Privacy Policy.
This policy explains how Orchis IV Ltd collects, uses, stores, shares and protects personal information when providing mobile diagnostic and screening services.
1. Who we are and who controls your information
Orchis IV Ltd, company number 16093600, is the data controller for personal information processed for its own services. Our registered office is 167 to 169 Great Portland Street, 5th Floor, London, W1W 5PF. Contact us at joyediran@orchis-iv.co.uk or 07399 177445.
A laboratory, GP, clinic, referrer, payment processor or other provider may be a separate controller for its own activities. Where a supplier processes information only on our instructions, it acts as our processor under an appropriate contract.
2. Information we collect
- Identity and contact details, including name, date of birth, address, telephone number, email and booking reference
- Health information, including medical history, symptoms, medicines, allergies, pregnancy status, relevant risks, test requests, samples, results and clinical notes
- GP, referrer, emergency contact and authorised representative details
- Booking, payment, invoice, travel zone and service use information
- Communications, complaints, consent records, safety incidents and audit records
- Website and device information, including IP address and technical security logs, and cookies only where stated in our Cookie Policy
- Corporate screening participation details, while preserving individual clinical confidentiality
3. Where information comes from
We may obtain information directly from you, an authorised representative, your GP or referrer, a laboratory, a corporate organiser, a payment provider, our website or records created by Orchis IV while providing the service.
4. Lawful bases for each purpose
Health information is special category data. For every use of health information we need both an Article 6 lawful basis and an Article 9 condition. The table below describes the bases we intend to use. We will document the specific basis before beginning any new purpose.
| Purpose | Information | Article 6 basis | Health data condition |
|---|---|---|---|
| Responding to enquiries, arranging and administering a booking, confirming location and taking payment | Identity, contact, appointment, address and payment details | Contract, Article 6(1)(b). Legal obligation, Article 6(1)(c), where financial records must be kept | Article 9(2)(h), health or social care, with Data Protection Act 2018 Schedule 1 Part 1 condition 2 where appointment details reveal health information |
| Assessing suitability, obtaining clinical consent and delivering blood collection, diagnostic and screening services | Health history, symptoms, medicines, risks, test requests, samples, measurements and clinical notes | Contract, Article 6(1)(b) | Article 9(2)(h), health or social care, with Schedule 1 Part 1 condition 2, processed by or under the responsibility of a health professional subject to confidentiality |
| Commissioning tests, tracking samples, receiving and reviewing results, explaining factual findings, safety netting and signposting | Identifiers, specimen information, laboratory reports, clinical review and contact records | Contract, Article 6(1)(b) | Article 9(2)(h), health or social care, with Schedule 1 Part 1 condition 2 |
| Responding to a serious emergency or risk to life | Relevant identity, contact, health, location and emergency contact information | Vital interests, Article 6(1)(d), where necessary to protect life; or recognised legitimate interests, Article 6(1)(ea), where its statutory conditions apply to an emergency | Article 9(2)(c), vital interests, where the person is physically or legally incapable of consenting; or Article 9(2)(h) where necessary for health care |
| Safeguarding an adult at risk and preventing or reporting serious harm | Relevant health, incident, contact and safeguarding information | Recognised legitimate interests, Article 6(1)(ea), where the statutory safeguarding condition applies; or legal obligation, Article 6(1)(c), where a law requires action | Article 9(2)(g), substantial public interest, with the applicable safeguarding condition in Schedule 1 Part 2; or Article 9(2)(h) for health care |
| Meeting CQC, professional, incident reporting, tax, court and other legal obligations | Only information necessary for the particular obligation | Legal obligation, Article 6(1)(c) | Article 9(2)(h), Article 9(2)(f) for legal claims, or Article 9(2)(g) with the applicable Schedule 1 condition, depending on the obligation |
| Handling complaints, insurance matters, incidents, legal advice and legal claims | Booking, communication, clinical, incident, payment and complaint records | Legal obligation, Article 6(1)(c), where applicable; otherwise legitimate interests, Article 6(1)(f), in resolving complaints and protecting legal rights | Article 9(2)(f), legal claims, or Article 9(2)(h) where the matter concerns management of the health service |
| Clinical governance, audit, quality improvement and preventing recurrence of incidents | Relevant clinical and operational records, minimised or deidentified where possible | Legitimate interests, Article 6(1)(f), in operating a safe and accountable service; legal obligation, Article 6(1)(c), where required | Article 9(2)(h), management of health care, with Schedule 1 Part 1 condition 2 |
| Corporate screening and confidential participant care | Participant identity, booking and health information; anonymous group statistics for the organiser | Contract, Article 6(1)(b), for the participant service; legitimate interests, Article 6(1)(f), for genuinely anonymous programme reporting | Article 9(2)(h), with Schedule 1 Part 1 condition 2. Anonymous statistics are not personal data where reidentification is not reasonably possible |
| Website security, fraud prevention and technical troubleshooting | IP address, device, access and security logs | Legitimate interests, Article 6(1)(f), in securing the website and services | No health data is intentionally used for this purpose. If health information becomes necessary for a legal claim, Article 9(2)(f) may apply |
| Optional email or text marketing | Name, contact details and recorded marketing preference | Consent, Article 6(1)(a), together with applicable PECR requirements. Consent may be withdrawn at any time | We do not use health information for marketing. Any exceptional use would require separate, explicit consent under Article 9(2)(a) |
Clinical consent is different from data protection lawful basis. Your voluntary informed consent is required before a clinical procedure. Routine clinical record keeping and safe handling of results are not based solely on data protection consent, because some records must continue to be used or retained for care, safety, accountability or law.
5. How we use information
We use information only where necessary to assess eligibility and clinical suitability, manage bookings and visits, verify identity, obtain informed consent, collect and track samples, commission tests, receive and review results, provide factual explanation and safety netting, contact appropriate services where lawful, process payments and refunds, handle complaints and meet regulatory, professional, insurance, tax and legal requirements.
6. Who we may share information with
Information may be shared on a need to know basis with contracted laboratories, GPs and referrers, couriers, emergency services, safeguarding authorities, regulators, insurers, professional advisers, secure IT and website providers, payment processors and other properly assessed suppliers.
The current booking pathway uses IONOS to host the website and protected booking connector, Cliniko for the appointment diary and patient record, and Stripe for card authorisation and payment. The Orchis IV connector sends Stripe only the information necessary for payment and an opaque booking reference; detailed health notes are not placed in Stripe metadata. Cliniko receives the identity, contact, appointment and service information needed to create and administer the clinical record. Supplier access is governed by contract, security controls and role based access.
For corporate screening, individual results are not routinely disclosed to the employer. Only genuinely anonymous aggregate reporting will be provided unless the participant specifically authorises a lawful individual disclosure or limited disclosure is required by law or to address a serious safety risk.
7. International transfers
Where an approved supplier processes personal information outside the UK, we will use an appropriate UK transfer mechanism and carry out proportionate due diligence. Clinical information will be kept within approved systems wherever reasonably practicable.
8. Security
Safeguards include named staff accounts, role based access, strong authentication, secure transmission of clinical reports, device and password controls, encrypted backups, incident management, confidential disposal, processor due diligence, confidentiality obligations, training and audit. The Orchis IV Results Hub uses an unguessable private link plus a separate single use code sent to the client’s registered email address. The code expires after ten minutes, authenticated sessions time out, uploaded reports are encrypted at rest and access to records and documents is logged. Uploaded documents remain unavailable to the client until an authorised practitioner deliberately releases them. Contact attempts, document releases and completion actions are recorded. Date of birth is not used as a portal password. No system can be guaranteed completely secure, but we apply controls proportionate to the sensitivity and risk.
9. How long we keep information
Clinical and complaint records will normally be retained for eight years after the end of care or closure, unless a longer or shorter period is justified by law, professional guidance, litigation, safeguarding, insurance or the nature of the record. Financial records are retained in line with tax and company law requirements. Marketing preference records are kept while necessary to respect the preference and demonstrate compliance.
10. Your rights
Depending on the lawful basis and circumstances, you may have rights to access, correction, erasure, restriction, objection and data portability. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Some rights are limited where information must be retained for clinical safety, legal obligations, public interest, legal claims or another lawful reason.
Send a request to joyediran@orchis-iv.co.uk. We may need to verify your identity. We will respond within the applicable legal timeframe and explain any lawful restriction or extension.
11. Data breaches
Suspected breaches will be contained, risk assessed, recorded and investigated. We will notify the Information Commissioner’s Office and affected individuals where the legal thresholds are met and will implement corrective action.
12. Automated decisions, children and marketing
We do not use solely automated decision making that produces legal or similarly significant effects in relation to clinical care. Clinical escalation decisions are reviewed by an appropriately qualified person.
Services are currently provided only to adults aged 18 and over. Marketing permission is optional, kept separate from clinical consent and may be withdrawn at any time. Refusal does not affect access to services.
13. Complaints and changes
Contact the Registered Manager using the details above. You may also complain to the Information Commissioner’s Office. We will update this policy when our purposes, technology, suppliers or legal obligations change and communicate material changes where appropriate.