Effective Date: 1st May 2025
Last Updated: 2nd June 2025
Healthwatch Wirral (“we”, “us”, or “our”) is committed to protecting the privacy of everyone who uses our website (the “Site”). This Privacy Policy explains how we collect, use, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR).
1. Who We Are
Healthwatch Wirral is a local, independent organisation that gathers feedback about people’s experiences with health and social care services.
If you have any questions about this policy or how we handle data, please contact us at:
Email: [email protected]
2. What Data We Collect
We collect the following types of information:
a) Free-Text Reviews
You may submit written reviews of your healthcare experiences. We ask that you do not include any personal information (such as your name, contact details, or health records). However, we cannot prevent users from doing so. If you submit such information, you do so at your own risk.
b) Demographic Information
We ask users to answer a set of required demographic questions to better understand the diversity and equity of healthcare experiences. These include:
- Age
- Gender
- Whether your gender identity is the same as your sex registered at birth
- Sexual orientation
- Ethnic background
- Disability status
- Financial status
Each question includes a “Prefer not to say” option. These questions are designed to be anonymous and are not used to identify individuals.
c) Technical Information
We collect anonymised technical data such as:
- IP address
- Browser type and version
- Device type
- Pages viewed
- Time and date of visits
This helps us improve the Site and ensure security.
3. How We Use Your Data
We use the data we collect for the following purposes:
- To summarise and present reviews on the Site
- To monitor diversity, equity, and representation in healthcare experiences
- To analyse and improve our services
- To comply with legal obligations where applicable
Important: Demographic responses are stored separately and are not used in AI summarisation or shared with any third-party processors.
4. Lawful Basis for Processing
Under the UK GDPR, we rely on the following lawful bases for processing:
- Consent – When you voluntarily submit reviews and demographic responses, and agree to our Terms of Use and this Privacy Policy.
- Legitimate interests – To operate and improve the Site in a way that respects your rights and freedoms.
- Substantial public interest – For processing certain special category data (such as ethnicity or sexual orientation) to support monitoring and improvement of equality in healthcare access, as permitted under the Data Protection Act 2018.
5. Data Retention
We retain data only for as long as necessary to fulfil the purposes outlined in this policy.
- Free-text reviews may be stored as part of our website content.
- Demographic data is anonymised where possible and used only for reporting and analysis.
- Personal data included in reviews (despite our guidance not to) may be removed or redacted.
6. Third-Party Services and Data Sharing
a) Free-Text Content
We use OpenAI’s API to summarise free-text reviews. We take steps to strip out any personal identifiers before content is processed.
We have entered into a Data Processing Agreement (DPA) with OpenAI to ensure appropriate safeguards are in place.
More on OpenAI’s privacy practices: https://openai.com/policies/privacy
b) Demographic Data
Demographic responses are stored securely and never sent to OpenAI or any other third-party data processors. They are used solely for internal analysis, equality monitoring, and reporting.
7. Cookies and Tracking
We may use essential and analytical cookies to enhance user experience and track aggregate usage of the Site. You can manage your cookie preferences through your browser settings. More information is available in our Cookie Policy.
8. Your Rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data
- Object to or restrict certain types of processing
- Withdraw consent at any time
- Lodge a complaint with the Information Commissioner’s Office (ICO)
To exercise any of these rights, please contact us at [email protected].
9. Data Security
We take appropriate technical and organisational measures to safeguard your data. This includes:
- Secure storage of review and demographic data
- Limiting access to authorised personnel only
- Separation of free-text and demographic responses
However, if you submit personal data in a review against our guidance, we cannot guarantee full confidentiality and accept no liability for any resulting disclosure.
10. International Transfers
Some data (such as reviews summarised using OpenAI) may be processed outside the UK. In such cases, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), in accordance with UK GDPR requirements.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date. Continued use of the Site constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we process your data, please contact:
Email: [email protected]
Address: Liscard Business Centre, The Old School, 188 Liscard Road, Liscard, CH44 5TN