Privacy and Cookies Policy

Last updated: 13.09.24

Privacy and Cookies Policy

1. Introduction

We are committed to protecting and respecting your privacy. Therefore this Privacy Policy (the “Policy“) sets out the basis on which any personal data we collect about you, or that you provide to us, is processed by us.  We may update this Policy from time to time.

Please read the Policy carefully to understand our views and practices regarding your personal data and how we will treat it. By using our online services (including our site located at https://www.medicspot.co.uk and purchasing products and accessing our services) you agree to the use we make in accordance with this Policy of all personal data you provide to us or we collect about you. If you do not agree with any term in this Policy, please do not use our online services.

2. The Company

Outcome Diagnostics Limited (“we”/”us”) operates Medicspot.co.uk and is responsible for delivering Medicspot services. We are a company registered in England and Wales under company number 13190700. Our registered office is located at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

For the purpose of the data protection rules, Outcome Diagnostics Limited is the controller of your personal data. If you have any queries about this privacy notice or about our use of personal data please contact help@medicspot.co.uk.

3. Data we may collect from you

In this Policy your “data” means information or pieces of information relating to you or that could allow you to be directly or indirectly identified. We may collect, use, store and transfer different kinds of data about you:

    • Contact Data includes data such as your email address, telephone number and correspondence address.
    • Identity Data includes data such as first name, last name, username or similar identifier, date of birth and gender assigned at birth, photographs of you that you send to us.
    • Health Data includes your responses to our online consultations and any other information you provide to us about your physical or mental health, including current medication and your GP details if you choose to provide that to us.
    • Financial Data includes bank account and payment card details.
    • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us
  • Profile Data includes your username and password for any account you have with us, purchases or orders made by you, your interests, preferences, feedback and survey responses
  • Technical Data includes data such as internet protocol (IP) address, your login data, browser type and version, cookies, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website and any communications we may send to you.
  • Usage Data includes information about how you use our website such as information about your visit to our website, including the full Uniform Resource Locators (URL) clickstream to and through, pages you viewed or searches you made, page response times, download errors, length of visit, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
  • Marketing and Communications Data includes your preferences in receiving marketing from us, selected third parties and your communication preferences.

We do not knowingly collect the data of children. Please do not provide data to us unless you are at least 18 years old.

We also collect, use and share aggregated data such as statistical or demographic data which is not personal data as it does not directly (or indirectly) reveal your identity. For example, we may aggregate individuals’ Usage Data to calculate the percentage of users accessing a specific website feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering.

Data you voluntarily provide

From time to time you may provide data to us. This may be because:

  • You create an account with us
  • You take one of our online consultations or register to receive communications.You contact us via email or phone. If you do, we may keep a record of that correspondence and record the phone call.
  • You request marketing to be sent to you
  • You complete surveys that we use for research purposes. These, however, are not mandatory.
  • You purchase services or products through our online services, or express an interest in receiving such services.
  • You respond to our request for identification documents.
  • You provide feedback to us.

You otherwise contact us, including with queries, comments, or complaints.You participate in a promotion, for example claiming under a money back guarantee or participating in a competition,We shall process all such data in accordance with this Policy. Certain data is mandatory and must be provided to us so that we can fulfil your request (for example, to purchase services or products on our website), and we shall make this clear to you at the point of collection of the data.

All data that you provide to us must be true, complete and accurate. If you provide us with inaccurate or false data and we suspect or identify fraud, we will record this and we may also report this to the appropriate authorities.

Data we automatically collect about you

When you use our website we may automatically collect and store information about your Technical Data and Usage Data for the purposes of research, analysis and to improve our services.

Some of this information is collected using cookies and similar tracking technologies. If you want to find out more about the types of cookies we use, why we use them, and how you can control them, please see section 12 on cookies in this policy.

Data we receive from others

We may receive further data from third parties – such as credit reference agencies, the electoral register, and our verification partners – for purposes such as verifying your identity and confirm the validity of data relating to you.

We may also receive data about you from our third party service providers, including our payment service provider and our analytic service providers. In addition, our business relies on collaboration with third parties such as our prescribers, pharmacies, doctors, and blood testing companies and so we may therefore receive information about you from them.

Technical Data is also collected from third party service providers, including analytics providers and advertising networks and search information providers.

Contact, Financial and Transaction Data is collected from providers of technical, payment and delivery services.

See paragraphs 5 and 6 for further detail.

 

4. Legal basis for processing your data

We will only use your data where we have a lawful basis to do so (also known as an Article 6 condition). The lawful basis that we rely on under this Policy are:

  • Consent (where you choose to provide it).
  • Performance of our contract with you – including carrying out any preliminary checks needed before agreeing to provide you with services.
  • Compliance with legal requirements.
  • Legitimate interests. When we refer to legitimate interests we mean our legitimate business interests in the normal running of our business which do not materially impact your rights, freedom or interests. We do not use your personal data for activities where our interests are overridden by the impact on you. Our legitimate Interests include:
  • Providing you with information on services products and feedback.
  • Keeping our records up to date.
  • For statistical research and analysis and to enable us to monitor and improve services.
  • To monitor how we are meeting our clinical and non-clinical performance in the case of health care providers.
  • Sharing your personal information with people or organisations in order to comply with any legal or regulatory obligations or to enable us to run our organisation.
  • To fulfil laws that apply to us and the third parties we work with.
  • To take part in or be the subject of any merger
  • Managing our relationships with you and third parties who assist us to provide the services to you.

 

There are special rules about how we can use Health Data.  For Health Data, in addition to the lawful basis outlined above, we must also comply with an Article 9 condition. Below we have set out the conditions that we are relying upon under both these Articles in order to use your data. 

Purpose  Type of data Article 6 Condition Article 9 Condition
To register you as a new customer (a) Identity 

(b) Contact

(c) Health

Performance of a contract with you Article 9(2)(h) – healthcare and social care purposes
Carry out identity and/ or soft credit checks (a) Identity 

(b) Contact

(c) Financial

(d) Profile

Article 6(1)(b) – performance of a contract Not applicable – no Health Data used
To process and deliver services to you including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(a) Identity 

(b) Contact 

(c) Health

(d) Financial 

(e) Transaction 

(f) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests (to recover debts due to us)

Article 9(2)(h) – healthcare and social care purposes
To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Dealing with your requests, complaints and queries

(a) Identity 

(b) Contact 

(c) Health

(d) Profile 

(e) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you)

Article 9(2)(h) – healthcare and social care purposes
To enable you to participate in marketing promotions such as competitions or complete a survey (a) Identity 

(b) Contact 

(c) Profile 

(d) Usage 

(e) Marketing and Communications

(a) Performance of a contract with you 

(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

Not applicable – no Health Data used
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data); to maintain and improve the quality of our services (a) Identity

(b) Contact

(c) Health

(d) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation

Article 9(2)(h) – healthcare and social care purposes
To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you (a) Identity 

(b) Contact 

(c) Profile 

(d) Usage 

(e) Marketing and Communications 

(f) Technical

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) Not applicable – no Health Data used
To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing a) Technical 

(b) Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) Not applicable – no Health Data used
To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to you based on your Profile Data (a) Identity 

(b) Contact 

(c) Technical 

(d) Usage 

(e) Profile 

(f) Marketing and Communications

Necessary for our legitimate interests (to carry out direct marketing, develop our products/services and grow our business)  Not applicable – no Health Data used
To carry out market research through your voluntary participation in surveys (a) Identity 

(b) Contact 

(c) Technical 

(d) Usage 

(e) Profile 

(f) Marketing and Communications

Necessary for our legitimate interests (to study how customers use our products/services and to help us improve and develop our products and services).  Not applicable – no Health Data used
Co-operate with regulators, like the Care Quality Commission (a) Identity 

(b) Contact 

(c) Health

(d) Profile

(e) Marketing and Communications

Article 6(1)(c) – compliance with a legal obligation Article 9(2)(g) – substantial public interest
  • Deal appropriately with any risk to public health
(a) Identity 

(b) Contact 

(c) Health

(d) Profile

(e) Marketing and Communications

Article 6(1)(c) – compliance with a legal obligation

Article 6(1)(f) – legitimate interests (we have a legitimate interest in being able to respond appropriately)

Article 9(2)(i) – public health
Comply with a legal obligation, like a court order requiring us to release information and anti-money laundering rules (a) Identity 

(b) Contact 

(c) Health

(d) Financial

(e) Transaction

(f) Profile

(g) Technical 

(h) Usage 

(i) Marketing and Communications

Article 6(1)(c) – compliance with a legal obligation Article 9(2)(f) – establishment, exercise or defence of legal claims

Article 9(2)(g) – substantial public interest

Deal with disputes and legal claims (a) Identity 

(b) Contact 

(c) Health

(d) Financial

(e) Transaction

(f) Profile

(g) Technical 

(h) Usage 

(i) Marketing and Communications

Article 6(1)(f) – legitimate interests (we have a legitimate interest in being able to deal with disputes and legal claims) Article 9(2)(f) – establishment, exercise or defence of legal claims
To obtain advice from our professional advisers, such as accountants and auditors (a) Identity 

(b) Contact 

(c) Health

(d) Financial

(e) Transaction

(f) Profile

(g) Technical 

(h) Usage 

(i) Marketing and Communications

Article 6(1)(f) – legitimate interests (we have a legitimate interest in being able to seek and obtain professional advice) Article 9(2)(f) – establishment, exercise or defence of legal claims

Article 9(2)(h) – healthcare and social care purposes

  • In connection with, or during negotiations of, any merger, sale of assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or into another company.
(a) Identity 

(b) Contact 

(d) Financial

(e) Transaction

(f) Profile

(g) Technical 

(h) Usage 

(i) Marketing and Communications

Article 6(1)(f) – legitimate interests (we have a legitimate interest in being able to participate in such negotiations/ transactions) Not applicable – no Health Data used

If we supply you with products and consulting services, this will be done in accordance with our Customer Terms and Conditions. We are not able to provide health-related service unless you provide us with relevant Health Data and keep that information complete and accurate.

We may also use any of your data, except your Health Data, for our legitimate interests including:

  • Providing you with information on services products and feedback.
  • Keeping our records up to date.
  • For statistical research and analysis and to enable us to monitor and improve services.
  • To monitor how we are meeting our clinical and non-clinical performance in the case of health care providers.
  • Sharing your personal information with people or organisations in order to comply with any legal or regulatory obligations or to enable us to run our organisation.
  • To fulfil laws that apply to us and the third parties we work with.
  • To take part in or be the subject of any merger
  • Managing our relationships with you and third parties who assist us to provide the services to you.

 

5. Who do we share your data with?

We may share your data with our service providers, sub-contractors, consultants and agents that we may appoint to perform functions on our behalf and in accordance with our instructions, including IT service providers, group companies, accountants, auditors and lawyers.

We shall provide our service providers, sub-contractors, consultants and agents only with such of your data as they need to provide the service for us and if we stop using their services, we shall request that they delete your data or make it anonymous within their systems

As noted above, our business relies on collaboration with third parties such as our prescribers, pharmacies, and blood testing companies, so we will share data about you with them – in particular your Contact Data and Health Data. Again, you acknowledge that we cannot provide consulting services or products to you unless we share your Contact Data and Health Data with these third parties.

If in accordance with our Customer Terms and Conditions we need to verify your identification, we shall share some of your Contact Data and Identity Data with our verification partners.

To facilitate the delivery of your order to you, you also understand and agree that we will use third-party delivery companies (such as Royal Mail and other delivery service companies) to deliver products to you and so we shall share your Contact Data with them.

To evaluate the performance of our business at a granular level we may occasionally send data to validated third parties for the purposes of evaluating ongoing performance.

We ensure that any data we disclose in accordance with our Policy is kept to the minimum required to allow the safe and effective delivery of services to you, and will never knowingly share with third parties who do not comply with data protection rules.

Only with your consent shall we provide your data, including your Health Data, to your own GP.

If we need to use your data to comply with any legal obligations, demands or requirements (for example, as part of anti-money laundering processes or to protect a third party’s rights, property, or safety), then in doing so, we may share your data with third party authorities and regulatory organisations and agencies.

If we choose to merge, sell assets, consolidate or restructure, finance, or sell all or a portion of our business by or into another company then the new owners may use your data in the same way that we do as set out in this Policy.

We may also occasionally use your data to receive feedback about our services.

6. Third Party Service providers

Currently, we work with the following third party service providers:

7. Where we store your data

The data that we collect from you may be transferred to, and stored at, a destination outside the United Kingdom and/or European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of services.

Where your data is transferred outside the United Kingdom and/or the EEA, it will only be transferred to countries that have been identified as providing adequate protection for data (this includes transfers to the US where the US organisation is participating in the US/ UK data bridge) or to a third party where we have approved transfer mechanisms in place to protect your data – i.e., by entering into the Information Commissioner’s International Data Transfer Agreement (IDTA) or IDTA Addendum, 

8. Information security

We take appropriate security measures to protect against unauthorised access to or unauthorised alteration, disclosure or destruction of data. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

These include internal reviews of our data collection, storage and processing practices and security measures, including appropriate encryption and physical security measures to guard against unauthorised access to systems where we store data.

All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology.

Where we have given you (or where you have chosen) a password which enables you to access certain parts of our online properties, you are responsible for keeping this password confidential. You should not share this password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your data, we cannot guarantee the security of your data transmitted to our site. Any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. Marketing

You may request or consent to receive marketing email messages such as special offers from us about our website and our services and business generally. You may do so by ticking the ‘Please keep me updated’ box when you sign up.

You can choose to no longer receive such marketing emails from us by contacting us via email at help@medicspot.co.uk. You can also opt out by clicking “Unsubscribe” at the bottom of any marketing email.

If you ask us to remove you from our marketing list, we shall keep a record of your name and email address to ensure that we do not send you marketing information.

10. Your rights

You have a number of rights under applicable data protection legislation. Some of these rights are complex, and not all of the details have been included below. You can exercise any of these rights at any time by contacting us at help@medicspot.co.uk.

  • Right of access: you have the right to obtain from us a copy of the data that we hold for you, and check that we are lawfully processing it.
  • Right to rectification: you can require us to correct errors in the data that we process for you if it is inaccurate, incomplete or out of date, though we may need to verify the accuracy of the new data you provide to us.
  • Right to portability: you can request that we transfer your data to another service provider if you initially provided consent for us to use the data or where we used the data to perform a contract with you. 
  • Right to restrict or object to processing: in certain circumstances, you have the right to require that we restrict the processing of your data if you believe our processing impacts on your fundamental rights and freedoms. However, we may demonstrate that we have legitimate grounds to process your data not withstanding your rights and freedoms.
  • Right to be forgotten: you also have the right at any time to require that we delete the data that we hold for you, where it is no longer necessary for us to hold it. However, whilst we respect your right to be forgotten, we may still retain your data in accordance with applicable laws, and when we respond to your request we shall notify you of any specific legal reasons that we have to retain your data.
  • Right to stop receiving marketing information: you can ask us to stop sending you information about our services, but please note we shall continue to contact you in relation to any matters relating to your account, if you have one.
  • Right to request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Request restriction of processing your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios: 
    • If you want us to establish the data’s accuracy;
    • Where our use of the data is unlawful but you do not want us to erase it;
    • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
    • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Note that there are some exceptions to these rights set out in the data protection legislation, which may apply to requests made by you.

We reserve the right to charge an administrative fee if your request in relation to your rights is manifestly unfounded or excessive.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

 

If you have any complaints in relation to this Policy or otherwise in relation to our processing of your data, please tell us by contacting help@medicspot.co.uk. We shall review and investigate your complaint and try to get back to you within a reasonable time. You do also have the right to contact the Information Commissioner (see www.ico.org.uk), or if you are based outside of the United Kingdom, please contact your local regulatory authority.

11. Retention of data

We will retain data in accordance with applicable laws for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

We typically archive electronic patient records including your personal information, communication and treatments for a minimum of 10 years, and basic information such as Contact, Identity, Financial and Transactional Data for 7 years after you cease to be a customer

Where we have no legal basis for continuing to process your data, we shall either delete or anonymise it.

13. Cookies


What are cookies?

We use cookies on our website. Cookies are small pieces of data that are stored on your computer, mobile phone or other devices.

 

We also use pixels, which are small blocks of code on web pages that do things like allow another server to measure viewing of a webpage. These are often used in connection with cookies.

 

We also use other tracking technologies like web beacons (sometimes called “tracking beacons” or “clear gifs”) and local storage. These are tiny graphics files that contain a unique identifier that enable us to recognise when someone has visited our website or opened an email that we have sent them.

 

You can find more information about cookies at AboutCookies.org and AllAboutCookies.org.

 

How we use cookies

 

Cookies help us to operate our website and provide services to you. In particular, they can:

 

  • Make your online experience more efficient and enjoyable, including by recognising you when you return to our website and by customising the website according to your individual interests.
  • Enhance and customise your experience across our website, including by speeding up your searches.
  • Enable us to perform research and carry out analytics.
  • Deliver advertising and marketing that is relevant to you.


Third party cookies enable third party features or functionality to be provided on or through our website, such as advertising, interactive content and analytics. These third parties are responsible for the cookies they set on our website and we have no control over them.

 

What cookies do we use?

 

We use the following cookies:

 

  • Strictly necessary cookies. These are cookies that are required for the operation of our website. These essential cookies are always enabled because our website won’t work properly without them. For instance, cookies to enable you to log in to access our services, or cookies that are needed to take advantage of our e-billing services.
  • Performance cookies. These cookies allow us to track how our users use our website, the number of visits on each page, and behaviour on each page. This helps us optimise our website so you can find the things you are looking for and have the best experience possible.
  • Functionality cookies. These cookies allow us to recognise you by name and create a more personalised experience for you by remembering your preferences.
  • Analytics cookies. These cookies record your visit to our website, the pages you have visited and the links you may have clicked. We will use this information to curate services and content based on your needs. This information may also be shared with third-party providers.
  • Advertising cookies. We use cookies to help us show adverts to you from other websites across the internet based on your actions on our website and elsewhere. If you have viewed a page about erectile dysfunction on our website, we may advertise our prescribing services to you on other websites. If you would like more information on behavioural advertising/retargeting, including how to opt out of it, please visit https://www.cookieyes.com.


What technical information do we collect about your device?

 

We collect the following information about the device you are using to access our website:

 

  • The type of device you use.
  • Network information.
  • Your operating system.
  • Your IP address.
  • The browser you are using and what version it is.
  • Your time zone setting.
  • Usage data

 

We collect usage data about your activities on our website, including:

 

  • The full Uniform Resource Locators (URL) clickstream to, through and from our online properties (including date and time).
  • The different types of services/products you viewed or searched for.
  • Page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
  • Any phone number used to call our customer service number.


How can you control cookies?

 

You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. However, if you select this setting you may be unable to access certain parts of our online services. Unless you have adjusted your browser’s settings so that it will refuse cookies or you have selected the reject cookies option when you land on our site, our system will issue cookies.      

 

To change your cookie settings, or if you want to be notified each time a cookie is about to be used, you should amend the settings provided in your web browser to prevent us from storing cookies on your computer hard drive.

 

Most advertising networks also offer you the option to opt out of targeted advertising. For more info, visit http://www.aboutads.info/choices/ .

 

You can manage your cookie settings by following your browser’s instructions. Here are some links that might be of assistance:

 

Google Chrome

https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en

Microsoft Internet Explorer

https://support.microsoft.com/en-nz/help/17442/windows-internet-explorer-delete-manage-cookies

Mozilla Firefox

https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences

Safari

https://support.apple.com/en-nz/guide/safari/manage-cookies-and-website-data-sfri11471/mac

Microsoft Edge

https://support.microsoft.com/en-gb/help/4468242/microsoft-edge-browsing-data-and-privacy-microsoft-privacy

 

Except for essential cookies, all cookies will expire after 1 year.

13. General

Our website may contain links to third party websites, plug-ins and applications. We are not responsible for the content of such third party content, or their privacy statement/s. If you provide any information to the third party, then you should check the third party website to find the applicable privacy policy.

Any changes we may make to our Policy in the future will be posted on this page and, if the changes substantially affect your rights or obligations, we shall notify you if we have your email address.

Questions, comments and requests regarding this Policy are welcomed and should be addressed to Outcome Diagnostics Limited, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ or via email at help@medicspot.co.uk.

This Policy was last updated on 13/09/2024. You may contact us if you wish to review any previous version.

Same Day Appointments Often Available

Don't stand for queuing. See a doctor in minutes