ORCHA respects the privacy and confidentiality of all users who engage with the ORCHA App Review platform, organisations who engage in partnership or project work with ORCHA, who we engage with in connection with the marketing and promotion of our products and services, and who use our website.
For the purposes of applicable data protection laws, ORCHA Health Limited is the Data Controller of personal data processed for the purposes described in this policy.
There are seven key principles that underpin Data Protection legislation:
These principles are central to how we store, manage and process data at ORCHA.
ORCHA strives to ensure that all data that is shared with us is treated with respect for personal, and client, privacy and protected in line with all our legal responsibilities and recognised best practice standards and processes.
ORCHA will only collect the minimum levels of personal data necessary to support our operational processes and will only use your personal data as described within this policy.
We publish this policy to demonstrate compliance with the requirements of the Data Protection Act 2018 and with the UK GDPR (General Data Protection Regulation).
ORCHA also publishes this policy to ensure all ORCHA data capture, data management and data utilisation processes are transparent to our end users; and to clearly explain what data we collect and how ORCHA uses any personal information that you supply to us.
ORCHA collects personal information about you directly from you when you:
All of these actions are required to enable ORCHA to deliver its services and only the minimum level of data is captured at each point.
We may also collect information about you from third party sources, such as LinkedIn or Companies House, where we identify you as someone who we think would be interested to hear more about our products and services.
The types of personal information ORCHA collects from you directly will vary depending on our interaction with you, but may include:
A user can access the ORCHA site without providing access to any of their personal data without hindrance, as the personal data collections only support the delivery of additional functionality for those users who proactively choose to share their data.
Where we collect information about you from third party sources (such as LinkedIn or Companies House) because we think you would be interested in hearing more about our products and services, we will limit that information to your name, basic contact information (such as a business email address) and limited information about your job role and employer.
ORCHA uses the information that you give to us:
ORCHA may link data captured from different ORCHA services, at a personal level, in order to improve our understanding of service utilisation and to support analyses on site utilisation and activity, but ORCHA will never publish, share or sell personally identifiable data without explicit, and informed, consent being received from all parties whose data is being used for those purposes.
We will only collect, use and share your personal information where we are satisfied that we have an appropriate legal basis to do this. This may be because:
If you would like to find out more about the legal basis for which we process personal information please contact us by e-mail at dpo@orchahealth.com
We may share your data with certain third parties set out below for the purposes described in the section above:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
There may be rare occasions where information gathered through the day to day collection of ORCHA data identifies a clear need to safeguard the welfare of the individual and/or his/her family and, on those occasions, it may be necessary to contact relevant authorities to address this. ORCHA will only undertake these actions in line with appropriate legal guidelines and using formal, recognised and auditable processes.
Our sharing of your personal data with the third parties identified above may result in the transfer of your personal data to locations outside of the UK. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
ORCHA will retain any personal data it captures for the duration of a registered relationship with the data subject. Once this formal, contractual relationship has ended ORCHA will maintain the personal data for a period of 2 years to support any operational management, or legal requirements that may arise. After this period, ORCHA converts any personally identifiable data into anonymous data and the personally identifiable elements of the stored data is destroyed using best practice data deletion standards.
Where possible, ORCHA strives to ensure that any personal data held by us is accurate and of a high quality, but individuals can inform us of any issues with data related to them and we will amend the data accordingly to ensure its ongoing accuracy. To request changes to your personal data, please see below under Right to rectification and we will make the necessary changes to your records as requested.
ORCHA implements a range of measures to ensure that any personal information that you provide to us is kept secure, accurate and up to date.
ORCHA’s protective measures include:
Access to this data is limited to accredited ORCHA staff and access is managed using role-based access controls.
The data that is captured through your interactions with ORCHA are stored securely in a protected data warehouse and are only accessible to accredited administrative users with specific access permissions. Data in transit between webpages and the data store are fully encrypted in transit, in line with best practice encryption methodologies to minimise the risk of interception.
Under the UK GDPR you have certain rights regarding the data which we gather and hold about you.
Individuals have the right to be informed about the collection and use of their personal data.
This Privacy Policy provides the information you need to understand our approach to managing personal data. The policy sets out:
You have the right at any time to ask for a copy of the information that ORCHA holds about you, and ORCHA will supply that data to you in line with its legal requirements to do so.
To request access to your data please place your request in an email to dpo@orchahealth.com quoting ‘Right of Access’ in the email header.
If any information that ORCHA holds about you is wrong, you have the right to ask ORCHA to make the necessary corrections.
To request amendments to your data please place your request in an email to dpo@orchahealth.com quoting ‘Right to Rectification’ in the email header.
You have the right to ask ORCHA to remove all personal data we hold about you from our systems.
To request that your personal data is securely deleted from our records, please place your request in an email to dpo@orchahealth.com quoting ‘Right to Erasure’ in the email header.
You have the right to request that your data is not used for specific forms of processing that ORCHA undertakes.
To request limits to be placed on how your data is processed by the ORCHA team, please place your request in an email to dpo@orchahealth.com quoting ‘Right to Restrict Processing’ in the email header.
The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services.
The data that ORCHA holds about you can be delivered directly to you, or to external organisations you grant permission to, in a variety of electronic formats depending on your request. This data will only be delivered when a written request is received from a validated user.
To request that your data can be shared/transferred to another system external to ORCHA, by the ORCHA team, please place your request in an email to dpo@orchahealth.com quoting ‘Right to Data Portability’ in the email header.
The UK GDPR gives individuals the right to object to the processing of their personal data in certain circumstances.
To request that your data is not processed under certain circumstances, please place your request in an email to dpo@orchahealth.com quoting ‘Right to Object’ in the email header. It is important to understand that certain types of processing are essential to ensure that ORCHA can deliver its services and requesting to be excluded from these processing tasks may limit your ability to access all of the functionality provided by the ORCHA platforms.
Where we rely on your consent to process your personal information, you have the right to withdraw that consent at any time.
Consent preference can be changed through accessing the User Profile page at any time.
Alternatively, you can email dpo@orchahealth.com to request that your consent is withdrawn. Please use ‘Consent Management’ in the header of the email you send for this purpose.
The UK GDPR has provisions on:
Please inform us if you do not want your data to be used in this way.
The ORCHA team will acknowledge all requests as soon as possible, and aims to address any queries you may have within 7 working days. However under UK GDPR we have up to 30 days to respond to requests.
If you have any complaint about the use of your personal data please contact dpo@orchahealth.com
If you remain dissatisfied you can also complain to the Information Commissioner’s Office about how we have used your data. The ICO’s address is:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline number: 0303 123 1113
Under 18-year olds
For users who are 18 or under, a parent/guardian’s permission is required before any personal information is captured relating to the individual.
Cookies are small text markers stored on your computer that enable us to understand how people use our website.
No personally identifiable information is stored in cookies. In common with many similar websites, ORCHA uses them to help remember preferences and for anonymous statistical measurements – for example so we know how many “visits” a page has had.
ORCHA uses cookies to:
You can control and delete cookies
Even though ORCHA does not use cookies to collect personally identifiable information about you, you might still want to restrict or block cookies.
You can do this through your chosen internet browser (Internet Explorer, Google Chrome, Mozilla Firefox etc.). Use the help function within the specific browser to find out how.
However, if you restrict cookies for the ORCHA website then there is a risk you will not be able to access the full functionality of the ORCHA website and your user experience may be undermined as a result.
What cookies are used on ORCHA sites?
The cookies applied on ORCHA websites are:
Interest-based ads
To serve you interest-based ads, we use information such as your interactions with ORCHA sites, content, or services. We do not use personally identifiable information such as name or email address to serve interest-based ads. We work with third parties, such as advertisers, publishers, social media networks, search engines, ad serving companies, and advertising companies working on their behalf, to improve the relevance of ads which we promote.
If your personal details change, please help the ORCHA team to keep those details up to date by telling us about any changes.
If you want to see what information we have about you, or need to tell us about any changes to the information that you have given to us, please contact:
ORCHA Health, The Innovation Centre, Sci-Tech Daresbury, Keckwick Lane, Daresbury, Cheshire, WA4 4FS
Email: dpo@orchahealth.com