Effective Date: 1st May 2025
Last Updated: 2nd June 2025

Healthwatch Wirral (“we”, “us”, or “our”) is committed to protecting the privacy of everyone who uses our website (the “Site”). This Privacy Policy explains how we collect, use, and protect personal data in accordance with the UK General Data Protection Regulation (UK GDPR).


1. Who We Are

Healthwatch Wirral is a local, independent organisation that gathers feedback about people’s experiences with health and social care services.

If you have any questions about this policy or how we handle data, please contact us at:
Email: [email protected]


2. What Data We Collect

We collect the following types of information:

a) Free-Text Reviews

You may submit written reviews of your healthcare experiences. We ask that you do not include any personal information (such as your name, contact details, or health records). However, we cannot prevent users from doing so. If you submit such information, you do so at your own risk.

b) Demographic Information

We ask users to answer a set of required demographic questions to better understand the diversity and equity of healthcare experiences. These include:

  • Age
  • Gender
  • Whether your gender identity is the same as your sex registered at birth
  • Sexual orientation
  • Ethnic background
  • Disability status
  • Financial status

Each question includes a “Prefer not to say” option. These questions are designed to be anonymous and are not used to identify individuals.

c) Technical Information

We collect anonymised technical data such as:

  • IP address
  • Browser type and version
  • Device type
  • Pages viewed
  • Time and date of visits

This helps us improve the Site and ensure security.


3. How We Use Your Data

We use the data we collect for the following purposes:

  • To summarise and present reviews on the Site
  • To monitor diversity, equity, and representation in healthcare experiences
  • To analyse and improve our services
  • To comply with legal obligations where applicable

Important: Demographic responses are stored separately and are not used in AI summarisation or shared with any third-party processors.


4. Lawful Basis for Processing

Under the UK GDPR, we rely on the following lawful bases for processing:

  • Consent – When you voluntarily submit reviews and demographic responses, and agree to our Terms of Use and this Privacy Policy.
  • Legitimate interests – To operate and improve the Site in a way that respects your rights and freedoms.
  • Substantial public interest – For processing certain special category data (such as ethnicity or sexual orientation) to support monitoring and improvement of equality in healthcare access, as permitted under the Data Protection Act 2018.

5. Data Retention

We retain data only for as long as necessary to fulfil the purposes outlined in this policy.

  • Free-text reviews may be stored as part of our website content.
  • Demographic data is anonymised where possible and used only for reporting and analysis.
  • Personal data included in reviews (despite our guidance not to) may be removed or redacted.

6. Third-Party Services and Data Sharing

a) Free-Text Content

We use OpenAI’s API to summarise free-text reviews. We take steps to strip out any personal identifiers before content is processed.
We have entered into a Data Processing Agreement (DPA) with OpenAI to ensure appropriate safeguards are in place.

More on OpenAI’s privacy practices: https://openai.com/policies/privacy

b) Demographic Data

Demographic responses are stored securely and never sent to OpenAI or any other third-party data processors. They are used solely for internal analysis, equality monitoring, and reporting.


7. Cookies and Tracking

We may use essential and analytical cookies to enhance user experience and track aggregate usage of the Site. You can manage your cookie preferences through your browser settings. More information is available in our Cookie Policy.


8. Your Rights

Under the UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data
  • Object to or restrict certain types of processing
  • Withdraw consent at any time
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

To exercise any of these rights, please contact us at [email protected].


9. Data Security

We take appropriate technical and organisational measures to safeguard your data. This includes:

  • Secure storage of review and demographic data
  • Limiting access to authorised personnel only
  • Separation of free-text and demographic responses

However, if you submit personal data in a review against our guidance, we cannot guarantee full confidentiality and accept no liability for any resulting disclosure.


10. International Transfers

Some data (such as reviews summarised using OpenAI) may be processed outside the UK. In such cases, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), in accordance with UK GDPR requirements.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date. Continued use of the Site constitutes acceptance of the updated policy.


12. Contact Us

If you have any questions about this Privacy Policy or how we process your data, please contact:
Email: [email protected]
Address: Liscard Business Centre, The Old School, 188 Liscard Road, Liscard, CH44 5TN