At tapGP, our medical and technical teams collaborate closely to redefine the delivery of healthcare services. We place you, whether you’re approaching us as an individual seeking health advice or as a patient in need of care, at the centre of everything we do. This Privacy Policy is designed to transparently communicate how we manage your personal data from the moment you register and begin using our app, to every interaction you have with our healthcare services.
In this Privacy Policy, we delve into the workings of tapGP for you as both a user and a patient. We outline our responsibilities regarding the processing of your personal data in connection with the services we provide. We detail the types of personal data we collect during your use of our services, the methods and reasons behind our data processing activities, and the legal foundations that support these processes. We identify the external parties involved in handling your personal data to ensure the seamless provision of our services. This document also aims to inform you about your rights concerning your personal data and guides you on how to exercise these rights effectively.
TAP GP Limited, the formal entity behind the tapGP platform, operates as the principal developer and provider of the tapGP application. As such, TAP GP Limited acts as the data controller for all personal data that you register within the app.
Healthcare service provision begins when you share your health status through initial assessments or questionnaires and continues through consultations, record-keeping, and the necessary administration of your care, as outlined in this Privacy Policy.
When you register and use your account with tapGP, we collect personal data that you provide, such as:
There are instances where tapGP receives patient data from other sources not directly associated with tapGP, such as other healthcare providers, your employer, partnerships or your insurance company. This information, when relevant to your ongoing care within tapGP services, will be processed and integrated into your medical records by the clinician responsible for your treatment.
In each of these scenarios, tapGP is committed to managing your data with the utmost care and security, ensuring compliance with applicable data protection regulations and respecting your privacy and rights at every step of the healthcare provision process.
tapGP places the utmost importance on the security and integrity of your personal data. All personal data is securely stored on Amazon Web Services (AWS) servers. tapGP has chosen AWS due to its robust security features, compliance certifications, and global infrastructure, which align with our commitment to safeguarding your data.
In keeping with our obligations to provide secure and compliant healthcare services, tapGP and our clinicians maintain detailed medical records as part of our service delivery. This data is stored on AWS servers, employing a medical record system that is specifically developed to meet the stringent requirements of applicable healthcare legislation. While tapGP oversees the management of this system, certain operations may be delegated to third-party service providers who are experts in managing healthcare data, ensuring that all patient data is treated with the utmost care and security.
Our choice to use AWS servers for storing all categories of personal data reflects our dedication to employing advanced technologies and services that meet our high standards for data protection, security, and compliance. AWS’s global reputation for reliability and security, combined with their commitment to data privacy, makes them an ideal partner in our efforts to provide secure, efficient, and compliant healthcare services.
At tapGP, the collection and processing of data are integral to our operation and delivery of personalised healthcare services. We process your data for several key reasons:
Our commitment to your privacy and the careful handling of your personal data underpins every aspect of our service provision. We ensure that all data processing activities are transparent, secure, and aligned with both our service delivery goals and your rights as a user.
tapGP is committed to offering comprehensive support as an integral component of our services. This support is essential for fulfilling the contractual obligations between you and tapGP, encompassing a range of activities from addressing inquiries to resolving complaints and providing technical assistance through our support services, accessible via telephone or our digital platforms.
tapGP uses your data to keep you informed with news, updates, and promotional content through various electronic communication channels, including email, text messages, push notifications, and in-app messages. Our communications strategy is tailored based on our understanding of your interactions with the app and the services, such as your usage patterns, previous communications preferences, searches, and basic demographic information like age, gender, and region. It’s important to note that your health data is only used for communication with your explicit consent.
Our basis for processing your personal data for marketing purposes aligns with our legitimate interests in providing an accessible online platform that connects you seamlessly with healthcare services. We may send you information about services like those you have previously engaged with, provided we obtained your contact details upon registration with the option for you to opt-out at any time.
This website is using Tidio, a chat platform that connects users with the customer support of tapGP. We are collecting email addresses and names only with the consent of the users, in order to start the chat. The messages and data exchanged are stored within the Tidio application. For more information, please refer to their Privacy Policy.
tapGP is not making use of these messages or data other than to follow up on users’ registered issues or inquiries. Your personal data will be processed and transmitted in accordance with the General Data Protection Regulation (GDPR).
tapGP may process your data as necessary to fulfil our legal obligations within the healthcare domain and other relevant legal requirements. This encompasses adherence to statutory regulations, court orders, or directives from public authorities related to healthcare provision and data protection.
Our aim to continuously enhance the quality and security of our services and the supporting IT infrastructure is grounded in legitimate interests. This involves processing User Data to develop and improve the app’s user-friendliness, such as optimising the user interface and enhancing features that are most valuable to our users, based on anonymised data.
Data retention
At tapGP, we adhere to the guidelines provided by healthcare authorities and professional associations regarding the duration for which your information is stored, known as the ‘retention period’. We aim to balance the need for retaining medical records for continuity of care and legal requirements against our commitment to data minimisation and privacy.
We may retain anonymised information to enhance our services and business operations. In certain cases, legal obligations may necessitate keeping data for extended periods.
Below is an overview of how long different types of your information are retained by tapGP:
Sharing your personal data with third parties
While providing tapGP services, we collaborate with a variety of third parties to ensure you receive comprehensive and efficient healthcare. The following outlines the types of third parties with whom your personal data may be shared:
Your data protection rights
At tapGP, we recognise the importance of your privacy and are committed to ensuring the protection of your personal data. Below are the rights you hold regarding the data we collect and process:
To exercise any of these rights or for inquiries related to the processing of your personal data by a third-party healthcare provider, please contact us directly through our website or at info@tapgp.co.uk. For third-party related requests, reaching out directly to the concerned provider is advised.
Please provide proof of identity when making a request. We are obliged by data protection laws to respond within one month.
tapGP adheres to regulations set by the Information Commissioner’s Office (ICO). If you have concerns about our data handling practices, you are entitled to lodge a complaint with the ICO at:
Telephone: +44 0303 123 1113
Email: casework@ico.org.uk
Website: www.ico.org.uk
Web-form: www.ico.org.uk/make-a-complaint/
Address: Water Lane, Wycliffe House, Wilmslow, Cheshire, SK9 5AF
Updates to our Privacy Policy
At tapGP, we are continually refining our services and how we handle your data to better serve your healthcare needs. This may result in changes to our Privacy Policy.
Should there be any significant amendments to how we manage, process, or protect your personal data, we will proactively inform you through our app, website, or via email. This notification will provide you with the opportunity to review the changes.
By continuing to use tapGP’s services after these updates take effect, your acceptance of the revised policy is implied. We understand this as your agreement to the updated terms regarding our use of your data.
If, however, you find that you do not agree with the changes, please understand that your continued use of our services may not be possible. We respect your decision and rights in this matter and will provide options for managing or withdrawing your data in accordance with the new policy terms.