We only collect the information needed to care for you, like your contact details, health information, and how you use our service, or to facilitate your visit to our website, for marketing or communication purposes, or to allow a representative of a healthcare provider to contract with us, or for our general business activities.
How we use your data will depend on the circumstances in which we collect it and your role as a data subject (i.e. it will depend on whether you provide your data as a patient, visitor to our website, or a representative of a contracted or prospective healthcare provider). We use it to monitor your health, update your healthcare provider, contact you when needed, meet legal requirements, provide our services to you and improve our services.
Your data is kept safe with strict security measures and shared only when required for your care or by law — never sold. We may also use your data to improve services, to support research and for statistical and historical purposes; however such data will be anonymised and/or aggregated such that the data is not linked to you and you cannot be identified from the data.
You have rights over your data, including seeing it, correcting it, deleting it, limiting its use, or transferring it (see paragraph 10 below). Questions: dpo@doccla.com
We are Doccla UK Limited (referred to as Doccla, we, us and our in this Data Privacy Policy), a company incorporated in England and Wales with company registration number 12206481 and whose registered office address is 184 Shepherds Bush Road, Hammersmith, London, England, W6 7NL.
If applicable, we provide remote health monitoring services to help you manage your health from home. We work closely with your healthcare provider and other members of your care team to make sure you receive safe, effective, and personalised care.
The information set out in this Data Privacy Policy is provided to individuals whose personal data we process (you or your), in compliance with our obligations under the Data Protection Act 2018 and the UK GDPR (as defined in the as defined in the Data Protection, Privacy and Electronic Communications Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations SI 2019/419) (GDPR).
We are the data controller in relation to the processing of the personal data that you provide to us. In some circumstances, we are the data processor in relation to the processing of your personal data that is provided by your healthcare provider. Our contact details are as follows:
We only collect the information we need to look after you properly. This may include:
Generally, the information we hold about you comes from your healthcare provider or from you directly by the way that you engage with us, for example by doing any of the following:
We may also obtain information from publicly available sources, including public databases, registers and records.
Other than health data, we do not collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
We use your information for the following (including the purpose and legal grounds for processing your personal information):
In respect of any health data concerning you that is processed by us for the purposes above, we are required by law to have a further lawful basis for such processing in addition to the legal ground identified above. In such scenarios, we will rely on the following additional legal grounds applicable to the situation which requires the processing of your health data:
We take great care to protect your information. We handle your data in line with data protection laws and follow recognised industry best practices, including by taking appropriate technical and organisational measures to guard against unauthorised or unlawful processing, accidental loss, destruction or damage. For example:
However, while we will do our best to protect your personal information, we cannot guarantee the security of your information which is transmitted via an internet or similar connection.
We share your personal data only when it’s necessary for your care, or when the law requires it. This may include sharing with:
However, in certain circumstances we may need to share your personal data with the following groups:
We may use your data in an anonymised and/or aggregated format — information that cannot identify you — to:
Such data will be anonymised and/or aggregated such that the data is not linked to you and you cannot be identified from the data.
We will not transfer personal data relating to you to a country which is outside the UK and EEA unless:
We have systems in place to periodically review and delete data that is no longer being used by us for the purposes set out in this Data Privacy Policy. Unless we are required or permitted by law to hold on to your data for a specific retention period, we will hold your personal information within our systems only until we are no longer providing services to you, except that we will retain your data to the extent necessary to provide you with information on similar products and services once your care ends but only if you have not opted out to receiving such information.
If services are being provided to you pursuant to an agreement between us and your healthcare provider, we will retain your personal information for the duration of our contract with your healthcare provider.
In relation to your health data, where we have an obligation to retain this data (for example, for health and safety purposes) we will retain such data for the duration required by our obligation.
Where we no longer need your personal information, we will dispose of it in a secure manner.
In some circumstances you can ask us to delete your data: see the Your Rights section at paragraph 10 below for further information.
In some circumstances we will anonymise and/or aggregate your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this anonymised and/or aggregated information indefinitely without further notice to you.
In respect of the personal data about you that we are processing in accordance with the Data Protection Act 2018 and the GDPR, in certain circumstances (and provided that exemptions do not apply) you will have the following rights over your personal information:
If you are receiving marketing communications from us, you have the right to unsubscribe from such communications at any time by following the link in the footer of the last email you received from us or by sending your request with detailed instructions to us (see contact details above).
Please note that if you withdraw your consent to the use of your personal information for the purposes set out in our Data Privacy Policy, we may not be able to provide you with all or certain parts of our service.
If you consider our use of your personal information to be unlawful, you have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office. Please see further information on their website: www.ico.org.uk.
If you want to use any of these rights, please email: dpo@doccla.com
We do not make decisions based solely on automated data processing, including profiling.
We may amend this Data Privacy Policy from time to time, for example to keep it up to date, to implement minor technical adjustments and improvements or to comply with legal requirements. We will always update this Data Privacy Policy on our website, so please try to read it when you visit the website (the “last updated” reference tells you when we last updated our Data Privacy Policy).
************
If you are not a patient we are providing services to and you are merely a visitor to our website (at www.doccla.com/) or a representative of a healthcare provider contracting or potentially contracting with us, the following clauses will apply to you in additional to certain clause above (as applicable, see paragraph 6 below):
We collect and process the following types of personal data when you interact with us on the website or otherwise with a view to entering into a business relationship:
We process your personal data for the following purposes:
We process your personal data under the following legal bases:
Unless we are required or permitted by law to hold on to your data for a specific retention period, we will only hold your personal information within our systems for a period of 12 months since your last interaction with us.
We use cookies to enhance website functionality and gather analytics. A cookie is a small file of letters and numbers that is sent to your device when you visit our website, allowing our website to recognise your browser if you revisit it. Cookies may store your online preferences and other information about the interaction you make in the site. Please refer to our Cookie Policy (https://www.doccla.com/cookie-policy) for more information about the type of cookies used and how we use cookies/tracking technologies within our site.
The provisions of the Who We Are, Data Controller Details, How We Keep Your Information Safe, When We Share Your Information, 7. How We Use Anonymised and/or Aggregated Data, International Transfers, Your Rights, Automatic Decision Making and Changes to this Data Privacy Policy sections set out above also apply to Website Visitors.