• Capri Healthcare Ltd
    • 124 City Road, London, EC1V 2NX
    • Mon - Fri 9.00 - 17.00

Secondary Care

Read more

Emergency Care

Read More

Primary Care

Read More
0330 133 4047

Privacy Policy

Privacy Policy

Introduction

By law, organisations that use personal information (personal data) must clearly explain how it is used and provide related information to ensure the processing is lawful, fair and transparent.

Roles

  • Controller: [Customer Name] determines the purposes and means of processing your personal data for this service.
  • Processor: Capri Healthcare Ltd provides and supports the digital service on the Controller’s documented instructions under UK GDPR and the Data Protection Act 2018

WHAT IS THE LAWFUL BASIS?

The Customer selects the legal basis appropriate to its setting:

  • Personal data:
    • Public-sector providers (e.g., NHS bodies): UK GDPR Article 6(1)(e) (public task/official authority).
    • Independent/private providers: Article 6(1)(b) (contract) and/or Article 6(1)(f) (legitimate interests).
  • Special category (health) data: UK GDPR Article 9(2)(h) (provision of health or social care and the management of health systems/services) and, where applicable, a UK DPA 2018 Schedule 1 condition.

WHAT ARE THE PURPOSES OF THE PROCESSING?

The digital service allows people to contact their care provider securely without needing to call or attend in person, especially where it is unclear whether a face-to-face appointment is required. Through the service you can submit requests, symptoms, questions, documents, or images so that the Customer can:

  • assess your information and direct you to the most appropriate care or professional;
  • communicate with you about next steps; and
  • support care coordination, safety, audit, and service quality.

WHAT PERSONAL INFORMATION IS USED?

To provide a confidential, secure, and high-quality online service, the Customer needs to identify you and record your request and their responses.

  • Identity & contact details: name, date of birth, national identifier (e.g., NHS number, where used), postal address, email address, telephone number.
    Where NHS login or another SSO is used, you may permit identity attributes to be shared to verify who you are and pre-populate your details.
  • Special category (health) data: symptoms, conditions, medications, clinical history, images/documents, and other information necessary for care—either already held in the Customer’s records or provided by you through the online process.

Only information needed for the service is collected.

DO WE SHARE YOUR PERSONAL INFORMATION?

  • Your personal data is used by the Customer for your care and safe operation of the service.
  • Capri (as Processor) receives personal data only to host, operate, secure, and support the service on the Customer’s instructions.
  • Data is not shared for marketing or unrelated purposes.
  • If you are advised online to seek urgent care elsewhere based on your inputs, information entered solely for that triage is not shared further.

Any sharing complies with data protection law and applicable healthcare information governance requirements.

WHERE IS YOUR INFORMATION PROCESSED AND STORED?

Processing and storage occur within the United Kingdom.
If processing outside the UK/EEA is introduced in future, the Customer will ensure appropriate safeguards (e.g., adequacy, UK IDTA/EU SCCs) and update its notices accordingly.

HOW LONG IS YOUR PERSONAL INFORMATION KEPT?

  • The Customer sets retention periods under its records policy (e.g., NHS Records Management Code of Practice) and instructs Capri accordingly.
  • Operational copies held by Capri are deleted once transferred to the Customer’s systems.
  • For case-related communication, Capri may retain limited contact details (e.g., name, email) for up to 6 weeks, after which they are automatically deleted.
  • If you are advised online to seek urgent care elsewhere and do not proceed with the service, your information is not transferred to the Customer and is not retained after you have viewed the advice.

YOUR DATA PROTECTION RIGHTS

Under data protection law, you may have the right to access, rectify, erase, restrict, object, and data portability (where applicable). You are not required to pay a fee for most requests. We will respond within one month (extendable by up to two months for complex or multiple requests, with notice).

  • To exercise your rights regarding processing performed for the online service, contact the Customer (Controller) using the details in its main Privacy Notice.
  • You may also contact Capri about processing we perform as Processor and we will support the Customer in responding.

Capri Healthcare Ltd (Processor) contact:
Compliance Officer, Capri Healthcare Ltd
17 Heathcroft Road, Sutton Coldfield B75 6RT
Phone: 07467 336 997
Email: info@caprihealthcare.co.uk
ICO Registration: ZA543839

HOW TO COMPLAIN

Please raise any concerns with the Customer in the first instance (see the Customer’s main Privacy Notice). You can also contact Capri using the details above. You have the right to complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 — ico.org.uk

Hi, How Can We Help You?