Total Billing Solutions Limited trading as Enhanced Technology

PRIVACY POLICY IN RELATION TO GP PROFIT RECOVERY

 

IMPORTANT INFORMATION AND WHO WE ARE

 

This Privacy Policy applies to our GP Profit Recovery service line.  It is issued on behalf of Total Billing Solutions Limited, trading as Enhanced Technology (“Enhanced Technology”).  Total Billing Solutions Limited is a limited liability company registered in Jersey with company number 95710 and having its registered office at Notre Reve, La Route De Noirmont, St. Brelade, JE3 8AJ, Jersey.  We will be referred to as “Enhance Technology”, “we”, “us” or “our” in this Privacy Policy.

 

Enhanced Technology respects your privacy and is committed to protecting your personal data. This Privacy Policy will inform you how we look after your personal data (including personal data in respect of individuals who are clients, suppliers, customers of our clients or other third parties or any individual connected to those parties) through your use of our website or where you provide personal data when purchasing a product or service or sign up to our marketing materials.  

 

This Privacy Policy also summarises the key points about how we collect use, disclose, transfer and store your personal data, sets out your privacy rights and explains how the law protects you.

 

We will be either a data controller or a data processor and during our interactions with you, we will let you know in what capacity we are handling your data.  Further details can be found in our terms of business or contract for services.  

 

If you use another service such as GP Billing, Medibooks or ITrackIT/IStoreIT, the way we handle and use data will differ so please refer to the appropriate Privacy Policy for that service line.

 

Should you have any questions on the content of this Privacy Policy or how we use your data, please contact our Data Protection Officer by email on: nathan.wright@enhancedtechnology.co.uk.

 

CHANGES TO THE PRIVACY POLICY AND YOUR DUTY TO INFORM US OF CHANGES

 

This version of our Privacy Policy was updated in February 2024. Historic versions can be obtained by contacting us.  We may update our Privacy Policy from time to time.  The latest version of our Privacy Policy will be made available on our website (or is available on request) and it is your responsibility to regularly check for updates.

 

It is important that we hold accurate and up to date personal data about you. Please keep us informed of any changes to your personal data.

OUR ROLE AS DATA PROCESSOR OR DATA CONTROLLER

We may be either a data controller and/or a data processor, depending on the nature of our relationship with you.

 

·  A data controller is an organisation or person who determines how and why your personal data will be processed (used).

 

·  A data processor is an organisation or person which processes personal data on behalf of the controller.


 

Service Line

 

Data Controller or Data Processor

 

Context / What we do

Further Information 

GP Profit Recovery

Data Controller

 

 

We interact with you on our website, social media, marketing literature or email correspondence.

We have a relationship with you where you are a shareholder, officer, employee, consultant, contractor or job applicant of Enhance Technology.

We have a relationship with you where you are a supplier or tother third party who supplies goods or services to us.

 

We interact with doctors, hospitals, practices and trusts to enter into a contractual relationship to provide GP Profit Recovery services.

 

We will be the data controller and we will process your personal data in accordance with this Privacy Policy.

If you are a doctor, hospital, practice or trust, we are the data controller in respect of your (the doctors, hospital, practice or trust’s) data or data of your employees or other third parties connected to you which shared by virtue of our contractual relationship.  But where patient data is shared by you under the provision of the GP Profit Recovery services, we are acting as Data Processor.

 

Data Processor

 

We provide GP Profit Recovery services.

We will be a data processor where we provide our services to doctors, hospitals, practices or trusts.  We will enter into a contract for services with them and as part of terms of that contract the doctors, hospitals, practices or trusts, as data controller, may disclose personal data relating to their patients to us.  We will process that personal data on the controller’s behalf, acting in accordance with their instructions. 

This processing allows your doctor, hospital, practice or trust to accurately bill you for any non-NHS services that you have used.  Your doctor, hospital, practice or trust will be able to provide you more details on what these services may include.

You should contact the data controller and review the data controller’s privacy policy for information in relation to how your personal data will be processed.

 


THE TYPES OF PERSONAL DATA WE COLLECT

Personal data means any information from which you can identify an individual.  

 

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

 

Identity data: includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth, age, gender and geographical location.

 

Contact data: includes postal address, email address, and telephone numbers.

 

Financial data: includes bank account and payment card details in so far as they relate to the services you use at your doctor, hospital, practice or trust.

 

Transaction data: includes details about payments to and from you, bank account details and other details of products and services you have purchased from us.

 

Marketing and Communication Data: includes your preference in receiving marketing from us and our third parties and your communication preferences.

 

Employment Data: includes your employers name, address, job title and work Contact Data.

 

NHS number: where we are providing services to doctors, hospitals, practices or trusts, this will refer to the NHS number of the doctor, hospital, practice or trust’s patients.

 

Technical data: IP address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.

 

Profile data: username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.

 

Usage data: information about how you use our website, products and services.

 

We also collect, use and share aggregated data such as statistical or demographic data which is not personal data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals' Usage Data to calculate the percentage of users accessing a specific website feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering.

 

Special category data

 

This includes information about your race or ethnicity, religious or philosophical beliefs, information relating to your sex life or sexual orientation, political opinions, trade union memberships, genetic or biometric information, information relating to your health and/or information relating to a criminal record or alleged criminal activity.  

 

We don’t routinely ask for this information but we may have access to special category data where you, or a third party, discloses this to us.

 

HOW YOUR PERSONAL DATA IS COLLECTED

We will collect your personal data from a number of sources as follows:

 

Your interactions with us: You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise.

 

This includes personal data you provide when you:

·  apply for our products or services;

·  apply for a job;

·  provide us with products or services;

·  create an account on our website;

·  subscribe to our service or publications;

·  request marketing to be sent to you; or

·  give us feedback or contact us.

Automated technologies or interactions: As you interact with our website or our software, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies.  Please see the section on cookies for further details.

 

Third parties or publicly available sources. We will receive personal data about you from various third parties and public sources as set out below:

·  your doctor, hospital, practice or trust;

·  government, tax and regulatory authorities;

·  social media accounts where you interact with us online.

Technical Data may be collected from analytics providers and search information providers.

 

Identity and Contact Data is collected from publicly available sources such as social media, Companies House and the Electoral Register.

 

If you provide us with the personal data of another third party, you must warrant that you have that party’s consent and that you have provided them with a copy of this Privacy Policy.

LEGAL BASIS FOR PROCESSING

We collect and process personal data only when we have a legal basis for doing so.  We rely on a number of legal bases to collect and process the personal data as set out below.

Service Line

 

Data Controller or Data Processor

 

Legal Basis for Processing

GP Profit Recovery

Data Processor

 

 

Your doctor, hospital, practice or trust is the data controller and we are the processor, meaning that our legal basis for processing your information Public interest: It is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, in this case, your doctor, hospital, practice or trust.

 

 

Data Controller

 

Legitimate business interest:We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience.  We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).

 

Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.

Legal and regulatory compliance: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.

Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to our marketing mailshot.

 

IF YOU FAIL TO PROVIDE PERSONAL DATA

Where we need to collect personal data by law or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you and, in this case, we may be unable to act for you and provide you with our services but we will notify you if this is the case at the time.

HOW WE USE PERSONAL DATA

We will only use your personal data for the purpose for which we collected it which includes the following to:

·  register you as a new customer;

·  process and deliver your order;

·  provide services to you;

·  allow you to provide services to us;

·  manage your relationship with us;

·  improve our website, products/services, marketing or customer relationships;

·  recommend products or services which may be of interest to you; and

·  employ or engage you as an officer, employee, consultant or contractor.

WHO WE SHARE PERSONAL DATA WITH

Where we provide our services to doctors, hospitals, practices or trusts, the doctors, hospitals, practices or trusts, as data controller, will share your personal data with us and we will process that data before sharing that personal data back to the doctors, hospitals, practices or trusts.

We may share your personal data where necessary with the parties set out below:

·  internal third parties such as shareholders, officers, employees, consultants or contractors;

·  external third parties such as the government, regulatory or tax authorities;

·  third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Policy.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

If you follow hyperlinks from our website to another website, please note that we are not responsible for and have no control over their privacy policies and practices.

TRANSFERRING DATA OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)

We do not transfer your personal data outside of Jersey or the United Kingdom.

HOW WE KEEP YOUR PERSONAL DATA SECURE

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

 

 

DATA RETENTION

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.  We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) after they cease being customers for tax purposes.  If you would like further information on retention periods please contact our Data Protection Officer on nathan.wright@enhancedtechnology.co.uk for further information.

In some circumstances you can ask us to delete your data: see the Your Rights below section for further information.

YOUR RIGHTS

Individuals have certain rights in respect of their own personal data which are set out below:

The right to be informed

 

This emphasises the need for transparency over how we use your personal data, this will be done typically through a privacy policy at the time your data is obtained.

 

The right of access

 

You have the right to obtain confirmation that your data is being processed and to request access to your personal data which is held by us.

 

The right to rectification

 

You are entitled to have personal data corrected if it is inaccurate or incomplete.

 

The right to erasure

 

The right to erasure is also known as ‘the right to be forgotten’. This enables you to request that we delete or remove your personal data where there is no compelling reason for its continued processing.

 

The right to restrict processing

 

You have the right to block or supress processing of personal data where there is no compelling reason for the processing. When processing is restricted the organisation will be permitted to store the personal data, but not further process it, and will retain just enough data about you to ensure that the restriction is respected in future.

 

The right to data portability

 

You have the right to obtain and reuse your personal data for your own purpose across different services. It allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability.

 

The right to object

 

You have the right to object to processing based on legitimate interests or the performance of a task in the public interest/exercises of official authority, direct marketing (including profiling) and processing for purposes of scientific/historical research and statistics.

 

Withdrawing consent

 

We don’t typically rely on consent as a lawful basis for processing your data but where we do you have the right to withdraw your consent.

 

COOKIE POLICY

A cookie is a small file, stored on a user’s hard drive by a website. Its purpose is to collect data relating to the user’s browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We use the following types of cookies on our website:

Functional cookies

Functional cookies are used to remember the selections you make on our website so that your selections are saved for your next visits.

Analytical cookies

Analytical cookies allow us to improve the design and functionality of our website by collecting data on how you access our website, for example data on the content you access, how long you stay on our website etc.

Targeting cookies

Targeting cookies collect data on how you use the website and your preferences. This allows us to personalise the information you see on our website for you.

Third-Party Cookies

Third-party cookies are created by a website other than ours. We may use third-party cookies to monitor user preferences to tailor advertisements around their interests.

THIRD PARTY LINKS

 

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

CONTACT US AND COMPLAINTS

If you have any queries, require further information or wish to exercise any of the rights set out in this Privacy Policy, please contact our Data Protection Officer on nathan.wright@enhancedtechnology.co.uk.

We are registered with the office of the information commissioner in Jersey. You have the right to make a complaint at any time to the relevant data protection authority in the jurisdiction in which the services are being provided to you. We would, however, appreciate the chance to deal with your concerns before you approach the data protection authority so please contact us in the first instance.