Who We Are
MEDlight may gather and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection Regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why and when we process your personal data.
MEDlight’s registered office is at Unit 1 Sovereign Centre, Farthing Road, Ipswich, Suffolk, IP1 5AP, United Kingdom and we are a company registered in England and Wales under company number 01264315. We are registered on the Information Commissioner’s Office Register; registration number ZA345707, and act as the data controller when processing your data. Our designated Data Protection Representative for MEDlight is Will Peake, who can be contacted at Unit 1 Sovereign Centre, Farthing Road, Ipswich, Suffolk, IP1 5AP, United Kingdom via writing or e-mail address firstname.lastname@example.org.
Information That We Collect
MEDlight processes your personal information to meet our legal, statutory and contractual obligations and to provide you with our products and services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.
The personal data that we collect from you is:-
– First Name
– Last name
– Position at Company
– Email address (Could be business or home address)
– Telephone Number (Could be mobile or home number)
– Mobile Telephone Number
– Comments (A customer may respond with more details if they so require within a comments box on our enquiry form).
– Information you give us when you report a problem with our site;
– Cookie information. (please see cookie notice below)
How We Use Your Personal Data (Legal Basis for Processing)
MEDlight takes your privacy very seriously and will never disclose, share or sell your data without your consent; unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. Where you have consented to us providing you with promotional offers and marketing, you are free to withdraw this consent at any time.
The purposes and reasons for processing your personal data are detailed below: –
– We collect your personal data with our provided web form to help assist you when you are enquiring and use the information provided to enable us to respond to you professionally.
– We will occasionally send you marketing information where we have assessed that it is beneficial to you as a customer and in our interests. Such information will be non-intrusive and is processed on the grounds of legitimate interests.
You have the right to access any personal information that MEDlight processes about you and to request information about: –
– What personal data we hold about you
– The purposes of the processing
– The categories of personal data concerned
– The recipients to whom the personal data has/will be disclosed
– How long we intend to store your personal data for
– If we did not collect the data directly from you, information about the source
If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information and we will strive to do so as quickly as possible; unless there is a valid reason for not doing so, at which point you will be notified.
You also have the right to request erasure of your personal data or to restrict processing (where applicable) in accordance with the data protection laws; as well as to object to any direct marketing from us. Where applicable, you have the right to data portability of your information and the right to be informed about any automated decision-making we may use. Currently MEDlight do not use any automated decision making and do not intend to.
If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request; this is to ensure that your data is protected and kept secure.
Sharing and Disclosing Your Personal Information
We utilise the below processors/controllers who act on our behalf to provide the below business functions and services. They act in accordance with instructions from us and comply fully with this and their own privacy notice, the data protection laws and any other appropriate confidentiality and security measures.
MEDlight takes your privacy very seriously and takes every reasonable measure and precaution to protect and secure your personal data. We work hard to protect you and your information from unauthorised access, alteration, disclosure or destruction and have several layers of security measures in place, including: –
Our Website includes an SSL certificate to ensure any personal information is kept safe from webserver to browser. We also include a captcha code to stop web bots sending spam and viruses. All personal data sent to the office’s at MEDlight is sent via a spam filter and virus checked before its arrival into the offices of MEDlight. Personal data is only kept for as long as is necessary to adhere to the GDPR Principals.
Consequences of Not Providing Your Data
You are not obligated to provide your personal information to MEDlight, however, as this information is required for us to provide you with our services we will not be able to offer some or all our services without it.
As noted in the ‘How We Use Your Personal Data’ section of this notice, we occasionally process your personal information under the legitimate interests’ legal basis. Where this is the case, we have carried out a thorough Legitimate Interests’ Assessment (LIA) to ensure that we have weighed your interests and any risk posed to you against our own interests; ensuring that they are proportionate and appropriate.
We use the legitimate interests’ legal basis for processing your personal details collected in the web form so we can respond to your query to the best of our ability. If you have requested a quote or to open an account we may send you marketing information if we feel it may be of interest to you under the legitimate interest principal.
How Long We Keep Your Data
MEDlight only ever retains personal information for as long as is necessary and we have strict review and retention policies in place to meet these obligations. We are required under UK tax law to keep certain information for a minimum of 6 years after which time it will be destroyed.
Where you have consented to us using your details for direct marketing, we will keep such data until you notify us otherwise and/or withdraw your consent.
MEDlight will occasionally send you new products, services, promotions and newsletters by email/and/or post that have been identified as being beneficial to our customers and in our interests. Such information will be relevant to you as a customer and is non-intrusive and you will always have the option to opt-out/unsubscribe at any time.
If you would prefer NOT to receive the above-mentioned marketing and offers, please let us and we will remove you off any mailing list. You may e-mail email@example.com.
Lodging A Complaint
MEDlight only processes your personal information in compliance with this privacy notice and in accordance with the relevant data protection laws. If, however, you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.
Will Peake (Data Protection Representative)
1 Sovereign Centre, Farthing Road, Ipswich, Suffolk, IP1 5AP, United Kingdom
Tel: +44 1473 466 300
Information Commissioners Office (ICO)
Wycliffe House, Water Ln, Wilmslow, SK9 5AF
Tel: +44 303 123 1113