Privacy Policy

Effective Date: 28th January 2025


Table of Contents

1.          Introduction

2.          Information We Collect

3.          How We Use Your Information

4.          Legal Basis for Processing

5.          Obtaining Explicit Consent

6.          Child Safety

7.          Data Sharing

8.          Data Security

9.          Data Retention

10.        Your Rights

11.        Contact Us

12.        ICO Registration

13.        Changes to This Policy

14.        Additional Information

1. Introduction

Med Automation Ltd (“we”, “our”, “us”) is dedicated to protecting and respecting your privacy. This Privacy Policy outlines how we collect, use, and safeguard your personal data when you use our AI voice solutions, appointment management services, and interact with our website, in partnership with both public and private sector clients, including but not limited to the NHS, in accordance with the UK General Data Protection Regulation (UK GDPR).

Scope: This policy applies to all users of our services and website, including patients, healthcare providers, and clients in both the public and private sectors.

Contact Information: If you have any questions or concerns about your privacy, please contact our Data Protection Officer using the details provided in the Contact Us section below.

2. Information We Collect

To provide our appointment management services (“our services”), we collect and store the following personal information:

1. Personal Identification Information

2. Appointment Details

3. Communication Data

4. Website Contact Information

If you choose to be contacted via our website, we collect:

5. Technical Data

3. How We Use Your Information

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

1. Performance of Contract

2. Legitimate Interests

Our legitimate interests include enhancing our services to better serve you and ensuring efficient operation of our business. We ensure that these interests are balanced against your privacy rights.

3. Consent

4. Legal Basis for Processing

We process your personal data based on the following legal bases under the UK GDPR:

1. General Data Processing

2. Special Category Data Processing

For processing special category data (e.g., health information) related to appointment bookings, we rely on:

5. Obtaining Explicit Consent

We may request explicit consent verbally, including via our voice-based system. To ensure compliance, we follow these steps:

1. Clear Information

2. Affirmative Action

3. Recording Consent

4. Withdrawal of Consent

5. Accessibility

6. Child Safety

Protecting the safety of children is important to us. Our services are intended for use only by individuals who are at least 18 years of age. By using our Services, you confirm that you meet this requirement.

For Users Under 18:

Reporting Unauthorized Use:

If you believe that a child under 18 is using our appointment management services and providing personal data without parental or guardian consent, please contact our Data Protection Officer at [email protected]. We will promptly investigate and remove or delete the unauthorized data as necessary.

7. Data Sharing

We may share your personal data with the following categories of third parties:

1. Service Providers and Business Partners

2. Healthcare Providers

3. Public and Private Sector Clients

4. Legal Authorities

5. Affiliates and Subsidiaries

6. International Transfers

Conditions for Data Sharing:

8. Data Security

We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it from unauthorized access, alteration, disclosure, or destruction. These measures include:

1. Technical Measures

2. Organizational Measures

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to comply with legal, regulatory, and reporting requirements. Our data retention periods are as follows:

1. Personal Identification Information and Appointment Details

2. Call Recordings

3. Website Contact Information

4. Technical Data

Data Deletion:

Once the retention period has expired, your data is securely deleted or anonymized to prevent any unauthorized access or use.

10. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

1. Right to Access

2. Right to Rectification

3. Right to Erasure (Right to be Forgotten)

4. Right to Restrict Processing

5. Right to Object

6. Right to Data Portability

7. Rights Related to Automated Decision-Making and Profiling

Exercising Your Rights:

To exercise any of these rights, please contact our Data Protection Officer using the details provided in the Contact Us section below. We will respond to your request within the statutory time frame as required by the UK GDPR.

11. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact our Data Protection Officer:

12. ICO Registration

We are registered with the Information Commissioner’s Office (ICO) under registration reference: ZB645385. You can verify our registration and find more information on the ICO website.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page, and where appropriate, we will notify you via email or through our website’s notification system.

Effective Date: 28th January 2025

14. Additional Information

a. Cookie Policy

We use cookies and similar tracking technologies to enhance your experience on our website. For detailed information about the types of cookies we use, their purposes, and how you can manage your preferences, please refer to our Cookie Policy.

b. Automated Decision-Making

Our AI voice solutions may involve automated decision-making or profiling to improve service delivery. If you are subject to such processes, you have the rights outlined in the Your Rights section to obtain human intervention, express your point of view, and contest the decision.

c. Third-Party Integrations

We integrate with third-party services and platforms to enhance our service offerings. These integrations are carefully selected to ensure they adhere to strict data protection standards. For more information about our third-party partners and their data handling practices, please contact us directly.

d. User Consent for Marketing

We respect your preferences regarding marketing communications. You can opt-in or opt-out of receiving marketing emails at any time by contacting us directly through the Contact Us section.

e. Accessibility and Language

We strive to make our Privacy Policy accessible to all users, including those with disabilities. The policy is written in clear and straightforward language to ensure that everyone can understand how their data is handled. If you require the information in an alternative format, please contact us, and we will accommodate your request.

© OTUA 2025. All Rights Reserved.