(Updated 15/12/2023)
This app is developed by Civica UK Ltd. (“Civica”). Use of this service is provided on behalf of the data controller, for whom Civica is acting as a data processor. The data controller is responsible for providing you with full privacy information for which you should refer to their privacy notice.
This privacy information covers the following:-
- The personal data processed by the app
- How your information is stored
- Sharing information
- International transfers
- Your rights
- How to complain
- Our contact details
- Changes to this privacy information
You will be provided with a privacy notice by the data controller (“Controller Privacy Notice”).
Please refer to it for more details including the following:
- The purpose of personal data processing
- The lawful bases for the processing of personal data
- How long your information is stored
- Rights related requests
The personal data processed by the app
In order to perform our services on behalf of the data controller, we collect (directly from you and/or our customer as data controller) and process the following data:
Categories of personal data:
Patients
- Full Name
- Age
- Date of Birth
- Gender
- Home Address
- Personal Email
- Personal Phone Numbers
- Emergency Contact Details
- Children’s Names
- Parents’ Names
Vulnerable Children
- Full Name
- Age
- Date of Birth
- Gender
Special categories of personal data:
Patients
- NHS Number
- NHS Number
How we store your information
Where the data controller is storing your data, you will be informed of this in their Privacy Notice, along with details relating to the conditions of storage.
Where the data controller utilises Civica for data storage, you can be assured that Civica is dedicated to keeping your data safe. We are certified under ISO27001 and ISO27701 as having put technical and organisational policies and procedures in place to protect personal data from loss, misuse, alteration or destruction. We ensure that access to your personal data is limited only to those who need to access it, and that those individuals are required to maintain the confidentiality of such information.
Sharing Information
Civica will never sell your data to third parties. We may, however, share your data with third party data processors (“subprocessors”) to provide our services.
These subprocessors have been agreed with, and approved by the data controller. Civica have contracts in place with our data processors. This means that they cannot do anything with your personal data unless instructed to do so. They will not share your personal data with any organisation and they will hold it securely and only retain it for the period specified.
The third parties used for this application are:
- Microsoft Azure Non-Corp- hosting of customer data for CITO.
International Transfers
Civica operates and provides services from its locations across the globe. As such we may transfer personal information to Civica group locations outside of the UK in order to provide our services. We have an Intra-Group Transfer Agreement including Standard Contract Clauses which provide legal safeguards for such transfers, where applicable.
Additionally, in order to support the provision of our services, we may transfer personal data to our third-party service providers outside the UK. We only transfer this data where it is necessary to do so and where a legal safeguard is in place.
Transfers that have been agreed with and approved by the data controller are as follows:
- N/A- All of CITO’s data is processed in the UK.
Your Rights
Under data protection legislation such as the GDPR, data subjects have the following rights regarding the use of their personal data:
Your right of access – You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not always receive all the information we process.
Your right to rectification – You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. This right always applies.
Your right to erasure – You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing – You have the right to ask us to restrict the processing of your information in certain circumstances.
Your right to object to processing – You have the right to object to processing if we are using legitimate interests as our lawful basis for processing.
Your right to data portability – This only applies to information you have given us. You have the right to ask that we transfer the information you gave us from one organisation to another, or give it to you. The right only applies if we are processing information based on your consent or as part of a contract, or in talks about entering into a contract and the processing is automated.
Your right to withdraw consent – You can withdraw your consent that you have previously given to one or more specified purposes to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw your consent. It may mean we are not able to provide certain products or services to you and we will advise you if this is the case.
If you wish to make a rights related request, you should contact the data controller. Details of how to do this are included in the controller’s Privacy Notice.
How to complain
If you disagree with how your data is being processed, please contact the data controller using the details provided within their Privacy Notice.
You can also complain to the ICO if you are unhappy with how your data is being processed.
The ICO’s address:
- Information Commissioner’s Office
- Wycliffe House
- Water Lane
- Wilmslow
- Cheshire
- SK9 5AF
- Helpline number: 0303 123 1113
Our contact details
Civica’s Headquarters is located at
Southbank Central (8th Floor)
30 Stamford Street
London
SE1 9LQ
Tel: 020 7760 2800
Civica is registered with the Information Commissioner’s Office, with registration number Z5268164.
If you have questions or comments about this privacy information or how we handle personal data, please direct your correspondence either to the above postal address (marking the envelope FAO – Data Protection Officer), or to DPO@Civica.co.uk.
Changes to this privacy information.
Civica will occasionally update this privacy information to reflect changes in legislation, our practices and services. When we post changes to this information, we will revise the “last updated” date at the top of this page. If there are any material changes in the way we collect, use, and share personal data, we will notify you by prominently posting notice of the changes below. We recommend that you check this page from time to time to inform yourself of any changes in this privacy information
Summary of changes:
Update | Detail |
15/12/2023 | Privacy Notice Published |