Data Retention & Security Policy

    Last Updated: 06.02.2025

    At MD.co.uk , we prioritize the security of your personal information and the proper management of your data. This Data Retention & Security Policy outlines how we retain and secure your data, ensuring its confidentiality, integrity, and availability when using our services. By using the MD.co.uk platform, you agree to the practices described in this policy.

    1. Data Retention

    1.1 Purpose of Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing healthcare services, processing transactions, and complying with legal obligations.

    1.2 Data Retention Period

    We will retain your personal information for a reasonable period based on the following criteria:

    • To provide ongoing healthcare services
    • To meet legal, regulatory, or contractual obligations
    • For business and operational purposes, such as auditing and accounting

    Once your data is no longer needed for these purposes, we will securely dispose of or anonymize it, in accordance with industry standards.

    1.3 Data Deletion Requests

    You have the right to request the deletion of your personal data. If you no longer require our services or wish to withdraw consent, you can request the deletion of your data, subject to any legal or contractual obligations that may require us to retain certain information.

    2. Data Security

    2.1 Security Measures

    We have implemented a range of physical, electronic, and administrative security measures to protect your data from unauthorized access, alteration, or destruction. These include:

    • Encryption technologies for data storage and transmission
    • Access controls and secure authentication methods
    • Regular security audits and vulnerability assessments

    2.2 Secure Data Storage

    Your data is securely stored in encrypted databases, ensuring that only authorized personnel have access. We utilize best practices for cloud storage and on-premise data protection to safeguard sensitive information.

    2.3 Data Access Control

    Access to personal data is restricted to authorized personnel who require it to perform their job duties. Each user’s access is governed by their role and permission level, ensuring that sensitive data is only accessible to those who need it.

    2.4 Third-Party Security

    We work with trusted third-party service providers who assist us in delivering our services. These providers are contractually obligated to adhere to data security standards and implement appropriate safeguards to protect your personal data.

    2.5 Data Breach Response

    In the unlikely event of a data breach, we have a comprehensive response plan in place. If any personal data is compromised, we will promptly notify affected individuals and relevant authorities, as required by applicable laws, and take immediate steps to mitigate any risks.

    3. Compliance with Legal and Regulatory Standards

    3.1 Legal Compliance

    We are committed to complying with relevant data protection and privacy laws, including the General Data Protection Regulation (GDPR) and the Data Protection Act of 2018. Our data retention and security practices are designed to meet or exceed the standards set by these regulations.

    3.2 Data Protection Officer (DPO)

    MD.co.uk has appointed a Data Protection Officer to oversee compliance with data protection laws and ensure that we adhere to best practices for data security. The DPO is available to answer any questions you may have regarding the security and retention of your personal data.

    4. Your Rights and Responsibilities

    4.1 Access and Correction

    You have the right to request access to the personal data we hold about you, as well as request corrections to any inaccurate or incomplete data.

    4.2 Data Retention Requests

    If you believe that your personal data has been retained beyond the necessary period, you may request that we review and delete such data.

    4.3 Responsibility for Secure Access

    You are responsible for maintaining the confidentiality of your login credentials and ensuring that your account is protected from unauthorized access. We advise you to regularly change your password and ensure that it is unique and strong.

    5. Changes to This Policy

    We reserve the right to update or modify this Data Retention & Security Policy at any time. Any changes will be posted on this page, and the "Last Updated" date will be revised accordingly. We encourage you to review this policy periodically to stay informed about how we protect your data.

    6. Contact Us

    If you have any questions or concerns about this Data Retention & Security Policy or how we manage and secure your data, please contact us at:

    MD.co.uk

    Suite 248, Linen Hall 162-168 Regent Street, London W1B 5TB

    Email: [email protected]

    Phone: 020 71832362

    logo

    MD.co.uk offers instant access to private GP appointments, consultations, and a wide range of medical services in London. Enjoy same-day care without leaving your NHS GP practice.

    Disclaimer

    The content provided on md.co.uk regarding various medical conditions and their respective treatments is intended for informational purposes only. It does not cover the full spectrum of health conditions or the array of treatment options that may be available. This information should not be considered a substitute for professional consultations with qualified healthcare professionals, including general practitioners and specialists. Accessing and using md.co.uk does not establish a doctor-patient relationship. We strongly encourage you to seek personalised medical advice from a healthcare professional before making any decisions based on the information found on our website. Your health and well-being are paramount, and professional guidance is crucial for effective health management.

    © 2024 MD.co.uk. All rights reserved.