Skip to content

Privacy Policy

You’re in control of your data

It is important to us that we are diligent when it comes to your privacy. That’s why we have built our service with user privacy at the centre of everything we do – and built processes to let you control your data.

Who We Are

Craetus Digital Healthcare Ltd. is the developer of Craetus App. It offers digital-first prehabilitation and perioperative services to its users.

When this policy talks about ‘Craetus’, ‘us’ or ‘we’, it means Craetus Digital Healthcare Ltd. When this policy talks about ‘App, it means the Craetus smartphone application. Craetus Digital Healthcare Ltd. is the controller of your data provided to, or collected by or for, or processed in connection with our prehab services

What personal data we hold and how we get it

We use the following categories of personal data:

  • Personal details
  • When you register with us, you complete forms and provide us with basic information about yourself, such as your name and phone number.
  • You are responsible for the accuracy of the information that you provide to us.

Health and medical information

The main type of information we hold about you is your interaction with our digital service. Your interactions with our digital service may be shared with our doctors in order to provide you with a better experience and for the purposes of providing you health care.

We may also hold information about you from other apps, devices and services where you have given your consent to that data being shared with us. Examples include where you decide to share information collected from a smart watch or similar device with our App.

Technical information and analytics

When you use our App or visit our website, we may automatically collect the following information where this is permitted by your device or browser settings:

  • technical information, including the address used to connect your mobile phone or other device to the Internet, your login information, system and operating system platform type and version, device model, browser or app version, time zone setting, language and location preferences, wireless carrier and your location (based on IP address); and
  • information about your visit (such as when you first used the App and when you last used it, and the total number of sessions you have had on that App), including products and services you viewed or used, App response times and updates, interaction information (such as button presses or the times and frequency of your interactions with the communications we deliver to you in the App or otherwise) and any phone number used to call our customer service number.

We work with partners who provide us with analytics and advertising services (for our services only and not for third party advertising). This includes helping us understand how users interact with our services, providing our advertisements on the internet, and measuring performance of our services and our adverts. Cookies and similar technologies may be used to collect this information, such as your interactions with our services. Our Cookie Policy is available at: craetus.com/terms/cookies. You can prevent the setting of cookies by adjusting the settings on your browser or your mobile phone.

Information obtained from third party services

You may choose to connect your existing accounts with other providers (such as a social media provider), for example, when signing up to make it easier to create an account with us. If you choose to do this, we will receive limited information about you from that provider, such as your email address and name.

Provided we are acting in accordance with data protection laws, we may also use information from other sources, such as specialist companies that supply information, online media channels, our commercial partners and public registers. This information can for example, help us to improve and measure the effectiveness of our services.

What we use your personal data for

The purposes for which we use your personal data and the legal grounds on which we do so are as follows:

Providing you a service

  • We obtain and use your personal details in order to establish and deliver our contract with you.
  • We use your medical information because this is necessary for medical purposes, including medical diagnosis and the provision of healthcare or treatment. This includes the information collected through our consultations with you (such as notes and recordings) and our digital services. It may also include sharing information with other healthcare professionals as necessary for the provision of care to you, such as your GP, specialist referral services, therapists, pharmacists, hospitals, accident and emergency services, pathology service providers, and diagnosis centres chosen by you for the purpose of imaging request forms.

Keeping you up to date

  • We use your email address, phone number and/or details to contact you or present you with occasional updates where you have not opted out.

Other uses

  • Based on our legitimate interest in managing and planning our services, we may analyse data about your use of our App to troubleshoot bugs or improve our website, forecast demand of service and to understand other trends in use, including which features users use the most and find most helpful, and what features users require from us. This does not involve making any decisions about you that would have a significant legal effect on you – it is only about improving our App so that we can deliver better services to you. Strict confidentiality and data security provisions will apply at all times.
  • Where necessary for safety, regulatory and/or compliance purposes, we may audit your interactions with our services. Strict confidentiality and data security provisions will apply at all times to any such audit and access

Sharing your personal data with other healthcare providers

We will, where necessary for your treatment or care, share your information with your other health and social care providers. For example, your NHS GP and other NHS bodies, specialist referral services, therapists, pharmacists, hospitals, accident and emergency services, pathology service providers, diagnosis centres chosen by you for the purpose of imaging requests, and other health and care bodies. This may include sharing information with such services for safeguarding purposes in accordance with our legal obligations.

Except as described above, we will never share your personal information with any other party without your consent.

Retention

We retain your medical records in accordance with national best practice guidance – in particular, advice provided by the Department of Health (2006) Records management: NHS code of practice, and summary guidance issued by the British Medical Association.

Data storage, security and transfers

We do not store your personal health data on your mobile device. We store all your personal data on secure servers.

Where you have chosen a password that enables you to access certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.

We encrypt data transmitted to and from the App. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.

Your data may be processed or stored via destinations outside of the UK and the European Economic Area (EEA), but always in accordance with data protection law, including mechanisms to lawfully transfer data across borders, and subject to strict safeguards. For example, we work with third parties who help deliver our services to you, whose servers may be located outside the UK or EEA

Your rights

As indicated above, whenever we rely on your consent to process your personal data, you have the right to withdraw your consent at any time.

You also have specific rights under the GDPR and DPA to:

  • wherever we process data based on your consent, withdraw that consent at any time. You can do this by sending us an email;
  • understand and request a copy of information we hold about you. Subject to our retention period;
  • ask us to erase information we hold about you, subject to limitations relating to our obligation to store records for medical diagnoses for prescribed periods of time;
  • ask us to restrict our processing of your personal data or object to our processing; and

You may also contact the Information Commissioners Office (the data protection regulator in the UK): Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone: 0303 123 1113 (local rate).

Contact us

For any questions or concerns, you can contact us by visiting our contact page