Plutus Health
GDPR Data Privacy notice for members
The Gwent Hospitals Workmen’s and Contributory Fund t/a Plutus Health are committed to protecting your data, respecting your privacy and complying with data protection legislation and the General Data Protection Regulation (GDPR). Plutus Health is a data controller. This means that we are responsible for deciding how we hold and use personal information about you.
This statement sets out how and why we are processing the information we have on you. It also explains your rights as a data subject.
This policy and any other documents referred to, sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
The rules on processing of personal data are set out in the General Data Protection Regulation (the “GDPR”).
Definitions
Data controller – A controller determines the purposes and means of processing personal data.
Data processor – A processor is responsible for processing personal data on behalf of a controller.
Data subject – Natural person
Categories of data: Personal data and special categories of personal data
Personal data – The GDPR applies to ‘personal data’ meaning any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier (as explained in Article 6 of GDPR). For example name, passport number, home address or private email address. Online identifiers include IP addresses and cookies.
Special categories personal data – The GDPR refers to sensitive personal data as ‘special categories of personal data’ (as explained in Article 9 of GDPR). The special categories specifically include genetic data, and biometric data where processed to uniquely identify an individual. Other examples include racial and ethnic origin, sexual orientation, health data, trade union membership, political opinions, religious or philosophical beliefs.
Processing – means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Third party – means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Our commitment to you
Our aim in processing your data is to successfully deliver our service to you with an appropriate level of data sharing whilst recognising the need to protect your fundamental rights to privacy.
Plutus Health is committed to:-
In order to meet its commitment, Plutus Health operates technical, physical and procedural controls to maintain the confidentiality, integrity and availability of information. Plutus Health maintains an information security policy which provides further details regarding the minimum standards of control to which it operates.
What are your rights?
At Plutus Health we recognise that your data is important to you and therefore we are committed to supporting you with your data protection rights. Within legal and regulatory constraints, you have the right to:
Right to withdraw consent
You have the right to withdraw your consent to specific processing at any time. Where you have provided your consent to the collection, processing and transfer of your personal information for a specific purpose, once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis to do so in law.
How to contact us about your data or your data rights
If you wish to contact us about your data, or if you require any further information in addition to what is included in this privacy notice, please contact Martin Ricketts, Senior Manager,
Plutus Health
WHA House
Greenwood Close
Cardiff
CF23 8RD
Email: admin@plutushealth.co.uk
How to make a complaint about the way your data is being processed
At Plutus Health we make every endeavour to protect your data. In the event that you are not happy with the manner in which we process your data, you may wish to make a complaint. In the first instance, please contact the Senior Manager in writing providing your contact details and the nature of your complaint.
If you are not happy with the response you receive you may also wish to contact the UK data protection regulator, the Information Commissioner, whose contact details are available at https://ico.org.uk
How and why we process your personal data
We will only process your personal information for the purpose for which we collected it i.e. the fulfilment of contracts of insurance. If we need to use your information for an unrelated purpose we will contact you and we will explain the legal basis that allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with our obligations in the case of criminal investigation.
Changes to this privacy notice
We reserve the right to update this privacy notice at any time.
Our legal basis for processing your personal data
Our lawful basis for processing your personal data:
Our lawful basis for processing your special categories of data:
The purpose of processing your personal data
Plutus Health processes your personal data in order to;
The categories of personal data concerned
With reference to the categories of personal data described in the definitions section, we process the following categories of your data:
Who has provided us with your data?
If you are a direct customer your data will have been provided directly by you, your representative or health professional. You may give us information about you by filling in paper application forms, on line application forms on our website, or by corresponding with us by letter, phone, email or otherwise
If you are a corporate client, or an employee of a corporate client, then the corporate client may have provided the data.
Will we share your data with anyone?
At Plutus Health we only work with trusted suppliers who have agreed to treat your information as respectfully as we do and in accordance with the requirements of the GDPR and only for the purpose of administering your policy or providing you with information.
In order to provide you with up to date information about our products and services we may share your data with emailing partners, public relations agencies or data profiling companies.
How long will we keep your data for?
We will keep your data for marketing purposes until your consent is withdrawn or the data is refreshed.
All contractual documentation and your electronic membership record are retained for seven years after the cessation of the contract. Claims records are retained normally for seven years or until the data is refreshed.
Will we use your data to make automated decisions?
No.
What happens if you fail to provide personal information?
You are under no statutory or contractual requirement or obligation to provide us with your personal data. If you fail to provide certain necessary personal information we may not be able to meet our expected level of customer service or fulfil our contract with you
Transfer of Data Abroad
We do not transfer personal data outside of the EEA
Further processing
If we wish to use your personal data for a new purpose, not covered by this Data Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions.
Changes to our privacy policy
Any changes we may make to our privacy policy in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy policy.
Complaints
If you wish to register a complaint, please contact us either by writing to the Chief Executive, Plutus Health, 60 Newport Road, Cardiff CF24 0YG, or by email admin@plutushealth.co.uk, or call us on 01633 266152
If you are not satisfied with our response, you may have the right to refer your complaint to the Financial Ombudsman Service, who can guide you with further steps:
Financial Ombudsman Service:
South Quay Plaza, 183 Marsh Wall, London , E14 9SR
Tel: 0300 123 9123
Freephone: 0800 023 4 567
Switchboard: 020 7964 1000
For calls from outside the UK: +44 20 7964 1000
Email: complaint.info@financial-ombudsman.org.uk
Website: www.financial-ombudsman.org.uk
For more information please go to the Complaints Procedure section at the foot of this page.
External Links – We are not responsible for the content or of any third-party websites linked to from our site.