How we use your personal data.
Your privacy, and the security of the data you share with us is the most important part of our business. We want you to know why we need your data, and what we do with it. Our privacy policy defines why we need your data, and how we look after it.
We are Lutra Health Ltd. Our registered office is 2 Oldfield Road, Bocam Park, Bridgend, CF35 5JL. Our company number is 13409714 (Lutra Health, we, us).
Lutra Health is a private company, based in the UK, which specialises in developing apps to help healthcare workers provide efficient and safe care for patients.
We are registered with the Information Commissioners Office to process personal and special categories of information under the Data Protection Act (2018), our registration number is A9028898.
For further information, please see our website www.lutrahealth.com
We collect information about you in order to transmit it to other healthcare professionals who will then be able to make decisions about your care. We do not alter, adjust or interfere with the data that you or healthcare professionals give us.
Personal data means any information about an individual from which that person can be identified. We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as below. This will assist us to make decisions about your care we need:
We use different methods to collect data from and about you including through:
The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:
We have set out below, in a table format, a description of all the ways we plan to use the various categories of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate:
Purpose/Use | Type of data | Legal basis |
---|---|---|
To register you as a new customer or user |
| Performance of a contract with you |
To process and deliver our services to you including:
|
|
|
To manage our relationship with you which will include:
|
|
|
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
|
|
To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you |
| Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing |
| Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to you based on your Profile Data |
| Necessary for our legitimate interests (to carry out direct marketing, develop our products/services and grow our business) |
To carry out market research through your voluntary participation in surveys | Necessary for our legitimate interests (to study how customers use our products/services and to help us improve and develop our products and services) |
Where we process special categories data, for example data concerning/ including health, racial or ethnic origin, or sexual orientation, we need to meet an additional condition in the GDPR. Where we are processing special categories personal data for purposes related to the commissioning and provision of health services the condition is:
Purpose | Type of Data | Legal Basis | Processing condition |
---|---|---|---|
For the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services | Data concerning health |
|
|
The personal data we collect about you may also be used to:
Where possible, we will always look to anonymise/ pseudonymise your personal information so as to protect patient confidentiality, unless there is a legal basis that permits us to use it and we will only use/ share the minimum information necessary.
We may share your personal data where necessary with the parties set out below for the purposes identified in section 5 above:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We may transfer your personal data to service providers that carry out certain functions on our behalf. This may involve transferring personal data outside the UK to countries which have laws that do not provide the same level of data protection as the UK law.
Whenever we transfer your personal data out of the UK to service providers, we ensure a similar degree of protection is afforded to it by ensuring that the following safeguards are in place:
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or decimallosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Your data is held securely on AWS (Amazon Web Services) cloud servers, which achieve the relevant security for healthcare records. AWS is the international gold standard for cloud based data storage as documented here and upheld by AWS's customer contract terms.
Our Service may contain links to other websites that are not operated by Us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
You will receive marketing communications from us if you have requested information from us or purchased goods or services from us and you have not opted out of receiving the marketing.
We may also analyse your Identity, Contact, Technical, Usage and Profile Data to form a view which products, services and offers may be of interest to you so that we can then send you relevant marketing communications.
We will get your express consent before we share your personal data with any third party for their own direct marketing purposes.
You can ask to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you or by contacting us.
If you opt out of receiving marketing communications, you will still receive service-related communications that are essential for administrative or customer service purposes.
For more information about the cookies we use and how to change your cookie preferences, please see our cookie policy.
We may update our Privacy Policy from time to time. We will let you know via email, a prominent notice on our service or by requesting that you read and accept the new Privacy notice before allowing access to our service. The change will become effective and when the "Last updated" date at the top of this Privacy Policy is published.
You are advised to review this Privacy Policy periodically for any changes.
We will retain your data as described in our data retention policy.
In general terms we retain data for adults for eight years after the last point at which the data was accessed. We retain data destruction certificates for twenty years.
When we are required to send your personal data using either email or delivery within the app, we cannot guarantee the security of your data if it is sent by email. We will only use email to transfer your personal data when this has been requested by the receiving organisation (for example the NHS). We are not responsible for any personal data processing which occurs after we have sent the information to the receiving healthcare organisation, and you should refer to that organisations data protection policies for information on how they will use the data we supply.
If we need to use your personal information for any reasons beyond those stated above, we will discuss this with you and ask for your explicit consent. The Data Protection Act 2018 gives you certain rights, including the right to:
If you wish to exercise any of these rights in relation to your data please contact us at iris@lutrahealth.com
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not decimallosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Please email us at iris@lutrahealth.com to discuss any questions you may have about how we collect, store and use your data.
The Information Commissioner's Office (ICO) is the body that regulates the Trust under Data Protection and Freedom of Information legislation. https://ico.org.uk/. If you are not satisfied with our response or believe we are processing your personal data not in accordance with the law you can complain to the ICO at:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate number
Fax: 01625 524 510
Email: casework@ico.org.uk
We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.