Your information

Privacy Policy.

This policy explains how Orchis IV Ltd collects, uses, stores, shares and protects personal information when providing mobile diagnostic and screening services.

Version 1.0, effective 13 July 2026, review date 13 July 2027

1. Who we are and who controls your information

Orchis IV Ltd, company number 16093600, is the data controller for personal information processed for its own services. Our registered office is 167 to 169 Great Portland Street, 5th Floor, London, W1W 5PF. Contact us at joyediran@orchis-iv.co.uk or 07399 177445.

A laboratory, GP, clinic, referrer, payment processor or other provider may be a separate controller for its own activities. Where a supplier processes information only on our instructions, it acts as our processor under an appropriate contract.

2. Information we collect

  • Identity and contact details, including name, date of birth, address, telephone number, email and booking reference
  • Health information, including medical history, symptoms, medicines, allergies, pregnancy status, relevant risks, test requests, samples, results and clinical notes
  • GP, referrer, emergency contact and authorised representative details
  • Booking, payment, invoice, travel zone and service use information
  • Communications, complaints, consent records, safety incidents and audit records
  • Website and device information, including IP address and technical security logs, and cookies only where stated in our Cookie Policy
  • Corporate screening participation details, while preserving individual clinical confidentiality

3. Where information comes from

We may obtain information directly from you, an authorised representative, your GP or referrer, a laboratory, a corporate organiser, a payment provider, our website or records created by Orchis IV while providing the service.

4. Lawful bases for each purpose

Health information is special category data. For every use of health information we need both an Article 6 lawful basis and an Article 9 condition. The table below describes the bases we intend to use. We will document the specific basis before beginning any new purpose.

PurposeInformationArticle 6 basisHealth data condition
Responding to enquiries, arranging and administering a booking, confirming location and taking paymentIdentity, contact, appointment, address and payment detailsContract, Article 6(1)(b). Legal obligation, Article 6(1)(c), where financial records must be keptArticle 9(2)(h), health or social care, with Data Protection Act 2018 Schedule 1 Part 1 condition 2 where appointment details reveal health information
Assessing suitability, obtaining clinical consent and delivering blood collection, diagnostic and screening servicesHealth history, symptoms, medicines, risks, test requests, samples, measurements and clinical notesContract, Article 6(1)(b)Article 9(2)(h), health or social care, with Schedule 1 Part 1 condition 2, processed by or under the responsibility of a health professional subject to confidentiality
Commissioning tests, tracking samples, receiving and reviewing results, explaining factual findings, safety netting and signpostingIdentifiers, specimen information, laboratory reports, clinical review and contact recordsContract, Article 6(1)(b)Article 9(2)(h), health or social care, with Schedule 1 Part 1 condition 2
Responding to a serious emergency or risk to lifeRelevant identity, contact, health, location and emergency contact informationVital interests, Article 6(1)(d), where necessary to protect life; or recognised legitimate interests, Article 6(1)(ea), where its statutory conditions apply to an emergencyArticle 9(2)(c), vital interests, where the person is physically or legally incapable of consenting; or Article 9(2)(h) where necessary for health care
Safeguarding an adult at risk and preventing or reporting serious harmRelevant health, incident, contact and safeguarding informationRecognised legitimate interests, Article 6(1)(ea), where the statutory safeguarding condition applies; or legal obligation, Article 6(1)(c), where a law requires actionArticle 9(2)(g), substantial public interest, with the applicable safeguarding condition in Schedule 1 Part 2; or Article 9(2)(h) for health care
Meeting CQC, professional, incident reporting, tax, court and other legal obligationsOnly information necessary for the particular obligationLegal obligation, Article 6(1)(c)Article 9(2)(h), Article 9(2)(f) for legal claims, or Article 9(2)(g) with the applicable Schedule 1 condition, depending on the obligation
Handling complaints, insurance matters, incidents, legal advice and legal claimsBooking, communication, clinical, incident, payment and complaint recordsLegal obligation, Article 6(1)(c), where applicable; otherwise legitimate interests, Article 6(1)(f), in resolving complaints and protecting legal rightsArticle 9(2)(f), legal claims, or Article 9(2)(h) where the matter concerns management of the health service
Clinical governance, audit, quality improvement and preventing recurrence of incidentsRelevant clinical and operational records, minimised or deidentified where possibleLegitimate interests, Article 6(1)(f), in operating a safe and accountable service; legal obligation, Article 6(1)(c), where requiredArticle 9(2)(h), management of health care, with Schedule 1 Part 1 condition 2
Corporate screening and confidential participant careParticipant identity, booking and health information; anonymous group statistics for the organiserContract, Article 6(1)(b), for the participant service; legitimate interests, Article 6(1)(f), for genuinely anonymous programme reportingArticle 9(2)(h), with Schedule 1 Part 1 condition 2. Anonymous statistics are not personal data where reidentification is not reasonably possible
Website security, fraud prevention and technical troubleshootingIP address, device, access and security logsLegitimate interests, Article 6(1)(f), in securing the website and servicesNo health data is intentionally used for this purpose. If health information becomes necessary for a legal claim, Article 9(2)(f) may apply
Optional email or text marketingName, contact details and recorded marketing preferenceConsent, Article 6(1)(a), together with applicable PECR requirements. Consent may be withdrawn at any timeWe do not use health information for marketing. Any exceptional use would require separate, explicit consent under Article 9(2)(a)

Clinical consent is different from data protection lawful basis. Your voluntary informed consent is required before a clinical procedure. Routine clinical record keeping and safe handling of results are not based solely on data protection consent, because some records must continue to be used or retained for care, safety, accountability or law.

5. How we use information

We use information only where necessary to assess eligibility and clinical suitability, manage bookings and visits, verify identity, obtain informed consent, collect and track samples, commission tests, receive and review results, provide factual explanation and safety netting, contact appropriate services where lawful, process payments and refunds, handle complaints and meet regulatory, professional, insurance, tax and legal requirements.

6. Who we may share information with

Information may be shared on a need to know basis with contracted laboratories, GPs and referrers, couriers, emergency services, safeguarding authorities, regulators, insurers, professional advisers, secure IT and website providers, payment processors and other properly assessed suppliers.

The current booking pathway uses IONOS to host the website and protected booking connector, Cliniko for the appointment diary and patient record, and Stripe for card authorisation and payment. The Orchis IV connector sends Stripe only the information necessary for payment and an opaque booking reference; detailed health notes are not placed in Stripe metadata. Cliniko receives the identity, contact, appointment and service information needed to create and administer the clinical record. Supplier access is governed by contract, security controls and role based access.

For corporate screening, individual results are not routinely disclosed to the employer. Only genuinely anonymous aggregate reporting will be provided unless the participant specifically authorises a lawful individual disclosure or limited disclosure is required by law or to address a serious safety risk.

7. International transfers

Where an approved supplier processes personal information outside the UK, we will use an appropriate UK transfer mechanism and carry out proportionate due diligence. Clinical information will be kept within approved systems wherever reasonably practicable.

8. Security

Safeguards include named staff accounts, role based access, strong authentication, secure transmission of clinical reports, device and password controls, encrypted backups, incident management, confidential disposal, processor due diligence, confidentiality obligations, training and audit. The Orchis IV Results Hub uses an unguessable private link plus a separate single use code sent to the client’s registered email address. The code expires after ten minutes, authenticated sessions time out, uploaded reports are encrypted at rest and access to records and documents is logged. Uploaded documents remain unavailable to the client until an authorised practitioner deliberately releases them. Contact attempts, document releases and completion actions are recorded. Date of birth is not used as a portal password. No system can be guaranteed completely secure, but we apply controls proportionate to the sensitivity and risk.

9. How long we keep information

Clinical and complaint records will normally be retained for eight years after the end of care or closure, unless a longer or shorter period is justified by law, professional guidance, litigation, safeguarding, insurance or the nature of the record. Financial records are retained in line with tax and company law requirements. Marketing preference records are kept while necessary to respect the preference and demonstrate compliance.

10. Your rights

Depending on the lawful basis and circumstances, you may have rights to access, correction, erasure, restriction, objection and data portability. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Some rights are limited where information must be retained for clinical safety, legal obligations, public interest, legal claims or another lawful reason.

Send a request to joyediran@orchis-iv.co.uk. We may need to verify your identity. We will respond within the applicable legal timeframe and explain any lawful restriction or extension.

11. Data breaches

Suspected breaches will be contained, risk assessed, recorded and investigated. We will notify the Information Commissioner’s Office and affected individuals where the legal thresholds are met and will implement corrective action.

12. Automated decisions, children and marketing

We do not use solely automated decision making that produces legal or similarly significant effects in relation to clinical care. Clinical escalation decisions are reviewed by an appropriately qualified person.

Services are currently provided only to adults aged 18 and over. Marketing permission is optional, kept separate from clinical consent and may be withdrawn at any time. Refusal does not affect access to services.

13. Complaints and changes

Contact the Registered Manager using the details above. You may also complain to the Information Commissioner’s Office. We will update this policy when our purposes, technology, suppliers or legal obligations change and communicate material changes where appropriate.