Legal
Privacy policy
This policy explains how ORIGIN Health Intelligence collects and uses personal data, the lawful bases we rely on, how long we keep information and how you can exercise your rights.
Who we are
ORIGIN Health Intelligence is a company registered in England and Wales, company number [COMPANY REGISTRATION NUMBER], with its registered office at [REGISTERED ADDRESS]. We are registered with the Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER].
Questions about this policy, or about how we handle personal data, should be sent to our data protection contact at [DPO CONTACT].
Our two roles
We act in two distinct roles, and the role determines who decides how personal data is used.
Controller for site data. When you visit this website, complete the contact form or correspond with us, we decide why and how your personal data is used, so we are the controller for that information.
Processor for client data. When an employer, insurer or broker engages us to analyse workforce health information, that client remains the controller. We process the data on documented instructions under a written contract that meets the requirements of Article 28 of the UK GDPR. We do not use client data for our own purposes.
Personal data we collect as controller
- Enquiry details you provide: full name, job title, organisation, work email, telephone number if you choose to give one, organisation size band, what you are enquiring as if you choose to say, areas of interest and the content of your message.
- A record of the consent wording shown to you at the time of submission and the date and time you gave it.
- Correspondence with us, including emails and meeting notes relating to your enquiry.
- Limited technical information needed to keep the site secure and available, such as the internet protocol address of a request and basic request logs.
Lawful bases
Where we contact you about an enquiry you submitted, we rely on your consent under Article 6(1)(a) of the UK GDPR, and on our legitimate interests under Article 6(1)(f) in responding to business correspondence and in keeping our systems secure. Where we provide services under a contract, we rely on Article 6(1)(b). Where we must retain records to meet a legal obligation, we rely on Article 6(1)(c).
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
Special category health data
Health information is special category data under Article 9 of the UK GDPR and receives additional protection. We do not ask for and do not want health information through this website. Please do not include it in the contact form.
When we process health information as part of a service engagement, we do so as processor on the client's instructions. The Article 9 condition relied on is Article 9(2)(h), processing necessary for the purposes of preventive or occupational medicine and for the assessment of the working capacity of the employee, read with paragraph 2 of Schedule 1 to the Data Protection Act 2018. That condition applies because the processing is carried out by, or under the responsibility of, a health professional or another person who owes an equivalent duty of confidentiality. Where the client instead relies on explicit consent under Article 9(2)(a), that consent is collected from the participant before any assessment begins, as described in the participant privacy notice.
An appropriate policy document is maintained for the relevant Schedule 1 conditions, as required by the Data Protection Act 2018.
Data minimisation and aggregation
We collect only the information we need for the purpose in hand. Reporting to employers is produced at the level of a group, not an individual. A minimum group size threshold of 100 is applied before any breakdown is reported, so that individuals cannot be identified by combining small categories. Individual responses are not disclosed to an employer in identifiable form.
Retention
Enquiry records are kept for [RETENTION PERIOD] from the date of your last contact with us, after which they are deleted or anonymised. Data processed under a client engagement is retained for the period set out in the contract with that client, and is returned or deleted at the end of the engagement on the client's instruction. Records we must keep for legal or accounting reasons are held for the statutory period only.
Hosting, sub-processors and international transfers
Our production platform is hosted on Amazon Web Services in the [AWS REGION] region. The services used include Amazon EC2 for compute, Amazon RDS for PostgreSQL for the database, Amazon S3 for generated report files, Amazon SES for transactional email and Amazon SNS for notifications. Personal data is stored at rest within [AWS REGION].
During the interim period before that platform is live, enquiry records submitted through this website are held in a managed PostgreSQL database operated by Supabase, hosted on Amazon Web Services in the eu-west-2 region (London). Those records will be migrated to the production platform and deleted from the interim store once migration is complete.
We use a short list of sub-processors, each engaged under a written contract that imposes equivalent data protection obligations. The current list, including the purpose and location of each, is available on request from [DPO CONTACT]. Clients are given notice of any intended change to sub-processors so that they may object.
We do not routinely transfer personal data outside the United Kingdom or the European Economic Area. Where a transfer is necessary, we rely on UK adequacy regulations or on the International Data Transfer Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role based access control, least privilege administration, audit logging, segregation of client environments, staff training and regular review of access rights. Access to data is limited to those who need it to deliver the service.
Your rights
Under the UK GDPR you have the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights in relation to automated decision making and profiling. We do not make decisions about individuals by automated means that produce legal or similarly significant effects.
To exercise a right, write to [DPO CONTACT]. We will respond within one month. That period may be extended by up to two further months for complex requests, and we will tell you if that happens. We may ask for information to confirm your identity. Where we act as processor for a client, we will pass your request to that client without undue delay and support them in answering it.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or by telephone on 0303 123 1113. We would ask you to raise the matter with us first so that we can try to resolve it.
Cookies
We set strictly necessary cookies to make the site work. Optional cookies are set only with your permission. See the cookie policy for the detail and to change your choices.
Changes to this policy
We review this policy regularly. When we make a material change we will update this page and, where appropriate, tell affected individuals directly.
