Introduction
Welcome to the Myhealthcare Clinic Ltd's
privacy policy.
1. IMPORTANT
INFORMATION AND WHO WE ARE
2. THE
DATA WE COLLECT ABOUT YOU
3. HOW
IS YOUR PERSONAL DATA COLLECTED?
4. HOW
WE USE YOUR PERSONAL DATA
5. DISCLOSURES
OF YOUR PERSONAL DATA
1.
Important information and who we are
Purpose of this privacy policy
This privacy policy aims to give you
information on how Myhealthcare Clinic Ltd collects and processes your personal
data through your use of this website and our mobile application, including any
data you may provide through this website/mobile application when you visit our
website/mobile application, fill out a form, or in connection with other
activities, services, features or resources we make available. This website and mobile application is not intended
for use by children.
Full name of legal entity: Myhealthcare Clinic
Ltd (registered company
number: 08503371)
Email address: info@myhealthcareclinic.com
Postal address: 18 Wimpole Street, London W1G 8GD
Telephone number: 020 7099 5555
Changes to the privacy policy and your duty
to inform us of changes
We keep our privacy policy under regular
review.
2.
The data we collect about you
·
Identity Data includes first name, maiden name, last name, username
or similar identifier, marital status, title, date of birth and gender.
·
Contact Data includes billing address, delivery address, email
address and telephone numbers.
·
Financial Data includes bank account and payment card details.
·
Transaction Data includes details about payments to and from you and
other details of products and services you have purchased from us.
·
Technical Data includes internet protocol (IP) address, your login
data, browser type and version, time zone setting and location, browser plug-in
types and versions, operating system and platform, and other technology on the
devices you use to access this website.
·
Profile Data includes your username and password, purchases
or orders made by you, your interests, preferences, feedback and survey
responses.
·
Usage Data includes information about how you use our website,
products and services.
·
Marketing and Communications Data includes your preferences in receiving marketing from
us and our third parties and your communication preferences.
·
Health Data includes clinical information discussed with one of
our health professionals relating to medical, dental and surgical conditions
and includes diagnoses, treatment plans, prescribed medications and/or other
related clinical information. This is one of the special categories of personal data under the applicable data
protection laws.
We also collect, use and share Aggregated Data
such as statistical or demographic data for any purpose. Aggregated Data could
be derived from your personal data but is not considered personal data in law
as this data will not directly or
indirectly reveal your identity. For example, we may aggregate your Usage Data
to calculate the percentage of users accessing a specific website feature.
However, if we combine or connect Aggregated Data with your personal data so
that it can directly or indirectly identify you, we treat the combined data as
personal data which will be used in accordance with this privacy policy. As
stated above, we may collect Health Data about you. This is one of the special categories of personal data,
which is subject to additional protections and restrictions under the
applicable data protection laws. Further
information regarding our use of your Health Data is set out below in this
privacy policy.
We do not we collect any
information about criminal convictions and offences.
If you fail to provide personal data
Where we need to collect personal data by law, or under the terms of a
contract we have with you, and you fail to provide that data when requested, we
may not be able to perform the contract we have or are trying to enter into
with you (for example, to provide you with goods or services). In this case, we
may have to cancel a product or service you have with us but we will notify you
if this is the case at the time.
3.
How is your personal data collected?
We use different methods to collect data
from and about you including through:
·
Direct
interactions.
You may give us your Identity, Contact, Health and Financial Data by filling in
forms or by corresponding with us by post, phone, email or otherwise or by otherwise
entering into a contract with us. This includes personal data you provide when
you:
·
apply
for our products or services;
·
create
an account on our website or mobile application;
·
subscribe
to our service or publications;
·
request
marketing to be sent to you;
·
enter
a competition, promotion or survey; or
·
give
us feedback or contact us.
·
Automated
technologies or interactions.
As you interact with our website, we will automatically collect Technical Data
about your equipment, browsing actions and patterns. We collect this personal
data by using cookies and other similar technologies. Please see our cookie
policy for further details.
·
Third
parties or publicly available sources. We will receive personal data about you from various
third parties and public sources as set out below:
Technical Data from the following parties:
(a)
analytics
providers such as Google based inside the UK;
(c)
search
information providers.
·
Contact,
Financial and Transaction Data from providers of technical, payment and
delivery services such as Stripe, Inc. based inside the UK.
·
Identity
and Contact Data from publicly available sources such as Companies House and
the Electoral Register based inside the UK.
4.
How we use your personal data
·
Where
we need to perform the contract we are about to enter into or have entered into
with you.
·
Where
it is necessary for our legitimate interests (or those of a third party) and
your interests and fundamental rights do not override those interests.
·
Where
we need to comply with a legal obligation.
Purposes for which we will use your
personal data
As stated below, we may process your Health Data.
Under the applicable data protection laws, we are required to have both a
lawful basis to process such Health Data and we are required to meet one of the
specific conditions in Article 9 of the retained EU law version of the General
Data Protection Regulation ((EU) 2016/679) and the associated conditions
in UK law, set out in Part 1 of Schedule 1 of the Data Protection Act 2018. Where
relevant, such conditions are identified in the table below.
Purpose/Activity |
Type of data |
Lawful basis and conditions for processing including
basis of legitimate interest |
To register you as a new customer |
(a) Identity (b) Contact (c) Health |
(a) Performance of a contract with you (b) Necessary for health or social care purposes
(including, but not limited to, the purposes of preventive or occupational
medicine, medical diagnosis, and/or the provision of health care or
treatment) |
To process and deliver your order including, but not
limited to: (a) Manage payments, fees and charges (b) Collect and recover money owed to us (c) Complete the services that we have contracted
with you to deliver (including, but not limited to, medical test and other
healthcare services) (d) Otherwise performing a contract that we have
with you |
(a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications (f) Health |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to
recover debts due to us) (c) Necessary for health or social care purposes (including,
but not limited to, the purposes of preventive or occupational medicine,
medical diagnosis, and/or the provision of health care or treatment) |
To manage our relationship with you which will
include, but is not limited to: (a) Notifying you about changes to our terms or
privacy policy (b) Asking you to leave a review or take a survey |
(a) Identity (b) Contact (c) Profile (d) Marketing and Communications (e) Health |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep
our records updated and to study how customers use our products/services) (d) Necessary for health or social care purposes
(including, but not limited to, the purposes of preventive or occupational
medicine, medical diagnosis, and/or the provision of health care or
treatment) |
To enable you to partake in a prize draw,
competition or complete a survey |
(a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to study
how customers use our products/services, to develop them and grow our
business) |
To administer and protect our business and this
website (including troubleshooting, data analysis, testing, system
maintenance, support, reporting and hosting of data) |
(a) Identity (b) Contact (c) Technical |
(a) Necessary for our legitimate interests (for
running our business, provision of administration and IT services, network
security, to prevent fraud and in the context of a business reorganisation or
group restructuring exercise) (b) Necessary to comply with a legal obligation |
To deliver relevant website content and
advertisements to you and measure or understand the effectiveness of the
advertising we serve to you |
(a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical |
Necessary for our legitimate interests (to study how
customers use our products/services, to develop them, to grow our business
and to inform our marketing strategy) |
To use data analytics to improve our website,
products/services, marketing, customer relationships and experiences |
(a) Technical (b) Usage |
Necessary for our legitimate interests (to define
types of customers for our products and services, to keep our website updated
and relevant, to develop our business and to inform our marketing strategy) |
To make suggestions and recommendations to you about
goods or services that may be of interest to you |
(a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and
Communications (g) Health |
(a) Necessary for our legitimate interests (to
develop our products/services and grow our business) (b) Necessary for health or social care purposes
(including, but not limited to, the purposes of preventive or occupational
medicine, medical diagnosis, and/or the provision of health care or
treatment) |
We will get your express opt-in consent before we share your personal
data with any third party for marketing purposes.
5.
Disclosures of your personal data
·
External
Third Parties as set out in the Glossary.
·
Third
parties to whom we are obliged to transfer or merge parts of our business or
our assets. Alternatively, we may seek to acquire other businesses or merge
with them. If a change happens to our business, then the new owners may use
your personal data in the same way as set out in this privacy policy.
We do not transfer your personal data
outside the UK.
In addition, we limit access
to your personal data to those employees, agents, contractors and other third
parties who have a business need to know. They will only process your personal
data on our instructions and they are subject to a duty of confidentiality. Further, all sensitive information is
encrypted via Secure Socket Layer (SSL) technology. We have put
in place procedures to deal with any suspected personal data breach and will
notify you and any applicable regulator of a breach where we are legally
required to do so.
How long will you use my personal data for?
To determine the appropriate retention
period for personal data, we consider the amount, nature and sensitivity of the
personal data, the potential risk of harm from unauthorised use or disclosure
of your personal data, the purposes for which we process your personal data and
whether we can achieve those purposes through other means, and the applicable
legal, regulatory, tax, accounting or other requirements. By law we have to keep
basic information about our customers (including Contact, Identity, Financial
and Transaction Data) for a minimum of six years after they cease being
customers for tax purposes.
·
Request access to your personal data.
·
Request correction of your personal data.
·
Request erasure of your personal data.
·
Object to processing of your personal data.
·
Request restriction of processing your
personal data.
·
Request transfer of your personal data.
·
Right to withdraw consent.
If you wish to exercise any of the rights
set out above, please contact us.
10.
Glossary
i.
Legitimate Interest means
the interest of our business in conducting and managing our business to enable
us to give you the best service/product and the best and most secure
experience. We make sure we consider and balance any potential impact on you
(both positive and negative) and your rights before we process your personal
data for our legitimate interests. We do not use your personal data for
activities where our interests are overridden by the impact on you (unless we
have your consent or are otherwise required or permitted to by law). You can
obtain further information about how we assess our legitimate interests against
any potential impact on you in respect of specific activities by contacting us.
ii.
Performance of Contract means
processing your data where it is necessary for the performance of a contract to
which you are a party or to take steps at your request before entering into
such a contract.
iii.
Comply with a legal obligation means
processing your personal data where it is necessary for compliance with a legal
obligation that we are subject to.
·
Service
providers acting as processors based in the UK who provide IT and system and
website administration services.
·
Professional
advisers acting as processors or joint controllers including lawyers, bankers,
auditors and insurers based in the UK who provide consultancy, banking, legal,
insurance and accounting services.
·
HM
Revenue & Customs, regulators and other authorities acting as processors or
joint controllers based in the United Kingdom who require reporting of
processing activities in certain circumstances.
i.
Request access to your
personal data (commonly known as a "data subject access request").
This enables you to receive a copy of the personal data we hold about you and
to check that we are lawfully processing it.
ii.
Request correction of the
personal data that we hold about you. This enables you to have any incomplete
or inaccurate data we hold about you corrected, though we may need to verify
the accuracy of the new data you provide to us.
iii.
Request erasure of your
personal data. This enables you to ask us to delete or remove personal data
where there is no good reason for us continuing to process it. You also have
the right to ask us to delete or remove your personal data where you have
successfully exercised your right to object to processing (see below), where we
may have processed your information unlawfully or where we are required to
erase your personal data to comply with local law. Note, however, that we may
not always be able to comply with your request of erasure for specific legal
reasons which will be notified to you, if applicable, at the time of your
request.
iv.
Object to processing of your
personal data where we are relying on a legitimate interest (or those of a
third party) and there is something about your particular situation which makes
you want to object to processing on this ground as you feel it impacts on your
fundamental rights and freedoms. You also have the right to object where we are
processing your personal data for direct marketing purposes. In some cases, we
may demonstrate that we have compelling legitimate grounds to process your
information which override your rights and freedoms.
v.
Request restriction of processing of your
personal data. This enables you to ask us to suspend the processing of your
personal data in the following scenarios:
·
If you
want us to establish the data's accuracy.
·
Where
our use of the data is unlawful but you do not want us to erase it.
·
Where
you need us to hold the data even if we no longer require it as you need it to
establish, exercise or defend legal claims.
·
You
have objected to our use of your data but we need to verify whether we have
overriding legitimate grounds to use it.
vi.
Request the transfer of your
personal data to you or to a third party. We will provide to you, or a third
party you have chosen, your personal data in a structured, commonly used,
machine-readable format. Note that this right only applies to automated
information which you initially provided consent for us to use or where we used
the information to perform a contract with you.
vii.
Withdraw consent at any time where we
are relying on consent to process your personal data. However, this will not
affect the lawfulness of any processing carried out before you withdraw your
consent. If you withdraw your consent, we may not be able to provide certain
products or services to you. We will advise you if this is the case at the time
you withdraw your consent.