Alertive Ltd (“Alertive”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy covers the privacy practices we adopt for the Alertive Website, Mobile Applications, Desktop Applications, and any products or services released through app stores or other distribution channels (collectively, the “Services”).
Controller vs. Processor Status
It is important to distinguish between the two roles Alertive plays regarding your data:
For the purposes of the Data Protection Act, the data controller is Alertive Ltd. If you have any questions about this policy or our privacy practices, please contact our Data Protection Officer (DPO)
We collect data in three distinct categories depending on how you interact with our services.
3.1. Custodian Data (App Usage)
This is personal data collected and shared within our applications on behalf of our customers (Data Controllers).
3.2. Special Category Data (Patient Data)
Although Alertive does not actively target Special Category Data, the messaging functionality allows users to input health-related data, or it may be integrated with Patient Administration Systems (PAS). This may include:
3.3. Website & Marketing Data (Personal Details)
Users can elect to provide Personal Data directly to us via the website or app on a strictly opt-in basis.
We only process your personal data where we have a valid legal basis under the UK GDPR.
4.1. Standard Personal Data (Article 6 UK GDPR)
4.2. Special Category Data (Article 9 UK GDPR)
Where health data is processed, we rely on the following conditions:
5.1. Use of Personal Details (Alertive as Controller)
Alertive may use Personal Details to:
5.2. Use of Custodian Data (Alertive as Processor)
5.3. Publishing of Data
No Relevant Data will be published on the internet or shared beyond what is covered in this document. Alertive does not sell, rent, or lease customer lists to third parties.
We adhere to high security standards. Alertive is ISO 27001 certified, Cyber Essentials Plus accredited, and compliant with the NHS Data Security and Protection Toolkit (DSPT).
6.1. Storage Locations
6.2. Security Measures
We share data with trusted sub-processors to deliver our services.
Sub-Processor | Purpose | Location |
Amazon Web Services (AWS) | Cloud Infrastructure & Hosting | UK (London) |
Microsoft Azure | Push Notification Services | UK / Global |
Google (Firebase/FCM) | Analytics & Android Push Notifications | Global (US) |
Apple (APNS) | iOS Push Notifications | Global (US) |
CRM & Workflow Management (Internal Use) | Cloud-based |
We use Monday.com for internal Customer Relationship Management (CRM) and workflow management. This allows us to organise customer contact details and track support or sales queries. No patient data or message content is stored on this platform
We primarily store and process all personal and patient data within the UK. However, to deliver Push Notifications (which wake your device to alert you of a message), limited technical data must pass through Apple and Google infrastructure, which may involve transfer to the USA.
Transfer Mechanisms & Safeguards We ensure that any restricted transfer of data complies with UK GDPR requirements by relying on the following legal and technical safeguards:
We retain personal data only for as long as necessary.
We use cookies and similar tracking technologies to improve user experience, ensure our services function correctly, and understand how our applications are used.
10.1. Types of Cookies We Use
10.2. Managing Your Cookie Preferences
You have the right to choose whether to accept or reject non-essential cookies.
Under the UK GDPR, you have specific rights regarding your personal data.
Important: As Alertive is often the Processor, you should usually direct requests (e.g., Access, Rectification, Erasure) to your employer (the Controller). We assist Controllers in fulfilling these requests.
Individual Data Requests Process: Requests made to Alertive via support channels will be validated, and a report will be securely sent to the requester within one calendar month.
We reserve the right to update our Privacy Policy at any time. Changes will be posted on our website. If we significantly alter how we use Relevant Data, we will notify customers directly.