Privacy Policy
Company Name: 360 Complex Care Limited
Policy Name: Privacy Policy and Procedure
Last Reviewed: 10 June ’24
Care Limited customer privacy notice
This privacy notice tells you what to expect us to do with your personal information.
Contact details
Telephone: 03456465360
Email: GDPR@360complexcare.co.uk
What information we collect, use, and why
We collect or use the following information to provide services and goods, including delivery:
- Names and contact details
- Addresses
- Date of birth
- Purchase or account history
- Payment details (including card or bank information for transfers and direct debits)
- Health information (including dietary requirements, allergies and health conditions)
- Health and safety information
- Account information
- Website user information (including user journeys and cookie tracking)
- Photographs or video recordings
- Call recordings
- Records of meetings and decisions
- Identification documents
- Information relating to compliments or complaints
We also collect or use the following information to provide services and goods, including delivery:
- Racial or ethnic origin
- Health information
We collect or use the following information for the operation of customer accounts and guarantees:
- Names and contact details
- Addresses
- Payment details (including card or bank information for transfers and direct debits)
- Account information, including registration details
- Information used for security purposes
We collect or use the following information to prevent crime, prosecute offenders, or defend against legal action:
- Names and contact information
- Customer or client accounts and records
- Criminal offence data (including Disclosure Barring Service (DBS), Access NI or Disclosure Scotland checks)
- Video and CCTV recordings of public areas (including indoor and outdoor spaces)
- Audio recordings of public areas (including indoor and outdoor spaces)
- Video and CCTV recordings of private or staff only areas
- Information relating to health and safety
We collect or use the following information for service updates or marketing purposes:
- Names and contact details
- Addresses
- Location data
- Recorded images, such as photos or videos
- Call recordings
- Website and app user journey information
- Records of consent, where appropriate
We collect or use the following information to comply with legal requirements:
- Name
- Contact information
- Identification documents
- Financial transaction information
- Criminal offence data (including Disclosure Barring Service (DBS), Access NI or Disclosure Scotland checks)
- Health and safety information
We also collect or use the following information to comply with legal requirements:
- Racial or ethnic origin
- Religious or philosophical beliefs
- Health information
We collect or use the following information for recruitment purposes:
- Contact details (eg name, address, telephone number or personal email address)
- Date of birth
- National Insurance number
- Copies of passports or other photo ID
- Employment history (eg job application, employment references or secondary employment)
- Education history (eg qualifications)
- Right to work information
- Details of any criminal convictions (eg Disclosure Barring Service (DBS), Access NI or Disclosure Scotland checks)
- Security clearance details (eg basic checks and higher security clearance)
We also collect or use the following information for recruitment purposes:
- Racial or ethnic origin
- Religious or philosophical beliefs
- Health information
Lawful bases
Our lawful bases for collecting or using personal information to provide services and goods are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
- Public task
Our lawful bases for collecting or using personal information for the operation of customer accounts and guarantees are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
Our lawful bases for collecting or using personal information to prevent crime, prosecute offenders or defend against legal action are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
Our lawful bases for collecting or using personal information for service updates or marketing purposes are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
- Public task
Our lawful bases for collecting or using personal information for legal requirements are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
- Public task
Our lawful bases for collecting or using personal information for recruitment purposes are:
- Consent
- Contract
- Legal obligation
- Legitimate interest:
- We collect information in order to provide bespoke care.
- Vital interests
- Public task
Where we get personal information from
- People directly
- Health care providers
- Legal and judicial sector organisations
- Schools, colleges, universities or other education organisations
- Councils and other public sector organisations
- Previous employers
How long we keep information
We retain personal data in accordance with the retention periods outlined below. If a retention period is not specified, personal information will only be retained for the longer of:
- As long as required for its purpose
- As required by law
- As recommended by the Chartered Institute of Personnel & Development
How long we keep information
We retain personal data in accordance with the retention periods outlined below. If a retention period is not specified, personal information will only be retained for the longer of:
- As long as required for its purpose
- As required by law
- As recommended by the Chartered Institute of Personnel & Development
Retention Periods
| Record Type | Retention Period | Comment |
|---|---|---|
| Application forms of non-shortlisted candidates | 6 months | Equality Act 2010 |
| Shortlists, interview notes, and related application forms | 6 months | CIPD recommendation |
| Personnel records (including training and disciplinary records) | 6 years after employment ceases | CIPD recommendation |
| Redundancy details and calculations | 6 years after redundancy | CIPD recommendation |
| Wage/salary/payment records | 6 years | Taxes Management Act 1970 |
| SMP & SSP records (including certificates & self-certifications) | 3 years after end of the related tax year | SMP and SSP Regulations |
| Parental leave records | 5 years from birth/adoption | CIPD recommendation |
| Incident details | 10 years after the incident | NHS England Records Management Code of Practice 2023 |
| Serious incident details (including RIDDOR reportable incidents) | 10 years after the incident | NHS England Records Management Code of Practice 2023 |
| Staff training and contact information | Significant records: Until the 75th birthday or 6 years after employment ceases. Non-significant records: 6 years after training completed. | NHS England Records Management Code of Practice 2023 |
Healthcare Records Retention Periods
| Type of Patient | Minimum Period of Retention |
|---|---|
| Patient under 17 at treatment conclusion | Until the patient’s 25th birthday |
| Patient aged 17 at treatment conclusion | Until the patient’s 26th birthday |
| Patient who died before age 18 | 8 years from the date of death |
| Patient treated for mental disorder | 20 years from the last entry in the record |
| Patient treated for mental disorder who died | 8 years from the date of death |
| Patient treated by a general practitioner | 10 years from the last entry in the record |
| Patient who received an organ transplant | 11 years from death or discharge, whichever is earlier |
| All other cases | 8 years from the last entry in the record |
Disposal of Information
All personal information is securely disposed of in line with data protection regulations:
- Paper records: Shredded using secure, locked consoles.
- Digital records: Permanently deleted from IT systems with guidance from an ISO-accredited IT specialist.
- Obsolete storage devices: Returned to the IT team for secure removal of information.
For further advice, please contact our Data Protection Lead.