privacy policy
Introduction
Please read the following information carefully. This Privacy Notice contains information about what data NexEndo Healthcare collects and stores about you and why. It also tells you who we share this information with, the security mechanisms we have put in place to protect your data and how to contact us if you have a complaint.
1. Important information and who we are
NexEndo Healthcare”), a company registered in Scotland under company number SC736330, is the controller and processor and is responsible for your personal data (collectively referred to as “NexEndo Healthcare”, “we”, “us” or “our” in this Privacy Notice).
This Privacy Notice gives you information about how NexEndo Healthcare collects and uses your personal data through your use of our website and the personal data you provide when you register your interest with us for a clinical study.
If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact us using the information set out in the contact details in section 9.
2. The types of personal data we collect about you
Personal data means any information which relates to you, or identifies you as an individual. It includes information which can directly identify you, and also information which may identify you if combined with other readily available information about you. Personal data does not include anonymous data where the identity has been removed.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
• Identity Data includes your first name, last name, marital status, title, date of birth, gender and images taken of you by any closed-circuit television (CCTV) systems that we may have installed in our units or on our business premises, including images and video taken with your consent for marketing or other purposes.
• Staff and Participant Contact Data includes your address, email address, telephone numbers and emergency contact details.
• Business Contacts Data includes work email, phone number, job title and business address.
• Technical Data includes internet protocol (IP) address, browser type, browser version, your login data, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access our website.
• Usage Data includes information about how you interact with and use our website including the pages of our website that you visit, the time and date of your visit, the time spent on those pages and other statistics.
• Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
• Special Category Data. If you are registering your interest to participate in a pilot trial or study we may also collect and use more sensitive personal data about you, such as information relating to your racial or ethnic origin, current and former physical or mental health, genetic data or biometric data relating to you, and sexual life or sexual orientation.
3. How we collect your personal data
We use different methods to collect data from and about you including through your direct dealings with us. You may share your personal data with us by:
• Corresponding with us by phone, email or otherwise.
• Completing our online registration form when registering for private clinical appointments
• Sending us a question or feedback through our website, or by email or social media.
• Attending our premises or units where we have CCTV installed.
• Requesting marketing information to be sent to you.
• Completing a survey or questionnaire.
Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies.
4. How we use your personal data
We use different methods to collect data from and about you including through your direct dealings with us. You may share your personal data with us by:
Lawful basis
The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following lawful bases:
Performance of a contract with you: Where we need to deliver the contract we are about to enter into or have entered into with you.
Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
Consent: We rely on consent where you have given express consent for us to use your personal data for a specified purpose. If we ask for your consent, we will be open and transparent about the reasons your consent is required. Where we are relying on consent to use your personal data, you have the right to withdraw your consent at any time by contacting us and we will stop using your personal data for that purpose.
Purposes for which we will use your personal data
At times we may ask for your consent to allow us to use your personal information for one or more purposes. We also use your personal information for business purposes. Your personal information helps us to operate and improve our business and minimise any disruption to the services that we may offer to you. It also allows us to make our communications with you more relevant and personalised to you, and to make your experience of our services efficient and effective.
Most of the personal information we process is provided to us directly by you, and we may also collect data as a result of automated technologies or interactions. We use this information in a number of different ways:
To register your interest in clinical any clinical pilots.
For use in clinical screenings and your participation in a clinical pilot. This involves evaluating your personal details, medical history and health information against the specific requirements of each pilot study so that we can ensure the pilot is appropriate for you.
For use in clinical screenings and your participation in a clinical pilot. This involves evaluating your personal details, medical history and health information against the specific requirements of each pilot study so that we can ensure the pilot is appropriate for you.
Storage in our participant database. As a participant, your personal data is stored, following consent, securely in the NexEndo Healthcare patient portal for the purpose of:
• Keeping track of your participation in the pilot study.
• To inform you about future pilot opportunities and or treatment/procedures.
Managing stakeholder relationships and improving communications with potential interested parties.
Analysis for improved services. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns, and may use these data to improve our services.
Investigating and responding to concerns, complaints or claims and complying with our legal or regulatory obligations.
Liaising with other healthcare professionals about your care.
Automated Decisions
We may use automated decision making to determine your eligibility to participate in pilot studies. This helps us to make decisions which are quick and efficient, based on the information provided by you meeting the pilot criteria.
You can object to an automated decision we have made and ask that a person reviews it.
Marketing
During the participant sign up process on our website when your personal data is collected, you will be asked to indicate your preferences for receiving direct marketing communications from us via email, SMS (text) or phone.
Opting out of marketing
You can ask us to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us – see contact details below.
If you choose to opt out of receiving marketing communications, you will still receive related communications that are essential for administrative or customer service purposes.
Opting out of participant database
You can choose to revoke your consent for your details to be included in the NexEndo Healthcare participant database for clinical research. We will handle deletion of your data in a safe and secure manner, in accordance with NexEndo Healthcare Policies and Procedures and applicable data protection regulations. Please note, if you have participated in a pilot study the data collected relevant to the performance of the pilot, such as test results and medical information will need to be retained for a specified period. Information about your data protection rights will be included in the clinical study specific consent patient information sheet.
Cookies
For more information about the cookies we use and how to change your cookie preferences, please see our policy.
5. Disclosures of your personal data
We may share your personal data where necessary with the parties set out below:
• A doctor, nurse, carer or any other healthcare professional involved in your care;
• Anyone that you ask us to communicate with or provide as an emergency contact, for example your next of kin or carer;
• NHS organisations;
• Other private sector healthcare providers;
• Your GP or healthcare professional (including their medical secretaries);
• Third parties who assist in the administration of your care;
• Government bodies;
• Regulators such as CQC, HIS
• The police and other third parties for the prevention or detection of crime;
• Our insurers;
As part of delivering safe, effective, and professional care, we sometimes need to share your personal information with trusted third parties. These may include:
•Specialist service providers who support our operations, such as IT systems, auditors, legal and tax advisers, and marketing partners.
•Business partners or successors in the event that NexEndo Healthcare undergoes a merger, transfer, or restructure. If this happens, the new organisation may use your information in the same way as outlined in our current Privacy Notice.
We want to reassure you that your information will always be handled securely and only used for legitimate purposes in line with data protection laws.
Please confirm that you are happy for us to share your data in this way if needed. If you have any questions or would like more information, we’re happy to provide this.
