CP+R Privacy Information Notice (UK GDPR)
Last updated: July 2026
Your privacy and the security of your personal information are extremely important to us. This Privacy Information Notice explains how CP+R collects, uses, stores and protects your personal and health information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Caldicott Principles.
1. Who We Are
CP+R 8 Upper Wimpole Street London W1G 6LH
We are the Data Controller for the personal and health information we collect and process. If you have any questions about this notice, please contact us at referrals@cpandr.co.uk.
2. What Information We Collect
We collect and process personal information so we can provide safe, effective cardiac rehabilitation and related clinical services. This includes:
-
Name, title and date of birth
-
Residential address
-
Telephone numbers and email addresses
-
Next of kin details
-
Details of your medical practitioner(s)
-
Medical conditions, diagnostic information and treatment history
-
Exercise testing and training records
-
Lifestyle information relevant to your care
-
Information you provide through forms, assessments, consultations or digital applications
We also process special category data, including physical and mental health information, under:
-
Article 9(2)(h) UK GDPR – provision of health or social care
-
Common Law Duty of Confidentiality – consent or reasonable expectation
3. How We Use Your Information
We use your personal and health information to:
-
Assess your suitability for our services
-
Deliver safe and effective rehabilitation
-
Design and monitor your personalised exercise programme
-
Communicate with you and your medical practitioners
-
Administer payments and manage your account
-
Meet legal, regulatory and clinical governance requirements
-
Protect our legal rights
-
Improve our services through anonymised research, audit and statistical analysis
-
Provide access to digital applications used in your programme
-
Notify you of changes to our services
Marketing communications
We may send you information about CP+R services only if you have given explicit consent. You can withdraw consent at any time.
4. Lawful Basis for Processing
We process your personal data under:
-
Article 6(1)(f) – legitimate interests (private provider)
-
Article 9(2)(h) – provision of health or social care
-
Common Law Duty of Confidentiality
5. How We Collect Information
We collect information:
-
Directly from you (forms, consultations, assessments, digital applications)
-
From medical practitioners involved in your care
-
From third‑party service providers where lawful and necessary
-
From publicly available sources where appropriate
6. Sharing Your Information
We may share your information with:
-
Healthcare professionals involved in your care
-
Your GP or referring clinician
-
Regulatory bodies, safeguarding teams or law enforcement where legally required
-
Our professional advisers (e.g., legal or clinical governance)
-
Approved service providers who process data on our behalf
-
Third parties involved in legal proceedings
-
Third parties in the event of a business transfer or acquisition
We do not share your information for commercial purposes.
7. International Transfers
If your data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
-
The International Data Transfer Agreement (IDTA)
-
The UK Addendum to EU Standard Contractual Clauses
-
ICO‑approved transfer mechanisms
8. Data Retention
We retain your information only for as long as necessary to meet clinical, legal and regulatory requirements.
In line with the Records Management Code of Practice 2021:
-
Adult health records are retained for 8 years
-
Some information may be retained longer where required for legal purposes
Where possible, personal identifiers are removed, and data is archived securely under the oversight of CP+R’s Caldicott Guardian. When the retention period expires, information is securely destroyed.
9. Security of Your Information
We use appropriate technical and organisational measures to protect your data, including:
-
Encryption
-
Secure access controls
-
Secure physical storage
-
Regular security testing
-
Staff training in data protection and confidentiality
When communicating sensitive information electronically, we use secure or encrypted methods wherever possible.
10. Automated Decision‑Making
We do not make decisions about your care solely through automated processes. If this ever changes, we will inform you and explain your rights.
11. Your Rights
Under UK GDPR, you have the right to:
-
Be informed about how your data is used
-
Access your personal information
-
Request correction of inaccurate information
-
Request restriction of processing
-
Request erasure (“right to be forgotten”)
-
Object to processing (including marketing)
-
Request data portability
-
Withdraw consent for marketing at any time
-
Object to automated decision‑making
-
Lodge a complaint with the Information Commissioner’s Office (ICO)
Some rights may be limited where we are required to retain health records for legal or clinical reasons.
To exercise your rights, contact: referrals@cpandr.co.uk
12. Cookies, Websites and Apps
If you use our website or digital applications, we may collect technical information such as IP address, device type and usage data.
Third‑party apps or websites have their own privacy notices. We are not responsible for their data handling practices.
13. Email and Electronic Communication
You or your medical practitioners may send personal information electronically. Where possible, we encourage the use of secure or encrypted methods. We will always use secure processes when sending sensitive information to you or your clinicians.
14. Changes to This Notice
We may update this Privacy Information Notice from time to time. The latest version will always be available at: www.cpandr.co.uk
15. Contact Us
If you have any questions or concerns about how we handle your information, please contact:
CP+R 8 Upper Wimpole Street London W1G 6LH Email: referrals@cpandr.co.uk
You may also contact the Information Commissioner’s Office at: https://ico.org.uk/concerns/