Privacy Policy

Overview

It is important that you read this privacy policy carefully, together with any other similar or additional information that SLC Care Ltd T/A Healthcare Matters (‘the Company’) may give you about how it collects and uses your personal data. The Company takes the security and privacy of your personal data seriously and it has a duty to notify you of the information contained in this privacy policy. This privacy policy explains how the Company will hold and process your personal data and about your rights.

When the Company processes your personal data, it is acting as a ‘data controller’. This means that it determines the purpose and means of the processing of your personal data. The Company’s contact details are Harrison House, Rackery Lane, Llay, Wrexham, LL12 0TB (‘Head Office’). Telephone 01978 269901. Email info@healthcare-matters.com.

The Company’s Data Protection Officer can be contacted at the Company’s Head Office. Telephone 01978 269901. Email info@healthcare-matters.com.

It is important that the personal data the Company holds about you is accurate and up to date. If applicable, please keep the Company informed if your personal data changes.

You should direct any questions in relation to this privacy policy or data protection to a Director or the Company’s Data Protection Officer.

This privacy policy does not give you any contractual rights and can be amended by the Company at any time. It is intended that this privacy policy is fully compliant with the Data Protection Act 2018 (the ‘2018 Act’) and the EU General Data Protection Regulation (‘GDPR’) (or such other legislation that may replace or amend the 2018 Act and GDPR). If any conflict arises between those laws and this privacy policy, the Company intends to comply with the 2018 Act and GDPR.

The personal data we collect and where it comes from

‘Personal data’ means information which relates to a living person who can be identified from that data on its own, or when taken together with other information which is likely to come into our possession. It includes any expression of opinion about the person and an indication of the intentions of us or others, in respect of that person. It does not include anonymised data.

We will collect and use the following types of personal data about you (where applicable):

We may obtain your personal data from you or from somewhere else such as somebody acting on your behalf, a health/social care professional and/or organisation or any other professional and/or organisation, a provider of healthcare products and/or services, a funding organisation, a charity, or it could be created by us.

How we process your personal data

We may use your personal data (including special categories of personal data) for the following reasons (where applicable):

managing our relationship with you; determining which products and/or services we can offer; providing our products and/or services to you; for administration and accounts purposes; carrying out any contracts between us; marketing; dealing with any enquires, compliments, concerns and complaints; liaising with whoever is acting on your behalf; liaising with health/social care professionals and/or organisations or other professionals and/or organisations; liaising with funding organisations; liaising with charities; enabling us to meet any legal and other regulatory obligations imposed on us; providing information to regulatory authorities or statutory bodies, and our legal or other professional advisers including insurers; retaining a record of our dealings; establishing quality, training and compliance with our obligations and best practice; complying with health and safety law and other laws which affect us; monitoring and protecting the security of the Company, its property and individuals who have permission to be on Company property; running our business and planning for the future; for Company operations; maintaining safety; safeguarding; preventing and/or detecting fraud or other criminal offences; defending the Company in respect of any investigation or litigation and complying with any court or tribunal orders for disclosure; compliance; audit usage of our website; to conduct data analytics studies to review and better understand how we provide our products and services; and for any other reason which we may notify you of from time to time.

The legal basis for processing your personal data

We must have a legal basis to process your personal data (including special categories of personal data). In most cases, the legal basis can be any of the following (where applicable):

By law we must treat special categories of personal data with even more care and must have an additional reason for processing this type of data. The additional reason can include any of the following (where applicable):

Consent is another legal basis for processing personal data (explicit consent is required in the case of processing a special category of personal data). In most situations we will not rely on your consent as a legal basis to process your personal data (including special categories of personal data). If we ask for your consent then we will explain the reason for our request. You do not need to consent and can withdraw your consent later if you choose by contacting a Director or the Company’s Data Protection Officer. If we are relying on consent to process your personal data and you decide to withdraw it, this will not affect the lawfulness of any processing we have carried out that was based on your consent before you withdrew it. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

We will not use your personal data for an unrelated purpose without telling you about it and the legal basis that we intend to rely on for processing it.

If you choose not to provide us with certain personal data, you should be aware that we may not be able to meet our legal obligations and duties such as if you do not provide us with your contact details we will not be able to deal with your VAT exemption application (if applicable). It may also stop us from entering into a contract to provide you with products and/or services or carrying out certain parts of a contract between us if, for example, we do not know about your health data.

We do not take automated decisions about using your personal data or profiling in relation to you.

Sharing your personal data

Sometimes we might share your personal data with third parties for us to take steps to enter into an agreement with you, for us to assess whether can provide you with our products and services, for us to provide you with our products and/or services and for our legitimate interests. We may also share your personal data if the law or a public authority says that we must do so, if we need to comply with a legal or regulatory obligation and if we need to in order to establish, exercise or defend our legal rights. Where such sharing is necessary, we will comply with the requirements of the 2018 Act, GDPR and our legal obligations.

We do not send your personal data outside the European Economic Area (‘the EEA’). If this changes you will be notified of this and the measures which are in place to protect the security of your data will be explained.

How long we keep your personal data for

We will only hold your personal data for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements. To determine the appropriate retention period for personal data, we shall consider:

the amount, nature, and sensitivity of the personal data; the purposes for which we process your personal data and whether we can achieve those purposes through other means; whether the law, our regulatory obligations, accounting or any reporting requirements require us to continue to process your personal data; if we need to keep your personal data in relation to establishing, exercising or defending a legal claim; whether we have any other need to continue to process your personal data; and the potential risk of harm from unauthorised use or disclosure of your personal data.

How we keep your personal data safe

We will take appropriate measures to secure your personal data and protect it against unauthorised or unlawful processing, as well as against its accidental loss, destruction or damage.

Your data subject rights

You have the following rights to your personal data:

Your ability to exercise these rights will depend upon a number of factors and in some circumstances, we may not be able to comply with your request, for example, if we have legitimate grounds for not doing so or where the right does not apply to the particular data we hold on you etc.

You are not required to pay any charge for exercising your rights. However, in certain circumstances we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.

We have one month to respond to you, unless there are specific circumstances in which we can extend the time to respond.

We may need to request specific information from you (or somebody on your behalf) to help us confirm your identity when you wish or somebody on your behalf wishes to exercise any of your rights.

If you have any questions concerning your rights or should you wish to exercise any of your rights, please contact a Director or the Company’s Data Protection Officer.

Complaints procedure

You have the right to complain about how the Company processes your personal data.

We are committed to processing personal data responsibly, securely, and in compliance with the 2018 Act and GDPR. We recognise the importance of transparency and accountability in our data processing activities.

We are dedicated to providing a fair, accessible, and transparent complaints process for all individuals (data subjects) whose personal data we process. We take all concerns seriously and aim to resolve them promptly and effectively.

If you have a concern about how we have processed your personal data, you must first raise a complaint with us using the process outlined below.

How to make a complaint

We have established an accessible process for individuals to raise concerns. Complaints can be submitted through the following channels:

How we handle your complaint

When we receive a complaint regarding personal data, we will follow these steps:

Escalation to the ico - when to escalate

You may escalate your complaint to the Information Commissioner's Office (‘ICO’) only if:

The ICO’s contact details are:
Website: ico.org.uk
Helpline: 0303 123 1113