At Evolutio Care Innovations Limited, we value the trust of our customers and patients. To earn your trust, we respect your privacy in handling personally identifiable information relating to you and your interactions with us. This Privacy Statement describes the personally identifiable information we gather about you, what we do with it, the safeguards we have in place to protect it, and how you can control our use of it.
Evolutio Care Innovations Limited may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from 15/02/2019.
We collect personally identifiable information that you voluntarily provide to us when you make a complete an application, give us a telephone call or send us a letter or e-mail.
We may also collect it from other sources where it is lawful to do so, including but not limited to, the NHS or other health care providers, institutions or individuals you have authorised to provide information on your behalf (e.g. parents or guardians), third party service providers, government, law enforcement agencies, and other third parties.
This personally identifiable information may include:
- your full name
- e-mail address
- telephone number
- postal address
- your relevant health details including:
-
- current and past eye conditions, general health condition and spectacles or contact lens;
- current medication details; and
- correspondence between optometrist and your GP/ophthalmologist
- your examination and test results – including your health data in reports and/or photos and/or images
- details of any prescription supplied to you by your healthcare professional or medical practitioner
- information that you provide by filling in forms on this website
- other optional demographic information.
You may browse our web site without supplying any personally identifiable information, but we will need to collect personally identifiable information to process any medical requests you make.
How does Evolutio Care Innovations Limited use personally identifiable information about me?
The personally identifiable information that is provided to us will be used to provide any relevant eyecare treatment and may be used to identify you within our systems. We may use your email address and/or telephone to contact you if we have any updates to your referral or eye care.
If you contact us through an online form on this website you may be providing us with personal information, including information outlined above. This may include medical information, where volunteered by you.
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
- Internal record keeping;
- Eye care referral processing and any subsequent treatment, including any changes to our services and products;
- Appointment information (times/dates, locations and reminders);
- We may use the information to improve our products and services;
- We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using the contact details which you have provided;
- From time to time, we may also use your information to contact you for research purposes. We may contact you by email, phone, fax or mail. We may use the information to improve our services and customise the website according to your interests;
- To establish and fulfil a contract with you, for example, if you enter into an agreement to provide or receive services. This may include verifying your identity, taking payments, communicating with you and providing customer services or other provision of products or services. We require this information in order to enter into a contract with you and are unable to do so without it;
- Responding to queries from you;
- to comply with applicable law and regulation;
- if you provide a credit or debit card, we may also use third parties to check the validity of the sort code, account number and card number you submit in order to prevent fraud, in accordance with our legitimate interests and those of third parties
In order to provide you with the products and services described above, we hold copies of your personal information at Evolutio Care Innovations Limited.
With whom might Evolutio Care Innovations Limited share personally identifiable information about me?
We will not disclose personally identifiable information about you to others except as disclosed in this Privacy Statement or as specifically authorised by you at the time the information is collected. We contract with third parties to provide specific services to you.
We may, where required, disclose your personal information to third parties in the following circumstances:
- Disclose personal information to the NHS and other health care providers, including NHS health authorities, NHS providers and subcontracted care providers delivering eye care on behalf of Evolutio Care Innovations Limited
- Where external agencies, including the police and other law enforcement agencies, for the prevention and detection of criminal activity.
- Where the company and its assets are acquired by a third party, patient personal information held by us will be transferred as one of the assets.
These service providers are provided with only the information that they need to perform their functions and are not permitted to use or disclose your personally identifiable information for other purposes without your authorisation.
How long will Evolutio Care Innovations Limited keep my personal data?
We will not keep your personal data for any purpose longer than necessary to fulfil the original or a compatible purpose. In some instances, we are required to retain certain information by law and for as long as reasonably necessary to meet regulatory or accreditation requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions. Where this is the case, your personal data will only be processed for the relevant legitimate purpose and not used for marketing.
Where you are a patient, we will keep your personal data for as long as is reasonably necessary (or as defined under applicable healthcare laws and regulations) to provide products and services, including aftercare services, and to maintain records as required to satisfy tax and other legal or regulatory requirements, as well as to protect and defend against claims.
What are my rights in relation to my personal data?
You have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data, clicking the unsubscribe button on any communication we have sent to you or by contacting us.
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions and qualifications, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) if you object to the use of your personal data and we don’t have a good reason to continue to use it; or (d) if we haven’t handled your personal data in accordance with our obligations.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
NHS Numbers
If you are receiving care from a health or care organisation, that organisation may share your NHS number with other organisations providing your care. This is so that the health and care organisations are using the same number to identify you whilst providing your care. By using the same number the health and care organisations can work together more closely to improve your care and support.
Your NHS number is accessed through an NHS Digital service called the Personal Demographic Service (PDS) https://digital.nhs.uk/services/demographics. A health or care organisation sends basic information such as your name, address and date of birth to the PDS in order to find your NHS Number. Once retrieved from the PDS the NHS Number is stored in our case management system. These data are retained in line with our record retention policies and in accordance with the Data Protection Act 1998, Government record retention regulations and best practice.
We will share information only to provide health and care professionals directly involved in your care access to the most up-to-date information about you. Access to information is strictly controlled, based on the role of the professional, and where the user has a direct care relationship with you.
The use of joined up information across health and social care brings many benefits. One specific example where this will be the case is the discharge of patients into social care. Delays in discharge (commonly known as bed blocking) can occur because details of social care involvement are not readily available to the staff on the hospital ward. The hospital does not know who to contact to discuss the ongoing care of a patient. The linking of social care and health information via the NHS Number will help hospital staff quickly identify if social care support is already in place and who the most appropriate contact is. Ongoing care can be planned earlier in the process, because hospital staff will know who to talk to.
You have the right to object to the processing of your NHS Number in this way. This will not stop you from receiving care, but will result in the benefits outlined above not being realised. To help you decide, we will discuss with you how this may affect our ability to provide you with care, and any other options that you have.”
If you wish to opt-out from the use of your NHS Number in this way, please contact us on 0203 7807860 or email to DPO@evolutio-uk.com
How the NHS and care services use your information
Evolutio Ophthalmology is one of many organisations working in the health and care system to improve care for patients and the public.
Whenever you use a health or care service, such as using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
- improving the quality and standards of care provided
- research into the development of new treatments
- preventing illness and diseases
- monitoring safety
- planning services
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. On this web page you will:
- See what is meant by confidential patient information
- Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
- Find out more about the benefits of sharing data
- Understand more about who uses the data
- Find out how your data is protected
- Be able to access the system to view, set or change your opt-out setting
- Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
- See the situations where the opt-out will not apply
You can also find out more about how patient information is used at:
- https://www.hra.nhs.uk/information-about-patients/ (which covers health and care research); and
- https://understandingpatientdata.org.uk/what-you-need-know (which covers how and why patient information is used, the safeguards and how decisions are made)
You can change your mind about your choice at any time.
Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.
Our organisation is compliant with the national data opt-out policy as of March 31st, 2022.
We collect and process personal data about you when you interact with us and our products and when you provide a service to us. The personal data we process includes:
- name;
- GOC Number;
- any GOC hearing outcomes / reports
- username and password;
- home or work address, email address and/or phone number;
- job title;
- billing address
- personal data related to the browser or device you use to access our website / eVonnect;
- internet browser and operating system;
- recordings of calls you make to our customer service team; and
- any other personal data you provide, including documents needed to verify your identity during the sign up process
How does Evolutio Care Innovations Limited use personally identifiable information about me?
We process the personal data listed above for the following purposes:
- to establish and fulfil a contract with you. This may include verifying your identity, communicating with you, providing customer services and arranging the delivery or other provision of products or services. We require this information in order to enter into a contract with you and are unable to do so without it;
- to comply with applicable law and regulation; in accordance with our legitimate interests in protecting Evolutio’s legitimate business interests, and legal rights, including but not limited to, use in connection with legal claims, compliance, regulatory and investigative purposes (including disclosure of such information in connection with legal process or litigation);
- Audit individual clinician performance and care outcomes;
- with your express consent to respond to any comments or complaints we may receive from you, or to investigate any complaints received from you or from others, about our website or our products or services;
we may use information you provide to personalise (i) our communications to you; (ii) our website; and (iii) products or services for you, in accordance with our legitimate interests; - to monitor use of our websites and online services. We may use your information to help us check, improve and protect our products, content, services and websites, both online and offline, in accordance with our legitimate interests;
- if you provide a credit or debit card, we may also use third parties (such as POS payment providers) to check the validity of the sort code, account number and card number you submit in order to prevent fraud, in accordance with our legitimate interests and those of third parties;
- we may monitor any providers account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law and our legitimate interests;
- in circumstances where you contact us by telephone, calls may be recorded for quality, training and security purposes, in accordance with our legitimate interests; and
- we may use your information to invite you to take part in market research or surveys.
- We may also send you marketing / newsletters in relation to relevant services and service updates. Electronic direct marketing will only be sent where you have given your consent to receive it, or (where this is allowed) you have been given an opportunity to opt-out. We will not send you direct marketing of third-party products or services although our own products or services may on occasion include co-operation with third parties. You will continue to be able to opt-out of electronic direct marketing at any time by following the instructions in the relevant communication.
With whom might Evolutio Care Innovations Limited share personally identifiable information about me?
We may share your personal data with our subsidiaries to process it for the purposes of inter-group administration and to deliver services where elements of these are provided by Evolutio companies other than those with which you have directly contracted.
We may also share your personal data with the below third parties:
- our professional advisors such as our auditors and external legal and financial advisors;
- the NHS contracting authority;
- your employer or nominating organisation;
- marketing and communications agencies where they have agreed to process your personal data in line with this Privacy Notice;
- market research companies where consent has been obtained from yourself;
our suppliers, business partners and Sub-Contractors / Users / Clinicians
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws.
Personal data may also be shared with third party service providers who will process it on behalf of Evolutio for the purposes above. Such third parties include, but are not limited to, providers of website hosting, maintenance, call centre operation and identity checking.
In the event that our business or any part of it is sold or integrated with another business, your details will be disclosed to our advisers and those of any prospective purchaser and will be passed to the new owners of the business.
How long will Evolutio Care Innovations Limited keep my personal data?
We will not keep your personal information for longer than is necessary and will only retain the personal information that is necessary to fulfil the purpose. We are also required to retain certain information by law or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We will keep your personal data for the length of any contractual relationship you have with us and after that for a period of up to 3 years.
In the case of any contact you may have with our patient services team, we will retain your details for as long as is necessary to resolve your query and for two weeks after the query is closed.
We may retain your personal data for a time beyond the specified retention period, to allow for information to be reviewed and any deletion to take place. After it is no longer necessary for us to retain your personal data, we dispose of it securely according to our Retention Policy.
What are my rights in relation to my personal data?
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) you object to the use of your personal data and we don’t have a good reason to continue to use it; or (d) we haven’t handled your personal data in accordance with our obligations.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
We collect personally identifiable information that you voluntarily provide to us when you make a complete an application, give us a telephone call or send us a letter or e-mail.
This personally identifiable information may include:
- your name, home address, email address and/or phone numbers;
- your date of birth, marital status, nationality and National Insurance number (where you provide this to us);
- your educational and employment history;
- other information contained within your CV or other documents or information you submit to us;
- information from the selection process, if any;
- references and assessments relating to your work for previous employers;
- medical and financial information (where you provide this to us);
- information to confirm your identity and right to work, such as a copy of your passport;
- details of any unspent criminal convictions; and
- information relating to your feedback on our organisation.
- With your specific consent, information relating to your ethnicity, gender, nationality, disability, religion, sexual orientation and other diversity-related information.
How does Evolutio Care Innovations Limited use personally identifiable information about me?
We process the personal data above for the following purposes only in accordance with our legitimate interests:
- to enable us to comply with our legal and regulatory obligations;
- to make recruitment decisions;
- to prevent and detect fraud and other wrongdoing;
- to establish, exercise or defend our legal rights; and
- to manage risk
With whom might Evolutio Care Innovations Limited share personally identifiable information about me?
We may share your personal data for the purposes of intra-group administration.
Personal data may be shared with government authorities and/or law enforcement officials if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws.
Personal data may also be shared with third party service providers who will process it on behalf of Evolutio for the purposes above. In the event that any part of our business is sold or integrated with another business, your details may be disclosed to our advisors and those of any prospective purchaser and would be passed to the new owners of the business.
How long will Evolutio Care Innovations Limited keep my personal data?
We will not keep your personal information for longer than is necessary and will only retain the personal information that is necessary to fulfil the purpose. We are also required to retain certain information by law or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We will keep the personal data connected to your job application (including any interview records) for 6 months from the date of their creation by us or receipt from you. If your application is successful and you become a member of staff we will provide you with a copy of the Employee Privacy Notice. The retention periods referred to therein will apply to your personal data during your employment.
What are my rights in relation to my personal data?
Where you have consented to us using your personal data, you can withdraw that consent at any time.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
You also have the right, with some exceptions, to ask us to provide a copy of any personal data we hold about you.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved. In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) you object to the use of your personal data and we don’t have a good reason to continue to use it; or (d) we haven’t handled your personal data in accordance with our obligations.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
END USERS
We collect and process personal data about you when you interact with us and our products.
The personal data we process include:
- Full name
- GOC Number
- Username and password
- Email address
- Phone number
- Work address (registered practice)
- Job title and role within the organisation
- Personal data related to the browser or device you use to access our website / eVonnect
- Internet browser and operating system
- IP address
- Recording of calls you make to our support line
- Any other personal data you provide, including documents needed to verify your identify during the sign up process
How does Evolutio Care Innovations Limited use personal identifiable information about me?
We process the personal data listed above for the following purposes:
- to establish and fulfil a contract with you (use of our product). This may include verifying your identity, communicating with you and providing customer services. We require this information in order to enter into a contract with you and are unable to do so without it;
- to comply with applicable law and regulation; in accordance with our legitimate interests in protecting Evolutio’s legitimate business interests, and legal rights, including but not limited to, use in connection with legal claims, compliance, regulatory and investigative purposes (including disclosure of such information in connection with legal process or litigation);
- with your express consent to respond to any comments or complaints we may receive from you, or to investigate any complaints received from you or from others, about our website or our products or service; we may use information you provide to personalise (i) our communications to you; (ii) our website; and (iii) products or services for you, in accordance with our legitimate interests;
- to monitor use of our websites and online services. We may use your information to help us check, improve and protect our products, content, services and websites, both online and offline, in accordance with our legitimate interests;
- we may monitor any providers account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime, in accordance with applicable law and our legitimate interests;
- in circumstances where you contact us by telephone, calls may be recorded for quality, training and security purposes, in accordance with our legitimate interests;
- we may use your information to invite you to take part in market research or surveys. We may also send you marketing / newsletters in relation to relevant services and service updates. Electronic direct marketing will only be sent where you have given your consent to receive it, or (where this is allowed) you have been given an opportunity to opt-out. We will not send you direct marketing of third-party products or services although our own products or services may on occasion include co-operation with third parties. You will continue to be able to opt-out of electronic direct marketing at any time by following the instructions in the relevant communication.
With whom might Evolutio Care Innovations Limited share personal identifiable information about me?
We may share your personal data with our subsidiaries to process it for the purposes of inter-group administration and to deliver services where elements of these are provided by Evolutio companies other than those with which you have directly contracted.
We may also share your personal data with the below third parties:
- our professional advisors such as our auditors and external legal and financial advisors;
- the NHS contracting authority;
- your employer or nominating organisation;
- marketing and communications agencies where they have agreed to process your personal data in line with this Privacy Notice;
- market research companies where consent has been obtained from yourself;
our suppliers, business partners and Sub-Contractors / Users / Clinicians
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if needed for the legal protection of our legitimate interests in compliance with applicable laws.
Personal data may also be shared with third party service providers who will process it on behalf of Evolutio for the purposes above. Such third parties include, but are not limited to, providers of website hosting, maintenance, call centre operation and identity checking.
In the event that our business or any part of it is sold or integrated with another business, your details will be disclosed to our advisers and those of any prospective purchaser and will be passed to the new owners of the business.
How long will Evolutio Care Innovations Limited keep my personal data?
We will not keep your personal information for longer than is necessary and will only retain the personal information that is necessary to fulfil the purpose. We are also required to retain certain information by law or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions.
We will keep your personal data for the length of any contractual relationship you have with us and after that for a period of up to 3 years.
In the case of any contact you may have with our support team, we will retain your details for as long as is necessary to resolve your query and for two weeks after the query is closed.
We may retain your personal data for a time beyond the specified retention period, to allow for information to be reviewed and any deletion to take place. After it is no longer necessary for us to retain your personal data, we dispose of it securely according to our Retention Policy.
What are my rights in relation to my personal data?
Where you have consented to us using your personal data, you can withdraw that consent at any time.
You have the right to be informed about the collection and use of your personal data i.e. purpose for processing, retention periods and who it will be shared with.
You also have the right, with some exceptions, to ask us to provide a copy of any personal data we hold about you.
If the information we hold about you is inaccurate or incomplete, you can notify us and ask us to correct or supplement it.
Where you have provided your data to us and it is processed by automated means, you may be able to request that we provide it to you in a structured, machine readable format.
If you have a complaint about how we have handled your personal data, you may be able to ask us to restrict how we use your personal data while your complaint is resolved.
In some circumstances you can ask us to erase your personal data (a) by withdrawing your consent for us to use it; (b) if it is no longer necessary for us to use your personal data; (c) you object to the use of your personal data and we don’t have a good reason to continue to use it; or (d) we haven’t handled your personal data in accordance with our obligations.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.
CCTV
In some instances, CCTV is utilised in clinic and office settings to help ensure the safety and security of employees and service users.
This data will only be processed by Evolutio. In certain circumstances we may be required to disclose CCTV images to certain bodies of authority, such as the police and emergency services.
We process CCTV footage for 31 days after the date of capture, although we may process footage for a longer period, for example if the footage is relevant to an investigation.
No data will be transferred to third parties, except to the extent that we are required to share this data with certain bodies of authority, such as the police and emergency services.
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
How do I access my data or make a complaint?
You may request details of personal information which we hold about you under the Data Protection Act 2018. This information will be provided free unless the request is manifestly unfounded or excessive then a small fee will be payable. If you would like a copy of the information held on you please write to:
DPO
Evolutio Care Innovations Limited
Newtown House
Newtown Road
Henley on Thames
Oxon RG9 1HG
Should you have any queries regarding this Privacy Notice, about the processing of your personal data or you wish to exercise your rights you can contact our Data Protection Office using this email address: DPO@evolutio-uk.com
If you are not happy with our response, you can contact the Information Commissioner’s Office: https://ico.org.uk/