eMed Privacy Policy
Hello
Welcome to the eMed privacy policy.
We take your privacy seriously. We want you to know why we need certain information from you, what we're doing with it, and how we keep it secure.
Table of contents
1. What this policy covers
This policy explains how we use your data to deliver our healthcare app, websites and services. This includes:
- our private service, including the enrollment and use of one of our programmes;
- our NHS service, GP at Hand;
- our app, including any beta versions;
- our websites (www.babylonhealth.com and www.gpathand.nhs.uk);
- some of our services we offer with our partners, or on behalf of them; and
- the technology we use to support our partners' services.
We provide these services through 2 companies in our group:
- Babylon Healthcare Services Limited (BHSL): the company that provides our medical services
- eMed Healthcare UK Limited (eMed UK): the company that supplies the technology and software for these services
When we talk about eMed, us or we in this policy, we mean these 2 companies.
BHSL is the controller of any health and medical data we may collect from you when you use our services, and may share this data with eMed UK as a processor on behalf of BHSL (for more information on this, see how and why we share your databelow). This means that we're responsible for how your personal data is handled and what it's used for through these 2 companies. If you wish to exercise any of your rights, both companies act as one.
Our NHS service is called GP at Hand. GP at Hand offers a digital-first primary care service to its registered patients. These services are provided by BHSL under a subcontract arrangement with the NHS.
Read more about GP at Hand.
See more about our registered companies.
2. What data we hold and how we get it
Personal data is any information we have that can identify you, such as your name, medical history or credit card details.
Personal details
When you register with us, we'll ask you for your:
- name;
- date of birth;
- address;
- contact details;
- any information needed in order to enrol and determine your eligibility on one of our programmes;
- a copy of your ID (identity documentation), such as a driving licence
The information you give us must be accurate. If you give us information about yourself or another person, you're confirming that you're authorised to do so.
Health and medical data
When you use our services, we collect information about your health, including:
- general health (including information necessary to determine eligibility on one our programmes);
- symptoms, treatments, participation in our programmes and medications;
- consultations, such as notes and recordings
- procedures, such as surgery, scans or X-rays; and
- interactions with our services, like using our Symptom Checker or other digital services. These interactions may be shared with our clinical staff so that we can provide you with healthcare, and so that we can provide a better experience
Some of this information comes directly from you, but it can also come from third parties, such as your GP.
If you use GP at Hand, we'll get your medical history from your previous GP.
If you use our private service, we'll send your appointment notes to your NHS GP, if you give us your consent.
We share children's appointment notes with their NHS GP, in line with current medical guidelines.
Details of your conversations with us
We also keep a record of your consultations and your conversations with us. This is so we have an easy way to access your consultations to monitor the quality of our service and healthcare.
And, if you have consented, so that we can use them to improve our services. This includes:
- your conversations with our Symptom Checker;
- your emails, calls or live chat conversations with our support team; and
- video and/or audio recordings from consultations, including your participation on our programmes.
We keep your health and medical data secure by applying technical and organisational measures to protect it.
Find out how long we keep your data.
Data from other sources
We might also receive some data about you and your health from other apps, devices and services.
This will only happen if you've agreed to sharing that data with us. For example, if you decided to share information collected from a smartwatch with our app.
Credit and debit card information
If you make a payment on the app, your credit and debit card details are processed by a third-party payment provider.
We don't store any of your credit or debit card information and we only keep details of the transactions on our secure servers.
Technical information and analytics
When you use our app, or visit our website, we may collect the following data, where this is allowed by your device or browser settings:
- the IP address used to connect your mobile phone or other device to the internet
- your browser information, such as Google Chrome or Apple Safari
- login and operating system
- the make and model of your device
- resettable device identifiers
- time zone, language and location settings
- your mobile network provider and your location (based on your IP address)
- information about your visit to our website or use of our app, for example when you first visited the site or how many times you've visited
- information about the products or services you viewed or used
- app response times and updates
- information about your interactions, like what notifications you opened; and
- any phone number used to call our customer service number.
We work with other companies that provide us with analytics and advertising services. This is to:
- help us understand how people interact with our services;
- provide the adverts for our services on the internet; and
- measure the performance of our services and our adverts
Cookies
We also use 'cookies'. Cookies are files saved on your phone, tablet or computer when you visit a website. They collect information about how you use the website and the pages you visit.
You can find out more about how we use cookies in our cookie policy.
Information from third-party services
It's possible to connect your social media accounts, or your wearable device (like a smartwatch) with our services. For example, you can sign up for eMed using your Facebook login details. If you choose to do this, we'll receive the following information about you from the third party:
- name;
- email address;
- username or ID; and
- health and lifestyle habits and information.
If you use login details from third parties, they will also process your login data, and they are solely responsible for handling this.
We may also get information from other sources, such as companies who offer information on consumer trends.
We use this information to help us make our services better. We comply with data protection laws when we do this. If this information is used alongside your personal data, we will make sure that our interests never come before your rights.
3. What we use your data for
This is how we use your data and the legal reasons for using it.
Providing you with a service
We need your personal information to enter into a contract with you and deliver services.
We use your financial details to charge you if you use our paid service or buy our products.
We use your health and medical information to provide you with a healthcare service. This includes:
- providing you with a health advice;
- diagnosis and treatments if you use our clinical services (our video and audio consultations, where you can talk with one of our medical professionals); and
- providing you with a service as part of one of our programmes.
This information is based on:
- providing you or planning for healthcare services in our 'legitimate interest'
- performing tasks in the public's interest (for example, our NHS services)
- when it is in your vital interests;
- your consent (for example, when you use our private service and agree to sharing information with your NHS GP); and
- to fulfil a contract with us (as a healthcare professional) as part of one of our programmes.
The health and medical information we use includes information from your:
- consultations, like notes, recordings, and transcripts;
- use of products like Symptom Checker and Healthcheck; and
- your previous NHS GP, if you use Babylon GP at Hand.
We might share this information with other health services. This is so we can give you the right care, including when it's in your vital interests. These services include:
- your GP, if you use our private service;
- our NHS or clinical service partners; and
- referral services like therapists, pharmacists and hospitals
We use your location to recommend services near you, like pharmacies and hospitals.
Depending on how you access our services, we get your location from your phone, internet browser, IP address or postal address.
Improving eMed's services
If you've given explicit consent, we use your health and medical information to improve our services. This helps us deliver better healthcare to you and other eMed users.
We remove details that could identify you from this information, such as your name, address and contact details. These are called 'personal identifiers'.
The health and medical information we collect (with your personal identifiers removed) includes information from your:
- medical records;
- consultations, like notes, recordings and transcripts; and
- use of products like Symptom Checker and Healthcheck.
This doesn't involve making any decisions which would have a big effect on you. We only use this information to deliver a better experience to you and other eMed users. This explicit consent relates to when we use your personal data.
Helping health research
As part of our work with the NHS we occasionally partner with universities, academic institutions and research organisations, to further medical science and ultimately improve healthcare for all.
As part of these partnerships, we may use your contact details to invite you to take part in clinical trials. You are not under any obligation to partake and can opt out of receiving information by contacting our support team via form.
More information can be found on the NHS GP at Hand FAQ website.
Using your data when it's in our 'legitimate interest'
We sometimes analyse your data and how you use our products to help us manage our business better.
This could be things like fixing bugs in our app, understanding current user trends, or working out what users might want in the future.
This doesn't involve making any decisions which would have a big effect on you. If this information is used alongside your personal data, we will make sure that our interests never come before your rights.
Keeping you up to date
We may contact you when marketing our service. This includes sending you product updates, surveys and marketing information. You can opt in or out at any time by going to 'Me', 'Settings' and 'Privacy Controls' in the app. You can also choose if you want to get app notifications in your device settings.
As part of providing you with a healthcare service or public service, we may send you health information by text message, email or in other ways. For example, we may send you public health messages or invite you to book an appointment for a free screening programme, such as cervical cancer screenings.
Regulating the quality and safety of our service
We use your health and medical information for safety, training, regulatory, and compliance purposes.
This means that:
- if we're legally required to, or asked by a regulator, we may need to share your information with regulatory bodies like the General Medical Council, Medicines and Healthcare Products Regulatory Agency or Care Quality Commission; and
- we may audit how you use our services, for example to review the quality of results provided by our products.
To detect and prevent fraud, we may need to share your personal and financial information with banks, financial institutions and fraud prevention services.
4. How we store and move your data
Personal health and medical information
Your personal health and medical information is stored on secure servers. This includes information like:
- your primary care information;
- information about your medications; and
- any information about a diagnosis of illness or other problems.
We don't store any of this information on your mobile device.
If you've chosen a password or authentication method to access the app, you're responsible for keeping this password and/or authentication method confidential. Please don't share it with anyone.
We encrypt data transmitted to and from the app. Once we have your information, we use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to make sure that your data is treated securely.
Credit and debit card information
We don't store any of your credit or debit card information. Payments are processed through a third-party payment provider that follows strict industry data security standards. These are known as Level 1 Payment Card Industry (PCI) data security standards.
Any payments you make are encrypted using SSL technology (which converts the information into code to stop fraud).
Where we store and process your health data
Your health data will be stored and processed in the UK only. We may sometimes need to work with companies outside of the UK or European Economic Area (EEA), including eMed affiliate companies, to help us deliver services to you. This will always be in line with applicable data protection laws and will include using appropriate safeguards such as the execution of appropriate data transfer agreements incorporating European Commission approved Standard Contractual Clauses along with other safeguards where appropriate or confirming other controls to comply with UK data protection requirements.
6. How long we keep your data
We follow advice from the Department of Health and the British Medical Association on how long to keep information found in your medical records. This is called a 'retention period'.
We might also keep some information that doesn't identify you to help improve our business and our services.
In some circumstances, we might keep data longer if the law says we have to.
Your information | How long we keep it (its 'retention period') |
GP recordsThis includes medical records, consultations with GPs and symptom checker interactions | We keep your GP records for 10 years after your death or after you've permanently left the country. We may keep your records longer if there are genetic implications for your family. We work on the advice from clinicians in this situation. Electronic patient records can't be destroyed or deleted for the foreseeable future. |
Video consultations | If we keep your video consultations, they are kept in the same way as your GP records (although that period of time could change if our product changes). |
Voice (or audio) consultations | We keep your voice consultations in the same way as your GP records (although that period of time could change if our product changes). |
Symptom Checker | We keep your interactions with our Symptom Checker in the same way as your GP records. They are also available in the app for 1 month (although that period of time could change if our product changes). After 1 month we can provide them if you ask us for them. |
Healthcheck | We keep your records from these services for 2 years after you close your account, unless you agree to them being a part of your medical record. If you do, we will store them in the same way as your GP records. . |
Participation in one of our programmes | Relevant clinical data will be transferred to your medical record and will be kept in the same way of your GP records (see above). Information that does not form part of your medical record, will be kept in the same way as Healthcheck data (above). |
Communications with support teams, including phone calls, emails and live chats | 1 year after you leave the service. |
Maternity records | We keep your records for 25 years after the birth of your last child. |
Records on any treatment for a mental disorder (as described in mental health legislation) | We keep your records for 20 years after the date of your last consultation. Or 10 years after your death if that is sooner. |
7. Your rights
You're in control of your personal information. Under data protection law, you have the right to:
- remove or change your consent at any time, if we are using your data in a certain way based on it. You can do this by:
- going to the app, selecting 'Me' and then 'Privacy preferences'; or
- going to the Babylon Health website, selecting 'Account' and then 'Privacy'
- ask for a copy of the personal data we hold about you. Your data is stored in line with our legal and medical obligations. See: how long we keep your data).
- ask us to correct information that's wrong, delete it, or ask that we only use it for certain purposes. There might be times when we're not able to help, like if the law or our medical obligations say we can't.
- ask us to restrict any automated (computer-made) decisions made with your data
- ask for your data to be provided in a portable format that allows you to move, copy or transfer it. Or ask us to send it in this format to someone else.
To exercise your rights, please complete our online webform here.
If you have any general queries about how we process your information, please contact us at DPO@babylonhealth.com.
184, 192 Drummond St
London
NW1 3HP
We'll ask you for a proof of identity. Data protection laws give us one month to get back to you.
We're regulated by the Information Commissioner's Office (ICO). If you're not happy with any aspect of our data handling, you can complain to the ICO directly. You can contact them at:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Phone: 0303 123 1113
8. Changes to this policy
We might update this policy from time to time.If we make any important changes, we'll let you know, and give you the chance to review them.
If you agree to the changes, you don't need to do anything. Just keep using our services with the updated policy and we'll assume you are happy with the way we use your data.
If you don't agree to the changes, then you can stop using our services at any time.