Log in Request staff
Data Protection

GDPR & Your Rights

Your rights under UK GDPR and the Data Protection Act 2018, and how MAP Health Care processes personal data across its recruitment platform.

MAP Health Care LTD Company No. 09723243 Version 1.0 Effective 28 June 2026

1Introduction

MAP Health Care LTD ("we", "our", "us") is committed to protecting and respecting your privacy and ensuring that your personal data is handled in accordance with applicable data protection laws.

This document explains your rights under:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)

It also explains how MAP Health Care processes personal data and how you can exercise your legal rights in relation to that data.

This document applies to all users of the MAP Health Care Platform, including healthcare professionals, healthcare providers, contractors and administrative users.

2Who We Are (Data Controller)

For the purposes of data protection law, MAP Health Care LTD is the "Data Controller" of your personal data when we determine the purposes and means of processing.

Company Name: MAP HEALTH CARE LTD

Company Number: 09723243

Registered Office:

Unit 36, Kingswood House, South Road, Kingswood, Bristol, BS15 8JF, United Kingdom

Contact Email: info@maphealthcare.co.uk

Data Protection Contact: Marius Popescu

3What Personal Data We Process

We may process personal data depending on your interaction with the Platform.

This may include:

  • identity information (name, date of birth, identification documents)
  • contact information (email, phone number, address)
  • employment history and CV data
  • professional qualifications and certifications
  • DBS checks and safeguarding records
  • right to work documentation
  • financial information (where applicable for payroll)
  • application and recruitment activity data
  • device and usage data
  • communication records
  • compliance documentation

We process only data that is necessary for recruitment, workforce management, compliance and legal obligations.

4How We Collect Personal Data

We collect personal data through:

  • direct user input (registration, profiles, applications)
  • uploaded documents (DBS, ID, certificates)
  • recruitment activity on the Platform
  • communication with our support team
  • automated system logs and usage data
  • third-party verification providers (where applicable)
  • healthcare providers using the Platform

All data is collected in a lawful, fair and transparent manner.

5Lawful Basis for Processing

We process personal data under the following lawful bases:

Contract

Where processing is necessary to provide our services, including:

  • account creation and management
  • recruitment matching
  • workforce management
  • compliance verification

Legal Obligation

Where required by UK law, including:

  • Right to Work checks
  • safeguarding requirements
  • employment law compliance
  • tax and payroll obligations

Legitimate Interests

Where necessary for:

  • Platform security
  • fraud prevention
  • service improvement
  • operational efficiency
  • audit and compliance monitoring

Consent

Where required, for example:

  • optional marketing communications
  • non-essential cookies
  • optional features or surveys

6Your Rights Under UK GDPR

Under UK data protection law, you have a number of rights in relation to your personal data. MAP Health Care LTD is committed to facilitating the exercise of these rights in a transparent and timely manner.

These rights are not absolute and may be subject to legal limitations, particularly where we are required to retain data for compliance, safeguarding, or regulatory purposes.

6.1Right of Access

You have the right to request confirmation as to whether we process your personal data and to obtain a copy of the personal data we hold about you.

This may include:

  • account information
  • recruitment records
  • compliance documentation
  • communication history
  • activity logs

We may request proof of identity before fulfilling such requests.

6.2Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

We encourage users to keep their profiles and documentation up to date, especially in relation to:

  • qualifications
  • DBS status
  • right to work documentation
  • contact details

6.3Right to Erasure ("Right to be Forgotten")

You may request deletion of your personal data in certain circumstances, such as where:

  • the data is no longer necessary for its original purpose
  • you withdraw consent (where applicable)
  • you object to processing and there are no overriding legitimate grounds

However, this right may be restricted where we are legally required to retain data, including for:

  • employment law compliance
  • safeguarding obligations
  • tax and financial regulations
  • fraud prevention
  • legal claims or disputes

6.4Right to Restrict Processing

You may request that we temporarily restrict the processing of your personal data where:

  • you contest its accuracy
  • processing is unlawful
  • we no longer need the data but you require it for legal claims
  • you have objected to processing pending verification of legitimate grounds

6.5Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may request a structured, commonly used and machine-readable copy of your personal data.

Where technically feasible, you may request transfer of your data to another service provider.

6.6Right to Object

You have the right to object to processing based on legitimate interests.

We will stop processing unless we can demonstrate:

  • compelling legitimate grounds overriding your rights, or
  • necessity for legal claims or compliance obligations

You may also object at any time to direct marketing.

6.7Rights in Relation to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing where such decisions produce legal or similarly significant effects.

MAP Health Care LTD does not make final recruitment decisions solely through automated systems.

Automated tools may assist in:

  • matching candidates to roles
  • compliance checks
  • scheduling processes

However, human oversight is always applied where required.

7How to Exercise Your Rights

You may exercise your rights by contacting us using the details provided in this document.

We will:

  • verify your identity where necessary
  • respond without undue delay
  • provide a response within one month (unless extended under UK GDPR provisions)

In complex cases, this period may be extended by an additional two months.

8Data Sharing and Disclosure

We may share personal data where necessary with:

  • healthcare providers and employers
  • recruitment partners
  • payroll and payment providers
  • regulatory authorities
  • safeguarding bodies
  • DBS and verification services
  • IT and cloud service providers (e.g., Supabase, Firebase)
  • legal and professional advisers

All third parties are required to process data in accordance with UK GDPR and strict confidentiality obligations.

We do not sell personal data.

9International Data Transfers

Some of our service providers may process data outside the United Kingdom.

Where this occurs, we ensure appropriate safeguards are in place, including:

  • UK adequacy regulations
  • International Data Transfer Agreements (IDTA)
  • standard contractual clauses approved under UK law
  • additional technical and organisational security measures

We ensure your data remains protected regardless of where it is processed.

10Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • encryption in transit (TLS/HTTPS)
  • encrypted data storage
  • access control restrictions
  • authentication and session management
  • audit logging
  • secure cloud infrastructure
  • regular security monitoring and updates
  • staff confidentiality obligations

While no system is completely secure, we take all reasonable steps to protect your data against unauthorised access, alteration or loss.

11Automated Processing and Profiling

We may use automated systems to support operational efficiency, including:

  • candidate-job matching
  • compliance validation reminders
  • shift allocation recommendations
  • fraud detection and risk scoring
  • system monitoring and analytics

These systems do not replace human decision-making in final employment or recruitment outcomes.

12Data Retention

MAP Health Care LTD retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, including legal, regulatory, safeguarding and operational requirements.

Retention periods may vary depending on the type of data and its purpose, including:

  • recruitment and employment records
  • compliance documentation (DBS, Right to Work, certifications)
  • payroll and financial records
  • communication logs
  • system and security logs
  • audit and legal records

Where data is no longer required, it will be securely deleted, anonymised or archived in accordance with applicable legal obligations and internal retention schedules.

In certain cases, data may be retained for longer periods where required by law or where necessary to establish, exercise or defend legal claims.

13Safeguarding and Healthcare Compliance

As a healthcare recruitment platform, MAP Health Care LTD operates within a regulated environment where safeguarding is a legal and ethical priority.

We may process personal data where necessary to:

  • assess safeguarding risks
  • verify suitability for healthcare roles
  • comply with NHS and regulatory requirements
  • support safe staffing decisions
  • investigate safeguarding concerns or incidents

Where safeguarding concerns arise, we may share relevant information with:

  • healthcare providers
  • regulatory bodies
  • safeguarding authorities
  • law enforcement agencies (where legally required)

Processing of safeguarding-related data may occur without consent where there is a legal obligation or where necessary to protect vulnerable individuals.

14Data Breaches

MAP Health Care LTD has procedures in place to detect, investigate and respond to personal data breaches in accordance with UK GDPR.

In the event of a personal data breach, we will:

  • assess the nature and severity of the breach
  • take immediate steps to contain and mitigate risk
  • notify the Information Commissioner’s Office (ICO) where required by law
  • notify affected individuals where there is a high risk to their rights and freedoms

We maintain appropriate technical and organisational safeguards to reduce the risk of breaches occurring.

15Complaints and the Information Commissioner’s Office (ICO)

If you have concerns about how your personal data has been handled, we encourage you to contact us first so we can attempt to resolve the issue directly.

However, you also have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner’s Office (ICO)

Website: https://ico.org.uk

The ICO is responsible for overseeing data protection compliance in the United Kingdom.

Submitting a complaint to the ICO does not affect any other legal rights or remedies you may have.

16Changes to This Document

We may update this GDPR & Your Rights document from time to time to reflect:

  • changes in legislation or regulatory guidance
  • changes in our services or technology
  • improvements in security or operational practices
  • updates to data processing activities

Any updated version will be published on our Platform.

Where appropriate, we may notify users of significant changes.

The “Last Updated” date at the top of this document indicates the most recent revision.

17Contact Us

If you have any questions about this document or wish to exercise your data protection rights, you may contact us using the details below:

MAP HEALTH CARE LTD

Company Number: 09723243

Registered Office:

Unit 36, Kingswood House, South Road, Kingswood, Bristol, BS15 8JF, United Kingdom

Email: info@maphealthcare.co.uk

Data Protection Contact: Marius Popescu

We aim to respond to all requests in a timely, transparent and professional manner.

18Final Statement

MAP Health Care LTD is committed to protecting personal data and ensuring compliance with UK data protection law.

We recognise the importance of transparency, accountability and trust when handling personal data, particularly within the healthcare sector.

By using the MAP Health Care Platform, you acknowledge that you have read and understood this document and your rights under UK GDPR.

We remain committed to maintaining the highest standards of data protection, safeguarding and information security across all our services.