This is a draft policy prepared as a starting point. Because Health in One products will process care-sector personal data, including potentially special category health data, it must be reviewed by a solicitor or data protection professional before publication, and registered with the ICO.
1. Who we are
Health in One is the data controller for personal data collected through this website. Health in One is a private limited company registered in England and Wales, company number 17455399, registered office 66 Paul Street, London EC2A 4NA. ICO registration number to be inserted before publication.
For our trading brands (Switch.ad, Carein.one, Carelitica and Hie), the controller/processor relationship depends on the product. Where a care provider uses our software to manage their own records, the provider is the controller and Health in One acts as processor under a data processing agreement.
2. What data we collect
This website itself collects limited data:
- Contact details you give us directly, such as your name and email address.
- Technical data such as IP address, browser type and pages visited, collected through server logs.
- Cookie data as described in our Cookie Policy.
Individual products collect additional data as described in their own privacy notices, provided at sign-up.
3. How we use your data
We use personal data to:
- Respond to enquiries and provide support.
- Operate, maintain and improve the website and our products.
- Meet legal and regulatory obligations.
Our lawful bases under UK GDPR are consent (where asked), performance of a contract, legitimate interests (running and improving our services), and legal obligation.
4. Special category data
Some Health in One products are designed to hold care and clinical records, which may include health data. Where we process such data as a processor on behalf of a care provider, we do so only under their documented instructions, with appropriate technical and organisational safeguards. We do not use special category data held on behalf of providers for our own purposes.
5. Sharing and transfers
We do not sell personal data. We may share data with vetted service providers (such as hosting and analytics providers) under contract, and with regulators or authorities where required by law. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as adequacy regulations or standard contractual clauses.
6. Retention
We keep personal data only as long as necessary for the purposes it was collected, or as required by law. Enquiry data is retained for up to 24 months unless a longer period is required.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data.
- Have inaccurate data corrected and incomplete data completed.
- Request erasure of your data in certain circumstances.
- Restrict or object to processing, and to data portability.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, contact us using the details below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and staff confidentiality obligations.
9. Contact
Data protection contact: hello@healthin.one. Company number 17455399. Complaints may also be made to the ICO at ico.org.uk or 0303 123 1113.