This Privacy Notice explains how iBox Healthcare Limited collects, uses, stores, and protects personal data. It is designed to help you understand what data we process, why we process it, and what your legal rights are.
iBox Healthcare Limited takes its responsibilities under data protection legislation very seriously. If there is anything in this notice you do not understand, or if you have any questions, please contact us using the details provided at the end of this notice.
This Privacy Notice covers our activities:
We are iBox Healthcare Limited , a private limited company registered in England and Wales.
Throughout this notice, iBox Healthcare Limited may be referred to as “we”, “us”, or “our”.
We only collect and process personal data where it is necessary to deliver our legitimate business services.
| Data subjects: | Categories of Personal Data: |
|---|---|
| Our staff, including temporary or agency staff | Name, address, telephone number, email address, employment and education history, occupational health information, limited financial information |
| Customers, prospective customers, and suppliers | Name, organisation, job title, address, telephone number, email address |
| Visitors to and users of our websites | Technical data such as IP address, browser type, device information, and website usage data |
In the course of providing software and technical support services to our healthcare customers (including NHS organisations), our staff may incidentally view patient data , for example when:
Where this occurs:
We do not use patient data for our own purposes.
We process personal data for the following purposes:
Under UK GDPR, we rely on the following lawful bases:
Special category data (such as health data) is processed only where permitted by law and subject to appropriate safeguards.
We may share personal data:
All third parties are subject to appropriate contractual, confidentiality, and security obligations.
In the event of a business sale, merger, or reorganisation, personal data may be transferred, but appropriate safeguards will be applied to protect your rights.
Our systems and infrastructure are hosted using secure cloud and hosting providers, including:
Data is stored in accordance with UK GDPR security requirements and industry best practices.
We retain personal data only for as long as necessary for the purposes for which it was collected.
| Data subjects: | Retention Period: |
|---|---|
| Staff and contractors | For the duration of employment/engagement and for a legally required period afterwards |
| Customers, prospective customers, and suppliers | For as long as the business relationship exists and where necessary thereafter |
| Website users | In accordance with operational and analytical needs |
Under UK data protection law, you have the following rights:
You can request a copy of the personal data we hold about you.
You can request correction of inaccurate or incomplete data.
You may object to certain types of processing, particularly where we rely on legitimate interests.
You may request that data you provided to us is transferred to you or another organisation in a machine-readable format.
If you are unhappy with how we handle your data, please contact us first so we can investigate. You also have the right to complain to the Information Commissioner’s Office (ICO) :
If you have any questions about this Privacy Notice or wish to exercise your rights, please contact us: