OcuPlan has issued this Privacy Notice to describe how we handle the personal data that we hold about patients, visitors to this website, professionals and any other third parties with whom OcuPlan has entered into a business relationship with.
We respect the privacy rights of individuals and are committed to handling personal information responsibility and in accordance with applicable laws. This Privacy Notice explains who we are, how we collect, share and use personal information about you and how you can exercise your privacy rights. It applies to all individuals who access our website at www.ocuplan.co.uk or engage our services.
We will always use your personal data in accordance with applicable lawWe will never sell your data- We will always respect your wishes about how you would like to be contacted
We are OcuPlan Limited, a company registered in England under number 12293810. Our office is OcuPlan Limited, Kingsway House, 40 Foregate Street, Worcester, WR1 1EE. The following information represents our practices regarding your Personal Data and how we will process it. The policy applies to all individuals who access our website and / or engage our services. We encourage you to read this Privacy Notice in full, to ensure that you are fully informed.
The term “GDPR” includes the EU General Data Protection Regulation (EU) (2016/679) (“EU GDPR”) and the equivalent retained EU law version applicable in the UK with effect from 1 January 2021 (“UK GDPR”)The privacy and cookie policies are referred to as the “Policy”OcuPlan Ltd. OcuPlan is referred to as “Company”, “we”, “us” and “our”The OcuPlan website at the following address: www.ocuplan.co.uk is referred to as “Website”, “site”The term “services(s)” refers to our products which include provision of a private health shared care scheme.The term “subscriber(s)” refers to a patient who has registered on our site for the purposes of engaging our services and for whom we provide contracted services.The term “personal data” includes all data that we collect by you that relates to a living individual who can be identified from that data (the “data subject”). The term personal data includes any information identifying a data subject or information relating to a data subject that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. Personal data includes special categories of personal data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour.The term “professional(s)” or “your professional(s)” refers to a doctor or their team, an optometrist, a clinic or a company, who provide health care, for our subscribersThe term “special categories of personal data” includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation.A visitor to the site, a user of the services, a subscriber or a professional is referred to as “you”, “yourself” and “your”
The following terms are used throughout:
What does OcuPlan do?
OcuPlan provides a health plan product, which facilitates the provision of private health care in a more affordable way. There are a number of levels of annual care packages, tailored to individual patient needs. For more information about OcuPlan. Please see the ‘About us’ section of our website at www.ocuplan.co.uk
We collect and process personal information where necessary to perform our services with you. Our legal basis for collecting and using the personal data will depend on our relationship with you and the specific context in which we collect it.We will normally collect personal data from you only where we have your consent to do so, where we need the personal data to perform a contract with you (for example, when providing our Services), or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to process personal information about you or may need to process personal data in order to exercise, establish or defend legal claims.If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as the possible consequences, if any, if you do not provide your personal information).Where we are processing special categories of personal data which will include data relating to health our lawful basis for so doing will include, depending on our relationship with you:
The legal bases for our processing of Personal Information is:
explicit consent of the data subject so that we can keep you informed about news, events, activities and services;
processing is necessary for carrying out obligations under employment, social security or social protection law, or a collective agreement;
processing is necessary to protect the vital interests of a data subject or another individual where the data subject is physically or legally incapable of giving consent. This will usually be in a situation where the health or life of a patient is at risk;
processing relates to personal data manifestly made public by the data subject;
processing is necessary for the establishment, exercise or defence of legal claims or where courts are acting in their judicial capacity;
processing is necessary for reasons of substantial public interest;
processing is necessary for reasons of preventative or occupational medicine, for assessing the working capacity of an employee, medical diagnosis, the provision of health or social care or treatment or management of health or social care systems and services or a contract with a health professional;
processing is necessary for the reasons of public interest in the area of public health;
processing is necessary for archiving purposes in the public interest, or scientific and historical research purposes or statistical purposes.
When do we collect your personal data
When you create an account with usWhen you register on our website to subscribe to our servicesWhen you engage with us on social media- When you download our appWhen you contact us by any means with requests about our products, our services, queries, etcWhen you give us feedback, comments or complaints on the service that we provideFor the purpose of general business relationships with OcuPlan and for contractual purposesFor direct marketing in connection with our business activities, products and servicesTo manage our daily business activities
We may collect and use personal data about you for the following purposes:
What sort of personal data do we collect?
In the context of your relationship with us, we may process the following personal information about you:
Personal information may be provided by filling in forms on our site or speaking to us on the telephone. Your medical and health information is supplied to us by you at registration or your professional for the purpose of accessing our services.
Information collected may include some or all of the following:
Identity data:Name-including any previous names, title, date of birth, gender-Hospital or clinic registration numberPersonal TitleJob titleCompany or organisation
Contact Data:Postal addresses, email address, your social media names, telephone numbers, including mobile numbers
Health Data:Medical information relating to your health condition, symptoms, medications and conditionsMedical information relating to treatment plannedMedical information relating to previous treatmentsAny other relevant health data relating to you or third parties for the purposes of contracting or using our services
Financial and Transaction data:Bank account, credit card, debit card detailsPayment detailsTransaction data- Purchase(s) of our services
Marketing data:Preferences in receiving marketing information from usYour communication preferencesOther information relevant to client surveys or similar researchAny other information that you voluntarily choose to provide to us
Demographic data:Preferences and interestsYour relationship to a person
Professional Data:General Medical Council or General Optical CouncilDisclosure and Barring Service (DBS)Safeguarding certificateIndemnity insurance
If we ask you to provide any other personal information not described above, the personal information that you are asked to provide and the reasons why you are asked to provide it will be made clear to you at the point that you are asked to provide your personal information.
If you fail to provide personal data, where we need to collect personal data under the terms of the contract we have with you, we may not be able to perform the contract that we have or are trying to enter with you (for example to provide you with the services). In this case, we may have to cancel the service that you have with us.
Information that we collect automatically: we may collect certain personal information from your device when you visit our website, which may include
How and why do we use your personal data?
Personal data that we collect and use to provide our services is supplied by your professional or directly by yourself. We will only use your data, in accordance with applicable law. These are the reasons that we collect and use your personal data:
We will process your data in accordance with applicable law. These are the reasons that we collect and use your personal data:
Your personalised data for direct marketing
You may opt out of our marketing messages by contacting usYou may opt out of our marketing messages by changing your preferences in settingsYou may unsubscribe from all marketing messages by selecting unsubscribe on our messages
We may use your email address, your postal address or telephone to send you occasional updates and marketing messages according to the preferences that you have expressed in the registration form
How do we protect your personal data?
We use appropriate technical and organisational measures to protect the personal information that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal information. We limit access to your personal data to those who have a business to know.
How long will we keep your personal data?
We will store your personal information for as long as we have an existing relationship with you and otherwise as required by applicable law. Generally, this means your personal data will be retained until the end of your relationship with us and as long as we have an ongoing legitimate business need to do so. We retain your personal data for as long as necessary to fulfil the purpose that we collected it. We retain your personal data for the purpose of satisfying any legal, accounting or reporting requirements. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it, or if this is not possible, we will securely store your personal information and isolate if from any further processing until deletion is possible.
Who do we share your personal data with?We take care to allow access to personal information only to those who require such access to perform their tasks and duties, and to third parties who have a legitimate purpose for accessing it. Wherever we allow a third party to access personal information, we will implement appropriate measures to ensure the information is used in a manner consistent with this Privacy Notice and that the security and confidentiality of the information is maintained.We never share your personal data with third parties for their direct marketing purpose. We share your personal data with professionals to allow us to deliver our contract to the patients. We share your personal data within our group, under the OcuPlan brand.We share your personal data with your professionals, IT companies who support our website, data insight companies to ensure your details are correct, credit reference agencies and debt collection agencies.We share your personal data with any competent law enforcement body, regulator, government agency or third party, where we believe that disclosure is necessary, as a matter of law or regulation, to defend our legal rights or to protect your vital interests or those of any other person.
Where your personal data may be processed
Your personal information is processed in the UK. Our website servers are located in the UK. OcuPlan operates in the UK. When we collect your personal information, we do so in accordance with applicable law.
Transfer of your personal data outside the UK
where relevant the European Commission and/or the ICO has issued a decision confirming that the country to which we transfer the personal data ensures an adequate level of protection for the data subjects' rights and freedoms;appropriate safeguards are in place such as binding corporate rules, standard contractual clauses approved by a relevant supervisory authority, an approved code of conduct or a certification mechanism;the data subject has provided explicit consent to the proposed transfer after being informed of any potential risks; orthe transfer is necessary for one of the other reasons set out in the GDPR including the performance of a contract between us and the data subject, reasons of public interest, to establish, exercise or defend legal claims or to protect the vital interests of the data subject where the data subject is physically or legally incapable of giving consent and, in some limited cases, for our legitimate interest.
We will only transfer personal data outside the UK if one of the following conditions applies:
What are your rights over your personal data?
The right to request a copy of your personal data which we hold about youThe right to request that we correct any personal data if it is found to be inaccurate or out of dateThe right to request your personal Data is erased where it is no longer necessary for us to retain such dataThe right to withdraw your consent to the processing at any time where consent is relied on by us as a processing condition;The right to request that we provide you with your personal data and where possible, to transmit that data directly to another data controller (known as the right to data portability), where applicable.The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing;The right to object to the processing of your personal data (where applicable)You can exercise these rights by contacting our customer service team.You have the right to lodge a complaint with us by contacting our customer service team.We respond to all requests received from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.You have the right to contact and lodge a complaint at any time by sending an email to the Information Commissioner’s Office, website: www.ico.org.uk
Unless subject to an exemption under applicable data protection laws you have the following rights with respect to your personal data:
If we wish to use your personal data for a new purpose, not covered by this Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
What personal data is collected through this website and how is it used?
General information, such as which pages users access, is automatically collected by our web server through use of your IP addresses. An IP address is a number automatically assigned to your computer whenever you are on the internet. We use your IP address to monitor the number of pages accessed, help diagnose problems with our server, and to administer our web site. We do not link your IP address to anything personally identifiable, so you will remain anonymous in the analysis of these logs.
How can you stop the use of your personal data for direct marketing?We never share your personal details with third parties for the purposes of direct marketing. You may opt out of our direct marketing by clicking the unsubscribe button in any email communication that we may send to you.You may opt out of our direct marketing by changing your preferences in your account, by logging into www.OcuPlan.co.uk , go to ‘my account’ and change your preferences. In our apps, you can manage your preferences and opt out from one or all of the different push notifications by selecting or deselecting the relevant options in the “settings’ section.
Third party sites and Services
Contacting the Data Protection Officer
Contact the Regulator
You may contact or lodge a complaint at any time by sending an email to the Information Commissioner’s Office, website: www. ico.org.uk/concerns or calling them on 0303 123 1113
Unless otherwise stated, the design and layout of this website, and all the material published on this website, including text, graphics, photos, logos, and attached documents, is the copyright of OcuPlan. You may not copy any material from this site without prior permission.
Limitation of Liability
OcuPlan will not be liable for any damages arising out of the use, inability to use, or results of use of this website, any websites linked to this site, or any material or information contained on this site.
Errors or Omissions
OcuPlan has taken every care in compiling information and material for this website. If you believe that any of the information provided on this website is inaccurate or misleading please contact us with the details using our contact form here.
We hope that this Privacy Notice has been helpful, in setting out the way that we handle your personal data and your rights to control it. If you have any questions, please contact our data protection officer, who will be pleased to help you.
If you have any questions or concerns about our use of your personal information, please email us: info at ocuplan.co.uk
We will post any modifications or changes to the Policy on our site. We reserve the right to modify the Policy at any time, so we encourage you to review it frequently. The “Last Updated” legend below indicates when this Policy was last changed. If we make any material change(s) to the Policy, we will post a notice on our site prior to such changes(s) taking effect. In the event that such a change could materially affect your privacy, you will be notified without delay by appropriate means.