Providing NHS services
Find out more about our Automated Telephone Service More
This privacy notice explains why Foundry Healthcare Lewes collects information about you, how we use it, how we keep it safe and confidential, who we may share it with, and what rights you have in relation to your information.
At Foundry Healthcare Lewes, we take your privacy seriously and are committed to protecting your personal information.
We process your data in accordance with:
• UK General Data Protection Regulation (UK GDPR)
• Data Protection Act 2018
• Common law duty of confidentiality
We also comply with relevant legislation including:
• Health and Social Care Act 2012
• Human Rights Act 1998
We ensure that your information is:
• Used lawfully, fairly and transparently
• Collected for specific and legitimate purposes
• Limited to what is necessary
• Accurate and kept up to date
• Stored securely and only for as long as necessary
All staff are trained in information governance and are required to keep your information confidential.
Healthcare professionals who provide you with care are required by law to maintain accurate and up-to-date records about your health and any treatment or care you receive.
These records are essential to:
• Provide you with safe and effective care
• Ensure continuity of care across services
• Protect your health and safety
We also collect and use your information to:
• Manage and run the practice
• Monitor and improve the quality of care we provide
• Plan and deliver services for our patients
Your information may be held in electronic systems and, where necessary, in paper records.
The lawful basis for processing your data for direct care is:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
Further details on lawful basis are provided later in this notice.
We collect and hold the following types of information about you:
Personal information
This includes:
• Name, address, date of birth, NHS number
• Contact details (such as phone number and email address)
Health and care information (special category data)
This includes:
• Medical history and clinical notes
• Test results, diagnoses and treatments
• Information from other healthcare providers involved in your care
Confidential patient information
This is information about your health and care that is provided in confidence and is expected to be kept private.
Other types of data we may use
In some circumstances, your information may be:
• Pseudonymised: where identifying details are replaced with a code
• Anonymised: where you cannot be identified at all
• Aggregated: where data is combined with others to show trends
We use your information in the following ways:
Direct care (your treatment and care)
We use your information to provide you with safe and effective healthcare.
This includes:
• Diagnosing and treating you
• Managing your care and appointments
• Sharing information with other healthcare professionals involved in your care
For example, authorised healthcare staff may access your record when you receive care from services such as hospitals, community services, or out-of-hours providers.
Running the practice and improving services
We use your information to:
• Manage and run the practice
• Monitor and improve the quality of care
• Train and support staff
• Ensure patient safety
Planning, research and public health
Your information may also be used to:
• Plan healthcare services
• Monitor population health
• Support research and development of new treatments
Where possible, this will use
• Anonymised or pseudonymised data, so you cannot be identified
Where identifiable information is required, this will only be used:
• Where there is a clear legal basis, or
• Where you have given consent, or
• Where specific legal approval (e.g. Section 251) is in place
Legal basis for processing
The main legal bases we rely on are:
• Article 6(1)(e) - Public task (providing healthcare)
• Article 9(2)(h) - Provision of health and care
Further details are provided in Appendix A.
We keep your information in line with the Records Management Code of Practice for Health and Social Care (2021).
Different types of records are kept for different periods of time, depending on their purpose. For example:
• GP patient records are typically kept for the lifetime of the patient and for a period after death in line with national guidance
• Some administrative records may be kept for shorter periods
We only keep your information for as long as necessary to fulfil the purposes for which it was collected. When your information is no longer required, it is:
• Securely deleted from electronic systems, or
• Confidentially destroyed (e.g. shredding of paper records)
We maintain retention schedules within our information governance framework to ensure compliance with national standards.
The NHS Constitution gives you the right to decide how your confidential information is used beyond your individual care. There are two main types of opt-out:
Type 1 Opt-out (GP Practice level)
A Type 1 Opt-out prevents your confidential information from being shared outside of this GP practice for purposes beyond your direct care.
This means your information will still be used:
• To provide your care
• Where required by law (e.g. safeguarding or public health emergencies)
To set a Type 1 Opt-out, please contact the practice.
National Data Opt-out
The National Data Opt-out allows you to choose whether your confidential information is used for:
• Research
• Planning
If you choose to opt out:
• Your information will still be used for your individual care
• But it will not be used for research and planning purposes (unless there is a legal requirement)
To find out more or to set your preference, visit: Opt out of sharing your health records - NHS
What this means for you
If you are happy for your information to be used in this way, you do not need to do anything. You can change your choice at any time.
You have the right to request access to the personal information we hold about you. This is known as a Subject Access Request (SAR).
You can:
• Request a copy of your medical record
• Request specific information we hold about you
Requests can be made:
• In writing
• Verbally
We may ask you to provide proof of identity to ensure your information is kept secure.
What you can expect
• We will respond to your request within one month
• There is no charge for providing your information in most cases
• A reasonable fee may be charged for repeated or excessive requests
Access to your records
You may not be given access to certain information if:
• It could cause serious harm to your physical or mental health
• It includes information about another person (third-party confidentiality)
Online access
You may be able to access your GP record online via the NHS App or online services.
Click here for more information.
It is important that the information we hold about you is accurate and up to date.
Please let us know as soon as possible if your details change, including:
• Name
• Address
• Telephone number
• Email address
This helps us ensure that your information is not shared incorrectly and that we can contact you when needed.
How we contact you
We may use your contact details to:
• Send appointment reminders
• Send health questionnaires
• Provide information about your care
• Invite you to relevant health services (e.g. screening programmes)
Text messages (SMS)
If you provide a mobile number, we may send you text messages for appointments and healthcare communications. Please let us know if you do not wish to receive text messages.
Email
If you provide an email address, we may use it to send information about your care and services.
You can opt out of email communications at any time.
NHS App and online services
You may receive communications and access your health information through the NHS App or other approved online services.
This may include:
• Viewing your medical record
• Booking appointments
• Receiving messages from the practice
Data Controller
Foundry Healthcare Lewes is registered with the Information Commissioner’s Office (ICO) as a Data Controller.
You can view our registration on the ICO register.
Data Protection Officer (DPO)
We have a Data Protection Officer responsible for overseeing how we use your information.
If you have any questions or concerns about how your data is handled, please contact:
Data Protection Officer - Dr James Annis
E. sxicb-esx.foundryhealthcarelewes@nhs.net
Changes to this privacy notice
We keep this privacy notice under regular review and may update it from time to time.
Any updates will be:
• Published on our website
• Available at the practice
Access to information (Freedom of Information)
The Freedom of Information Act 2000 (FOIA) gives you the right to request access to non-personal information held by the practice.
This helps promote openness and transparency in how public organisations operate.
You can request information such as:
• Policies and procedures
• Practice operations and services
Important note
FOIA does not apply to personal information about you.
If you want access to your own personal or medical information, you should make a Subject Access Request (SAR) (see section above).
Complaints about how your data is used
If you have any concerns about how your personal information is handled, please contact us in the first instance:
Data Protection Officer - Dr James Annis
E. sxicb-esx.foundryhealthcarelewes@nhs.net
We will do our best to resolve your concerns promptly.
Complaints about our services
Go to our feedback, compliments and complaints page to find out more.
Right to complain to the Information Commissioner's Office (ICO)
You have the right to lodge a complaint with the ICO if you believe your data has been handled incorrectly.
A. Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
T: 0303 123 1113
W. ico.org.uk
The NHS Care Record Guarantee for England sets out the rules that govern how patient information is used in the NHS, what control the patient can have over this, the rights individuals have to request copies of their data and how data is protected under Data Protection Legislation. National Care Records Service - NHS England Digital
The NHS Constitution establishes the principles and values of the NHS in England. It sets out the rights patients, the public and staff are entitled to. These rights cover how patients access health services, the quality of care you’ll receive, the treatments and programs available to you, confidentiality, information and your right to complain if things go wrong.
Purpose:
We share information with the Integrated Care Board (ICB) to support the planning, monitoring and improvement of healthcare services. This may include the use of anonymised or pseudonymised data to understand population health needs and service demand.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision and management of health and care services
Processor:
NHS Sussex Integrated Care Board (ICB)
Purpose:
The Summary Care Record (SCR) is a national NHS system that contains important information from your GP record, including:
• Current medications
• Allergies
• Adverse reactions
It allows authorised healthcare professionals to access essential information about you in an emergency or when you receive care outside of the practice.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
Processor:
NHS England
Additional information:
Your Summary Care Record may also include additional information from your GP record, such as:
• Significant medical history
• Care plans
• Immunisations
This information is commonly included to support your direct care.
Your choice
You can choose:
• To have a Summary Care Record with full information
• To limit it to core information only
• Or to opt out completely
If you choose to opt out or limit your record healthcare professionals outside this practice may not have access to important information about your care in an emergency.
You can change your preference at any time by contacting the practice.
Further information
For more information about the Summary Care Record, visit: NHS England
Purpose:
We may use your information to support approved research that helps improve healthcare, develop new treatments, and plan services for the future.
How your data is used:
Wherever possible, anonymised or pseudonymised data is used so that you cannot be identified.
If identifiable information is required, this will only be used where:
• You have given your consent, or
• There is a legal basis (such as approval under Section 251 of the NHS Act 2006)
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Health and care
• Or consent, where required
Processor:
Approved NHS organisations, universities, and research bodies
Your choice
You can choose whether your confidential information is used for research through the National Data Opt-Out
Purpose:
We may use approved systems to analyse patient information to identify individuals who may be at risk of certain health conditions. This helps clinicians provide timely and appropriate care and improve health outcomes.
How your data is used:
• Data may be analysed securely using approved systems
• Wherever possible, pseudonymised data is used
• Only authorised healthcare professionals can access identifiable information where necessary for your care
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
Processor:
Approved NHS system suppliers (e.g. Metadvice or equivalent providers)
Purpose:
We may share your information with the Integrated Care Board (ICB) where a request is made for funding for a specific treatment that is not routinely available. This helps determine whether the treatment can be approved based on your individual clinical needs.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
Processor:
NHS Sussex Integrated Care Board (ICB) and associated commissioning support services
Your information:
Only the minimum necessary information will be shared to support the request. Where appropriate, your clinician will discuss this with you.
Purpose:
We may share your information with safeguarding services where there is a concern about the safety or welfare of a vulnerable adult. This is to ensure individuals are protected from harm, abuse, or neglect.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Health and care
• Article 9(2)(g) - Substantial public interest (safeguarding)
Processor:
Local Authority Safeguarding Adults Team (e.g. East Sussex County Council)
Important information
Where there are serious concerns about safety:
• Information may be shared without your consent
• This is done only where necessary to protect you or others
Purpose:
We may share information about children with safeguarding services where there are concerns about a child’s safety or welfare.
This is to help protect children from harm, abuse, or neglect.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Health and care
• Article 9(2)(g) - Substantial public interest (safeguarding)
Processor:
Local Authority Safeguarding Children’s Services (e.g. East Sussex Safeguarding Children Partnership)
Important information
Where there are safeguarding concerns:
• Information may be shared without consent
• The safety and wellbeing of the child is the priority.
Purpose: We may analyse patient information to identify individuals who may be at risk of developing certain health conditions or who may need additional support.
This helps us: • Provide early intervention • Improve long-term health outcomes • Plan care more effectively
How your data is used: Data may be analysed using secure NHS-approved systems • Wherever possible, pseudonymised data is used • Identifiable data is only used where necessary for your care
Legal basis: • Article 6(1)(e) - Public task • Article 9(2)(h) - Provision of health and care
Processor: Approved NHS organisations and system suppliers (e.g. NHS England, ICB, or approved analytics providers)
Purpose:
We may use data to understand how our services are used and to help plan and improve how care is delivered.
This includes reviewing:
• Appointment demand
• Service use
• Workforce requirements
How your data is used:
• Wherever possible, pseudonymised or anonymised data is used
• This means you cannot be directly identified
• Identifiable data is only used where necessary and lawful
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision and management of health and care services
Processor:
Approved NHS organisations and system providers, including workforce and analytics systems (e.g. NHS Sussex ICB, SCW CSU, or systems such as Tempo)
Purpose:
We may share your information with public health organisations to support:
• National screening programmes (e.g. cancer screening)
• Monitoring and controlling infectious diseases
• Improving public health and preventing illness
How your data is used:
Identifiable information may be shared where required for screening and public health purposes. Anonymised data may be used to monitor trends and improve services.
Legal basis:
• Article 6(1)(c) - Legal obligation
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Health and care
• Article 9(2)(i) - Public health
Processor:
Public health organisations (e.g. UK Health Security Agency, NHS England, local authorities such as East Sussex County Council)
Important information
In some cases, we are legally required to share information for public health purposes, such as reporting certain infectious diseases.
Purpose:
We share your information with other healthcare providers to support your care and treatment.
This may include:
• Hospitals
• Community health services
• Mental health services
• Ambulance services
• Other healthcare professionals involved in your care
How your data is used:
Information is shared securely to ensure continuity of care.
Only relevant information is shared with those directly involved in your care.
Legal basis:
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
Processor:
NHS Trusts, community providers, and other authorised healthcare organisations.
Purpose:
The Care Quality Commission (CQC) is the independent regulator of health and social care services in England.
They may access information, including identifiable patient data, to:
• Inspect services
• Monitor quality and safety
• Ensure that appropriate standards of care are being met
Legal basis:
• Article 6(1)(c) - Legal obligation
• Article 9(2)(h) - Health and care
Processor:
Care Quality Commission (CQC)
Important information
The law allows the CQC to access information as part of their regulatory duties.
Purpose:
We may share relevant information with NHS England, NHS Sussex ICB and other authorised bodies to support payment, invoice validation, quality monitoring and contractual reporting for GP services.
Legal basis:
• Article 6(1)(c) - Legal obligation
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision and management of health and care services
Processor:
NHS England, NHS Sussex ICB, Public Health and authorised payment validation services.
Purpose:
Your medical record will be shared, in order that a database can be maintained and managed in a secure way.
Legal Basis:
• Article 6(1)(e); 'necessary… in the exercise of official authority vested in the controller,' and
• Article 9(2)(h) as stated below.
Processor:
SystmOne (TPP)
Purpose
SystmOne’s Enhanced Data Sharing Model (eDSM) enables GP practices to share patient records securely with other healthcare organisations to support direct care. Implied sharing allows essential medical information to be accessible to an approved list of authorised NHS Sussex organisations, ensuring timely and effective care. Patients can record explicit consent or dissent to tailor how their data is shared.
Legal Basis
The processing of patient data under eDSM is supported by the following legal bases:
• Article 6(1)(e): "Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller."
• Article 9(2)(h): "Necessary for the provision of health or social care or treatment or the management of health or social care systems."
These legal bases ensure the appropriate and lawful sharing of medical information for patient care.
Patient Options
• Implied Sharing: Patient records are shared by default to support care unless a specific preference is recorded.
• Explicit Consent: Patients can authorise specific organisations to access their records.
• Dissent: Patients can opt out of sharing their records entirely or restrict access to certain organisations.
Patients can update their sharing preferences at any time through their GP practice or via SystmOnline.
Processor
TPP SystmOne
For more information, please contact your GP practice.
Purpose:
Patients personal confidential data will be extracted and shared with NHS England in order to support vital health and care planning and research. Further information can be found here
Patients may opt out of having their information shared for Planning or Research by applying a National Data Opt Out or a Type 1 Opt Out. Details of how to Opt Out can be found on our Privacy Notice. For the National Data Opt Out patients are required to register their preference below.
Legal Basis :
• Article 6(1)(e) - Public task
• Article 9(2)(h) - Provision of health and care
The legal basis for this activity can be found at this link : General Practice Data for Planning and Research (GPDPR) - NHS England Digital
Purpose:
Personal confidential and special category data in the form of medical record, is extracted under contract for the purpose of pseudonymisation. This will allow no patient to be identified within the data set that is created. SCWCSU has been commissioned to provide a data processing service for the GPs, no other processing will be undertaken under this contract.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision and management of health and care services
Processor:
SCW CSU
Purpose:
In order for the practice to have access to a shared record, the Integrated Care Service has commissioned a number of systems including GP connect, which is managed by NHS England, to enable a shared care record, which will assist in patient information to be used for a number of care related services.
These may include Population Health Management, Direct Care, and analytics to assist with planning services for the use of the local health population. Where data is used for secondary uses no personal identifiable data will be used. Where personal confidential data is used for Research, explicit consent will be required.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
Processor:
Plexus, NHS England, ESHT, ICS member providers
Purpose:
Personal Confidential data is shared with LumiraDX in order to provide an anticoagulation clinic to patients who are on anticoagulation medication. This will only affect patients who are within this criteria.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
Processor:
LumiraDX INRStar
Purpose
Your anonymous aggregated information will be shared in order to optimise medication. This will enable your GP to provide a more efficient medication regime for your personal care. Some of the anonymous information may be used nationally to drive wider understanding of the medication is used.
No patients will be able to identified from the data shared.
Legal Basis
Article 6(1)(e); “necessary… in the exercise of official authority vested in the controller’ And Article 9(2)(h) as stated below
Processor
FDB
Purpose:
Your medical record is shared with the ICB medicines management team, in order that your medication can be kept up to date and any changes can be implemented.
Legal Basis:
• Article 6(1)(e); “necessary… in the exercise of official authority vested in the controller,’ and
• Article 9(2)(h) as stated below
Processor:
Medicines Management team at NHS Sussex ICB
Purpose:
Your medical record is shared with the medicines management team, in order that your medication can be managed, kept up to date, and any changes can be implemented. Carrying out medication reviews, medication reconciliation of discharge summaries, clinical letters etc.
Legal Basis:
• Article 6(1)(e); “necessary… in the exercise of official authority vested in the controller,’ and
• Article 9(2)(h) as stated below
Processor:
The Medicines Management Team ltd:
Purpose:
Personal information is shared in order for the smoking cessation service to be provided.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
• Or consent, where required
Processor:
OneYou
Purpose:
The practice patient recording system will be made available to the AGE UK organisation in order to provide a social prescribing service to their patients. Patients will be asked to consent to being referred into the service, and allow their individual record to be accessed at the time of contact.
All access in to the GP medical recording system will be monitored.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
Processor:
AGE UK
Purpose:
The practice has contracted the use of a third party processor to email the Practices newsletter to patients. This is achieved by using a secure portal to upload and send information to patients about essential information relating to the function of the practice. The practice will have total control over the information shared, namely email addresses. Patients will have the right to decline receipt of the newsletter in this way by unsubscribing or letting the practice know their wishes. No patient data will be used for any other purpose. The processor will not have access to any other data relating to the patient.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 6(1)(a) – Consent (for communications)
Processor:
Mailchimp
Purpose:
PREVENTIVE OR OCCUPATIONAL MEDICINE: Collect medical information and symptoms direct from patients to support the practice in triage, consultations and appointment prioritisation.
Legal Basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
Processor:
Anima (Continuum Health Limited)- Privacy Policy
Purpose:
To securely manage and process patient-related documents and correspondence, enabling efficient healthcare administration and supporting the delivery of patient care.
Legal Basis:
• Article 6(1)(e) of GDPR: Processing necessary for tasks in the public interest
• Article 9(2)(h) of GDPR: Processing necessary for medical diagnosis, provision of health care, and management of health systems.
Processor:
Anima (Continuum Health Limited) - Privacy Policy
Purpose:
Personal information is shared with Healthtech 1 for the providers’ administrative purposes of registering patients at the practice using the clinical system, SystmOne.
Legal Basis:
Providing services for: the provision of health care or treatment the management of health care systems or services or social care systems or services
The lawful basis lies within Article 6 of the UK GDPR
6(1)(e) Public task: the processing is necessary for ‘You’ to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law. The lawful basis of processing special category data lies within Article 9 of the UK GDPR: 9(2)(h) ‘…medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems…’
Additionally in Data Protection Act 2018 (Schedule 10, 8. Medical Purposes (1,b)): Medical purposes: 8(1)The processing is necessary for medical purposes and is undertaken by —
(a) a health professional, or
(b) a person who in the circumstances owes a duty of confidentiality which is equivalent to that which would arise if that person were a health professional.
Processor:
Healthtech1
Purpose:
Your medical record is shared with Insight Solutions, an outsourced service, to assist with the processing of GP practice documents. This ensures that your records are accurately maintained, enabling the efficient delivery of administrative tasks to support your care.
Legal Basis:
• Article 6(1)(e) "Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller."
• Article 9(2)(h) "Necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems."
Processor:
Insight Solutions, acting under the direction of Foundry Healthcare, processes GP practice documents securely and in accordance with data protection regulations - Privacy Policy
Purpose:
The data is being processed for the purpose of delivery of a programme, sponsored by NHS England, to monitor urine for indications of chronic kidney disease (CKD) which is recommended to be undertaken annually for patients at risk of chronic kidney disease e.g., patients living with diabetes. The programme enables patients to test their kidney function from home.
We will share your contact details with Healthy.io to enable them to contact you and confirm that you wish them to send you a test kit. This will help identify patients at risk of kidney disease and help us agree any early interventions that can be put in place for the benefit of your care. Healthy.io will only use your data for the purposes of delivering their service to you. If you do not wish to receive a home test kit from Healthy.io, we will continue to manage your care within the Practice. Healthy.io are required to hold data we send them in line with retention periods outlined in the Records Management code of Practice for Health and Social Care.
Further information about this is available at:
Legal Basis:
The sharing is to support Direct Care which is covered under;
• Article 6(1)(e) “necessary… in the exercise of official authority vested in the controller,’ and
• Article 9(2)(h) ‘necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services...”
Processor:
Healthy.io
Purpose:
To allow patients to access their GP medical record online via the NHS App. The view all documents and entries made into their record by the GP, including information sent to the GP Practice where exemptions do not apply. Where a patient has requested third party access (family/friends) to their medical records, it is the patient’s responsibility to ensure removal of this access if no longer required. Proxy access to the patient’s record will be limited unless the patient has requested full access.
Legal Basis:
UK GDPR:
• Article 6(1)(e) Necessary for the performance of a task carried out in the public interest
• Article 9(2)(h) Necessary for provision of health and/or social care, including preventative or occupational medicine
Common Law Duty of Confidentiality (CLDC):
• The CLDC is satisfied as the data subjects are accessing their own data following sign up for a relevant app or platform and selecting the option to view their GP record.
Processor:
NHS England, TPP SystmOne
Purpose:
Foundry Healthcare uses Heidi Health, an AI scribe software, to transcribe consultations and enhance documentation processes. Explicit consent is obtained from patients before using Heidi during consultations, ensuring accurate and efficient record-keeping.
Legal Basis:
The processing of patient data via Heidi Health is supported by:
• Article 6(1)(e): "Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller."
• Article 9(2)(h): "Necessary for the provision of health or social care or treatment or the management of health or social care systems."
• Explicit Consent (Article 6(1)(a) and Article 9(2)(a)): Explicit consent is obtained before Heidi Health is used during consultations.
Processor:
Heidi Health operates under the direction of Foundry Healthcare to securely transcribe consultation notes. Heidi Health ensures no patient data is used to train or improve AI models.
For more information, visit Heidi Health's website or contact support@heidihealth.com
Purpose:
When you call to order medication or book appointments, your call and relevant details may be processed via Voice Connect on behalf of the practice. This enables secure PIN-protected ordering of repeat prescriptions and appointment booking, with your instructions entered directly into the clinical system. Personal and special category data (such as name, date of birth, NHS number, medication details, appointment information) may be processed. Voice Connect acts as a secure processor, and no personal data is used for training or analysis—only anonymised data is handled if any system audits or improvements are conducted. All processing is subject to human oversight to ensure accuracy and protection.
Legal Basis:
• Article 6(1)(e): Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (i.e., the practice).
• Article 9(2)(h): Necessary for the provision of health or social care or treatment, or the management of health or social care systems and services.
Processor:
Voice Connect Ltd (a specialist telephony processor working with EMIS, SystmOne, Vision, and other clinical systems processes your call data securely under the direction of the practice. Technical and organisational safeguards are in place to comply with GDPR and NHS data security standards. Voice Connect retains call logs according to NHS and contractual requirements and deletes them per their retention policy. https://voiceconnect.co.uk/wp-content/uploads/2023/11/Voice_Connect_-_Privacy_Notice_-_2023-10-31.pdf
Purpose:
Your clinical letters may be processed by Practice Unbound and its technical partner Blum on behalf of Foundry Healthcare. This is part of a project to develop an AI tool that supports administrative staff in handling patient correspondence more efficiently. The tool analyses clinical letters and recommends appropriate coding and actions within your Electronic Patient Record (EPR). While the letters may contain personal and special category data (such as your name, NHS number, and clinical information), only pseudonymised information will be used to train the AI model. Identifiable information will not be used for model training. All data is handled under strict human oversight to ensure appropriate and secure use.
Legal Basis:
• Article 6(1)(e): "Necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller."
• Article 9(2)(h): "Necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems."
Processor:
Practice Unbound and Blum are acting on behalf of Foundry Healthcare to support the processing of clinical letters. Only pseudonymised data is used to train AI models. All processing is carried out securely and in compliance with data protection legislation. https://practiceunbound.org/
Purpose:
This service reviews the prescribing of blood glucose test strips and lancets at the GP practice to ensure they align with ICB formulary guidance and practice preferences. Where appropriate, prescriptions may be updated to Contour Plus test strips and Microlet lancets to support safe and effective diabetes management.
Legal Basis:
The processing of patient data under this service is based on:
• Article 6(1)(e) – Necessary for tasks carried out in the public interest.
• Article 9(2)(h) – Necessary for the provision and management of health care.
These legal bases allow the GP practice to review and update prescriptions to ensure best practice prescribing.
Processor:
The GP practice is the Data Controller, with a designated Data Processor conducting the review securely and in compliance with data protection regulations.
Patient Choice:
Patients can contact the GP practice if they wish to discuss their prescription or opt out of any changes.
Purpose:
Foundry Healthcare contributes to the Sussex Integrated Dataset (SID), which supports Population Health Management across the Sussex Health and Care Partnership (SHCP).
The SID enables health and care organisations across Sussex to analyse and plan services more effectively, improving health outcomes and care coordination for local residents.
Data shared into the SID is pseudonymised before transfer, meaning individuals are not directly identifiable. The pseudonymised data may, in limited cases, be re-identified for direct care purposes (for example, to support specific patient groups identified through population health analysis).
Legal Basis:
The processing of personal data for inclusion in the Sussex Integrated Dataset is underpinned by the following legal bases:
• Article 6(1)(e) – Public Task: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, as defined in the Health and Social Care Act 2012.
• Article 9(2)(h) – Provision and management of health and social care systems: Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, or the management of health and social care systems and services.
These legal bases enable the sharing and analysis of data for research, planning and system improvement (secondary uses / indirect care) across SHCP, while maintaining the confidentiality and protection of individuals’ information.
Processor:
The Sussex Health and Care Partnership (SHCP) acts as the data processor for the SID, managing the combined dataset on behalf of contributing organisations.
Data is stored securely, with strict governance, and is only accessible to approved projects that demonstrate clear benefit to health and care services across Sussex.
For more information on Population Health Management in Sussex, visit the Sussex Health and Care Partnership website or contact sxicb.contactus@nhs.net
Purpose:
We use a secure hybrid mail service (Docmail) to print and send letters on our behalf.
This may include:
• Appointment letters
• Clinical correspondence
• Administrative communications
How your data is used:
Your information is transferred securely to the provider for printing and posting only the minimum necessary information is shared (e.g. name, address, and relevant letter content)
The provider acts strictly on our instructions and does not use your data for any other purpose
Legal basis:
• Article 6(1)(e) – Public task
• Article 9(2)(h) – Provision of health and care
Processor:
CFH Docmail (UK-based hybrid mail provider)
Important information
All processing is carried out under strict contractual controls, including:
• Data protection agreements
• Confidentiality requirements
• Secure handling and transmission of data
Last reviewed: January 2026
Next Review Due: January 2027
Owner: Data Protection Officer / Information Governance Lead