Privacy Notice
Graphnet Health Limited is responsible for your personal data. This notice explains how we collect and use your data when you use our website or visit our offices or sign up for newsletters or buy a product or service.
If you are a user of Graphnet products you may also be interested in our page on Managing personal information with the NHS Login and Personal Demographic Service.
1. Keeping your information accurate
Please let us know if your personal data changes during your relationship with us to keep it accurate and current.
2. The data we collect about you
We may collect and use different types of personal data, including:
- Identity data: Name, job title, username, marital status, etc.
- Contact data: Address, email, phone numbers.
- Technical data: IP address, browser type, time zone, etc.
- Profile data: Username, password, purchases, interests, feedback.
- Usage data: How you use our website, products, and services.
- Marketing data: Your preferences for receiving marketing from us and third parties.
- Surveillance footage used to secure the premises for the purpose of crime prevention, detection and security monitoring.
3. How we collect your data
We collect data through direct interactions, such as:
- Creating an account.
- Subscribing to services or publications.
- Requesting marketing.
- Entering competitions or surveys.
- Providing feedback.
- Video surveillance.
4. How we use your data
We use your data when the law allows, such as:
- To fulfil a contract with you.
- For our legitimate interests, unless your rights override these.
- To comply with legal obligations.
We usually do not rely on consent, except for direct marketing via email or text. You can withdraw consent anytime by contacting us.
You can opt out of marketing messages anytime by following the opt-out links or contacting us. Opting out does not affect data provided for services you receive.
5. Sharing your data
We may share your data with:
- Other companies in the Graphnet Health group.
- Service providers.
- Professional advisers (lawyers, bankers, auditors, insurers).
- Third parties in case of business transfers or mergers.
- The Police, if we are sent a request under the Crime and Disorder Act 1998
Specifically, we may share data with:
- Health Service Journal.
- Digital Health.
We require third parties to respect your data's security and use it only for specified purposes.
6. International transfers
We do not transfer your data outside the European Economic Area unless extra protection is in place.
7. Data security
We have security measures to protect your data from loss, misuse, or unauthorised access. Only those who need to know will have access to your data.
We have procedures for data breaches and will notify you and the ICO if required.
8. Data retention
We keep your data only as long as necessary for the purposes we collected it, including legal, accounting, or reporting requirements. Contact us for details on retention periods.
9. Cookies
We use cookies and similar technologies to enhance your experience and understand how our website is used. This includes:
- Google Analytics, which helps us measure website performance and usage patterns.
- HubSpot, which we use to manage form submissions, including event bookings and improve our communications with you.
These cookies help us analyse visitor engagement and support efficient communication, but they are non-essential and will only be set if you choose to accept them. You can manage or withdraw your consent at any time by clicking the grey star at the bottom right of our site.
10. Legal basis
Depending on the processing activity and the category of personal data, we rely on the following lawful bases for processing your data under the UK General Data Protection Regulation and Data Protection Act 2018. The following legal bases are commonly relied upon:
- Consent and Explicit Consent –registering an account, signing up to an event, subscribing to services or publications, entering competitions, surveys or consenting to cookies on our website.
- Legitimate Interest – video surveillance if you come to our offices. It is in our legitimate interests to help ensure the safety of our staff, visitors, property and to facilitate detection and prevention of crime or misconduct.
11. Your legal rights
You have rights under data protection law, including:
- Access: Request copies of your data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request data deletion in certain circumstances.
- Restriction: Limit data processing in certain circumstances.
- Objection: Object to data processing in certain circumstances.
- Data portability: Transfer your data to another organization or to you.
12. How do I exercise my rights or make a data protection complaint
If you wish to exercise your rights, have any questions about your personal data you can contact the Data Protection Officer (DPO) below:
Mail: Graphnet Health Limited, Ground Floor, Building 5 Caldecotte Lake Drive, Caldecotte, Milton Keynes, Buckinghamshire, MK7 8LE.
- Email: dataprotectionofficer@graphnethealth.com
- Phone: 03330 771988
If you are unhappy with how we have handled your personal data and would like to make a data protection complaint, please contact the DPO using the contact details above. When you contact us, please provide as much detail as possible about your complaint. This will help us understand the issue and investigate it thoroughly. We will acknowledge receipt of your complaint within 30 days.
If you remain unhappy, you have the right to complaint to the Information Commissioner’s Officer (ICO) for advice:
- Mail: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
- Phone: 0303 123 1113
- Website: www.ico.org.uk
- Email: icocasework@ico.org.uk