1. Introduction
Omniserve Group Ltd ("we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
As a home care provider, we handle sensitive personal and health information with the utmost care and confidentiality. This policy applies to all individuals who use our services, their families, and anyone who interacts with our organization.
2. Information We Collect
2.1 Personal Information
- Full name, date of birth, and contact details
- Address and living arrangements
- Next of kin and emergency contacts
- National Insurance number (where required)
- Financial information for billing purposes
2.2 Health and Care Information
- Medical history and current health conditions
- Medication details and allergies
- Mobility and care requirements
- Dietary requirements and preferences
- GP and healthcare provider information
- Care notes and daily records
2.3 Communication Records
- Email correspondence
- Phone call records
- Messages and care updates
- Feedback and complaints
3. How We Use Your Information
We use your personal information for the following purposes:
- Care Delivery: To provide safe, appropriate, and personalized care services
- Care Planning: To develop and maintain your individual care plan
- Staff Allocation: To match you with suitable care professionals
- Billing: To process payments and maintain financial records
- Communication: To keep you and your family informed about care services
- Legal Compliance: To meet regulatory and legal obligations
- Quality Improvement: To monitor and improve service quality
- Safeguarding: To ensure your safety and wellbeing
4. Legal Basis for Processing
We process your personal information under the following legal bases:
- Consent: You have given explicit consent for us to process your data
- Contract: Processing is necessary to fulfill our care service contract with you
- Legal Obligation: We must process data to comply with care regulations and safeguarding duties
- Vital Interests: Processing is necessary to protect your life or health in emergency situations
- Legitimate Interests: For service improvement and administrative purposes where this does not override your rights
5. Information Sharing
We may share your information with:
5.1 Healthcare Providers
Your GP, hospitals, community nurses, and other healthcare professionals involved in your care (with your consent or where necessary for your wellbeing).
5.2 Family Members
Family members and representatives you have authorized us to communicate with.
5.3 Regulatory Bodies
Care Quality Commission (CQC) and other regulatory authorities as required by law.
5.4 Local Authorities
Social services departments where they are funding or coordinating your care.
5.5 Emergency Services
Police, ambulance, or fire services in emergency situations.
Important: We will never sell your personal information to third parties for marketing purposes.
6. Data Security
We implement robust security measures to protect your information:
- Encrypted digital records and secure servers
- Password-protected systems with restricted access
- Locked filing cabinets for paper records
- Staff training on data protection and confidentiality
- Regular security audits and updates
- Secure disposal of records when no longer needed
- Confidentiality agreements for all staff
7. Data Retention
We retain your information for the following periods:
- Care Records: 7 years after service ends (or until age 25 for children)
- Financial Records: 6 years for tax and accounting purposes
- Safeguarding Records: As required by local safeguarding procedures
- Complaints Records: 3 years after resolution
After these periods, records are securely destroyed or permanently deleted.
8. Your Rights
Under UK GDPR, you have the following rights:
- Right to Access: Request copies of your personal information
- Right to Rectification: Request corrections to inaccurate information
- Right to Erasure: Request deletion of your data (subject to legal requirements)
- Right to Restrict Processing: Request limitations on how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to certain types of processing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us using the details at the end of this policy.
9. Cookies and Website Data
Our website may use cookies to improve your browsing experience. Cookies are small text files stored on your device. You can control cookie settings through your browser preferences.
We use essential cookies for website functionality and analytics cookies (with your consent) to understand how visitors use our site.
10. Children's Privacy
If we provide care services to children under 16, we obtain consent from parents or legal guardians for processing their personal information. We take extra care to protect children's data and comply with additional safeguarding requirements.
11. Data Breaches
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office (ICO) within 72 hours as required by law. We have procedures in place to detect, report, and respond to data breaches.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on our website and, where appropriate, communicated to you directly. We encourage you to review this policy periodically.
13. Complaints
If you have concerns about how we handle your personal information, please contact us first so we can try to resolve the issue. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk
14. Contact Us
For questions about this Privacy Policy or to exercise your data protection rights, please contact us:
Omniserve Group Ltd
Data Protection Officer
Ashley Park House, 42-50 Hersham Road, 1st Floor, Walton-on-Thames, KT12 1RZ
Phone: 020 3355 2989
Email: info@omniservegroup.co.uk