1. Introduction
Amvale Medical Transport Ltd. (“we,” “our,” “us”) is committed to safeguarding your personal information in compliance with the General Data Protection Regulation (GDPR). This privacy policy outlines how we collect, use, and protect personal data provided by users of our website and services. We aim to provide clarity and transparency regarding your privacy rights and our data processing practices.
2. Data Controller and Data Protection Officer
Amvale Medical Transport Ltd. is the data controller for the purposes of GDPR. If you have any questions regarding our privacy practices or if you wish to exercise your rights, you may contact our Data Protection Officer (DPO) at:
Data Protection Officer
Chris Albert
The Privacy Worx, Linden House, Linden Close
Tunbridge Wells
TN4 8HH
0203 343 9043
07667345081
3. Types of Data Collected
-
- Personal Identification Information: We collect personal data such as names, addresses, phone numbers, email addresses, and other contact details when you communicate with us or use our services.
-
- Health and Medical Information: In some cases, we may need to collect sensitive health data to provide medical transport services. This information is handled with strict confidentiality and is only processed to provide the service requested.
-
- Payment Information: When a user is redirected to a third-party payment processor such as Stripe, any payment details provided fall under Stripe’s GDPR-compliant policy.
-
- Cookies and Usage Data: We use essential cookies that are necessary for the operation of the website. These cookies collect usage information (e.g., IP address, browser type, pages visited, and time spent on the site) to optimize user experience. We do not collect any personally identifiable information through non-essential tracking or third-party marketing cookies.
4. How We Collect Data
-
- Direct Interactions: You may provide personal data by filling in forms, corresponding with us via email, phone, or using our website’s contact forms.
-
- Automated Technologies: As you interact with our site, we may automatically collect technical data about your equipment, browsing actions, and patterns. We collect this data through server logs and essential cookies.
5. Lawful Basis for Processing Data
We process personal data in accordance with GDPR Article 6, based on the following legal grounds:
-
- Performance of a Contract: To fulfill the services requested, such as medical transport.
-
- Legal Obligations: To comply with legal or regulatory requirements, particularly those relating to the medical and transport industry.
-
- Legitimate Interests: To improve our services and safeguard our operations, provided that your fundamental rights are not overridden.
6. Special Categories of Data
In some cases, we may process health-related data as required for medical transport services. This is done in accordance with GDPR Article 9(2)(h) – for the purposes of providing health care or management services. We ensure that special category data is only shared with authorized personnel and protected by additional security measures.
7. Data Storage and Security Measures
We take the security of your personal data very seriously. We implement robust technical and organizational measures to ensure your information is protected against unauthorized access, disclosure, or misuse, including:
-
- Encryption: All data, including emails and user interactions, is stored on secure servers with encryption protocols.
-
- Restricted Access: Only authorized staff can access personal and sensitive data, with access controls in place.
-
- Data Backups: Regular backups are performed to prevent data loss.
Personal data is stored for as long as necessary to provide the service, comply with legal obligations, or fulfill our legitimate interests. Medical records or transport details may be retained for an extended period where legally required.
8. Data Sharing and Third-Party Services
We do not sell or share your personal data with third parties for marketing purposes. However, your data may be shared with trusted third parties to facilitate our services, including:
-
- Feedback Collection: For user feedback, our website may redirect users to JotForm. JotForm’s GDPR-compliant privacy policy governs the handling of data submitted through this platform, ensuring secure collection and processing of feedback.
- Secure Communication: For certain communications, users may also be redirected to use a secure email program of their choice. This practice helps us maintain GDPR compliance by allowing users to choose an email provider they trust, enhancing data security.
- Payment Processing: We redirect users to Stripe for secure payment processing. Stripe’s privacy policy governs the handling of your payment details.
- Service Providers: We may engage third-party service providers for IT support, hosting, or other essential services. These parties are bound by confidentiality agreements and GDPR compliance requirements.
All third parties we work with are carefully vetted to ensure they comply with GDPR.
9. International Data Transfers
If we need to transfer your personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect your information. This includes using Standard Contractual Clauses approved by the European Commission, or ensuring third parties have Privacy Shield certification (for US-based entities).
10. Your Data Rights
As a data subject, you have several rights under GDPR, including:
-
- Right to Access: You can request access to the personal data we hold about you.
-
- Right to Rectification: You can request correction of any inaccurate or incomplete data.
-
- Right to Erasure (“Right to be Forgotten”): You can request the deletion of your data in certain circumstances, provided that the data is no longer necessary for the purpose it was collected.
-
- Right to Restrict Processing: You can request that we suspend processing your data.
-
- Right to Data Portability: You can request that your personal data be transferred to another service provider in a machine-readable format.
-
- Right to Object: You can object to the processing of your data for certain purposes.
To exercise these rights, please contact us at the details provided above. We aim to respond to all legitimate requests within one month.
11. Cookies and Tracking Technologies
Our website uses cookies to ensure that we provide you with the best user experience. By using our website, you consent to the use of essential cookies. These include:
-
- Session Cookies: Necessary for site functionality.
-
- Analytical Cookies: Used to collect anonymized data on website usage, such as visitor numbers and traffic sources. No personally identifiable information is captured.
Anonymization of Data and Cookies
To ensure compliance with GDPR, we employ techniques to anonymize the data and cookies collected from users. This means that personal identifiers, such as IP addresses, are processed in a way that prevents them from being linked to an individual. For example, IP anonymization is implemented, where the last part of the IP address is removed before storage. We also use functional cookies, which do not contain any personally identifiable information, ensuring that user privacy is fully maintained.
We do not use third-party or advertising cookies. For more information, visit our Cookie Policy page.
12. Changes to This Privacy Policy
We reserve the right to update this privacy policy as required by law or business changes. We recommend reviewing this page periodically to stay informed about how we handle your data.
13. Contact Information
If you have any questions, concerns, or complaints about how we handle your data, please contact us:
Data Protection Officer
Mr Simon Hudson
Amvale Medical Transport Ltd.
Birkdale Rd, Scunthorpe DN17 2A
[email protected]
01724 874 999