Medtech Compass
Medtech Compass

Privacy and Cookie Notice

How we use personal data when providing MedTech Compass

Version 1.0 | Effective date: 21/09/2026

This notice explains how Health Analytical Solutions Limited collects and uses personal data about MedTech Compass users, prospective users, customer contacts and people who contact us about the service. It also explains the cookies and similar technologies used on the MedTech Compass pages and platform covered by this notice.

MedTech Compass is a business-to-business decision support service using NHS and related information. A privacy notice provides information about processing. It is not a request for consent and accepting the subscription terms does not, by itself, provide consent to any processing that requires consent.

1. Who we are and how to contact us

Health Analytical Solutions Limited is registered in England and Wales under company number 08843582. Our registered office is Faircroft House, 101 Ryles Park Road, Macclesfield, Cheshire, SK11 8AL.

For privacy questions, rights requests or complaints, contact the MedTech Compass Privacy Contact at mtcsupport@healthanalyticalsolutions.co.uk, or write to our registered office marked "Privacy".

We are the controller for the account, business-contact, service administration and security processing described here. Where a separately agreed service involves processing personal data solely on a customer's documented instructions, the customer is the controller for that processing and our data processing agreement governs our processor obligations. The customer's privacy information will also apply. Roles depend on what each party actually does.

2. Personal data we use

Depending on your relationship with us, we use your name, business email address, job title, organisation, business contact details, account identifier, account status, permissions and authentication records. We also use customer contact and billing correspondence, subscription and order records, and records of support requests, complaints, feedback and other communications.

Technical and usage information may include IP addresses, browser and device information, login and session records, security events, feature-access records and diagnostic information needed to provide, protect and troubleshoot the service. This information can be personal data even where it is generated automatically.

The platform is not intended to receive patient-level data, special category personal data or criminal-offence information from customers. Do not enter or send these through the platform, support messages, screenshots or attachments. Public availability does not remove data protection obligations. Where prohibited information is received, we will restrict access, assess what action is required, and remove or otherwise deal with it lawfully.

3. Where the information comes from

We obtain information directly when you request access, use the service, provide feedback or contact us. Your employer or another authorised customer representative may provide your business details and access permissions. Our systems and service providers generate account, technical and security records during use. We may receive necessary subscription or payment-status information from the organisation paying for your access and any payment provider used for that transaction.

When your organisation supplies your details, we make this notice available when we first contact you or otherwise within the period required by law. Your organisation may also explain its own use of employee information in its privacy notice.

4. Why we use personal data and our lawful bases

We apply the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, as amended, including applicable changes made by the Data (Use and Access) Act 2025.

Purpose and data Lawful basis and relevant interest
Create and manage accounts, authenticate users and allocate access. Identity, contact, permissions and authentication records. Legitimate interests in providing the service requested by your organisation and managing authorised access. Contract applies instead where you personally contract with us and the processing is necessary for that contract.
Handle enquiries, demonstrations, support, complaints, feedback and service communications. Contact and correspondence records. Legitimate interests in responding to business enquiries and supporting customers. Contract where necessary for a contract with you personally or pre-contractual steps you request. Legal obligation for statutory complaints handling and rights requests.
Administer subscriptions, invoices, collections and business records. Order, billing and contact information. Legitimate interests in administering our customer contracts and collecting sums due. Legal obligation for applicable accounting and tax records. Contract where you personally are the contracting customer.
Protect the service, detect misuse, investigate incidents, diagnose faults and make proportionate service improvements. Technical, access and usage records. Legitimate interests in secure, reliable operation, protecting accounts and improving the service. Any storage or access technology that needs consent is used only after consent. We assess necessity and privacy impact before using identifiable usage information.
Meet legal duties, establish or defend legal claims and handle a business reorganisation. Relevant contact, account and transaction records. Legal obligation where the processing is required by law. Otherwise legitimate interests in protecting legal rights and managing a transaction, subject to necessity, confidentiality and appropriate safeguards.

Where we rely on legitimate interests, we assess whether the processing is necessary and balance our interests, or those of our customers, against your interests, rights and freedoms. We do not treat your employer's contract as a contract with you personally.

Account, security, billing and availability messages are service communications. Any optional marketing subscription will explain its purpose and provide the choices required by law separately. We do not treat acceptance of this notice or the Terms as marketing consent.

5. Information needed to provide the service

We need accurate account and business contact details to authenticate you, allocate your organisation's access and communicate about the service. Without the necessary information, we may be unable to create or maintain your account, provide support or administer a subscription. Optional feedback is voluntary. We will explain where information is required by law or is a condition of a particular service.

6. Cookies and similar technologies

Cookies are small files stored on your device. Similar technologies include browser storage and technologies that read information from a device. The rules apply to these technologies, not only to files labelled as cookies.

We use the technologies listed below for session management, authentication and security. Technologies used solely where strictly necessary to provide a service you request, or solely to transmit a communication, do not require prior consent under the applicable exception. We explain their purpose and duration even where consent is not required.

Cookie Provider Purpose Duration Basis
medtech_compass_session MedTech Compass / Laravel Maintains the user's authenticated/session state. 2 Hours Strictly necessary
XSRF-TOKEN MedTech Compass / Laravel Helps protect requests against cross-site request forgery (CSRF). 2 Hours Strictly necessary

The current service described by this notice does not use advertising or marketing cookies. You can control browser storage through your browser settings, but blocking necessary technologies may prevent sign-in or other requested features from working.

Before introducing other technologies, we will update this information and implement the applicable consent or objection controls. Some limited uses may qualify for another statutory exception only where all its conditions are met. Technologies requiring consent will not be activated before a valid choice. Where consent is used, withdrawing it will be as easy as giving it. Essential account processing is not made conditional on optional consent.

7. Who receives personal data

We disclose information only where necessary for the relevant purpose, to authorised personnel and to providers delivering hosting, infrastructure, authentication, communications, support and other services for us. Processors are subject to appropriate contractual restrictions, confidentiality and security obligations. Some recipients, such as professional advisers, payment providers or public authorities, may act as independent controllers for their own lawful purposes.

We may share relevant information with legal, accounting and insurance advisers, with authorities where lawfully required, and with parties involved in a proposed sale or restructuring under appropriate confidentiality and data protection safeguards. We do not sell personal data.

Where your organisation provides your account, its authorised contacts may receive information reasonably needed to administer access, such as your account status, permissions and whether access has been activated or misused. Any wider sharing of identifiable usage information requires a defined purpose and appropriate privacy information. Your organisation controls its own use of information it receives.

8. International transfers

Personal data may be stored in one country and accessed for support from another. Both hosting and remote access are considered when we assess international transfers. The current position is:

Processing arrangement Country or countries Transfer basis
[HOSTING / AUTHENTICATION / SUPPORT PROVIDER AND ROLE] [STORAGE AND REMOTE ACCESS LOCATIONS] [NO RESTRICTED TRANSFER / APPLICABLE ADEQUACY REGULATIONS / SPECIFIED SAFEGUARD]

Where a restricted transfer takes place, we use a lawful mechanism appropriate to that transfer. This may be applicable UK adequacy regulations or safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, together with the required assessment and any supplementary measures. Routine transfers are not justified merely by your use of the service.

You can request details of the arrangements relevant to your information and a copy of the applicable safeguards by contacting mtcsupport@healthanalyticalsolutions.co.uk. We may redact commercially confidential information that is not needed to explain the protection provided.

9. Retention

We keep information only for the relevant purpose and an appropriate period afterwards. We consider account administration, fault and security investigations, applicable legal record-keeping duties, limitation periods for claims and any continuing dispute. The operational retention periods are:

Record category Retention period or trigger
Account profile and access permissions While access is active, then [ACCOUNT CLOSURE RETENTION PERIOD]. Records needed for another purpose are retained separately under the relevant category.
Support, feedback and routine correspondence [PERIOD] after closure of the issue or last substantive contact, unless linked to a continuing dispute.
Security, login and diagnostic records [PERIOD] from creation, with relevant extracts kept longer where needed to investigate a specific incident or legal claim.
Contracts, billing and statutory business records [PERIOD AND STARTING EVENT], reflecting the applicable record-keeping requirements and legal claims period.
Backups Deleted records age out within [BACKUP RETENTION PERIOD]. Residual backup copies are restricted to recovery and are not used as live account records.
Rights requests, complaints and consent or objection records [PERIOD AND STARTING EVENT]. A minimal objection record may be retained for as long as needed to respect the objection.

Where information is no longer required, it is securely deleted or irreversibly anonymised. We may preserve relevant records during a legal hold or an unresolved complaint, but do not retain all account or usage records indefinitely for that reason.

10. Security

We use technical and organisational measures appropriate to the nature of the data and the risks of processing. These include restricting access to those who need it, managing permissions and authentication, protecting service infrastructure, and maintaining procedures for security incidents and supplier oversight. No online service can guarantee absolute security. This does not reduce our legal obligations.

11. Your rights

Depending on the circumstances, you can request access to your personal data, correction of inaccuracies, erasure, restriction of processing and, where applicable, portability. Where processing relies on consent, you may withdraw that consent at any time without affecting the lawfulness of earlier processing. These rights have conditions and exemptions, which we will explain where relevant.

Your right to object

You may object to processing based on legitimate interests on grounds relating to your particular situation. We must then stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You may object to use of your personal data for direct marketing at any time; that use must then stop.

Send requests to mtcsupport@healthanalyticalsolutions.co.uk or our postal address. No special wording or mandatory form is needed. We may request proportionate information to verify identity or clarify a request where legally permitted. We normally respond without undue delay and within one month. Any lawful extension or adjustment to the time limit will be explained. Requests are normally free of charge; charges or refusal apply only where the law permits.

12. Complaints

You can make a data protection complaint by emailing mtcsupport@healthanalyticalsolutions.co.uk, writing to our registered office or contacting us through a support channel. Please describe the concern and how we can contact you. You do not need to use a particular form.

We will acknowledge a data protection complaint within 30 days of receiving it. We will investigate appropriately, keep you informed and communicate the outcome without undue delay. We will take account of reasonable accessibility needs.

You also have the right to complain to the Information Commissioner's Office (ICO). Its complaints information is available at https://ico.org.uk/make-a-complaint/. Contacting us first can help resolve an issue, but does not remove your statutory right to complain to the regulator.

13. Automated decisions and children

We do not use the personal data described in this notice to make solely automated decisions about you that have legal or similarly significant effects. Routine authentication and security checks are used to protect the service. A change to this position would require an assessment, the applicable safeguards and updated information.

MedTech Compass is intended for adult business and professional users, not children. Please contact us if you believe we have received a child's information through an account or support request.

14. Changes to this notice

We will update this notice when the service, processing arrangements or legal requirements change. The current version and effective date will be available through the service. We will draw significant changes to the attention of affected users where appropriate. A notice update does not provide consent or authorise a new purpose that otherwise needs a lawful basis or additional information.

Contact Us
Contact Us

Have a question, issue, or suggestion? Let us know.

Name
Email
Category
Issue
Suggestion
Question
Title
Message