How IThirtyFour collects, uses, and protects your personal data
IThirtyFour ("IThirtyFour", "we", "us", or "our") is a software consultancy and development contractor registered in England and Wales. We provide digital and technology services exclusively to NHS and health sector organisations, including patient portal application development, NHS England API integrations, FHIR API implementations, and education and learning management systems.
For the purposes of UK data protection law, IThirtyFour is the Data Controller in respect of personal data collected through this website and in connection with our business activities.
Our registered address and contact details are set out in Section 15 of this policy.
We are registered with the Information Commissioner's Office (ICO) as a Data Controller. ICO Registration Number: ZC189633. You can verify our registration at ico.org.uk.
We collect personal data in the following ways and for the following purposes:
| Data collected | Source | Purpose |
|---|---|---|
| Name, job title, NHS organisation, work email address, telephone number | Contact form submissions | To respond to enquiries and progress potential business engagements |
| Project description and requirements | Contact form submissions | To understand and respond to your specific needs |
| Name and email address | Newsletter sign-up | To send you updates, insights, and information about our services |
| IP address, browser type, pages visited, time on site, referring URL | Cookies and analytics tools | To understand how visitors use our website and improve our content |
| Name, contact details, professional information | Business cards, emails, events, referrals | To manage business relationships and communications |
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we must have a lawful basis for processing your personal data. We rely on the following lawful bases:
When you submit an enquiry through our website contact form, we collect the personal data you provide, which typically includes your name, NHS organisation, work email address, and a description of your project or enquiry.
We use this information solely to:
We will not use the personal data submitted via our contact form for unsolicited marketing purposes unless you have separately opted in to receive marketing communications from us.
Contact form data is stored securely and retained in accordance with the retention periods set out in Section 10.
Our website uses cookies โ small text files placed on your device โ to help us understand how visitors use the site and to improve your experience.
We use the following categories of cookies:
| Category | Description | Basis |
|---|---|---|
| Strictly necessary | Essential for the website to function. These cannot be disabled. | Not required (necessary for service) |
| Analytics / performance | Help us understand how visitors interact with our website (e.g. Google Analytics). Data is aggregated and anonymised where possible. | Consent |
| Functional | Remember your preferences to improve your experience. | Consent |
You can manage your cookie preferences at any time via our cookie consent tool on our website. You can also control cookies through your browser settings, though disabling certain cookies may affect the functionality of the site.
Where we use Google Analytics, data may be processed by Google LLC. We have enabled IP anonymisation and have entered into appropriate data processing agreements with Google. For more information, see Google's Privacy Policy.
We may send you newsletters, updates, and information about our services if you have opted in to receive such communications from us.
In line with the Privacy and Electronic Communications Regulations (PECR) and UK GDPR:
We will honour unsubscribe requests promptly and within no more than 10 working days.
IThirtyFour provides software consultancy services exclusively to NHS and health sector organisations. In the course of delivering these services, we may handle personal data on behalf of our NHS clients as a Data Processor.
Where we act as a Data Processor:
If you are a patient or service user of an NHS organisation and have a query about how your personal data is used, please contact that NHS organisation directly. They are the Data Controller for your health records and personal information.
We do not sell, rent, or trade your personal data to any third party. We may share your data only in the following limited circumstances:
We aim to store and process your personal data within the United Kingdom. Where we use third-party service providers that transfer data outside the UK (for example, to the United States or European Economic Area), we ensure that appropriate safeguards are in place in accordance with UK GDPR, such as:
You may request details of the specific safeguards in place for any international transfers by contacting us at privacy@ithirtyfour.co.uk.
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our general retention periods are as follows:
| Data type | Retention period |
|---|---|
| Contact form enquiries (where no contract results) | 12 months from last contact |
| Contact form enquiries (where a contract results) | Duration of contract plus 7 years |
| Newsletter subscribers | Until you unsubscribe or withdraw consent |
| Business contact records | Duration of relationship plus 3 years |
| Analytics data | 26 months (in line with Google Analytics defaults) |
| Financial and contractual records | 7 years (as required by HMRC) |
When personal data is no longer required, we securely delete or anonymise it in accordance with our data retention procedures.
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at privacy@ithirtyfour.co.uk. We will respond to all requests within one calendar month, as required by UK GDPR.
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
We would, however, appreciate the opportunity to address your concerns directly before you contact the ICO.
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include:
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it, and will inform affected individuals without undue delay where required.
Our website and services are directed at healthcare and NHS organisations and their professional staff. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data without appropriate consent, please contact us at privacy@ithirtyfour.co.uk and we will take steps to delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the effective date at the top of this policy and, where appropriate, notify you by email or by a prominent notice on our website.
We encourage you to review this policy periodically. Your continued use of our website following any updates constitutes your acknowledgement of the revised policy.
If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a concern about how we handle your personal data, please contact us:
๐ง Email: privacy@ithirtyfour.co.uk
๐ฎ Post: IThirtyFour, Roseacre, Six Arches Lane, Scorton, PR3 1AL
๐ Website: www.ithirtyfour.co.uk
We aim to respond to all privacy-related enquiries within 5 working days and to all formal data subject rights requests within one calendar month as required by UK GDPR.