MEDIPARTNER LTD PRIVACY NOTICE
September 2026 Version 2.0
This notice explains how MEDIPARTNER LTD collects and uses personal data when you apply for or use the Wellbeing Services, contact us, or receive communications from us. It also explains your rights and how to contact us or the Information Commissioner's Office.
1 Who We Are
MEDIPARTNER LTD is the controller of the personal data described in this notice unless we tell you that another organisation is the controller for a particular service.
Our company number is 12823291. Our registered office is Westhill House, 1st Floor, Devonshire Road, Bexleyheath, England, DA6 8DS.
You can contact us about this notice or your personal data by emailing complaints@medipartner.co.uk or writing to the registered office above. Please mark correspondence for the attention of Data Protection.
2 The Personal Data We Collect
Depending on how you interact with us and which services you use, we may collect the following categories of personal data:
- identity and eligibility information, including your name, date of birth, membership status and unique identification number;
- contact information, including your postal address, email address and telephone number;
- account and technical information, including login records, device information, IP address, browser type, security logs and cookie identifiers;
- membership and service information, including the benefits you use, appointments, referrals, communications and support requests;
- payment and transaction information where you pay Membership Fees directly;
- marketing preferences and records of consent, unsubscribe requests and engagement with messages; and
- correspondence, complaints, feedback and any other information you give us.
Health information is special category data and receives additional protection under data protection law.
3 How We Obtain Personal Data
We normally collect personal data directly from you through an application, the Portal, questionnaires, calls, emails, website forms and cookies or similar technologies.
We may also receive personal data from your insurer, your employer, or another scheme sponsor, where Membership is provided through a Group Scheme, healthcare and technology providers, payment providers, and another person acting with your authority. Where we receive data from another source, we will provide any additional privacy information required by law.
4 How and Why We Use Personal Data
We use personal data only where we have a lawful basis under the UK GDPR. The main purposes and bases are set out below.
Purpose | Lawful basis |
Set up and administer Membership, verify eligibility, operate the Portal and provide Member Benefits | Performance of our contract with you; legitimate interests in administering a sponsored scheme where another organisation pays for Membership |
Respond to queries, provide support and manage complaints | Performance of our contract; legitimate interests in operating and improving our services |
Facilitate, health questionnaires, and healthcare services | Performance of our contract or steps taken at your request; for health data, healthcare or treatment under Article 9(2)(h) where applicable, or explicit consent under Article 9(2)(a) |
Process payments and maintain financial records | Performance of our contract; compliance with legal obligations; legitimate interests in preventing and recovering debt |
Protect accounts, systems, members and providers; prevent fraud and misuse; investigate security incidents | Legitimate interests in security and fraud prevention; compliance with legal obligations |
Keep records, establish or defend legal claims, and meet legal, regulatory or professional obligations | Compliance with legal obligations; legitimate interests in governance and legal claims; Article 9(2)(f) where special category data is necessary for legal claims |
Send electronic marketing and measure engagement | Consent, or another basis permitted by PECR; you may opt out at any time |
Use non-essential cookies and similar technologies | Consent; essential technologies are used where necessary to provide or secure the service |
Analyse and improve services using appropriately minimised or aggregated information | Legitimate interests in understanding and improving service performance, provided those interests are not overridden by your rights |
Where we rely on legitimate interests, we consider the purpose, necessity and effect on your rights before processing. You may ask us for further information about this assessment.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.
5 Health and Other Special Category Data
We may process health data when you complete a health risk questionnaire, request a referral or use a healthcare-related Member Benefit. We limit access to people who need the information for their role and require appropriate confidentiality and security safeguards.
Where healthcare professionals process health data to provide health or social care, we rely on Article 9(2)(h) of the UK GDPR and applicable provisions of the Data Protection Act 2018. Where that condition does not apply and the processing is optional, we may ask for explicit consent. Other conditions may apply where processing is necessary to protect vital interests or establish, exercise or defend legal claims.
An independent healthcare provider may be a separate controller for the clinical service it provides. It should give you its own privacy information explaining how it handles clinical records.
6 Who We Share Personal Data With
We may share personal data, where necessary and proportionate, with:
- Your insurer an employer or another scheme sponsor, limited to information needed to establish eligibility, administer the scheme and report on service delivery;
- Nurse Champions, clinicians and independent healthcare providers involved in a service you request;
- technology, hosting, communications, analytics, customer-support and cybersecurity providers;
- payment processors, banks, professional advisers, auditors and insurers;
- regulators, courts, law-enforcement agencies and public authorities where disclosure is required or permitted by law; and
- a purchaser, investor or successor organisation in connection with a proposed or completed corporate transaction, subject to appropriate safeguards.
Service providers acting as processors may use personal data only on our documented instructions and must protect it. Where another organisation acts as a separate controller, its own privacy notice applies to its processing.
We do not sell personal data.
7 International Transfers
Some suppliers may store personal data outside the United Kingdom or permit access from another country. Before making a restricted transfer, we use a lawful transfer mechanism. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another lawful safeguard. We also assess the circumstances of the transfer and use additional safeguards where appropriate.
You may contact us for further information about an applicable transfer safeguard and how to obtain a copy.
8 How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing Membership and Member Benefits and meeting legal, accounting, regulatory, professional and claims-related requirements.
Retention periods depend on the type of record, the sensitivity of the data, whether an account or Membership remains active, applicable limitation periods, clinical or professional requirements and any legal duty to retain or delete information. We securely delete or anonymise data when it is no longer required. You may contact us for information about the retention period that applies to a particular record.
9 Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls, authentication, system monitoring, supplier due diligence, staff confidentiality and incident-management procedures appropriate to the risk.
No internet transmission or storage system is completely secure. You must keep your Portal login details confidential and tell us promptly if you suspect unauthorised access to your account.
10 Cookies and Similar Technologies
The website uses cookies and similar technologies. Strictly necessary technologies support functions such as security, authentication, network management and remembering privacy choices. They may be used without consent where the law permits.
We will ask for consent before placing or accessing analytics, advertising or other non-essential technologies. You can accept, reject or change your choices through the website's cookie controls. Withdrawing consent does not affect the lawfulness of earlier use.
Our Cookie Policy and consent tool should identify the technologies in use, their providers, purposes and durations. Browser settings can also block or delete cookies, but doing so may prevent parts of the website from working correctly.
11 Marketing
We may send electronic marketing where you have consented or where another rule under PECR permits it. Marketing may contain tracking pixels or measured links that record delivery, opens, clicks, device information and related engagement data where permitted by law and your choices.
You may opt out at any time by using the unsubscribe link in a message or contacting us. Opting out of marketing does not stop essential communications about Membership, security or a service you have requested.
12 External Links Downloads and Social Media
The website may link to websites, downloads or social-media services operated by other organisations. Those organisations control their own services and personal data practices. Review their privacy information before providing personal data or using their services.
Social sharing features may send information to the relevant platform and may publish content to your social-media account, depending on your settings. Use them only if you are comfortable with the platform's privacy practices.
We take reasonable steps to maintain website security, but you should use appropriate device protection and take care when following external or shortened links and downloading files.
13 Your Data Protection Rights
Depending on the circumstances, you may have the right to:
- be informed about how we use your personal data;
- request access to your personal data and supporting information;
- ask us to correct inaccurate or incomplete personal data;
- ask us to erase personal data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain personal data in a structured, commonly used and machine-readable format and ask us to transmit it to another controller;
- withdraw consent where processing relies on consent; and
- rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
These rights are not absolute and exemptions may apply. We may ask for information needed to verify your identity. We normally respond within one month, although the law permits an extension for complex or numerous requests. We do not usually charge a fee.
We do not currently use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will provide the information required by law.
14 How to Exercise Your Rights or Complain
To exercise a right or raise a concern, email complaints@medipartner.co.uk or write to MEDIPARTNER LTD at the address in section 1. Please explain what you are asking us to do and provide enough information to identify the relevant records.
We would appreciate the opportunity to address your concern first. You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113. You may contact another relevant supervisory authority if you live outside the United Kingdom.
15 Children and Family Members
The website and Membership application are intended for adults. A Member Benefit may permit an adult Member to arrange access for an eligible family member. In that situation, we will provide appropriate privacy information and obtain any authority or consent required for the family member's age and circumstances. Children should not submit personal data through the general website without the involvement of a parent or guardian.
16 Changes to This Notice
We may update this notice when our services, suppliers or legal obligations change. The current version will be published on the website with its effective date. We will provide additional notice where a change materially affects how we use personal data or your rights.