Last updated: April 2026 | Version 1.0 | Document Ref: AMS-DP-001
| Document Title | Data Protection & GDPR Compliance Policy |
| Document Reference | AMS-DP-001 |
| Version | 1.0 |
| Date Issued | April 2026 |
| Next Review Date | April 2027 |
| Document Owner | Artensia Medical Services |
| Classification | Confidential – authorised recipients only |
This policy sets out how Artensia Medical Services meets its obligations under UK GDPR and the Data Protection Act 2018. It applies to all personal data processed by us in connection with our occupational health services, including data relating to clients, employees, referrers, and workers whose health is assessed.
Artensia Medical Services is the data controller for all personal data processed in connection with our business activities.
Email: admin@artensiamedical.com
Website: www.artensiamedical.com
We are committed to processing personal data in accordance with the six principles of UK GDPR. Personal data must be:
We process name, contact details, employer information, and correspondence data for the purposes of delivering and administering our occupational health services.
As an occupational health provider, we process health data. This is special category data under Article 9 UK GDPR and is handled with the highest level of confidentiality and security. It is processed solely under Article 9(2)(h) – provision of health or occupational medicine services by a health professional subject to a professional secrecy obligation.
We rely on the following lawful bases:
We collect only the personal data necessary for the specific purpose of each service or interaction. We do not collect data speculatively or for undefined future use. Clinical data is collected only where a formal referral or assessment is in progress.
We respect and facilitate the rights of data subjects under UK GDPR, including:
Requests should be directed to admin@artensiamedical.com and will be acknowledged promptly and responded to within the statutory timeframe.
We use the following data processors, with whom appropriate Data Processing Agreements (DPAs) in accordance with Article 28 UK GDPR are maintained:
We do not transfer personal data outside the United Kingdom. We do not sell personal data.
We apply appropriate technical and organisational measures to protect personal data, including:
Whilst we do not currently hold ISO 27001 or SOC 2 certification, our platforms (Microsoft 365 and Orchid Live) operate under recognised security frameworks, and we are subject to regulatory oversight as an occupational health provider.
In the event of a suspected or confirmed personal data breach:
Personal data is retained in accordance with applicable professional and legal requirements:
Data is securely deleted or anonymised at the end of the applicable retention period.
Any individual who believes their personal data has not been handled in accordance with this policy or UK GDPR may raise a complaint with us at admin@artensiamedical.com. They also have the right to complain directly to the ICO at ico.org.uk or by calling 0303 123 1113.
This policy will be reviewed at least annually and updated as required to reflect changes in law, regulation, or our business practices. The next scheduled review date is April 2027.
Artensia Medical Services
Email: admin@artensiamedical.com
Website: www.artensiamedical.com
| Version | Date | Author | Summary of Changes |
|---|---|---|---|
| 1.0 | April 2026 | Artensia Medical Services | Initial version – policy created |