Last updated: 26 November 2024
Introduction
This privacy notice, created in line with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018, explains how we collect, use and protect personal information from trusts we collaborate with, patients, contractors and other third parties. It applies to personal information provided to us directly by individuals or through third parties. This notice complements the privacy notice for Prometheus Safe and Secure Ltd (PSS) and Prometheus Complex Care (PCC) employees, which are available from HR.
Data controller
PSS and PCC are two separate legal entities under an intergroup data processing agreement, and both belong to the parent company RCI Group Limited. Each entity acts as an independent controller, but they may also process information for each other when appropriate and lawful. The companies share the same senior management team, ensuring consistency in their operations and oversight.
PSS is registered with the Information Commissioner’s Office (ICO) under registration number ZA049039. PCC is registered with the ICO under registration number ZA884822. Both may also process information on behalf of clients, such as patient information for the purpose of delivering their care services. All data processing activities are conducted with a lawful basis and in line with relevant data protection laws.
Contact details and Data Protection Officer
Prometheus Safe and Secure Ltd and Prometheus Complex Care Ltd, Unit 603, Fort Dunlop, Fort Parkway, Birmingham, B24 9FD. Tel: 0800 009 6668.
For any queries or complaints in relation to how your data is being used, please contact us at compliance@psecure.co.uk. Our Data Protection Officer is Lorain Morrison, who can be contacted at the same address.
How we collect your personal information
When we collect personal information on behalf of our clients (for example, if a trust asks us to deliver a service for a patient), we act as a data processor. In this role, we don’t decide how the information is used; instead, we process it solely to provide the requested service. In these cases, the trust remains the data controller.
We are, however, a data controller for any information where we decide on the purposes and means of processing. There are also situations where we may need to act as a separate data controller for some information provided by the trust to meet legal or regulatory obligations. This means we may act as both a data controller and a data processor for different aspects of the same information, depending on the circumstances.
How we will use your personal information
The personal information provided to us is predominantly used to provide our core services, including:
- Healthcare observation services
- Secure patient transport
Data protection principles
We are committed to fully applying and adhering to the data protection principles in relation to your personal data as required by the UK GDPR and the Data Protection Act 2018:
- Lawfulness, fairness and transparency — we process personal data lawfully, fairly and transparently, with clear communication through privacy notices and policies.
- Purpose limitation — we collect personal data only for specified, explicit and legitimate purposes.
- Data minimisation — only the minimum amount of personal data required for specific purposes is collected and processed.
- Accuracy — regular reviews and updates are conducted to ensure the accuracy of the personal data we process.
- Storage limitation — personal data is kept no longer than necessary, in accordance with our Data Retention Schedule (available on request).
- Integrity and confidentiality — robust security measures, including encryption and access controls, protect personal data.
- Accountability — we maintain records of our processing activities, conduct data protection impact assessments where necessary, and regularly review our practices.
Types of data we process
We collect and process two types of data: personal data (information that identifies you, such as name, telephone number, email address, postal address or date of birth) and special category data (more sensitive information subject to a higher level of protection, such as health data). When it comes to special category data, we generally only collect health data; however, we may receive additional relevant information for specific purposes.
Legal basis
We collect and process personal data based on several legal grounds, depending on the specific activity and purpose:
- Contractual necessity — processing essential for fulfilling our obligations under a contract or formal agreement with you.
- Legal obligation — where we are legally required to collect and use your information to meet regulatory or statutory requirements.
- Vital interests — in rare cases, such as a medical emergency, to protect your life or wellbeing.
- Legitimate interests — following a thorough Legitimate Interest Assessment to ensure these interests do not override your rights or freedoms.
Where we are acting as a processor, our clients and those instructing us establish a legal basis for processing, which tends to be public task, as we generally work for healthcare providers in the public sector.
Data retention, storage and protection
We only keep your personal information for as long as needed. Once the purpose for processing is no longer justifiable, the data is securely deleted from our database and from the databases of our processors. Physical documents are kept in locked cabinets with strictly controlled access, and digital data is held in a highly secure, access-restricted cloud storage system that complies with industry-leading standards for data protection and encryption.
We take all reasonable steps to keep your personal data protected from accidental loss, disclosure, destruction or misuse, with organisational and technical security measures that are regularly monitored and updated. Our employees are trained on data protection legislation, access is governed by “least privilege” principles, and we have physical controls and CCTV in place on site.
Sharing your personal information
Our intergroup data processing agreement ensures that we can lawfully share your data within our organisation and our parent organisation, but only where it is necessary and for specific purposes. We may also share your information with third parties where required to meet regulatory, contractual or legal obligations — for example, the Care Quality Commission (CQC), the Health and Safety Executive (HSE), or law enforcement authorities when legally required to do so.
We have implemented thorough checks to ensure compliance with data protection legislation, including the UK GDPR and Data Security and Protection Toolkit (DSPT) requirements where necessary. Our processes and systems are subject to continuous review, and we conduct regular audits and staff training to maintain the highest standards of data protection.
Transfers of personal data
Sometimes we need to use systems, software or suppliers located outside the UK. We only do this when necessary, and we make sure your data is protected by safeguards similar to those in the UK — either because the destination country has been granted adequacy status, or because contractual safeguards oblige the recipient to protect your data to the same standard. If you would like more information about the systems or suppliers we use, please get in touch.
Your rights
Under data protection law, you have rights including:
- Right of access — to ask us for copies of your personal information.
- Right to rectification — to ask us to correct information you think is inaccurate or complete information you think is incomplete.
- Right to erasure — to ask us to erase your personal information in certain circumstances.
- Right to restriction of processing — to ask us to restrict processing in certain circumstances.
- Right to object — to object to the processing of your personal information in certain circumstances.
- Right to data portability — to ask that we transfer the information you gave us to another organisation, or to you.
- Right not to be subject to automated decision-making — decisions made without any human involvement.
You are not required to pay any charge for exercising your rights. Adhering to the UK GDPR, we typically respond within one month of receiving a request; for complex or numerous requests, a two-month extension may apply.
Queries & complaints
We would encourage you to contact us directly should you have any questions or wish to raise a complaint. You also have the right to complain to the ICO if you are unhappy with how we use your data: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113. Website: ico.org.uk.
Changes to this privacy notice
We review this privacy notice annually or whenever there are changes to our processing activities or updates in data protection legislation.