Privacy Policy

This is the privacy notice for the collection and use of personal data by Ultralase Eye Clinics Limited. Our registered office is at 96 Bristol Road, Birmingham, B5 7XJ.

 

Joint Controllers

Ultralase Eye Clinics Limited (Ultralase) is part of the Eye Hospital Group Limited that also includes Optimax Clinics Limited (Optimax).

Optimax and Ultralase are considered joint data controllers under the General Data Protection Regulation (GDPR), as we jointly determine why and how your personal data will be processed.

When we collect your personal data, it is stored in the same systems and processed for the same purposes whether you are a patient of Optimax or Ultralase. This allows us to provide services to you from any of our clinics throughout the UK.

You can view the Ultralase Privacy Notice here or by requesting a copy from the clinic staff.

The rights detailed below you have under GDPR, such as to access your personal data, are still available to both Optimax and Ultralase. To make this as simple as possible we have a single point of contact and will ensure your request is completed on behalf of both controllers.

Contact

Please contact us if you have any queries regarding this privacy notice, concerns over your personal data, or if you wish to exercise your rights as a data subject. 

Our GDPR Owner can be contacted via gdprowner@ultralase.com, 0800 988 6390, or F.A.O. GDPR Owner, Customer Services, 172 Lincoln Road, Peterborough PE1 2NW.

Our Data Protection Officer is provided by RGDP LLP and can be contacted via info@rgdp.co.uk, 0131 222 3239, or One Edinburgh Quay, 133 Fountainbridge, Edinburgh EH3 9QG. 

Introduction

This privacy notice explains how we collect and use personal data about you. In general, we use personal data to:

  • Assist you with any enquiries and to make appointments
  • To treat you as our patient
  • To provide you with information and offers related to our products and services
  • Maintain our records

Exactly what data we may collect and how we may use it, is determined by the services you receive from us for e.g. you may have made an enquiry and be a patient.

If you make an enquiry

If you make an enquiry directly to us by contacting our customer services team, filling out an enquiry form on our website or via social media or make an enquiry via a third party such as a price comparison website.

Personal data, Purpose and Legal Basis

We collect, use and store different types of personal data about you. Detailed below is the data we may collect, what it is used for and our legal basis for processing this data.

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To allow us to contact you regarding your enquiry

To potentially enter into a contract with you

Communications

Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded)

To maintain a record of our communications with you in order to potentially provide you with a service

To potentially enter into a contract with you

 

Tracking information*

Pixels, ad tags, cookies which can be seen / changed at:

 

https://www.ultralase.com/about-us/cookie-policy/

 

 

 

*only relevant if you use our website

To allow us to understand user behaviour to improve our website and give the best possible experience to those learning about our services

 

Serve tailored online advertising to share benefits of our services that you may have missed on our website

With your consent

And/or legitimate interests

Marketing Preferences

To maintain a record of your marketing choices

To send marketing communications to you

With your consent*

And/or legitimate interests

 

 

*Consent to Marketing

You can update your preferences or withdraw your consent to Marketing at any time by:

  • Clicking unsubscribe from any email you receive
  • By contacting our customer service team 172 Lincoln Road, Peterborough, PE1 2NW or calling us on 0800 988 6390
  • By emailing enquiries@ultralase.com

If you attend an appointment

When you visit one of our clinics for an appointment.

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To contact you regarding your appointment

Necessary for our contract with you

 

Occupation

To ensure you receive the correct advice in relation to your occupation

Necessary for our contract with you

 

 

Health Information

e.g. prescription, biometry, existing health conditions, medications

To provide you with the relevant advice and treatment

Necessary for our contract with you

 

Necessary to meet a Legal Obligation

 

Article 9: Necessary for the provision of healthcare

Ethnic Origin

 

To provide you with the relevant advice and treatment. (some conditions run in families and can affect your suitability for treatment)

Necessary for our contract with you

 

Article 9: Necessary for the provision of healthcare

CCTV Images

To protect our premises and staff

Legitimate Interests

Communications

Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded)

To maintain a record of our communications with you in order to potentially provide you with a service

Necessary for our contract with you

 

 

If you receive treatment

When you visit one of our clinics (or another treatment centre) for an appointment

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To contact you regarding treatment or aftercare

Necessary for our contract with you

 

Health Information

e.g. prescription, biometry, existing health conditions, medications

To provide you with the relevant advice and treatment

Necessary for our contract with you

 

Article 9: Necessary for the provision of healthcare

Ethnic Origin

 

To provide you with the relevant advice and treatment. (some conditions run in families and can affect your suitability for treatment)

Necessary for our contract with you

 

Article 9: Necessary for the provision of healthcare

Payment details

e.g. bank details for direct debit

To take payment

Necessary for our contract with you

 

Necessary to meet a Legal Obligation

 

Communications

Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded)

To maintain a record of our communications with you in order to potentially provide you with a service

Necessary for our contract with you

 

 

If you use Our Finance Options

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To verify your identity and contact you regarding your finance agreement

Necessary for our contract with you

Employer

To assess if you are eligible for credit

Necessary for our contract with you

 

 

Financial information

To assess if you are eligible for credit

Necessary for our contract with you

 

 

If you have been referred for treatment under an NHS contract

Patients may be referred for treatment as part of a contract with an NHS trust or NHS CCG

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To contact you regarding consultation, treatment or follow up care

Necessary for our contractwith you

Health Information

e.g. existing health conditions, medications and allergies, records related to treatment provided

To provide you with the relevant treatment or healthcare service

Necessary for our contract with you

 

Article 9: Necessary for the provision of healthcare

Communications

Information we may learn about you from emails, calls, letter between us. (Calls to customer services are recorded)

To maintain a record of our communications with you in order to potentially provide you with a service

Necessary for our

contract with you

NB: We are compliant with the National Data Opt-Out Policy as we do not share any personal data for the purposes of research or planning.

 

If you are a Surgeon’s Private Patient

If Ultralase facilities are being used by your Surgeon for your treatment, we are required to collect personal data about you to ensure that we keep accurate records to evidence any treatment carried out on our premises

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name)`

To maintain records of the treatment carried out in our premises

Necessary for a Legal Obligation

Health Information

To maintain records of the treatment carried out in our premises

Necessary for a Legal Obligation

 

Article 9: Necessary for the provision of health care or treatment

CCTV Images

To protect our premises and staff

Legitimate Interests

If you apply for a job

Personal data, Purpose and Legal Basis

Personal Data

Purpose for processing

Our legal basis for processing

Personal contact details (name, address, email, telephone number)

To contact you regarding the recruitment process and any offer of employment

To enter into a contract with you

Information about a disability, the effects of that disability, and adjustments that may need to be made during the recruitment process

To allow for reasonable adjustments to the recruitment process for disabled applicants

 

To comply with a legal obligation

To exercise rights and obligations under employment law.

Information provided in your CV, covering letter or application form. (Education, Qualifications, Experience)

 

Information gathered from interview notes or assessments

To make a decision about your suitability for the role applied for.

 

 

To enter into a contract with you.

 

 

Offer letter, and proposed employment contract

To provide you with details of the terms and conditions of the potential contract between you and Ultralase.

To enter into a contract with you.

To comply with a legal obligation

 

Information on your right to work in the UK (copies of identity documents)

To evidence and record your right to work in the UK

To enter into a contract with you.

To comply with a legal obligation

 

 

Where we collect your personal information from

  • NHS Hospital trusts and CCG's
  • Directly from you
  • Health Professionals
  • Third party referrals
  • Finance Providers
  • Google Analytics
  • Recruitment Agencies
  • Former employers or other referees

Who we may share your data with

We may share your personal data with the following:

  • Third parties who provide us with services such as Email and Postal services
  • Relevant regulators, e.g. Care Quality Commission
  • Legal advisors and Insurance providers
  • Other treatment centres
  • Finance Providers
  • The police and other law enforcement agencies where we have a legal or regulatory obligation to do so

Third Parties

We may use third parties (data processors) as required to deliver certain services, such as, IT systems, software providers, confidential waste disposal, records storage, email and postal distribution, surveys who will process personal information on our behalf and only on our instruction.

We conduct an appropriate level of due diligence and put in place contractual documentation in relation to any contractor to ensure that they process personal information appropriately and according to our legal and regulatory obligations.

Your Rights

You have the following rights in respect of the personal data we process about you:

  • Right of access – you have the right to request a copy of the information that we hold about you.
  • Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
  • Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
  • Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
  • Right of portability – you have the right to have the data we hold about you transferred to another organisation.
  • Right to object – you have the right to object to certain types of processing such as direct marketing.
  • Right to object to automated processing, including profiling – you also have the right to be subject to the legal effects of automated processing or profiling.
  • Right to withdraw your consent – if you have given your consent for us to process your data you have the right to withdraw this at any time.

Security

We are fully committed to keeping your personal data secure and we have implemented appropriate information security policies, rules and technical measures to protect the personal data that we have under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss.

International Transfers

Most of your data is processed in the UK, but some is processed in the EEA. If your data is to be processed outside the UK or the EEA in the future, then we will ensure that it is protected to the same standards as if it were being processed within the UK by using appropriate safeguards.

Retention

We keep your personal data only for as long as necessary for the purposes of:

  1. Providing you with the services you have requested;
  2. to maintain records of treatment;
  3. to support a claim or to defend ourselves against legal proceedings
  4. to comply with the law

Our retention schedule is available on request.

Complaints

We aim to resolve all complaints about how we handle personal data directly and would like you to give us the opportunity to address any concern you have by contacting us by email at GDPROwner@ultralase.com, writing to us – F.A.O. GDPR Owner, 172 Lincoln Road, Peterborough PE1 2NW or calling us on 0800 988 6390.

You also have the right to make a complaint directly with the Information Commissioner’s Office (ICO). https://ico.org.uk/ 0303 123 1113

Changes to our privacy notice

We keep this privacy notice under regular review and will place any updated versions in our clinics Patient Guidebook. If you would like a copy of this statement printed or sent to you, please contact us via email to enquiries@ultralase.com, writing to us – Customer Services, 172 Lincoln Road, Peterborough PE1 2NW or calling us on 0800 988 6390.

 

This privacy notice was last updated on 18th August 2022.