Privacy Policy

Last Updated: 12-03-2019

www.infohealth.co.uk (our “Website“) is operated by Infohealth Limited (company number 04004930, whose registered office is at Lynwood House, 373-375 Station Road, Harrow Middlesex, England, HA1 2AW. Throughout this Policy, “we”, “us” and “our” refer to Infohealth Limited.

A. Our approach

We are committed to protecting and respecting your privacy and this Privacy Policy (the “Policy“) (together with our Terms of Use and Terms of Sale ) and any other documents referred to therein) sets out how we process the Personal Data of each visitor and customer to our Website, where such Personal Data is provided to us through our Website or via email communication. Please read the following carefully to understand our views and practices regarding your Personal Data and how we will treat it.

By clicking the “I Accept” box where indicated, submitting your Personal Data to us, and using the services you acknowledge and accept the practices described in this Policy.

For the purpose of the Data Protection Act 2018, the data controller is Infohealth Limited, a registered data controller with the UK Information Commissioner’s Office (registration number Z9217372).

If you have any questions about this Policy, please contact data@infohealth.co.uk.

We may amend this Policy at any time. Any changes we may make will be posted on this page, so please check back frequently. Your continued use of our Website and our services after posting will constitute your acceptance of, and agreement to, any changes.

Please note, our Website is only intended for use by UK residents who are aged 16 or over.

B. What is Personally Identifiable Information (PII) / Personal Data?

Personal Data or PII means any information relating to a person who can be identified either directly or indirectly by that information; it may include (amongst other things) name, address, email address, phone number, credit / debit card number, IP address, location data, purchase history (“Personal Data“).

We may process special category data (“Special Category Data”) which is more sensitive and requires more protection. Special Category Data includes (amongst other things) information about an individual’s health, sex life or sexual orientation.

C. Personal Data we may collect from you

We may collect and process the following information about you:

Information you provide to us – You may provide us with information by answering questions or filling in forms on our Website or by corresponding with us by e-mail or otherwise. This includes information you provide when you purchase products from us, reply to an email, enter a competition, promotion or survey or when you report a problem with our Website. The personal information you provide may include your name, address, e-mail address and phone number, financial information and other information about yourself to enable us to provide you with our services.

Information we collect about you – When you visit our Website we may automatically collect information about your computer or device, including your IP address, information about your visit, your browsing history, and how you use our Website. This information may be combined with other information you provide to us, as described above.

Information we receive from other sources – We are also working closely with third parties (including, for example, business partners, service providers, advertising networks, analytics providers, and search information providers) and may receive information about you from them. This may be combined with other information you provide to us, as described above.

D. Purposes for which we process Personal Data

We will only process your Personal Data, in accordance with applicable law.

We will process your Personal Data for the following purposes as is necessary for the performance of a contract between you and us, or to answer questions or take steps at your request prior to entering into a contract:

To create and maintain your customer account, if you become a registered customer;

To handle and fulfil your orders, if you request to purchase products from us. This may also include processing of information that we receive from third parties, for example, address data to verify your correct address;

To notify you about changes to our services, and to send you service emails relating to the activities you have asked us to undertake on your behalf; and

To administer any promotion or competition, that you enter via our Website or via email communication.

We will process your Personal Data for the following purposes as necessary for certain legitimate interests, or where you have given your informed consent to such processing as required by applicable law (such consent can be withdrawn at any time):

To offer our services to you in a personalised way, for example, we may provide suggestions based on your previous requests to enable you to identify suitable products and services more quickly. This may also include, where legally permitted, processing data related to your location;

To allow you to participate in interactive features of our services, when you choose to do so;

To send you personalised marketing communications, in order to keep you informed of our and our selected partner’s products and services, which we consider may be of interest to you;

To provide you, or allowing selected third parties to provide you, with information about products or services, that may interest you; and

To serve personalised advertising to your devices; delivering ads based on your interests ascertained from your past requests, visits of subpages and purchases on our websites, and other data obtained using “cookies” placed on your devices. For more information, please see our Cookie Statement;

We will process your Special Category Data (also known as “sensitive personal data”) for the following purposes where you have given your explicit consent to such processing as required by applicable law (such explicit consent can be withdrawn at any time):

To handle and fulfil your orders, if you request to purchase products from us. This may also include processing of information that we receive from third parties, for example, address data to verify your correct address.

We will process your Personal Data for the following purposes as necessary in our legitimate business interests, (provided such interests are not overridden by your interests or fundamental rights):

To resolve any disputes, if you lawfully exercise your rights or if you wish to dispute any part of our service offering;

To ensuring the security of your account and our business, preventing or detecting fraud or abuses of our Website, for example, by requesting verification information in order to reset your account password (if applicable);

To developing and improving our products and services, for example, by reviewing visits to our Website and its various subpages, demand for specific products and services and user comments;

To administer our Website and for internal business administration and operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes;

As part of our efforts to keep our Website safe and secure; and

To comply with applicable law, for example, in response to a request from a court or regulatory body, where such request is made in accordance with the law.

We may process your Personal Data in order to protect your vital interests or the vital interests of another person, including (without limitation) if we have significant concerns about your health and/or wellbeing.

E. Disclosure of Personal Data

There are circumstances where we wish to disclose or are compelled to disclose your Personal Data to third parties. This will only take place in accordance with the applicable law and for the purposes listed above.

These scenarios include disclosure to:

Our subsidiaries, branches or associated offices;

Our outsourced service providers or suppliers to facilitate the provision of our products to you, for example, service providers who host and administer our Website, process your order and payment, provide customer services and respond to your enquiries on our behalf, and handle the fulfilment and delivery of our products;

Our data centre provider and web hosting provider and to identity verification partners in order to verify your identity against public databases;

Our advertising partners who enable us to deliver personalised ads to your devices or similar advertising where you have given your consent if required by the applicable law;

Subject to your consent, to our marketing partners, who may contact you by post, email, telephone, SMS or by other means. If you do not wish to be contacted, you may unsubscribe by notifying us at data@infohealth.co.uk or by clicking “unsubscribe” in the message concerned;

Analytics and search engine providers that assist us in the improvement and optimisation of our Website. Your Personal Data is generally shared in a form that does not directly identify you;

Third party service providers and consultants in order to protect the security or integrity of our business, including our databases and systems and for business continuity reasons;

Another legal entity, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation, change of legal form, dissolution or similar event. In the case of a merger or sale, your Personal Data will be permanently transferred to a successor company. If a change happens to our business, then the new owners may use your Personal Data in the same way as set out in this Policy;

Public authorities where we are required by law to do so;

If required, in order to receive legal advice; and

Any other third party where you have provided your consent.

F. International transfer of Personal Data

We may transfer your Personal Data to a third party in countries outside the country in which it was originally collected for further processing in accordance with the purposes set out above. In particular, your Personal Data may be transferred throughout our group and to our outsourced service providers located abroad. In these circumstances we will, as required by applicable law, ensure that your privacy rights are adequately protected by appropriate technical, organisation, contractual or other lawful means. Please contact data@infohealth.co.uk for a copy of the safeguards which we have put in place to protect your Personal Data and privacy rights in these circumstances.

G. Retention of Personal Data

Your Personal Data will be retained until your last use of our services and normally for a period of three years thereafter, unless longer retention is required by applicable local law or where we have a legitimate and lawful purpose to do so. However, we will not retain beyond this period any of your Personal Data that is no longer required for the purposes set out in this Policy. The retention of your Personal Data will be subject to periodic review.

We may keep an anonymised form of your Personal Data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so.

Please contact us at data@infohealth.co.uk if you would further details about our data retention periods.

H. Data subject rights

In certain circumstances, you have the following rights under the data protection law in relation to your Personal Data:

Request access to your Personal Data. You may have the right to request access to any Personal Data we hold about you as well as related information, including the purposes for processing the Personal Data, the recipients or categories of recipients with whom the Personal Data has been shared, where possible, the period for which the Personal Data will be stored, the source of the Personal Data, and the existence of any automated decision making.

Request correction of your Personal Data. You may have the right to obtain without undue delay the rectification of any inaccurate Personal Data we hold about you.

Request erasure of your Personal Data. You may have the right to request that Personal Data held about you is deleted.

Request restriction of processing your Personal Data. You may have the right to prevent or restrict processing of your Personal Data.

Request transfer of your Personal Data. You may have the right to request transfer of Personal Data directly to a third party where this is technically feasible.

Where you believe that we have not complied with our obligation under this Policy or applicable data protection law, you have the right to make a complaint to a Data Protection Authority, such as the UK Information Commissioner’s Office.

I. Links

The Website may, from time to time, contain links to and from the websites of our partner networks, advertisers, affiliates and other third parties. If you follow a link to any of these websites, please note that these websites may have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal information to these websites.