Privacy Policy
This Privacy Policy explains how Evermore Hospitals (“Evermore”, “we”, “us”) collects, uses, and protects personal information when you use our website, services, and patient portal. It’s written in a clear UK-friendly way. Replace placeholders with your final legal wording before production.
[Insert date] (update this when you publish)
1) Information we collect
- Account details: name, email, phone, and login/security events.
- Bookings & services: appointment requests, preferences, and visit-related metadata.
- Billing & receipts: invoice references, payment status, and transaction metadata (not full card details if processed by a payment provider).
- Usage data: device/browser info, basic analytics, and security logs to protect the platform.
2) How we use your information
- To create and manage your portal account and authenticate you securely.
- To process bookings, follow-ups, notifications, and support requests.
- To generate receipts/invoices and show your billing history.
- To protect the platform (fraud prevention, auditing, incident response).
- To improve the service performance and user experience (aggregated insights).
3) Legal bases (UK GDPR)
Depending on the context, we may process your data under one or more lawful bases such as: contract, legitimate interests, legal obligation, and/or consent. Finalise this section with your legal counsel for production.
4) Sharing & processors
We may share limited data with trusted service providers (“processors”) who help operate the platform, such as hosting, email/SMS delivery, analytics, and payment processing—only as necessary to provide the service. We do not sell personal data.
5) Data retention
We keep personal data only as long as needed for the purposes described above, including legal, accounting, and security obligations. Retention periods should be documented internally and reviewed regularly.
6) Your rights
- Access your personal data and receive a copy where applicable.
- Request correction of inaccurate or incomplete data.
- Request deletion (where applicable) or restriction of processing.
- Object to processing based on legitimate interests (subject to balancing tests).
- Data portability (in certain cases).
- Withdraw consent at any time (where consent is the lawful basis).
7) Contact
For privacy requests, contact [privacy@evermore.health] or use our contact page. If you are in the UK, you may also have the right to lodge a complaint with the ICO.
Use the portal for bookings and sensitive details instead of sending them over random chats or emails.
