This privacy statement applies to all GPTOOLS UK LTD owned websites, domains, services, applications and products including but not limited to GPTOOLS UK LTD 360, GPTOOLS UK LTD & GPTOOLS UK LTD PSQ Surveys.
GPTOOLS UK LTD of Kemp House, 152 City Road, London EC1V 2NX is committed to protecting the privacy of the data that we process and hold and complying with GDPR.
We hold personal data about our users, their nominated appraisers and appraisal administrators; this document explains what information we hold, how we use it and your rights regarding that information.
What data do we hold?
Only data entered by you or by nominated persons is held by us.
All data entered by you is owned by you and you are responsible for anything you enter into our system.
We will always maintain the highest levels of security and not share your data with anyone else unless you authorise it.
The data we hold may include some or all of the following:
- Identifying information – e.g. name, GMC number
- Contact information – e.g. email address, postal address, phone number
- Professional information – e.g. job title, specialty, place of qualification, year of qualification, CV / biography, education level, job grade or level, employment start date, department/ function, location (your place of work), contract type, working hours
- Appraisal preparation and documentation
- Continuing Professional Development information
- Survey information provided by your nominees
Online payment information
In addition to the above, if you elect to pay for our services by Stripe or PayPal, we may hold the last four digits of your payment card number.
Where do we get your data from?
The personal data that we hold is provided to us by you, your respondents to your 360° feedback or your employer.
You are the complete owner of this data and you are reponsible for the contents of this data.
If you elect to pay by PayPal or Stripe, they may provide us with the last 4 digits of your payment card number.
How do we use your personal data?
1. Contractual relationship. We may use your data to fulfil a contract to provide services to you.
In carrying out these services we may do one or more of the following:
- use data provided to us by Stripe and PayPal for the purpose of matching service users and payments
- use your details so that we can communicate with you by email or phone
- use data provided by respondents completing 360⁰ feedback to provide a view of an individual’s performance
- use feedback requested during 360⁰ from colleagues, peers and patients to support the revalidation process for hospital doctors and GPs
- all feedback data is anonymised at point of entry and contains no patient identifiable information. We do not store or use browser fingerprinting to track or collect data on users of our system
2. Legal compliance. We may hold your data if we are legally required to do so.
3. Legitimate business interests. We may anonymise your data for research purposes in order to:
- Produce relevant norm groups so that individuals, teams and organisations can compare themselves to other
- Improve the quality of our services and products
- Conduct and publish research to provide thought leadership in our field.
All data we use for research is completely anonymised at the point of data entry.
How we protect your data.
The personal information we hold is stored and processed securely in line with the UK government’s guidelines for Cyber security controls, Cyber Essentials Plus*.
Your personal information is held and processed in the UK.
Where we share your personal information with your apprasier and/or appraisal admin team we will ensure that this is only with authorised persons that you allow.
What we don’t do with your personal data
- We do not make automated decisions relating to your personal data
- We do not sell your personal data to any third party
- We do not transfer your personal data to any third parties other than sub-contractors whose services are necessary for us to carry out our contracted service
- We do not collect or store credit card details
How long do we keep your personal data?
The information we use to communicate with you will be kept until you notify us that you no longer wish to receive information from us, or you want us to delete your personal data. Any personal data that we hold will be kept in line with the requirements of the Data Controller (this is usually your employer), or if the Data Controller has not provided a deletion policy, we will hold the data until we are requested to delete it.
What are your personal data rights?
If at any point you believe the personal data we hold on you is incorrect, you want us to correct or delete that information, or you no longer want us to hold that information or contact you, you can exercise your rights under the current Data Protection laws. These rights include:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
For more information about your personal data rights please visit the Information Commissioner Office website at: https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/individuals-rights/
Who do I contact if I have an issue with or question about the personal data relating to me?
Please contact our Data Protection Officer at support at gptools org dot uk
If you are not satisfied with our response or believe we are processing your personal data in a manner which is not in accordance with the instructions of the Data Controller or the law, you can contact the Information Commissioner’s Office (ICO) https://ico.org.uk/ Their Helpdesk number is 0303 123 1113.
* For more information about Cyber Essentials Plus please visit: https://www.gov.uk/government/publications/cyber-essentials-scheme-overview