Privacy Policy
This is the privacy notice for the collection and use of personal data by Ultralase Eye Clinics Limited. Our registered office is at 96 Bristol Road, Birmingham, B5 7XJ.
Joint Controllers
Ultralase Eye Clinics Limited (Ultralase) is part of the Eye Hospital Group Limited that also includes Optimax Clinics Limited (Optimax).
Optimax and Ultralase are considered joint data controllers under the General Data Protection Regulation (GDPR), as we jointly determine why and how your personal data will be processed.
When we collect your personal data, it is stored in the same systems and processed for the same purposes whether you are a patient of Optimax or Ultralase. This allows us to provide services to you from any of our clinics throughout the UK.
You can view the Ultralase Privacy Notice here or by requesting a copy from the clinic staff.
The rights detailed below you have under GDPR, such as to access your personal data, are still available to both Optimax and Ultralase. To make this as simple as possible we have a single point of contact and will ensure your request is completed on behalf of both controllers.
Contact
Please contact us if you have any queries regarding this privacy notice, concerns over your personal data, or if you wish to exercise your rights as a data subject.
Our GDPR Owner can be contacted via gdprowner@ultralase.com, 0800 988 6390, or F.A.O. GDPR Owner, Customer Services, 172 Lincoln Road, Peterborough PE1 2NW.
Our Data Protection Officer is provided by RGDP LLP and can be contacted via info@rgdp.co.uk, 0131 222 3239, or One Edinburgh Quay, 133 Fountainbridge, Edinburgh EH3 9QG.
Introduction
This privacy notice explains how we collect and use personal data about you. In general, we use personal data to:
- Assist you with any enquiries and to make appointments
- To treat you as our patient
- To provide you with information and offers related to our products and services
- Maintain our records
Exactly what data we may collect and how we may use it, is determined by the services you receive from us for e.g. you may have made an enquiry and be a patient.
If you make an enquiry
If you make an enquiry directly to us by contacting our customer services team, filling out an enquiry form on our website or via social media or make an enquiry via a third party such as a price comparison website.
Personal data, Purpose and Legal Basis
We collect, use and store different types of personal data about you. Detailed below is the data we may collect, what it is used for and our legal basis for processing this data.
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To allow us to contact you regarding your enquiry |
To potentially enter into a contract with you |
Communications Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded) |
To maintain a record of our communications with you in order to potentially provide you with a service |
To potentially enter into a contract with you
|
Tracking information* Pixels, ad tags, cookies which can be seen / changed at:
https://www.ultralase.com/about-us/cookie-policy/
*only relevant if you use our website |
To allow us to understand user behaviour to improve our website and give the best possible experience to those learning about our services
Serve tailored online advertising to share benefits of our services that you may have missed on our website |
With your consent And/or legitimate interests |
Marketing Preferences |
To maintain a record of your marketing choices To send marketing communications to you |
With your consent* And/or legitimate interests
|
*Consent to Marketing
You can update your preferences or withdraw your consent to Marketing at any time by:
- Clicking unsubscribe from any email you receive
- By contacting our customer service team 172 Lincoln Road, Peterborough, PE1 2NW or calling us on 0800 988 6390
- By emailing enquiries@ultralase.com
If you attend an appointment
When you visit one of our clinics for an appointment.
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To contact you regarding your appointment |
Necessary for our contract with you
|
Occupation |
To ensure you receive the correct advice in relation to your occupation |
Necessary for our contract with you
|
Health Information e.g. prescription, biometry, existing health conditions, medications |
To provide you with the relevant advice and treatment |
Necessary for our contract with you
Necessary to meet a Legal Obligation
Article 9: Necessary for the provision of healthcare |
Ethnic Origin
|
To provide you with the relevant advice and treatment. (some conditions run in families and can affect your suitability for treatment) |
Necessary for our contract with you
Article 9: Necessary for the provision of healthcare |
CCTV Images |
To protect our premises and staff |
Legitimate Interests |
Communications Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded) |
To maintain a record of our communications with you in order to potentially provide you with a service |
Necessary for our contract with you
|
If you receive treatment
When you visit one of our clinics (or another treatment centre) for an appointment
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To contact you regarding treatment or aftercare |
Necessary for our contract with you
|
Health Information e.g. prescription, biometry, existing health conditions, medications |
To provide you with the relevant advice and treatment |
Necessary for our contract with you
Article 9: Necessary for the provision of healthcare |
Ethnic Origin
|
To provide you with the relevant advice and treatment. (some conditions run in families and can affect your suitability for treatment) |
Necessary for our contract with you
Article 9: Necessary for the provision of healthcare |
Payment details e.g. bank details for direct debit |
To take payment |
Necessary for our contract with you
Necessary to meet a Legal Obligation
|
Communications Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded) |
To maintain a record of our communications with you in order to potentially provide you with a service |
Necessary for our contract with you
|
If you use Our Finance Options
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To verify your identity and contact you regarding your finance agreement |
Necessary for our contract with you |
Employer |
To assess if you are eligible for credit |
Necessary for our contract with you
|
Financial information |
To assess if you are eligible for credit |
Necessary for our contract with you
|
If you have been referred for treatment under an NHS contract
Patients may be referred for treatment as part of a contract with an NHS trust or NHS CCG
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To contact you regarding consultation, treatment or follow up care |
Necessary for our contractwith you |
Health Information e.g. existing health conditions, medications and allergies, records related to treatment provided |
To provide you with the relevant treatment or healthcare service |
Necessary for our contract with you
Article 9: Necessary for the provision of healthcare |
Communications Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded) |
To maintain a record of our communications with you in order to potentially provide you with a service |
Necessary for our contract with you |
NB: We are compliant with the National Data Opt-Out Policy as we do not share any personal data for the purposes of research or planning.
If you are a Surgeon’s Private Patient
If Ultralase facilities are being used by your Surgeon for your treatment, we are required to collect personal data about you to ensure that we keep accurate records to evidence any treatment carried out on our premises
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name)` |
To maintain records of the treatment carried out in our premises |
Necessary for a Legal Obligation |
Health Information |
To maintain records of the treatment carried out in our premises |
Necessary for a Legal Obligation
Article 9: Necessary for the provision of health care or treatment |
CCTV Images |
To protect our premises and staff |
Legitimate Interests |
If you apply for a job
Personal data, Purpose and Legal Basis
Personal Data |
Purpose for processing |
Our legal basis for processing |
Personal contact details (name, address, email, telephone number) |
To contact you regarding the recruitment process and any offer of employment |
To enter into a contract with you |
Information about a disability, the effects of that disability, and adjustments that may need to be made during the recruitment process |
To allow for reasonable adjustments to the recruitment process for disabled applicants
|
To comply with a legal obligation To exercise rights and obligations under employment law. |
Information provided in your CV, covering letter or application form. (Education, Qualifications, Experience)
Information gathered from interview notes or assessments |
To make a decision about your suitability for the role applied for.
|
To enter into a contract with you.
|
Offer letter, and proposed employment contract |
To provide you with details of the terms and conditions of the potential contract between you and Ultralase. |
To enter into a contract with you. To comply with a legal obligation
|
Information on your right to work in the UK (copies of identity documents) |
To evidence and record your right to work in the UK |
To enter into a contract with you. To comply with a legal obligation
|
Where we collect your personal information from
- NHS Hospital trusts and CCG's
- Directly from you
- Health Professionals
- Third party referrals
- Finance Providers
- Google Analytics
- Recruitment Agencies
- Former employers or other referees
Who we may share your data with
We may share your personal data with the following:
- Third parties who provide us with services such as Email and Postal services
- Relevant regulators, e.g. Care Quality Commission
- Legal advisors and Insurance providers
- Other treatment centres
- Finance Providers
- The police and other law enforcement agencies where we have a legal or regulatory obligation to do so
Third Parties
We may use third parties (data processors) as required to deliver certain services, such as, IT systems, software providers, confidential waste disposal, records storage, email and postal distribution, surveys who will process personal information on our behalf and only on our instruction.
We conduct an appropriate level of due diligence and put in place contractual documentation in relation to any contractor to ensure that they process personal information appropriately and according to our legal and regulatory obligations.
Your Rights
You have the following rights in respect of the personal data we process about you:
- Right of access – you have the right to request a copy of the information that we hold about you.
- Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
- Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
- Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
- Right of portability – you have the right to have the data we hold about you transferred to another organisation.
- Right to object – you have the right to object to certain types of processing such as direct marketing.
- Right to object to automated processing, including profiling – you also have the right to be subject to the legal effects of automated processing or profiling.
- Right to withdraw your consent – if you have given your consent for us to process your data you have the right to withdraw this at any time.
Security
We are fully committed to keeping your personal data secure and we have implemented appropriate information security policies, rules and technical measures to protect the personal data that we have under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss.
International Transfers
Most of your data is processed in the UK, but some is processed in the EEA. If your data is to be processed outside the UK or the EEA in the future, then we will ensure that it is protected to the same standards as if it were being processed within the UK by using appropriate safeguards.
Retention
We keep your personal data only for as long as necessary for the purposes of:
- Providing you with the services you have requested;
- to maintain records of treatment;
- to support a claim or to defend ourselves against legal proceedings
- to comply with the law
Our retention schedule is available on request.
Complaints
We aim to resolve all complaints about how we handle personal data directly and would like you to give us the opportunity to address any concern you have by contacting us by email at GDPROwner@ultralase.com, writing to us – F.A.O. GDPR Owner, 172 Lincoln Road, Peterborough PE1 2NW or calling us on 0800 988 6390.
You also have the right to make a complaint directly with the Information Commissioner’s Office (ICO). https://ico.org.uk/ 0303 123 1113
Changes to our privacy notice
We keep this privacy notice under regular review and will place any updated versions in our clinics Patient Guidebook. If you would like a copy of this statement printed or sent to you, please contact us via email to enquiries@ultralase.com, writing to us – Customer Services, 172 Lincoln Road, Peterborough PE1 2NW or calling us on 0800 988 6390.
This privacy notice was last updated on 18th August 2022.