This privacy notice describes the personal data the E-Health Productivity and Innovation in Cornwall (EPIC2) project collects from you, explaining why we collect this data, what we do with it, how long it is stored and whether it is shared with anyone.
Who are we and who is our representative?
EPIC2 is a European Regional Development Fund (‘ERDF’) project led by the University of Plymouth, with key delivery partners in Kernow Health CIC and South West Academic Science Health Network (SW AHSN).
The data controller is the University of Plymouth, registered with the Information Commissioner’s Office (ICO) under registration number Z7546264. Its Data Protection Officer can be contacted at firstname.lastname@example.org. The EPIC2 project can be contacted at email@example.com.
What information do we collect and why?
EPIC2 collects different types of personal data to provide the best possible experience and service, to ensure the effective operation of the project and to meeting statutory or contractual reporting obligations set out in this notice.
The following are examples of personal data (not exhaustive) that may be collected, stored and used:
In certain limited circumstances (e.g. event booking), special category data may be collected. These are more sensitive categories of identifying information including but not limited to the following: racial or ethnic origin, political opinions, religious or philosophical beliefs, data concerning health or data concerning a natural person’s sex life or sexual orientation and data relating to criminal convictions.
When and how do we collect your data?
EPIC2 will collect your information in different ways during its relationship with you. These will include:
How do we use your personal data?
EPIC2 will use your personal data in the following ways:
What is the lawful basis for processing personal data?
EPIC2 must have a lawful basis in order to process personal data. For the processing of your data, this includes:
EPIC2 may also use your data, typically in an emergency, where this is necessary to protect your vital interests, or someone else’s vital interests.
In relation to more sensitive personal data (special category data), the additional legal bases for these are:
If consent is required for any additional uses of your personal information, including your image and more sensitive personal information, we will collect it at the appropriate time and explain this to you. Where the University is processing your data on the basis of your consent, you can withdraw your consent at any time. We will not use your personal information to carry out any wholly automated decision-making that affects you.
How long do we hold your data?
The EPIC2 project runs until April 2023. As a Grant Recipient, we are required to comply with and assist the Managing Authority to comply with document retention requirements under any applicable State Aid rules. Where Projects are operating under a State Aid scheme in accordance with the General Block Exemption Regulation (Commission Regulation (EU) No 651/2014) or De Minimis Regulation (Commission Regulation (EU) No 1407/2013), Grant Recipients must maintain detailed records with the information and supporting documentation necessary to establish that all the conditions laid down in the Regulation are fulfilled. Such records must be kept for 10 years after the last aid is granted under the scheme, meaning that documents will need to be retained until 2033.
Who do we share your data with?
Where there is a legitimate need or statutory obligations the University will disclose necessary personal data to third parties. Depending on individual circumstances, these may include the following:
Kernow Health CIC
Members of the EPIC2 team, including consultants
What rights do you have?
The General Data Protection Regulation (GDPR) and the Data Protection Act 2018 increased the number of rights an individual has in relation to the gathering, processing and storage of personal data. These are:
Please note the rights are not absolute and may not apply in all circumstances. Further information on accessing these rights can be found at Your information rights or by emailing firstname.lastname@example.org.
Changes to this notice
This privacy notice is reviewed annually or when required, to ensure compliance with data protection legislation. If significant changes are made to this notice and the way we treat your personal information, we will make this clear and may seek to communicate this directly to you.
Date of Notice: June 2021