WHAT INFORMATION IS REQUIRED FOR THE CONTRACT/ORDER
When an order* is placed the following information will be requested.
a) Contact name
b) Invoice address
c) Delivery address
d) Telephone number (either landline or mobile)
e) E-mail (online orders for confirmation of order, NHS orders for sending invoice)
f) Online order: The White Medical online store website is hosted on a secure server, and all personal details, including your name, address and contact details are protected through a process of encryption sometimes termed SSL and provided under the umbrella of British Telecommunications PLC. White Medical does not collect or have access to any of your credit/ debit card details. When you select the ‘Pay’ button on the site you will be forwarded to WorldPay, a secure payment gateway that handles all the payment processing. WorldPay are approved by online consumer groups Safebuy and Trustwise UK.
Once the payment has been processed WorldPay will forward information to White Medical to prove payment has been made and may also include other information i.e. order number, card address, e-mail, fraud detection information etc. Whenever you enter personal details, first ensure that a padlock is displayed somewhere on your internet browser's window. Clicking or double-clicking the padlock will display details of the certificate. Our online store is hosted on the domain btowstore.com.
If you have any queries or concerns about using the website, send an email with your concerns to our Web Support team at email@example.com
WHAT WE DO WITH THE INFORMATION WE GATHER
We require this information for the following reasons:
White Medical will not use the information given at the time of the contract / order to contact you after the order has been processed unless this contact is requested by you. Personal/Retail customers will not be contacted directly after the order has been delivered. NHS accounts may be contacted so that we can communicate with you and send offers and information we feel may interest you. This contact may be by means of post or email. If you want to opt-out of this, please let us know when you place your order and you will not be contacted. Unfortunately, there may be a situation that goes against your wishes and we need to contact you (e.g. delivery issues, warranty, product recalls etc).
So that we can improve our website and make it more user friendly we collect general information about the visitors. This includes, dates, times, durations and the pages you look at; we never record personal information about you from your browsing behavior.
WHO WE SHARE YOUR INFORMATION WITH
For White Medical to fully process your order a third-party carrier will be used to deliver your order. White Medical’s carriers are TNT, APC and Royal Mail. The only information given to them is the delivery address which has been provided. Your information may be requested by the manufacturer of the goods supplied for the purposes of product recall only. We do not sell or give your details to anyone else.This excludes any request by the UK's law enforcement agencies.
We are committed to ensuring that your information is secure. To prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online. White Medical is compliant with PCI DSS and our processes run to ISO9001:2015 which is externally audited annually by UKAS accredited ACM.
CONTROLLING YOUR PERSONAL INFORMATION
You may exercise any of the rights described in this section by sending an email to firstname.lastname@example.org. Please note that we will ask you to verify your identity before taking further action on your request. We try to respond to all legitimate requests within one month. Occasionaly it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.
You can manage your own information. For our online store you may access and update some of your information through your account settings. Account information held on our database at White Medical please contact our customer services to update your account information. You can ask us to correct inaccurate or incomplete personal information concerning you.
You have the right to data access and portability and request copies of your personal information held by us. You may also be entitled to request copies of personal information that you have provided to us in a structured, commonly used, and machine-readable format.
Your personal information will be retained for as long as we feel necessary (due to the products we sell are medical devices and most them are in NHS Trust establishments). Paper files are kept for a minimum of seven years (in line with our legal obligation to keep order information for this duration for tax, legal reporting and auditing obligations). If you no longer want us to keep your information, you can request that we erase your personal information and close your account. Please note that if you request the erasure of your personal information:
a) We may retain some of your personal information as necessary for our business interests, such as fraud detection and prevention and enhancing safety. For example, if we suspend an account for fraud, certain information from that Account will be saved to prevent that user from opening a new account in the future.
b) We may retain and use your personal information to the extent necessary to comply with our legal obligations. For example, we may keep some of your information for tax, legal reporting and auditing obligations.
c) Additionally, some copies of your information (e.g. log records) may remain in our database but are disassociated from personal identifiers.
Once a contract is in place i.e. an order has been quoted for and processed between White Medical and a customer, the customer can cancel the contract however if the goods have already been sent a requested under the contract it is the customers responsibility to return the goods to us to cancel the contract within 7 days of receiving the goods. A refund will be issued when the goods are received back at White Medical. Once the refund has been issued the contract is terminated and your account will be deleted if requested.
White Medical complies to the Payment Card Industry Data Security Standards (PCIDSS). The standards are a set of technical and operational requirements to protect cardholder information. Essentially PCIDSS are the rules of engagement for processing payments.
You have the right to lodge complaints about the data processing activities carried out by White Medical before the Information Commissioner's Office. In the UK, please read: https://ico.org.uk/for-the-public/raising-concerns/ for details of how to do this. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us first.
Our ICO Registration number is: Z7841498
* An order placed with White Medical takes one of the following definitions:
i) NHS order by official Purchase Order from a Trust, to be invoiced
ii) GP order either by telephone or e-mail, to be invoiced or payment with order
iii) Personal/retail order by telephone/mail/in-person (payment with order by cheque, cash or card)
iv) Personal/retail order via our online store www.white-medical.co.uk(payment through WorldPay)
EXTERNAL WEB SITES
YOUR ACCESS RIGHTS
White Medical conforms to the requirements of the GDPR which came into effect on 25.05.2018. You always have access to the information we hold about you. To obtain a copy of this information please contact: The Data Protection Officer, White Medical, Meranti Lodge, Hillmorton Lane, Clifton upon Dunsmore, Rugby, UK, CV23 0BA or alternatively e-mail email@example.com.
VISITORS TO WHITE MEDICAL
Whilst we are a mail order company if you plan to visit us please telephone to make an appointment and be aware that CCTV is operational 24 hours a day. Recordings are kept for 10 days then automatically deleted. Should you require a copy of any recordings please e-mail firstname.lastname@example.org. Once your request has been received you will be contacted within 2 working days.