could be disclosed to; and (iv) let you have a copy of it (this may include providing an electronic copy).
13. Right to have information corrected
If you identify that any personal data we hold about you needs to be corrected, inaccurate, or updated, you may ask us to correct or update it. Please contact us using the details below; we will review each request and respond accordingly.
14. Right to stop or limit our processing of your personal data
This is also known as the ‘right to be forgotten.’ You have the right to require us to stop or limit any processing we are undertaking regarding your personal data if we no longer have a valid reason to do so or if we have held it for too long.
This is not an absolute right, but every request we receive will be considered carefully, and we will respond accordingly (providing grounds for any decision we make).
15. Right to withdraw consent
You are free to withdraw any consent you have given to us regarding our use of your personal data at any time. As noted above, you have the right to tell us to stop sending you any direct marketing materials at any time.
16. Right to complain
If you are unhappy about the way in which we have processed your personal data then you have a right to raise the issue or to lodge a complaint with the Information Commissioner’s Office – as noted above please see https://ico.org.uk/for-the-public/ for further details.
17. Changes to our privacy notice
We will keep this privacy notice under regular review and we may update it from time to time (for example, to reflect changes we might make to our services or to reflect changes in the law or best practice).
Any changes we may make to our privacy notice will be posted on this page. Please visit this page periodically so that you are aware of any changes that have been made.
This version of the privacy notice is effective from 07-November-2024.
Contact
If you have any comments or concerns regarding our privacy notice, or how We handle your personal data, or if you would like to exercise any of the rights outlined above, then please do feel free to contact us by one of the following means, and we will consider your comments and respond accordingly:
By email: dpo@umed.org