The following sections set out why we are processing your information, what information we collect, the legal basis for and duration of our processing of your information and (if applicable) who your information will be shared with and where those recipients are based.
Which information do we process and for what purpose?
We process the following information from you:
- Information you give us. Information that you provide by filling in forms on our site www.permahealth.co.uk (our site). This includes information you provide when you register to use our site, request marketing information, use our online chat feature, enter a competition, promotion or survey and when you report a problem with our site. The information you give us may include your name, address, company name, email address, Date Of Birth and phone number.
- Details of Your Visit to our Website. We collect non-personally identifying information of the sort that web browsers and servers typically make available. This includes, but is not limited to, traffic data, location data, weblogs and records of how you navigate the pages on our site and how you interact with the pages.
- IP addresses. We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
We process information you give us and that we collect about you for the following purposes:
- To ensure that content from our site is presented in the most effective manner for you and for your computer.
- To provide you with information, products or services that you request from us or which we feel may interest you, where you have consented to be contacted for such purposes.
- To carry out our obligations arising from any contracts entered into between you and us.
- To allow you to participate in interactive features of our service, when you choose to do so.
- To notify you about changes to our service.
What are the grounds for processing your information?
We are processing your data on the following ground(s):
- you have previously given your consent to us processing your data the purposes stated in section 2.2, above; and/or
- the processing is necessary for achieving our legitimate interest in respect of the goods or services you have requested or purchased. In accordance with data protection law, we have carefully weighed your interests and fundamental rights and freedoms against our interest to process your information and are satisfied that we are justified in processing your information for this purpose.
- for the fulfilment of contract GDPR Article 6.1(b)
- processing health and social care data under GDPR Article 9.2(h)
Duration and further processing
We will regularly review the personal data which we are holding about you, and will delete it as appropriate. We will store your personal data for no longer than is necessary for us to fulfil the purpose for which it was obtained and given consent for provided that we have a reasonable commercial case for doing so.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Who is your information shared with?
It may be possible that we will share your information with other partner organisations if this is required and we will apply very strong controls. The current organisations who we share data with includes:
- Partner Private Hospitals
- Electronic Records Management Provider
- Invoice & Billing Partner
- GP
- Referring specialists/Opticians
- NHS Trusts
It is noted that the above list is not exhaustive, and we may contract with other external organisations to undertake processing of your personal information. These 3rd party organisations will abide with our stringent contractual conditions regarding the protection of personal data. In some cases, you will be requested to provide positive consent if we intend to share your personal details with other organisations.
Subject to the above paragraph, we will never sell, share, or rent your personal data without your prior consent. It should be noted that, because we do not control the privacy practices of third parties, we advise that you read and fully understand their privacy policies in addition to this privacy policy. We do not disclose information about identifiable individuals to our advertisers. We may disclose your personal information to third parties:
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
- If Prema Health Ltd or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
- If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use or terms and conditions of supply and other agreements; or to protect the rights, property, or safety of Prema Health Ltd., our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
We will not share your personal information with or sell it to third-party marketers.
We may use the following third-party service providers named below to process and store your data:
- Brevo (Sendinblue INC), which we use to manage email marketing subscriber lists and send emails to our subscribers. You can read their privacy policy here https://www.brevo.com/legal/privacypolicy/
- Carebit, which we use to store and process patient information. Read their privacy policy.
- Enquiry Bot, which collates and collect a wide variety of data which relating to its primary role as chatbot provider on our website. To clarify the word, collect, this means with the use of a form on a website. A customer/client enters the details manually themselves for a purpose stated at the time. Read their privacy policy here https://www.enquirybot.com/privacy-policy
The data that we collect from you will not be transferred to or stored at a destination outside the European Economic Area (“EEA”) without your prior consent.
Automated decision making. As part of our practice management software, your data may be subject to automated processing in order to generate letters and email communications relating to your treatment and aftercare. This is carried out under our legitimate interest in doing so in order to complete any obligations under contracts or services entered into by you with us. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
Automated decision making
As part of our clinical software platform, Carebit, your data may be subject to automated processing in order to generate letters and email communications relating to your treatment and aftercare. This is carried out under our legitimate interest in doing so in order to complete any obligations under contracts or services entered into by you with us.
Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmission to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.