This Privacy Notice explains how we collect, use and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
We are committed to protecting your privacy and handling your personal data transparently and securely.
Who We Are
We are the Radis Group (“Radis”) comprising the companies of Radis Limited, G P Homecare Limited (t/as Radis Community Care) and its subsidiary companies.
For the purposes of data protection law, the data controller responsible for your personal data will usually be the relevant Radis Group company providing services to you or employing you.
If you have any questions about this notice or how we process your information, you can contact us via post, telephone or email.
The Data Protection Officer
Mercia House
15 Galena Close
Tamworth
Staffordshire
B77 4AS
Telephone: 0330 100 8150
Email: dataprotection@radis.co.uk
Who We Collect Personal Data About
We may collect personal data about:
- People we support
- Relatives, next of kin, attorneys, deputies and bill payers
- People who contact us with enquiries or complaints
- People referred to us by healthcare or social care professionals
- Website and online service users
- Visitors to our premises (including CCTV recordings)
- Job applicants
- Current and former employees
- Contractors, suppliers and their staff
The Types of Personal Data We Collect
The information we collect depends on your relationship with us.
Personal data may include:
- Name, address and contact details
- Date of birth
- NHS number
- National Insurance number
- Next of kin and emergency contact details
- Employment and education history (for recruitment)
- Financial and payment information
- Visual images (photographs or CCTV)
- Account login and security information
- Records of meetings, decisions, and correspondence
Special Category (Sensitive) Data
In order to provide care and meet legal obligations, we process special category data including:
- Physical and mental health information
- Medical history and care needs
- Disabilities and support requirements
- Racial or ethnic origin
- Religious or philosophical beliefs
- Sexual orientation (where relevant to care)
- Genetic or biometric data (where applicable)
We may also process information relating to criminal convictions where legally required (e.g., DBS checks).
Special category data receives additional protection under UK GDPR.
Collecting Information About Children
We may process personal information relating to children where this is necessary in connection with the services we provide, safeguarding responsibilities or other legal obligations.
Children should seek permission from a parent/guardian before providing us with personal information. As a parent/guardian, if you believe we have been provided with personal information without your consent then please contact us at dataprotection@radis.co.uk.
Why We Collect and Use Your Information
We process personal data for the following purposes:
1. Providing Health and Social Care
- Delivering care, treatment and support
- Communicating with healthcare professionals
- Safeguarding individuals at risk
- Maintaining care records
- Meeting our legal and regulatory obligations as a health and social care provider
2. Managing Our Services
- Handling enquiries and complaints
- Quality monitoring and training
- Managing payments and debts
- Auditing and regulatory compliance
3. Recruitment and Employment
- Assessing job applications
- Carrying out right to work and DBS checks
- Managing employment contracts
4. Website and Digital Services
- Managing accounts and secure access
- Responding to online enquiries
- Improving website functionality
- Monitoring usage and service performance
5. Marketing and Communications
- Sending newsletters (where consent is given)
- Providing updates about our services
- Seeking feedback
You can opt out of marketing communications at any time.
Our Lawful Bases for Processing
Under UK GDPR, we must have a lawful basis for processing personal data.
Depending on the purpose, we rely on:
Contract
Where processing is necessary to provide care, services, or employment.
Legal Obligation
Where we must comply with laws or regulatory requirements.
Legitimate Interests
Where processing is necessary for running our organisation effectively, provided this does not override your rights. This includes:
- Improving services
- Ensuring business continuity
- Preventing fraud
- Managing enquiries
- Training and quality monitoring
Vital Interests
Where processing is necessary to protect someone’s life.
Consent
Where required (for example, marketing communications or use of photographs for promotional purposes).
You may withdraw consent at any time.
Additional Conditions for Special Category Data
When processing health and other sensitive data, we rely on conditions under Article 9 UK GDPR, including:
- Provision of health or social care
- Safeguarding of individuals at risk
- Legal claims
- Explicit consent (where required)
Duty of Confidentiality
As a health and social care provider, we are subject to a common law duty of confidentiality.
We may share confidential information where:
- You have consented
- There is a legal requirement
- There is an overriding public interest
- We are required to do so under health service regulations
Where We Get Personal Data From
We collect information:
- Directly from you
- From family members or carers
- From GPs, hospitals and other health providers
- From local authorities or social services
- From regulatory bodies
- From previous employers (recruitment)
Sharing Your Information
We may share personal data with:
- Healthcare professionals (e.g., GPs, consultants)
- Local authorities and safeguarding teams
- Emergency services
- Regulatory bodies and inspectors
- Professional advisers and auditors
- IT and system providers (acting as data processors)
- Group companies (where applicable)
We do not sell personal data.
Where third parties process data on our behalf, we ensure appropriate contractual safeguards are in place.
International Transfers
We do not routinely transfer personal data outside the United Kingdom.
Where third-party providers (such as cloud or IT service providers) process data internationally, appropriate safeguards are in place in accordance with UK GDPR. These may include UK adequacy regulations or International Data Transfer Agreements (IDTAs) supported by a documented Transfer Risk Assessment.
In limited circumstances, personal data may be transferred overseas at your request, for example to a family member located abroad. In such cases, the transfer will be based on the data subject’s explicit consent or another applicable UK GDPR derogation.
Automated Decision-Making and Profiling
We may use limited profiling to:
- Improve service delivery
- Detect fraud
- Assess service usage trends
We do not make solely automated decisions that have significant legal or similar effects without human involvement.
CCTV
We may use CCTV on some of our premises for:
- Security
- Safety
- Crime prevention
Footage is retained for a limited period unless required for investigation purposes.
Cookies
Our website uses cookies to:
- Ensure website functionality
- Analyse usage
- Improve user experience
You can control cookies through your browser settings.
How Long We Keep Your Information
We retain information in line with:
- Our Records Retention Policy
- Legal and regulatory requirements
We only keep personal data for as long as necessary and securely delete or anonymise it when no longer required.
Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
You have the right to access personal information that we hold about you by making a subject access request. We will explain why if all or any part of the information is to be withheld.
- Request correction of inaccurate data
You can request that your personal information be corrected if you believe the information we hold about you is incorrect or incomplete. Inaccurate data is not necessarily the same as a difference of opinion. If you don’t agree with our opinion, we will record your view alongside ours.
- Request erasure
Under certain circumstances, you have the right to request the deletion or removal of personal information we hold about you. This right is available if the information is no longer covered by a lawful purpose or if we rely on your consent as a lawful basis and you withdraw your consent. We may be required to retain information as required by our Retention Policy and/or in the case of legal claims. In some cases, we may request a reasonable fee based on our administrative costs or be unable to comply if a request is unfounded or excessive.
- Restrict processing
You have the right to restrict the processing of your personal data if you have issues with the content of the information we hold or disagree with how we have processed your information.
- Object to processing
You have the right to object to specific types of information processing, including direct marketing and automated decision making except where there are compelling legitimate interests in us processing your information.
- Data portability
You have the right to receive personal information in an electronic format or if technically feasible to have it transferred to another data controller in some circumstances. This right covers information you have provided us under the lawful basis of consent and where the information is stored in an electronic format that has not been anonymised.
- Withdraw consent
Where you have given consent for us to collect and use your personal information (for example, when you subscribe to a mailing list) you can change your mind and withdraw that consent and stop the further use of it for those purposes. This does not apply if we have collected your personal data in line with our legal obligations or other lawful basis for processing.
To exercise your rights, contact us using the details above. We will respond within one month unless an extension is legally permitted.
How to Complain
If you are unhappy with how we handle your personal data, please contact us first.
You also have the right to complain to the Information Commissioner’s Office (ICO):
Website: https://ico.org.uk
Telephone: 0303 123 1113


