Privacy Policy

Consultant Connect recognises the importance of keeping data safe and secure and acting in compliance with UK GDPR (UK General Data Protection Regulation).

In accordance with UK GDPR we have Privacy Notices relevant to our various data subject categories which are as follows:

  1. Patients
  2. GPs (and other primary care clinicians)
  3. Hospital Consultants (and other secondary care clinicians)
  4. Consultant Connect Staff
  5. Data for Marketing Purposes
1 – Privacy Notice – Patient Data

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the “GDPR”).

This Privacy Notice tells you what to expect in relation to personal information about you which is collected, handled and processed by Consultant Connect Limited.

Who are we?

We are Consultant Connect Limited of One St Aldates, St. Aldates, Oxford, OX1 1DE.

Consultant Connect provides a number of services for which it holds certain GDPR roles:

  • Advice & Guidance and Referral Triage services: the provision of communications systems to the NHS and Private Health Providers that facilitate easier and faster patient-specific discussions between different teams of clinicians. The overall objective is to ensure patient pathways are not delayed unnecessarily on account of clinicians being unable to contact each other – Consultant Connect acts as Data Processor for these services, working on behalf of Data Controllers who will typically be one of: individual GP Practices; Health Boards/Clinical Commissioning Groups; Hospitals/Hospital Trusts or Community Service Providers – Consultant Connect acts as Data Processor for these services.
  • Community Clinical Services – the provision of a range of community based clinical services to NHS patients, working in partnership with clinical service providers and via contracts with NHS commissioners – Consultant Connect acts as Data Controller for these services.

We acknowledge and agree that any personal data of yours that we handle will be processed in accordance with all applicable data protection laws in force from time to time.

The information we may collect – Patient Data

The information about you that we may collect, hold and process is set out below:

  • NHS Number – Your 10-digit NHS Number
  • Name and Date of Birth – Your NHS number links to an NHS Digital service called the Personal Demographic Service (PDS) https://digital.nhs.uk/services/demographics that enables clinicians to cross-check your name and date of birth before proceeding with a communication
  • Call Recording – verbatim recording of an advice conversation between your GP and a medical specialist (e.g. an expert NHS hospital consultant) which could on occasion include your name
  • Photo Images – relevant photos taken by your GP in order to support a request for specialist advice
  • Associated Notes – any notes sent by one clinician to another to support the clinical advice discussion
  • Referral Information – any notes and attachments associated with a referral, typically from a GP to a hospital team

The above information will have been provided, or will be provided, by you, your GP or other clinician from whom you are requesting healthcare advice/services in order to provide those services to you to the highest possible standard.

How we use the information

The above information is used/retained, upon the instruction of the Data Controller, as part of your medical records and serves as a record of advice given should any healthcare organisation need to access it in the future with regard to providing high quality care to you.

How we hold the information

All the personal data we have is stored on our databases in the UK.

Disclosure of your information

Your personal data will be treated as strictly confidential and will not be shared with any organisation other than those involved in the advice discussion and those involved in providing you with ongoing care, unless required so by law or upon your explicit consent.

Legal basis for processing the information

The legal basis upon which we hold and process your Personal Data (including name and contact details) is as Public Task.

Public Task: processing being necessary for the purposes of preventative or occupational medicine, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services.

The legal basis upon which we hold and process your Special Category Data (including biometric and health data) is Health & Social Care.

Health & Social Care: processing being necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional.

Retention of your data

Your data will be retained in accordance with NHSx Records Management Code of Practice and Information Commissioners Office guidelines, subject to approval from the relevant Data Controller.

Your rights

You currently have the right at any time to ask for:

  • Access to your data – a copy of the information about you that we hold.
  • Erasure of your data – removal of data
  • Restriction of processing – restriction in the way data is processed
  • Objection – Correction of erroneous data
  • Data Portability – Transfer of your data to another provider of services
  • Complaint – you can complain to the Information Commissioners Office (0303 123 1113 or via ico.org.uk\concerns)

If you would like to make a request for any of the above, please email DPO@consultantconnect.org.uk.

Withdrawal of consent

If you have provided consent to the Data Controller to process your data, you have the right to withdraw this at any time.  In order to do so you should contact us by emailing our Governance Lead at DPO@consultantconnect.org.uk

Concerns

If you have a concern about the way we are collecting or processing your personal data, you should raise your concern with us in the first instance or directly to Information Commissioners Office at www.ico.org.uk\concerns.

Contact

Please address any questions, comments and requests regarding our data processing practices to emailing our Governance Lead at DPO@consultantconnect.org.uk

Changes to the Privacy Notice

This Privacy Notice may be changed by us at any time.

2 – Privacy Notice – GPs (and other primary care clinicians)

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the “GDPR”).

This Privacy Notice tells you what to expect in relation to personal information about you which is collected, handled and processed by Consultant Connect Limited.

Who are we?

We are Consultant Connect Limited of One St Aldates, St Aldates, Oxford, OX1 1DE.

Consultant Connect is the Data Controller for the purposes of retaining data relating to GPs (and other primary care clinicians).

Consultant Connect is the provider of communications systems to the NHS and Private Health Providers that facilitate easier and faster patient-specific discussions between different teams of clinicians. The overall objective is to ensure patient pathways are not delayed unnecessarily on account of clinicians being unable to contact each other.

We acknowledge and agree that any personal data of yours that we handle will be processed in accordance with all applicable data protection laws in force from time to time.

The information we may collect – Data relating to GPs (and other primary care clinicians)

The information about you that we may collect, hold and process is set out below:

  • Name
  • Job title
  • Employing organisation
  • GMC number (or equivalent)
  • Email address
  • Mobile phone number
  • IP address of any device used to access the system

This information will have been provided, or will be provided, by you or a third party who we work with, such as your employing organisation.

Please note that if you access our service using your NHS Care Identity credentials, the identity access and management services are managed by NHS Digital. NHS Digital is the controller for any personal information you provided to NHS Digital to get a national digital identity and authenticate your claim to that identity and uses that personal information solely for that single purpose. For any such personal information we are the Data Processor acting under instruction provided by NHS Digital (as the “controller”) when verifying your identity.  This restriction does not apply to the personal information you provide to us separately which is managed in accordance with our Privacy Policy.

How we use the information

The above information is/will be used to facilitate clinician to clinician contact via the Consultant Connect system, for the purposes of providing high quality care to patients.

How we hold the information

All the personal data we have is stored on our database in the UK.

Disclosure of your information

Your personal data will be treated as strictly confidential and will be not be shared with any third-party organisation other than with your explicit consent.

Legal basis for processing the information

The legal basis upon which we hold and process your data is Contractual Necessity.

Contractual Necessity: processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Retention of your data

Your data will be retained for no longer than is necessary and in accordance with our Data Retention Policy.

Your rights

You currently have the right at any time to ask for:

  • Access to your data – a copy of the information about you that we hold.
  • Erasure of your data – removal of data
  • Restriction of processing – restriction in the way data is processed
  • Objection – Correction of erroneous data
  • Data Portability – Transfer of your data to another provider of services
  • Complaint – you can complain to the Information Commissioners Office (0303 123 1113 or via ico.org.uk\concerns)

If you would like to make a request for any of the above, please email DPO@consultantconnect.org.uk

Withdrawal of consent

If you have provided us with your consent to process your data, for the purpose of using our services and us finding you suitable work, you have the right to withdraw this at any time.  In order to do so you should contact us by emailing our Governance Lead at DPO@consultantconnect.org.uk

Concerns

If you have a concern about the way we are collecting or using your personal data, you should raise your concern with us in the first instance or directly to Information Commissioners Office at www.ico.org.uk\concerns.

Contact

Please address any questions, comments and requests regarding our data processing practices to our Governance Lead at DPO@consultantconnect.org.uk

Changes to the Privacy Notice

This Privacy Notice may be changed by us at any time.

3 – Privacy Notice – Hospital Consultants (and other secondary care clinicians)

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the “GDPR”).

This Privacy Notice tells you what to expect in relation to personal information about you which is collected, handled and processed by Consultant Connect Limited.

Who are we?

We are Consultant Connect Limited of One St Aldates, St Aldates, Oxford, OX1 1DE.

Consultant Connect is the Data Controller for the purposes of retaining data relating to Hospital Consultants (and other secondary care clinicians).

Consultant Connect is the provider of communications systems to the NHS and Private Health Providers that facilitate easier and faster patient-specific discussions between different teams of clinicians. The overall objective is to ensure patient pathways are not delayed unnecessarily on account of clinicians being unable to contact each other.

We acknowledge and agree that any personal data of yours that we handle will be processed in accordance with all applicable data protection laws in force from time to time.

The information we may collect – Data relating to Hospital Consultants (and other secondary care clinicians)

The information about you that we may collect, hold and process is set out below:

  • Name
  • Job title
  • Employing organisation
  • GMC number (or equivalent)
  • Email address
  • Mobile phone number
  • IP address of any device used to access the system

This information will have been provided, or will be provided, by you or a third party who we work with, such as your employing organisation.

Please note that if you access our service using your NHS Care Identity credentials, the identity access and management services are managed by NHS Digital. NHS Digital is the controller for any personal information you provided to NHS Digital to get a national digital identity and authenticate your claim to that identity and uses that personal information solely for that single purpose. For any such personal information we are the Data Processor acting under instruction provided by NHS Digital (as the “controller”) when verifying your identity.  This restriction does not apply to the personal information you provide to us separately which is managed in accordance with our Privacy Policy.

How we use the information

The above information is/will be used to facilitate clinician to clinician contact via the Consultant Connect system, for the purposes of providing high quality care to patients.

How we hold the information

All the personal data we have is stored on our database in the UK.

Disclosure of your information

Your personal data will be treated as strictly confidential and will be not be shared with any third-party organisation other than with your explicit consent.

Legal basis for processing the information

The legal basis upon which we hold and process your data is Contractual Necessity.

Contractual Necessity: processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Retention of your data

Your data will be retained for no longer than is necessary and in accordance with our Data Retention Policy.

Your rights

You currently have the right at any time to ask for:

  • Access to your data – a copy of the information about you that we hold.
  • Erasure of your data – removal of data
  • Restriction of processing – restriction in the way data is processed
  • Objection – Correction of erroneous data
  • Data Portability – Transfer of your data to another provider of services
  • Complaint – you can complain to the Information Commissioners Office (0303 123 1113 or via ico.org.uk\concerns)

If you would like to make a request for any of the above, please email our Governance Lead at DPO@consultantconnect.org.uk

Withdrawal of consent

If you have provided us with your consent to process your data, for the purpose of using our services and us finding you suitable work, you have the right to withdraw this at any time.  In order to do so you should contact us by emailing our Governance Lead at DPO@consultantconnect.org.uk

Concerns

If you have a concern about the way we are collecting or using your personal data, you should raise your concern with us in the first instance or directly to Information Commissioners Office at www.ico.org.uk\concerns.

Contact

Please address any questions, comments and requests regarding our data processing practices to our Governance Lead at DPO@consultantconnect.org.uk

Changes to the Privacy Notice

This Privacy Notice may be changed by us at any time.

4 – Privacy Notice – Consultant Connect Staff Data

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the “GDPR”).

This Privacy Notice tells you what to expect in relation to personal information about you which is collected, handled and processed by Consultant Connect Limited.

Who are we?

We are Consultant Connect Limited of One St Aldates, St Aldates, Oxford, OX1 1DE.

Consultant Connect is the Data Controller for the purposes of retaining Consultant Connect Staff Data.

Consultant Connect is the provider of communications systems to the NHS and Private Health Providers that facilitate easier and faster patient-specific discussions between different teams of clinicians. The overall objective is to ensure patient pathways are not delayed unnecessarily on account of clinicians being unable to contact each other.

We acknowledge and agree that any personal data of yours that we handle will be processed in accordance with all applicable data protection laws in force from time to time

The information we may collect – Consultant Connect Staff Data

The information about you that we may collect, hold and process is set out below:

  • Name
  • Sex
  • Date of Birth
  • National Insurance Number
  • Passport
  • Outcome of criminal record checks and security clearances
  • Postal address
  • Email address
  • Telephone number (home and/or mobile)
  • CV/work history
  • Full details of job offer
  • Work references
  • Relevant medical information
  • Job preferences including role, geographical areas and salary
  • Financial information including bank account, pension and tax details
  • Any other work-related information you provide, for example education or training certificates
  • A log of communication with you
  • Email address
  • Mobile phone number
  • IP address of any device used to access the system

This information will have been provided, or will be provided, by you or a third party who we work with, such as recruitment agencies.  In the case of references, these will typically be from your previous employer but may be from other persons that you offer as a point of reference.

Medical information may be supplied by a third party such as your GP, Consultant or Occupational Health.

The outcome of criminal record checks and security clearance checks, where relevant, will be supplied by the Disclosure and Barring Service or other external company applicable to the placement.

How we use the information

The above information is used to assess your suitability for initial employment and subsequent promotions in our capacity as an employer.

The information above may be used as follows:

  • Match your skill sets with job vacancies
  • Establish that you have the right to work
  • Undertake relevant security and criminal record checks
  • Deal with any medical and health and safety issues relating to certain positions
  • Put in place contractual arrangements and documentation once a role has been offered
  • Pay you as per the contract with you
  • Support you in your ongoing and future roles with the organisation

How we hold the information

All the personal data we have is stored on our database in the UK.

Disclosure of your information

Your personal data will be treated as strictly confidential and will be shared only with senior management. We will only share your data with third parties outside of the organisation with your explicit consent.

Legal basis for processing the information

The legal bases upon which we hold and process the various elements of your personal data are Legitimate Interest, Contractual Necessity, Legal Obligation and Health & Social Care.

Legitimate Interest – the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

Contractual Necessity – the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.

Legal Obligation – the processing is necessary for you to comply with the law.

Health & Social Care – processing being necessary for the purposes of assessing the working capacity of the employee.

Retention of your data

Your data will be retained for no longer than is necessary and in accordance with our Data Retention Policy.

Your rights

You currently have the right at any time to ask for:

  • Access to your data – a copy of the information about you that we hold.
  • Erasure of your data – removal of data
  • Restriction of processing – restriction in the way data is processed
  • Objection – Correction of erroneous data
  • Data Portability – Transfer of your data to another provider of services
  • Complaint – you can complain to the Information Commissioners Office (0303 123 1113 or via ico.org.uk\concerns)

If you would like to make a request for any of the above, please email our Governance Lead at DPO@consultantconnect.org.uk

Withdrawal of consent

If you have provided us with your consent to process your data, for the purpose of using our services and us finding you suitable work, you have the right to withdraw this at any time.  In order to do so you should contact us by emailing our Governance Lead at DPO@consultantconnect.org.uk

Concerns

If you have a concern about the way we are collecting or using your personal data, you should raise your concern with us in the first instance or directly to Information Commissioners Office at www.ico.org.uk\concerns.

Contact

Please address any questions, comments and requests regarding our data processing practices to our Governance Lead at DPO@consultantconnect.org.uk

Changes to the Privacy Notice

This Privacy Notice may be changed by us at any time.

5 – Privacy Notice – Data for Marketing Purposes

Your personal data – what is it?

Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller’s possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the “GDPR”).

This Privacy Notice tells you what to expect in relation to personal information about you which is collected, handled and processed by Consultant Connect Limited.

Who are we?

We are Consultant Connect Limited of One St Aldates, St Aldates, Oxford, OX1 1DE.

Consultant Connect is the Data Controller for the purposes of retaining personal data in the form of Marketing Databases and Mailing Lists.

Consultant Connect is the provider of communications systems to the NHS and Private Health Providers that facilitate easier and faster patient-specific discussions between different teams of clinicians. The overall objective is to ensure patient pathways are not delayed unnecessarily on account of clinicians being unable to contact each other.

We acknowledge and agree that any personal data of yours that we handle will be processed in accordance with all applicable data protection laws in force from time to time.

The information we may collect – Personal Data within Marketing Databases and Mailing Lists

We collect your data for marketing purposes in 4 instances:

  • If you sign up to our mailing lists
  • If you use our contact form to get in touch
  • If you email us directly
  • If you sign up to the live session or recording of our webinars

In any of these instances we might ask for your name, organisation name, job title, phone number and email address. If you provide any further data, this is by your own choice.

This information will have been provided, or will be provided, by you or a third party who we work with, such as external database providers such as Wilmington Business Information.

How we use the information

We collect data to be able to respond to use it in one of three ways:

  • To respond to your enquiry
  • To sign you up to our mailing updates
  • To register you to our webinars

How we hold the information

All the personal data we have is stored on our database in the UK.

Disclosure of your information

Your personal data will be treated as strictly confidential and will be not be shared with any third-party organisation other than with your explicit consent.

Legal basis for processing the information

The legal basis upon which we hold and process your personal data is Legitimate Interest.

Legitimate interests: the processing of a person’s data is necessary for their legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.

Retention of your data

Your data will be retained for no longer than is necessary and in accordance with our Data Retention Policy.

Your rights

You currently have the right at any time to ask for:

  • Access to your data – a copy of the information about you that we hold.
  • Erasure of your data – removal of data
  • Restriction of processing – restriction in the way data is processed
  • Objection – Correction of erroneous data
  • Data Portability – Transfer of your data to another provider of services
  • Complaint – you can complain to the Information Commissioners Office (0303 123 1113 or via ico.org.uk\concerns)

If you would like to make a request for any of the above, please email our Governance Lead at DPO@consultantconnect.org.uk

Withdrawal of consent

If you have provided us with your consent to process your data, for the purpose of using our services and us finding you suitable work, you have the right to withdraw this at any time.  In order to do so you should contact us by emailing our Governance Lead DPO@consultantconnect.org.uk

Concerns

If you have a concern about the way we are collecting or using your personal data, you should raise your concern with us in the first instance or directly to Information Commissioners Office at www.ico.org.uk\concerns.

Contact

Please address any questions, comments and requests regarding our data processing practices to our Governance Lead at DPO@consultantconnect.org.uk

Changes to the Privacy Notice

This Privacy Notice may be changed by us at any time.