privacy policy

Introduction

Please read the following information carefully. This Privacy Notice contains information about what data NexEndo Healthcare collects and stores about you and why. It also tells you who we share this information with, the security mechanisms we have put in place to protect your data and how to contact us if you have a complaint.

1. Important information and who we are

NexEndo Healthcare”), a company registered in Scotland under company number SC736330, is the controller and processor and is responsible for your personal data (collectively referred to as “NexEndo Healthcare”, “we”, “us” or “our” in this Privacy Notice).

This Privacy Notice gives you information about how NexEndo Healthcare collects and uses your personal data through your use of our website and the personal data you provide when you register your interest with us for a clinical study.

If you have any questions about this Privacy Notice, including any requests to exercise your legal rights, please contact us using the information set out in the contact details in section 9.

 

2. The types of personal data we collect about you

Personal data means any information which relates to you, or identifies you as an individual. It includes information which can directly identify you, and also information which may identify you if combined with other readily available information about you. Personal data does not include anonymous data where the identity has been removed.

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

• Identity Data includes your first name, last name, marital status, title, date of birth, gender and images taken of you by any closed-circuit television (CCTV) systems that we may have installed in our units or on our business premises, including images and video taken with your consent for marketing or other purposes.

• Staff and Participant Contact Data includes your address, email address, telephone numbers and emergency contact details.

• Business Contacts Data includes work email, phone number, job title and business address.

• Technical Data includes internet protocol (IP) address, browser type, browser version, your login data, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access our website.

• Usage Data includes information about how you interact with and use our website including the pages of our website that you visit, the time and date of your visit, the time spent on those pages and other statistics.

• Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

• Special Category Data. If you are registering your interest to participate in a pilot trial or study we may also collect and use more sensitive personal data about you, such as information relating to your racial or ethnic origin, current and former physical or mental health, genetic data or biometric data relating to you, and sexual life or sexual orientation.

 

3. How we collect your personal data

We use different methods to collect data from and about you including through your direct dealings with us. You may share your personal data with us by: 

• Corresponding with us by phone, email or otherwise. 

• Completing our online registration form when registering for private clinical appointments 

• Sending us a question or feedback through our website, or by email or social media. 

• Attending our premises or units where we have CCTV installed. 

• Requesting marketing information to be sent to you.

• Completing a survey or questionnaire.

Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies.

4. How we use your personal data

We use different methods to collect data from and about you including through your direct dealings with us. You may share your personal data with us by: 

Lawful basis

The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following lawful bases:

Performance of a contract with you: Where we need to deliver the contract we are about to enter into or have entered into with you.

Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.

Consent: We rely on consent where you have given express consent for us to use your personal data for a specified purpose. If we ask for your consent, we will be open and transparent about the reasons your consent is required. Where we are relying on consent to use your personal data, you have the right to withdraw your consent at any time by contacting us and we will stop using your personal data for that purpose.

Purposes for which we will use your personal data

At times we may ask for your consent to allow us to use your personal information for one or more purposes. We also use your personal information for business purposes. Your personal information helps us to operate and improve our business and minimise any disruption to the services that we may offer to you. It also allows us to make our communications with you more relevant and personalised to you, and to make your experience of our services efficient and effective.

Most of the personal information we process is provided to us directly by you, and we may also collect data as a result of automated technologies or interactions. We use this information in a number of different ways:

To register your interest in clinical any clinical pilots.

For use in clinical screenings and your participation in a clinical pilot. This involves evaluating your personal details, medical history and health information against the specific requirements of each pilot study so that we can ensure the pilot is appropriate for you.

For use in clinical screenings and your participation in a clinical pilot. This involves evaluating your personal details, medical history and health information against the specific requirements of each pilot study so that we can ensure the pilot is appropriate for you.

Storage in our participant database. As a participant, your personal data is stored, following consent, securely in the NexEndo Healthcare patient portal for the purpose of:

• Keeping track of your participation in the pilot study. 

• To inform you about future pilot opportunities and or treatment/procedures.

Managing stakeholder relationships and improving communications with potential interested parties.

Analysis for improved services. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns, and may use these data to improve our services.

Investigating and responding to concerns, complaints or claims and complying with our legal or regulatory obligations.

Liaising with other healthcare professionals about your care.

Automated Decisions

We may use automated decision making to determine your eligibility to participate in pilot studies. This helps us to make decisions which are quick and efficient, based on the information provided by you meeting the pilot criteria.

You can object to an automated decision we have made and ask that a person reviews it.

Marketing

During the participant sign up process on our website when your personal data is collected, you will be asked to indicate your preferences for receiving direct marketing communications from us via email, SMS (text) or phone.

Opting out of marketing

You can ask us to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us – see contact details below.

If you choose to opt out of receiving marketing communications, you will still receive related communications that are essential for administrative or customer service purposes.

Opting out of participant database

You can choose to revoke your consent for your details to be included in the NexEndo Healthcare participant database for clinical research. We will handle deletion of your data in a safe and secure manner, in accordance with NexEndo Healthcare Policies and Procedures and applicable data protection regulations. Please note, if you have participated in a pilot study the data collected relevant to the performance of the pilot, such as test results and medical information will need to be retained for a specified period. Information about your data protection rights will be included in the clinical study specific consent patient information sheet.

Cookies

For more information about the cookies we use and how to change your cookie preferences, please see our policy.

 

5. Disclosures of your personal data

We may share your personal data where necessary with the parties set out below: 

• A doctor, nurse, carer or any other healthcare professional involved in your care; 

• Anyone that you ask us to communicate with or provide as an emergency contact, for example your next of kin or carer; 

• NHS organisations; 

• Other private sector healthcare providers; 

• Your GP or healthcare professional (including their medical secretaries); 

• Third parties who assist in the administration of your care; 

• Government bodies; 

• Regulators such as CQC, HIS

• The police and other third parties for the prevention or detection of crime; 

• Our insurers;

As part of delivering safe, effective, and professional care, we sometimes need to share your personal information with trusted third parties. These may include:

Specialist service providers who support our operations, such as IT systems, auditors, legal and tax advisers, and marketing partners.

Business partners or successors in the event that NexEndo Healthcare undergoes a merger, transfer, or restructure. If this happens, the new organisation may use your information in the same way as outlined in our current Privacy Notice.

We want to reassure you that your information will always be handled securely and only used for legitimate purposes in line with data protection laws.

Please confirm that you are happy for us to share your data in this way if needed. If you have any questions or would like more information, we’re happy to provide this.

 

6. How we protect your personal data

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In doing so, we comply with UK data protection law, including the Data Protection Act 2018 and the EU General Data Protection Regulations as well as applicable healthcare confidentiality guidelines.
 
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only
 
process your personal data on our instructions and they are subject to a duty of confidentiality.
 
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

7. For how long do we hold your personal data

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
 
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
 
We will retain your data while you are registered in our participant database as long as it remains relevant, up to date and necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements, and until such time that you ask us to delete it from our records in accordance with your rights.
 
If you participate in a pilot study, your data will be stored for the period specified in the pilot protocol in accordance with sponsor requirements and required legislation, which may be a minimum of 25 years.
 
In some circumstances you can ask us to delete your data: see section 8 below for further information.
 
In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

8. Your legal rights

You have a number of rights under data protection laws in relation to your personal data.
 
You have the right to:
 
Request access to your personal data (commonly known as a “subject access request” (SAR). This enables you to receive a copy of the personal data we hold about you and to confirm that we are lawfully processing it.
 
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we will need to verify the accuracy of the new data you provide to us.
 
Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. Please note, if you have participated in a clinical study the data collected relevant to the performance of the clinical study, such as test results and medical information will need to be retained for a period specified in each clinical study protocol and in accordance with our sponsor requirements. Information about your data protection rights will be included in the clinical study specific consent patient information sheet.
 
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
 
Object to marketing. You also have the absolute right to object any time to the processing of your personal data for direct marketing purposes (see “Opting out of marketing” above for details of how to object to receiving direct marketing communications).
 
Data portability. Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to information which you initially provided consent for us to use or where we used the information to perform a contract with you.
 
Withdraw consent at any time. Where we are relying on consent to process your personal data you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent.
 
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:
 
• If you want us to establish the data’s accuracy; 
• Where our use of the data is unlawful but you do not want us to erase it; 
• Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or 
• You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
 
Not to be subject to automatic decisions. You have the right not to be subject to solely automated decision-making (decisions solely by automated means without any human involvement) and profiling (automated processing of personal data to evaluate certain things about you).
 
What we may need from you
 
We may need to request specific or further information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
 
Time limit to respond
 
We will try to respond to your request without undue delay and within legally bound timeframes.

9. Contact details

We have a Data Privacy Officer (DPO) who is responsible for ensuring NexEndo Healthcare complies with its data protection obligations. If you have any questions about this Privacy Notice or about the use of your personal data or you want to exercise your privacy rights, the DPO can be contacted in the following ways:
 
• Email address: enquires@nexendo-healthcare.com (with the subject heading GDPR) 
• Postal address: GDPR Request, 2 St Swithin Row, Aberdeen AB20 6DL

10. Complaints

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). However, please contact us in the first instance so that we can try and deal with your concerns.

11. Changes to the privacy policy

The Privacy Policy is effective as of October 2024 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted to this page.

12. Third-party links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the Privacy Notice of every website you visit.