Privacy Statement (UK)
Last updated: 22nd December 2024.
In this privacy statement, we explain what we do with the data we obtain about you via https://www.wearewell.org.uk. We recommend you carefully read this statement. In our processing, we comply with the requirements of privacy legislation.
That means, among other things, that:
- we clearly state the purposes for which we process personal data. We do this by means of this privacy statement;
- we aim to limit our collection of personal data to only the personal data required for legitimate purposes;
- we first request your explicit consent to process your personal data in cases requiring your consent;
- we take appropriate security measures to protect your personal data and also require this from parties that process personal data on our behalf;
- we respect your right to access your personal data or have it corrected or deleted, at your request.
If you have any questions or want to know exactly what data we keep of you, please contact us.
- WHO IS THE DATA CONTROLLER?
Organization name: SW Healthcare Services Ltd
Organization business address: 38 Kenilworth Close, Redditch, Worcestershire, B97 5JX
United Kingdom
Website: https://www.wearewell.org.uk
Email: team@wearewell.org.uk
Phone number: 01905969843
- HOW DO WE COLLECT YOUR DATA?
We collect and process your data via one of the following ways:
-Data you directly provide to us
When you fill out inquiry forms on our website, when you place an order, and when you make a payment, you voluntarily and directly provide your personal data to us.
-Data we automatically collect about you
When you visit and browse our website, content, and services, we use cookies and similar technologies to automatically collect data about you such as how you browse our website, what content you click, your IP address, and your device information.
- WHAT PERSONAL DATA DO WE COLLECT ABOUT YOU?
- Basic details and contact information
A first and last name
A home or other physical address, including street name and name of a city or town
An email address
A telephone number
Date of birth
- Financial information
Financial information such as bank account number or credit card number
- Technical information
-IP Address
-Device information such as device name, device model, screen resolution, operating system, network information
-Information about how the referral page
-You geolocation when you access and use our website and services
- Analytics information
Information about how you browse through our website, content, and services such as content you interact with, your clicks, your purchases, data you submit, time you spend on each page.
- Account related information
Photos
Social Media accounts
A signature
- Health data
Your physical characteristic
Your health information such as your height, weight, your BMI score
Your medical history
Your dietary habits
Your health Insurance information
Whether you are pregnant, breastfeeding, or trying to conceive
Whether you have a pre-existing medical condition such as diabetes or blood pressure
Whether you have allergic reaction to certain substances
- Sensitive data about your nationality, your marital status
We ask for your passport, driving license, or ID card to confirm that you are based in the UK.
- FOR WHAT PURPOSES DO WE COLLECT AND PROCESS YOUR DATA?
We collect and process your data for the following purposes:
-To provide you with our core services of assessing your eligibility for our product and prescribing the product
-To dispatch and deliver the ordered products to your address
-To process payments
-To verify your identity
-To share your data with our clinicians so that they can assess your eligibility and prescribe the product to you
-To share your data with your GP
-To comply with our legal obligations
-To ensure and maintain the security of our website and platform
-To analyze user behavior on our website
-To offer personalized products to you
-To improve our website, product, content and services
To protect our rights and those of third parties
To send you marketing emails and newsletters
- LEGAL BASIS FOR THE COLLECTION AND PROCESSING OF YOUR DATA
We rely on the following legal bases to collect and process your personal data:
Purpose of data collection and processing | The legal basis we rely on under the UK GDPR |
-To provide you with our core services of assessing your eligibility for our product and prescribing the product | Contractual necessity under article 6.1.b of the UK GDPR Explicit consent under article 9.2.a of the GDPR |
-To dispatch and deliver the ordered products to your address | Contractual necessity under article 6.1.b of the UK GDPR |
-To process payments | Contractual necessity under article 6.1.b of the UK GDPR |
-To verify your identity | Contractual necessity under article 6.1.b of the UK GDPR |
-To share your data with our clinicians so that they can assess your eligibility and prescribe the product to you | Contractual necessity under article 6.1.b of the UK GDPR Explicit consent under article 9.2.a of the GDPR |
-To share your data with your GP | Legitimate Interests under Article 6.1.f of the UK GDPR Explicit consent under article 9.2.a of the GDPR |
-To comply with our legal obligations | To comply with our legal obligation under article 6.1.c of the UK GDPR |
-To ensure and maintain the security of our website and platform | Legitimate interests under article 6.1.f of the UK GPDR |
To protect our rights and those of third parties | Legitimate interests under article 6.1.f of the UK GPDR |
-To analyze user behavior on our website | Consent under article 6.1.a of the UK GDPR |
-To offer personalized products to you | Consent under article 6.1.a of the UK GDPR |
-To improve our website, product, content and services | Consent under article 6.1.a of the UK GDPR |
To send you marketing emails and newsletters | Soft opt-in under the PECR and legitimate interests under article 6.1.f of the UK GDPR |
- SHARING YOUR DATA WITH CLINICIANS
We share your submitted health data with our third-party service provider clinician so that he/she can prescribe you the product you ordered.
We share the following categories of health data you submitted with the third-party clinician:
Your physical characteristic
Your health information such as your height, weight, your BMI score
Your medical history
Your dietary habits
Your health Insurance information
Whether you are pregnant, breastfeeding, or trying to conceive
Whether you have a pre-existing medical condition such as diabetes or blood pressure
Whether you have an allergic reaction to certain substances
We rely on “Contractual Necessity” legal ground to share your data with third-party clinicians so that we can assess your eligibility for the product and prescribe the product to you.
We share this data only for the purposes of providing our services to you.
- SHARING YOUR DATA WITH GP
We share the following categories of health data you submitted with your GP:
Your physical characteristic
Your health information such as your height, weight, your BMI score
Your medical history
Your dietary habits
Your health Insurance information
Whether you are pregnant, breastfeeding, or trying to conceive
Whether you have a pre-existing medical condition such as diabetes or blood pressure
Whether you have allergic reaction to certain substances
We rely on “Legitimate Interests” legal ground to share your data with your GP so that your GP will have access to the types of medicines you are taking and will be able to take this into account.
We share this data only for the purposes of protecting your health.
- DISCLOSURE OF YOUR DATA WITH THIRD PARTIES
We disclose personal information if we are required by law or by a court order, in response to a law enforcement agency, to the extent permitted under other provisions of law, to provide information, or for an investigation on a matter related to public safety.
If our website or organization is taken over, sold, or involved in a merger or acquisition, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.
We have concluded a data processing agreement with Google.
- INTERNATIONAL DATA TRANSFERS
When we transfer your personal data abroad to a inadequate country, we rely on one of the transfer mechanisms described under Article 46 of the UK GDPR.
- DATA SECURITY
We are committed to the security of personal data. We take appropriate security measures to limit abuse of and unauthorised access to personal data. This ensures that only the necessary persons have access to your data, that access to the data is protected, and that our security measures are regularly reviewed.
- DATA RETENTION
We retain your data for as long as necessary for the purpose for which it is collected.
When determining the specific data retention period, we take into account the statutory retention periods, sensitivity of data, your reasonable expectations, and our legitimate interests.
We retain your submitted data for 12 months from the date on which you submit it.
You can contact us to find out about the applicable retention periods for each specific data category.
- YOUR RIGHTS
You have the following rights in relation to your personal data:
- You have the right to know why your personal data is needed, what will happen to it, and how long it will be retained.
- Right of access: You have the right to access your personal data that is known to us.
- Right to rectification: you have the right to supplement, correct, delete, or block your personal data whenever you wish.
- If you give us your consent to process your data, you have the right to revoke that consent and to have your personal data deleted.
- Right to transfer your data: you have the right to request all your personal data from the controller and transfer it in its entirety to another controller.
- Right to object: you may object to the processing of your data. We comply with this unless there are justified grounds for processing.
- Right to deletion: You have the right to request that we delete your data.
Please make sure to always clearly state who you are, so that we can be certain that we do not modify or delete any data of the wrong person.
- HOW TO EXERCISE YOUR RIGHTS
To exercise your rights described above, you can contact us via one of the following methods:
By post: SW Healthcare Services 38 Kenilworth Close, Redditch, Worcestershire, B97 5JX
United Kingdom
By email: team@wearewell.org.uk
- HOW TO FILE A COMPLAINT WITH THE UK DATA PROTECTION AUTHORITY
If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Information Commissioner’s Office:
The ICO’s contact details can be found on their website at https://ico.org.uk.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
Jersey Office of The Information Commissioner
2nd Floor 5 Castle Street
St. Helier
Jersey
JE2 3BT
St Martin’s House
Le Bordage
St. Peter Port
Guernsey
GY1 1BR
- AMENDMENTS TO THIS PRIVACY POLICY
We reserve the right to make amendments to this privacy statement. It is recommended that you consult this privacy statement regularly in order to be aware of any changes. In addition, we will actively inform you wherever possible.
- THIRD-PARTY WEBSITES
This privacy statement does not apply to third-party websites connected by links on our website. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner. We recommend you read the privacy statements of these websites prior to making use of these websites.
- DATA PROTECTION OFFICER
Our Data Protection Officer has been registered with the Information Commissioner’s Office. If you have any questions or requests with respect to this privacy statement or for the Data Protection Officer, you may contact Claire Goodall, or via claire.goodall5@nhs.net.
- CHILDREN
Our website is not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us.
- CATEGORIES OF THIRD-PARTY DATA PROCESSORS
In processing your data, we use the following categories of service providers:
-Payment processors to process payments
-Cloud service providers to store your data
-Email marketing tools to manage our email marketing activities
-User authentication service providers to verify your ID
- NOTICE ABOUT STRIPE
We use Stripe to process your payment.
Stripe may use a variety of additional data about you such as the time and date of your purchase, your card information, and your bank details.
To learn more about how Stripe collects and processes your data, visit the Stripe’s privacy policy at:
- HOW TO CONTACT US
SW Healthcare Services
38 Kenilworth Close, Redditch, Worcestershire, B97 5JX
United Kingdom
Website: https://www.wearewell.org.uk
Email: team@wearewell.org.uk
Phone number: 01905969843