Who we are
HSC (‘we’ or ‘us’ or ‘our’) gathers and processes your personal information in accordance with this privacy notice and in compliance with the relevant data protection regulation and law. This notice provides you with the necessary information regarding your rights and obligations, and explains how, why and when we collect and process your personal data.
HSC’s registered office is at Regent House, 316 Beulah Hill, London, SE19 3HF and we are a company registered in England and Wales under company number 8331310. We are registered on the Information Commissioner’s Office Register of Data Controllers under registration number ZA033036, and act as a data controller & data processor.
Our designated Data Protection Officer/Appointed Person for the organisation is Vicky Pollitt, and we can be contacted at HSC, The Square, Basing View, Basingstoke, Hampshire, RG21 4EB.
Information that we collect
HSC processes your personal information to meet our legal, statutory and contractual obligations and to provide you with our products and services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than already specified in this notice.
The personal data that we collect from you is:-
* Date of Birth
* Home Address
* Personal Email
* Business Email (if applicable)
* Home Telephone Number
* Mobile Telephone Number
* Employer Name (if applicable)
* Employer ID (if applicable)
* Relationship to main member (if applicable)
* NHS Number
* Health data including diagnosis, full medical history (including imaging) and details of any treatment received
We collect information in the below ways:-
* On-line forms
* Via websites
* In person
* Over the phone
* Via third party organisations (e.g. the NHS, your employer, your broker or benefit platform)
* By e-mail
* Via the post
How we use your personal data
HSC takes your privacy very seriously and will never disclose, share or sell your data without your consent, unless required to do so by law. We only retain your data for as long as is necessary and for the purposes specified in this notice. Where you have consented to us providing you with promotional offers or marketing, you are free to withdraw consent at any time.
The purposes and reasons for processing your personal data are detailed below:-
* We collect your personal data in the performance of a contract or to provide a service requested by you.
* We collect and store your personal data as part of our legal obligation for business accounting and tax purposes.
You have the right to access any personal information that HSC processes about you and to request information about: –
* What personal data we hold about you
* The purposes of the processing
* The categories of personal data concerned
* The recipients to whom the personal data has/will be disclosed
* How long we intend to store your personal data for
* If we did not collect the data directly from you, information about the source
If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to update/correct it as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
You also have the right to request erasure of your personal data or to restrict processing in accordance with data protection laws, as well as to object to any direct marketing from us and to be informed about any automated decision-making that we use.
If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the relevant request; this is to ensure that your data is protected and kept secure.
Sharing and disclosing your personal information
We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. HSC uses third-parties to provide the below services and business functions, however all processors acting on our behalf only process your data in accordance with instructions from us and comply fully with this privacy notice, the data protection laws and any other appropriate confidentiality and security measures.
Clinicians & Medical Service Providers
We will share your name, contact information and your relevant medical records with a variety of Clinicians and Medical Service Providers to enable the performance of the contract you enter with us for a specific service. This information will only be shared when you have given us your consent. We will send you relevant documentation prior to us commencing our services that will allow you to provide your consent.
Where relevant, we will use Paypal to invoice our clients for the services they purchase from HSC. Paypal act in the capacity of a processor on our behalf. The only information we provide them with is your name, address and order details to meet their business and legal requirements.
Where relevant, we will share your name, your gender, your date of birth, your home address, your personal and business e‐mail, your telephone numbers, you employer name and employer ID, relationship to the main member (if applicable), your NHS number and any relevant health data including diagnosis and treatment information with your insurer, AmTrust. This information will only be shared when you have given us your consent. We will send you relevant documentation prior to us commencing our services that will allow you to provide your consent.
HSC takes your privacy seriously and we take every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: –
Data access restrictions
Privacy By Design
Staff training and awareness on Data Protection
Consequences of not providing your data
You are not obligated to provide your personal information to HSC, however, as this information is required for us to provide you with our services, we will not be able to offer our products or services without it.
How long we keep your data
HSC only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations. We are required under UK tax law to keep your basic personal data (name, address, contact details) for a minimum of 7 years after which time it will be destroyed.
Where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.
Special categories data
Owing to the products and services we offer, HSC sometimes need to request sensitive personal information from you such as your health data and medical history. Where we collect sensitive personal data, we will only request the information required for the specified purpose and always ask for your explicit consent through a signature. You can modify or remove consent at any time, which we will act on immediately, unless there is a legitimate interest or legal reason for not doing so.
Occasionally, HSC would like to contact you with details of the products, services and information that we provide. If you consent to us using your contact details for these purposes, you have the right to modify or withdraw your consent at any time by using the opt-out/unsubscribe options or by contacting HSC directly.
Cookies and how we use them
What is a cookie?
A cookie is a small file placed on your computer’s hard drive. It enables our website to identify your computer as you view different pages on our website.
Cookies allow websites and applications to store your preferences in order to present content, options or functions that are specific to you. They also enable us to see information like how many people use the website and what pages they tend to visit.
* Analyse our web traffic using an analytics package. Aggregated usage data helps us improve the website structure, design, content and functions.
* Identify whether you are signed in to our website. A cookie allows us to check whether you are signed in to the site.
* Test content on our website. For example, 50% of our users might see one piece of content, the other 50% a different piece of content.
* Store information about your preferences. The website can then present you with information you will find more relevant and interesting.
* To recognise when you return to our website. We may show your relevant content, or provide functionality you used previously.
Cookies do not provide us with access to your computer or any information about you, other than that which you choose to share with us.
However, please note that doing this may affect how our website functions. Some pages and services may become unavailable to you.
To learn more about cookies and how they are used, visit http://www.allaboutcookies.org/.
Lodging a complaint
HSC only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.
The Square, Basing View, Basingstoke, Hampshire, RG21 4EB
0207 965 0309 or firstname.lastname@example.org
Information Commissioners Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
0303 123 1113 or www.ico.org.uk