Legal
Privacy policy
How we collect, use and protect personal data, and the rights you have over it.
Who we are
PatientZer0 is a website and server malware removal service operated by [REGISTERED COMPANY NAME], a company registered in England and Wales under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS].
For the purposes of UK data protection law we are the data controller for the personal data described in this policy. Our ICO registration number is [ICO REGISTRATION NUMBER].
If you have any question about this policy or about how we handle your data, contact us at data@patientzerosolutions.co.uk or on 01932 593642.
What personal data we collect
Information you give us
When you book a demo or request an emergency callback, we ask for:
- Your name
- Your email address
- Your phone number
- Your company name, where you give one
- A preferred time to be contacted, where you give one
- Details about what you are protecting — how many sites, which platform and hosting, and whether you are currently compromised
Information we collect during an engagement
If you become a customer, delivering the service necessarily involves access to your systems. That may include server and site credentials, access logs, file listings and database contents. Those may contain personal data belonging to your users. Where that happens we act as a data processor on your instructions, and the terms of that processing are set out in our terms of service and any data processing agreement between us.
Information collected automatically
Our web host records standard technical information when you visit, such as IP address, browser type and pages requested. This is used to keep the site running and secure.
Why we use it, and our lawful basis
- To respond to your enquiry and provide a quote — lawful basis: steps taken at your request prior to entering a contract.
- To deliver the service you have bought — lawful basis: performance of a contract.
- To keep records of incidents we have handled — lawful basis: legitimate interests, namely being able to evidence what work was carried out and to defend legal claims.
- To keep the website secure and working — lawful basis: legitimate interests in the security of our own systems.
- To meet accounting and tax obligations — lawful basis: legal obligation.
- To send marketing, if you have asked for it — lawful basis: consent, which you may withdraw at any time.
We do not sell your personal data, and we do not use it for automated decision making or profiling.
Cookies
This site sets no cookies of its own. We store a single preference in your browser's local storage to remember your choice about non-essential cookies, so that we do not ask you again on every page. That is strictly necessary to honour your choice and so does not itself require consent.
[IF ANALYTICS ARE ADDED: name each provider here, say what it does, and state that it only loads after consent.] Nothing that requires consent will load unless you select "Accept all". You can change your mind at any time using the Cookie settings link in the footer.
Who we share it with
We share personal data only with suppliers who process it on our behalf, under contract, and only as far as needed to run the service:
- [FORM / ENQUIRY HANDLING PROVIDER] — receives enquiry form submissions
- [EMAIL PROVIDER] — used to correspond with you
- [WEB HOSTING PROVIDER] — hosts this website
- [ANALYTICS PROVIDER, IF USED] — measures site usage, only with your consent
- [ACCOUNTING / PAYMENT PROVIDER] — processes subscription billing
We may also disclose personal data where we are required to by law, or to establish or defend legal claims.
Transfers outside the UK
Some of the suppliers above may process data outside the UK. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum, so that your data keeps an equivalent level of protection. [CONFIRM WHICH SUPPLIERS TRANSFER DATA AND ON WHAT BASIS.]
How long we keep it
- Enquiries that do not become customers — [RETENTION PERIOD, e.g. 12 months] from your last contact with us, then deleted.
- Customer records and incident reports — for the life of the contract and [RETENTION PERIOD, e.g. 6 years] afterwards, to match the limitation period for contractual claims.
- Accounting records — six years, as required by HMRC.
How we protect it
We apply the same standards to our own systems that we apply to our customers': access is limited to people who need it, credentials are unique and multi-factor where supported, and systems are patched and monitored. Any credentials you share with us are held only for as long as the engagement requires and are rotated on your instruction at the end of it.
Your rights
Under UK GDPR you have the right to:
- Ask what personal data we hold about you, and get a copy
- Have inaccurate data corrected
- Ask us to delete data where there is no continuing reason to keep it
- Object to, or ask us to restrict, processing based on legitimate interests
- Ask for data you gave us to be provided in a portable format
- Withdraw consent at any time, where we rely on consent
To exercise any of these, email data@patientzerosolutions.co.uk. We will respond within one month.
Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or on 0303 123 1113.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed. Where a change materially affects how we use your data, we will tell customers directly.