Preventative Healthcare Company Ltd is committed to protecting your personal information.

Our Privacy Policy contains important information about what personal details we collect; what we do with that information; who we may share it with and why; and your choices and rights when it comes to the personal information you have given us and the data given to us by your employer.

We may need to make changes to our Privacy Policy; so please check our website for updates from time to time. If there are important changes, such as changes to how your personal data will be processed; we will update our policy on our website.

This version of our Privacy Policy was last updated 4th May 2018.

Who we are

We are The Preventative Healthcare Company Limited (“PHC”), a Specialist Occupational Health Service Provider. Registered address; PHC House, St Leonard’s Road, Maidstone, Kent, ME16 0FJ. Registered in England: 01998510.

This Privacy Policy applies to PHC Ltd.

How to contact us

If you have any questions about our Privacy Policy or the information we collect or use about you, please contact;

FAO Data Protection Officer
Preventative Healthcare Company Limited,
PHC House,
St Leonard’s Road
Maidstone,
ME16 0FJ

Email: talk2us@phcohealth.co.uk

Information we collect and use

Information about you that we collect and use includes:

Information about who you are e.g. your name, date of birth and contact details, job title and employer’s details.
Information about your contact with us e.g. consultations, phone calls, emails / letters
Information if you visit one of our offices e.g. visual images collected via closed circuit television (CCTV)
Information classified as ‘sensitive’ personal information e.g. relating to your health.
Information provided by your employer in connection with your occupational health referral or health surveillance.

This information will only be collected and used where it’s needed to provide the service we have been requested to supply, or to comply with our legal obligations

Where we collect your information

We may collect your personal information directly from you, and from a variety of sources, including:

medical forms completed by you
management referral forms completed by your employer
phone conversations with us
emails or letters you send to us
consultations with one of our clinical staff and technicians.

What we collect and use your information for

We take your privacy seriously and we will only ever collect and use information which is personal to you where it is necessary, fair and lawful to do so. We will collect and use your information only where:

you have given us your express permission [consent] to assess you from an occupational health perspective.

we may require some personal information including your name, address, contact details, date of birth, job title and employer

to deliver appropriate information and guidance with regard to your health, safety and welfare in the workplace.

it’s in the legitimate interests of a third party e.g. sharing information with your employer with regard to your health.

for statutory purposes e.g. Health and Safety Executive.

If you do not wish us to collect and use your personal information in these ways, it will mean that we will be unable to provide you and your employer with our services.

Who we may share your information with

We will share your information with your employer and third parties as outlined in ‘What we collect and use your information for.’

These third parties include:
Your employer
Our regulators and supervisory authority e.g. the Information Commissioner’s Office for the UK (the ICO)
Law enforcement, for the prevention and detection of crime
Health and Safety Executive

We will never sell your details to someone else. Whenever we share your personal information, we will do so in line with our obligations to keep your information safe and secure.

Where your information is processed

Your information is processed in the UK and European Economic Area (EEA).

Your information is processed by PHC Ltd.

Should your information need to be processed outside of the EEA, we will take additional steps to ensure that your information is protected to at least an equivalent level as would be applied by UK / EEA data privacy laws.

How we protect your information

We take information and system security very seriously and we strive to comply with our obligations at all times. Any personal information which is collected, recorded or used in any way, whether on paper, online or any other media, will have appropriate safeguards applied in line with our data protection obligations.

Your information is protected by controls designed to minimise loss or damage through accident, negligence or deliberate actions. Our employees also protect sensitive or confidential information when storing or transmitting information electronically and must undertake annual training on this.

Our security controls are aligned to industry standards and good practice; providing a controlled environment that effectively manages risks to the confidentiality, integrity and availability of your information.

How long we keep your information

We will keep your personal information only where it is necessary to provide you with our services whilst you are an employee of our client (employer).

We may also keep your information after this period but only where required to meet our legal or regulatory obligations. The length of time we keep your information for these purposes will vary depending on the obligations we need to meet.

Your individual rights

You have several rights in relation to how PHC uses your information. To access your rights detailed below please contact PHC’s data protection officer. Your Rights are;

Right to be informed

You have a right to receive clear and easy to understand information on what personal information we have, why and who we share it with – we do this in this Privacy Policy and subsequent privacy notices displayed on our website.

Right of access

You have the right of access to your personal information. If you wish to receive a copy of the personal information we hold on you, you may make a data subject access request (DSAR)

Right to request that your personal information be rectified

If your personal information is inaccurate or incomplete, you can request that it is corrected.

Right to request erasure

You can ask for your information to be deleted or removed if there is not a compelling reason for PHC to continue to have it.

Right to restrict processing

You can ask that we block or suppress the processing of your personal information for certain reasons. This means that we are still permitted to keep your information – but only to ensure we don’t use it in the future for those reasons you have restricted.

Right to data portability

You can ask for a copy of your personal information for your own purposes. In certain circumstances, you may move, copy or transfer the personal information we hold to another company in a safe and secure way. For example, if your employer were to move their occupational health services to another supplier.

Right to object

You can object to PHC processing your personal information by withdrawing your consent.

You have the right to ask PHC to:

give you information about its processing of your personal information.

How to make a complaint

We will always strive to collect, use and safeguard your personal information in line with data protection laws. If you do not believe we have handled your information as set out in our Privacy Policy, please visit our Contact us page, select ‘Make a complaint’ and we will do our utmost to make things right.

If you are still unhappy, you can complain to the Information Commissioners Office. Their contact details are:
ICO
Wycliffe House,
Water Lane,
Wilmslow,
Cheshire,
SK9 5AF

www.ico.org.uk

© 2018 Preventative Healthcare Company Ltd
Specialist Occupational Health Service Provider