We collect personal data in the following ways:
|Representatives and/or Individual's may provide personal data when: requesting Lab Testing Services; a Sample is collected; a pathology request form is completed (either electronically or hard copy); a Test is completed; they respond to us in respect of a survey or they otherwise correspond with us (via post, phone or email);
|Provision of our Services
|We collect special categories of personal data when you provide the patient information required by the phlebotomist as part of the Sample collection process and when we process Samples in our Lab in order to produce and create a Report.
|We may receive personal data from third parties who provide Representative Personal Data or Individual Personal Data on their behalf such as the Individual’s Medical Professional or employer.
|Billing address, delivery address, email address and telephone number.
|First name, maiden name, last name, date of birth and gender.
|Bank account and payment card details.
|Special categories of personal data
|Individual's health data including medical information (such as medical history and blood group), racial or ethnic origin, biometric data and genetic data.
|Details about payments to and from the Individual or Representative (as applicable) and other details of Lab Testing Services purchased from us.
The lawful basis upon which we may rely on to process your personal data are:
|The Individual or Representative (as applicable) has given their express consent for us to process the Individual Personal Data for a specific purpose.
|The processing is necessary for us to perform our contractual obligations with the Individual or Representative (as applicable), or because they have asked us to take specific steps before entering into a contract with them for the provision of our Lab Testing Services.
|The processing is necessary for us to comply with legal or regulatory obligation.
|Where it is necessary to carry out our legitimate interests (or those of a third party) and the Representative’s and/or Individual’s fundamental rights do not override those interests. Before we process your personal data on this basis we make sure we consider and balance any potential impact on you, and we will not use your personal data on this basis where such impact outweighs our interest.
Processing is necessary for reasons of substantial public interest or the purposes of preventative medicine, provision of health care or treatment
Where the processing of the special categories of personal data is necessary for the purpose of the potentially preventative medicine, medical diagnosis and/or provision of health care or treatment available by the provision of a Report to the Individual's Medical Professional.
We rely upon this exemption (available under Article 9(2)(h) of the UK GDPR) in accordance with the further requirements of Article 9(3) of the UK GDPR: the personal data is processed by or under the responsibility of a professional who is subject to the obligation of professional secrecy and confidentiality. Such professionals in this instance are health professionals who are subject to professional obligations of patient confidentiality.
Set out below are specific details of the processing activities we undertake with your personal data and the lawful basis for doing this.
|Type of data
|Lawful basis for processing
|To book an appointment with a phlebotomist.
|Identity & contact
|(i) To perform our contract with the Individual or Representative (as applicable);
|To process and deliver a request for Lab Testing Services, manage payments, fees and charges and debt recovery.
|Identity, contact, financial, transaction, marketing & communications
(i) To perform our contract the Individual or Representative (as applicable);
(ii) As necessary for our legitimate interest in recovering debts due to us.
|To collect the Sample, undertake the Test and prepare the Report.
|Identity, contact & special categories of personal data
(i) Consent - to provide those elements of our Lab Testing Services in respect of the Individual; or
(ii) To provide preventative medicine, medical diagnosis, healthcare or treatment.
|To provide the Report to the Individual, the Medical Professional or other third party requesting the Lab Testing Services.
|Identity, contact and special categories of data
(i) Consent - where the Individual’s employer has requested the Test be undertaken in respect of the Individual;
(ii) Consent - where the Individual has asked us to send a copy of the Report to their Medical Professional; or
(iii) To provide preventative medicine, medical diagnosis, healthcare or treatment.
You have the following legal rights in relation to your personal data:
|Access your data
|The Representative can ask for a copy of the Representative Personal Data and Individual Personal Data and the Individual can ask for a copy of the Individual Personal Data and can check we are lawfully processing it.
|The Representative and/or Individual can ask us to correct any incomplete or inaccurate personal data we hold about the Representative and/or Individual (as applicable).
The Representative and/or Individual can ask us to delete or remove the Representative Personal Data and/or Individual Personal Data (as applicable) where:
(a) there is no good reason for us continuing to process it;
(b) they have successfully exercised the right to object (see below);
(c) we may have processed information unlawfully; or
(d) we are required to erase the personal data to comply with local law.
We may not always be able to comply with the Representative and/or Individual's request for specific legal reasons, which will be notified to the Representative and/or Individual (as applicable) at the time of their request.
The Representative and/or Individual can object to the processing of the Representative Personal Data or Individual Personal Data (as applicable) where:
(a) we are relying on our legitimate interest (or those of a third party) as the basis for processing the personal data, if the Representative and/or Individual feels it impacts on their fundamental rights and freedoms;
(b) we are processing Representative Personal Data or Individual Personal Data for direct marketing purposes.
In some cases, we may demonstrate that we have compelling legitimate grounds to process Representative Personal Data or Individual Personal Data which override the Representative's or Individual's rights and freedoms and, in such circumstances, we can continue to process the Representative Personal Data or Individual Personal Data for such purposes.
The Representative and/or Individual can ask us to suspend or restrict the processing of the Representative Personal Data or Individual Personal Data (as applicable), if:
(a) the Representative and/or Individual want us to establish the accuracy of the personal data;
(b) our use of the Representative Personal Data or Individual Personal Data is unlawful, but they do not want us to erase it;
(c) the Representative and/or Individual needs us to hold the Representative Personal Data or Individual Personal Data (where we no longer require it) as they need it to establish, exercise or defend legal claims; or
(d) the Representative and/or Individual have objected to our use of the Representative Personal Data or Individual Personal Data (as applicable), but we need to verify whether we have overriding legitimate grounds to use it.
|Request a transfer
|The Representative and/or Individual can request a transfer of the Representative Personal Data or Individual Personal Data (as applicable) which is held in an automated manner and which the Representative or Individual provided consent for us to process such personal data or which we need to process to perform our contract with the Representative or Individual or a third party. We will provide the Representative Personal Data and/or Individual Personal Data in a structured, commonly used, machine-readable format.
|Withdraw your consent
|The Representative (on behalf of the Individual) or the Individual (as applicable) can withdraw consent at any time (where we are relying on consent to process Individual Personal Data). This does not affect the lawfulness of any processing carried out before consent was withdrawn.
|Information such as statistical or demographic data which may be derived from personal data but which cannot by itself identify a data subject;
|A body that determines the purposes and means of processing personal data;
|an individual living person identified by personal data;
|Information Commissioner's Office, the UK supervisory authority for data protection issues.
|the person whom the Sample is to be taken from;
|our laboratory testing facility located at 1-5 Portpool Lane, London, EC1N 7UU.
|Lab Testing Services
|the Lab testing services which include collection of Samples, undertaking the Test(s) and producing Reports;
|GP or other medical practitioner, healthcare provider, clinician, nurse or nutritionist.
|information identifying a data subject from that data alone or with other data we may hold but it does not include anonymised or aggregated data;
|a body that is responsible for processing personal data on behalf of a controller;
|the report of a Test;
|a person who is the parent, guardian, carer of the Individual and is to represent or act in that Individual’s best interests;
|a sample of an blood or other bodily fluid to be taken/or taken by our phlebotomist for the purpose of the Test;
|Special categories of personal data
|information about race, ethnicity, political opinions, religious or philosophical beliefs, trade union membership, health, genetic, biometric data, sex life and sexual orientation;
|the analysis to be run on a Sample; and
|Third Party Lab
|any third party laboratory which we may instruct from time to time to carry out all of any part of the Lab Testing Services.