GDPR Compliance

Our commitment to protecting your personal data in accordance with UK GDPR and data protection laws.

ICO Registered
UK GDPR Compliant
Data Protection

Comprehensive data protection measures ensuring personal information is processed lawfully, fairly, and transparently.

Individual Rights

Full support for all data subject rights including access, rectification, erasure, and data portability.

Security Measures

Technical and organizational measures to ensure appropriate security of personal data.

Legal Basis for Processing

We process personal data under the following legal bases as defined by UK GDPR:

Legitimate Interest (Article 6(1)(f))

  • • Platform operation and improvement
  • • Security monitoring and fraud prevention
  • • Analytics and usage optimization

Contract Performance (Article 6(1)(b))

  • • Service delivery to NHS trusts
  • • User account management
  • • Support and customer service

Legal Obligation (Article 6(1)(c))

  • • Compliance with healthcare regulations
  • • Financial record keeping
  • • Regulatory reporting requirements

Consent (Article 6(1)(a))

  • • Marketing communications
  • • Optional platform features
  • • Research participation
Data Subject Rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of Access (Article 15)

Request copies of your personal data and information about how it's processed.

Right to Rectification (Article 16)

Request correction of inaccurate or incomplete personal data.

Right to Erasure (Article 17)

Request deletion of your personal data in certain circumstances.

Right to Portability (Article 20)

Receive your personal data in a structured, machine-readable format.

Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing.

Right to Restrict (Article 18)

Request limitation of processing in certain circumstances.

How to Exercise Your Rights: Contact our Data Protection Officer at privacy@metrixhealth.com. We will respond within 30 days of receiving your request.

Technical & Organizational Measures

Technical Measures

  • End-to-end encryption for data in transit and at rest
  • Multi-factor authentication for all user accounts
  • Regular security updates and patch management
  • Automated backup and disaster recovery systems
  • Intrusion detection and monitoring systems

Organizational Measures

  • Data protection impact assessments (DPIAs)
  • Regular staff training on data protection
  • Access controls based on principle of least privilege
  • Incident response and breach notification procedures
  • Third-party vendor assessment and monitoring
Compliance & Contact Information

Regulatory Compliance

  • ICO Registration: ZB123456
  • ISO 27001: Information Security Management
  • Cyber Essentials Plus: Certified
  • NHS IG Toolkit: Compliant

Contact Our DPO

Data Protection Officer

Email: privacy@metrixhealth.com

Phone: +44 20 7946 0958

Post: 123 Harley Street, London, W1G 6BA

Complaints: If you're not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Metrix Search Logo
Metrix Search
by Metrix Health

Revolutionary AI-powered healthcare policy search platform developed by practicing doctors for healthcare professionals across the UK and New Zealand.

info@metrix-health.com
+44 20 7946 0958
London, UK & Auckland, NZ

Platform

© 2025 Metrix Health. All rights reserved. Developed by healthcare professionals in the UK and New Zealand.