Privacy Policy
1. Purpose
This notice explains how verkind uses personal information when people enquire about or receive services from the clinic. verkind is a private clinic providing assessment, prescribing and monitoring services for cannabis-based medicinal products. The notice is intended to meet the transparency requirements of UK data protection law.
verkind / THE GP SERVICE (UK) LTD acts as the data controller for the personal information described in this notice. The Data Protection Officer is Umar Sabat and can be contacted at [email protected].
2. Scope
This notice applies to patients, prospective patients, former patients, people acting on a patient’s behalf, carers, family members, referrers, website users and other individuals whose information is processed in connection with verkind’s services. Separate privacy information may apply to employees, applicants and suppliers.
3. Privacy Statement
erkind will only use personal information where there is a lawful and legitimate reason, will collect no more than is necessary, will protect it with appropriate security and will keep it only for as long as required. Health information is special category data and receives additional protection. verkind does not sell patient information.
Information We Collect and Where It Comes From
4.1 Categories of information
Identity and contact information, including name, date of birth, address, email, telephone number, NHS number, photographic identification and communication preferences.
• GP, specialist, carer, next-of-kin and representative details.
• Medical history, diagnoses, symptoms, previous treatments, current and historic medicines, allergies, test results, correspondence, mental health, substance use, safeguarding and risk information.
• Information used to assess suitability for cannabis-based medicinal products, clinical decisions, multidisciplinary review, prescriptions, dosage, formulation, dispensing and delivery coordination, treatment response, side effects and adverse events.
• Consultation notes, questionnaires, patient-reported outcome measures, messages, calls and recordings where recording has been clearly explained and lawfully approved.
• Payment, billing, refund and transaction information. verkind will not normally retain full payment-card details where a regulated payment provider processes them.
• Complaints, concerns, incidents, consent or authority records, audit logs and correspondence.
• Website and technical information
4.2 Sources of information
Information may be obtained directly from the individual or their authorised representative, from GPs and other healthcare professionals, referral letters, shared records made available with appropriate authority, dispensing pharmacies, laboratories, service providers, regulators and publicly available professional registers. verkind may need relevant medical and medication history before a clinician can safely decide whether to prescribe.
5. How and Why, We Use Information
The precise lawful basis may vary according to the circumstances. Consent used for confidentiality or an optional activity is distinct from the data protection lawful basis used for necessary clinical care.
6. Who We Share Information With
Treating clinicians, authorised clinical and administrative staff and members of an appropriate multidisciplinary team.
• The patient’s GP, specialist or other healthcare provider where necessary for safe prescribing, continuity of care, safeguarding or the patient’s interests, with confidentiality requirements considered.
• Dispensing pharmacies, prescription processing services, laboratories, delivery providers and other partners involved in providing the service.
• IT hosting, clinical system, video consultation, communication, payment, accounting, document storage and professional service providers acting under contract.
• CQC, ICO, GMC, GPhC, MHRA, Home Office or controlled-drugs authorities and other regulators where disclosure is required or justified.
• Emergency services, safeguarding bodies, courts, law-enforcement agencies, insurers, legal advisers or others where there are a lawful basis and the disclosure is necessary and proportionate.
verkind will check that processors provide appropriate security and contractual protections. Where information is transferred outside the United Kingdom, an approved transfer mechanism and appropriate safeguards will be used.
7. Retention, Security and Automated Decisions
7.1 Retention
Information is kept in accordance with verkind’s retention schedule, legal and regulatory requirements, the Records Management Code of Practice for Health and Social Care where relevant, limitation periods and the need to support safe care. Clinical records are not deleted solely because treatment ends or because a person asks for erasure where continued retention is required for healthcare, legal, regulatory or safety reasons.
7.2 Security
Iverkind uses access controls, authentication, encryption, secure hosting, audit logging, staff training, supplier assurance, backups and incident management. Staff may only access records where required for their role. No system can be guaranteed to be completely risk-free, but security is reviewed according to the sensitivity of the information and current threats.
7.3 Automated decision-making
verkind does not intend to make solely automated decisions using health information that produce legal or similarly significant effects without lawful authority and appropriate safeguards. Digital questionnaires or decision-support tools may assist clinicians, but clinical decisions remain subject to professional review.
8. Your Rights, Complaints and Contact Details
The right to be informed, request access and ask for inaccurate or incomplete information to be corrected.
• The right to request erasure, restriction or objection where the legal conditions apply; erasure is not absolute for clinical records.
• The right to data portability where the legal conditions are met.
• Rights relating to solely automated decision-making and profiling.
Requests and complaints should be sent to the Data Protection Officer at [email protected]. Data protection complaints will be acknowledged within 30 days and handled without undue delay. Individuals may also complain to the Information Commissioner’s Office on 0303 123 1113 or through its website.
