Privacy practices we adopt

    1. Introduction

    Alertive Ltd (“Alertive”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy covers the privacy practices we adopt for the Alertive Website, Mobile Applications, Desktop Applications, and any products or services released through app stores or other distribution channels (collectively, the “Services”).

    Controller vs. Processor Status

    It is important to distinguish between the two roles Alertive plays regarding your data:

    • Alertive as Data Processor: For the vast majority of data processed via the Alertive App (e.g., messages, patient data, staff contact details), the Alertive Customer (e.g., your NHS Trust or Employer) is the primary Data Controller. We process this data solely on their instructions to protect its confidentiality, integrity, and accessibility.
    • Alertive as Data Controller: We are the Data Controller for data collected directly from you via our website (e.g., “Contact Us” forms, cookies) or when you provide personal details directly to us for marketing communications

    2. Contact Details

    For the purposes of the Data Protection Act, the data controller is Alertive Ltd. If you have any questions about this policy or our privacy practices, please contact our Data Protection Officer (DPO)

    • Company Name: Alertive Ltd
    • Address: The Old Vicarage, 51 St John Street, Ashbourne, Derbyshire, DE6 1GP
    • Data Protection Officer: Dave Juby
    • Email: dpo@alertive.co.uk
    • ICO Registration Number: Z4928923

    3. The Data We Collect

    We collect data in three distinct categories depending on how you interact with our services.

    3.1. Custodian Data (App Usage)

    This is personal data collected and shared within our applications on behalf of our customers (Data Controllers).

    • Identity Data: First Name, Last Name, UserID, Job Title, Department/Ward.
    • Contact Data: Telephone numbers (if enabled) and email addresses.
    • Communication Data: Message content, conversation titles, timestamps, and read receipts.
    • Multimedia: Message attachments in the form of images, audio files, and documents, which may contain personal data.
    • Technical Data: IP address, device model, operating system, crash logs, and unique device identifiers.

    3.2. Special Category Data (Patient Data)

    Although Alertive does not actively target Special Category Data, the messaging functionality allows users to input health-related data, or it may be integrated with Patient Administration Systems (PAS). This may include:

    • Patient Name, NHS Number, Date of Birth, Gender, and Ward/Bed location.
    • Medical notes or images shared by clinicians for treatment purposes.

    3.3. Website & Marketing Data (Personal Details)

    Users can elect to provide Personal Data directly to us via the website or app on a strictly opt-in basis.

    • Personal Details: Name, email address, and phone number.
    • Usage Data: Anonymous demographic information, including IP addresses, browser types, domain names, access times, and referring website addresses.

    4. Lawful Basis for Processing

    We only process your personal data where we have a valid legal basis under the UK GDPR.

    4.1. Standard Personal Data (Article 6 UK GDPR)

    • Legitimate Interests (Article 6(f)): Processing is necessary for the legitimate interests pursued by the Controller (your employer) or third party to provide secure clinical communication and improve efficiency, provided these interests are not overridden by your rights.
    • Consent (Article 6(a)): For website cookies and direct marketing communications where you have opted in.

    4.2. Special Category Data (Article 9 UK GDPR)

    Where health data is processed, we rely on the following conditions:

    • Health or Social Care (Article 9(2)(h)): Processing is necessary for medical diagnosis or the provision of health or social care.
    • Public Interest in Public Health (Article 9(2)(i)): Ensuring high standards of quality and safety of health care and medical devices.

    5. How We Use Your Data

    5.1. Use of Personal Details (Alertive as Controller)

    Alertive may use Personal Details to:

    • Provide services, customer support, or arrange deliveries.
    • Perform statistical analysis to improve user experience.
    • Send emails or surveys about current or potential new services (marketing), subject to your consent.
    • Comply with legal obligations, enforce terms of use, or protect rights and safety.

    5.2. Use of Custodian Data (Alertive as Processor)

    • Alertive processes Custodian Data solely to facilitate secure communication and data storage as instructed by the customer.
    • Static personal data (e.g., Name, Job Title) allows product users to identify individuals.
    • We rely upon customers to provide accurate, up-to-date information.

    5.3. Publishing of Data

    No Relevant Data will be published on the internet or shared beyond what is covered in this document. Alertive does not sell, rent, or lease customer lists to third parties.

    6. Data Security and Storage

    We adhere to high security standards. Alertive is ISO 27001 certified, Cyber Essentials Plus accredited, and compliant with the NHS Data Security and Protection Toolkit (DSPT).

    6.1. Storage Locations

    • Servers: Personal data is stored in an encrypted database within AWS RDS (London).
    • Mobile Apps (iOS/Android): Personal data is stored in an encrypted database within the local private storage area, inaccessible to other users.
    • Desktop/Web: Data is stored securely in local storage or encrypted databases.

    6.2. Security Measures

    • Encryption at Rest: Data on servers and mobile devices is encrypted using AES-256 standards.
    • Encryption in Transit: All data transmitted between the App and our Servers is encrypted via TLS.
    • Access Control: Access is restricted via role-based controls and IP Whitelisting, where applicable.
    • App Security: The app runs in a secure sandbox and checks for “Jailbroken” or “Rooted” devices to prevent insecure usage.

    7. Sub-Processors and Data Sharing

    We share data with trusted sub-processors to deliver our services.

    Sub-Processor

    Purpose

    Location

    Amazon Web Services (AWS)

    Cloud Infrastructure & Hosting

    UK (London)

    Microsoft Azure

    Push Notification Services

    UK / Global

    Google (Firebase/FCM)

    Analytics & Android Push Notifications

    Global (US)

    Apple (APNS)

    iOS Push Notifications

    Global (US)

    Monday.com

    CRM & Workflow Management (Internal Use)

    Cloud-based

    We use Monday.com for internal Customer Relationship Management (CRM) and workflow management. This allows us to organise customer contact details and track support or sales queries. No patient data or message content is stored on this platform

    8. International Data Transfers

    We primarily store and process all personal and patient data within the UK. However, to deliver Push Notifications (which wake your device to alert you of a message), limited technical data must pass through Apple and Google infrastructure, which may involve transfer to the USA.

    Transfer Mechanisms & Safeguards We ensure that any restricted transfer of data complies with UK GDPR requirements by relying on the following legal and technical safeguards:

    • Adequacy & Legal Frameworks: We rely on the UK Extension to the EU-US Data Privacy Framework for transfers to certified US organisations. Where this does not apply, we utilise the UK International Data Transfer Agreement (IDTA) or approved Standard Contractual Clauses (SCCs) to provide a binding legal guarantee of protection.
    • Supplementary Security Measures: 
      • Encryption: The payload data sent via push notifications is encrypted, ensuring that the content remains inaccessible to the infrastructure providers during transit.
      • Data Minimisation: We restrict data in push notifications to essential items only (such as a notification ID), ensuring no unnecessary personal identifiers are transferred.
      • Transfer Risk Assessment (TRA): We have conducted a formal assessment of these transfers to ensure they provide a standard of protection essentially equivalent to the UK regime.

    9. Data Retention and Deletion

    We retain personal data only for as long as necessary.

    • Message Data: Retention periods are defined by the Data Controller (Customer) in accordance with their retention policy.
    • Device Cache: Local conversations are automatically deleted after a configured “Time to Live” (TTL) expires.
    • Crash Logs: Retained for up to 90 days for debugging.
    • Deletion Policy: We implement configurations to ensure data is deleted in compliance with the customer’s policy.

    10. Cookies and Analytics

    We use cookies and similar tracking technologies to improve user experience, ensure our services function correctly, and understand how our applications are used.

    10.1. Types of Cookies We Use 

    • Strictly Necessary (Functional) Cookies: These are essential for the operation of our website and services (e.g., maintaining your secure session login). Because these are strictly necessary for the service you requested, they cannot be switched off, but they do not collect personally identifiable data.
    • Analytics & Performance Cookies: With your permission, we use third-party tools such as Google Analytics and Google Firebase (Crashlytics) to collect anonymous data on visitor interactions and app stability. This data helps us resolve crashes and improve performance. It is aggregated and does not directly identify you.

    10.2. Managing Your Cookie Preferences

    You have the right to choose whether to accept or reject non-essential cookies.

    • Consent Tool: Upon your first visit to our website, you will be presented with a cookie banner allowing you to “Accept” or “Decline” analytics cookies. You can update these preferences at any time via the “Cookie Settings” link in our website footer.
    • Browser Settings: Most web browsers allow you to control cookies through their settings preferences. You can configure your browser to refuse cookies or delete them; however, please note that disabling strictly necessary cookies may prevent our services from functioning correctly.

    11. Your Rights

    Under the UK GDPR, you have specific rights regarding your personal data.

    Important: As Alertive is often the Processor, you should usually direct requests (e.g., Access, Rectification, Erasure) to your employer (the Controller). We assist Controllers in fulfilling these requests.

    • Right of Access: Request a copy of the personal data held about you.
    • Right to Rectification: Request correction of inaccurate data. Static data (e.g., names) must be updated via your employer’s directory.
    • Right to Erasure: Request deletion of data where it is no longer necessary.
    • Right to Complain: You have the right to lodge a complaint with the ICO (www.ico.org.uk) if you are dissatisfied with how we process your data.

    Individual Data Requests Process: Requests made to Alertive via support channels will be validated, and a report will be securely sent to the requester within one calendar month.

    12. Changes to This Policy

    We reserve the right to update our Privacy Policy at any time. Changes will be posted on our website. If we significantly alter how we use Relevant Data, we will notify customers directly.