Privacy Policy
Overview
Resoken (“Resoken.com” “we” or “us”) are strongly committed to protecting the privacy, personal information and account security of our visitors and users. Our website and platform is a user-centric initiative, built with one solitary purpose in mind – to help people find reliable, expert musculoskeletal, regenerative and rejuvenative local providers and to equip people with multi-perspective, comprehensive data points, so they can make independent decisions which align with the current scientific consensus.
This Privacy Policy describes how we handle personal information from our users and visitors when they use or visit our website and platform, since we offer account creation, booking and form submissions, along with other types of interactive services which require varying degrees of data processing.
We implore you to read this Privacy Policy alongside our Terms & Conditions to get a more complete understanding of how our website and platform operates.
If you have questions regarding our Privacy Policy, feel free to contact us.
Resoken is the trading name for Dalch Ventures Ltd with company number 14434585. Our VAT Registration Number is 454 7277 67.
Our registered office address is: Forma House, 40 Bowling Green Lane, London, United Kingdom, EC1R 0NE.
You can reach out to us via email at [email protected] for anything related to our Privacy Policy and how we protect your data.
You can reach out to us via email at [email protected] for any other general queries you may have.
Additionally, if you prefer traditional mail, correspondence can be sent to our registered office, the address of which is shown above.
Our dedicated team and/or Data Protection Officer and/or GDPR solicitors are available to address any queries you may have regarding how we use cookies (feel free to also read our Cookie Policy), and any other related privacy issues. We always strive to communicate in a plain, easy-to-understand manner, that’s why we’ve carefully hand-written every single paragraph in our legal documentation, including this Privacy Policy.
By using our platform, website and services, you (the User) or you (the Provider) acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy.
Commitment to Protecting Privacy
Our commitment to user protection, user privacy and information security is unwavering. We are completely aware and understand that some of the information you may provide on our platform can have varying degrees of sensitivity, especially in the context of healthcare and treatment options. For this reason we use multiple layers of enterprise-grade encryption protocols, such as AES-256, ChaCha20, LUKS2 and more to protect user data.
On top of that, we have a robust and secure server and cloud infrastructure, a secure web application firewall (WAF), a monitoring software with real-time scanning, plus more.
Therefore, any information you submit on our website or platform will be fully protected with best-in-class enterprise-grade security and encryption standards.
Relation to Website Terms and Conditions
We encourage you read this Privacy Policy in conjunction with our website’s Terms and Conditions. The Terms and Conditions outline the legal framework within which we operate and provide services to you. They include important information about your rights and obligations, as well as limitations and exclusions that apply to our services.
In the event of any inconsistency between this Privacy Policy and the Terms and Conditions, the provisions of the Terms and Conditions shall prevail. By accepting our Privacy Policy, you also agree to be bound by the Terms and Conditions of our website.
Data Collection Summary
As aforementioned, we take great in how we collect, use, and store the personal data of our users.
In this section, we’ll outline the types of user and provider data we gather, how we gather or collect it, how we store it and more.
Depending on whether you are a patient seeking treatment or a healthcare provider listed on our platform, we may collect different data types.
But in both cases, you’ll always know what type of data you’re submitting through our platform when using our Service. And you’ll always have the option to not submit this data if you don’t want to.
Types of Data Collected
1. Personal and Contact Details: This includes basic identification information such as your name, age, sex, and date of birth. Contact details such as your telephone numbers, email addresses, and postal addresses. We require this information when creating your account, managing your appointments, and to maintain uninterrupted communication between us, you and your chosen healthcare provider.
2. Insurance Information: For patients, we may collect details related to your health insurance. This may include your insurance policy number and authorisation code. Again, this is essential information we need to setup your appointment, treatment plan and to check the service you’re enquiring about aligns with your insurance coverage.
3. Feedback and Reviews: When you publish a review on our website or platform, that information is publicly-facing. You’ll be notified before publishing the review that the information is publicly-facing and you’ll have the option to decline and not publish the review if you don’t wish to do that. We encourage users to leave feedback about their experiences with the healthcare providers listed on Resoken. If you have any comments about the quality of care, facilities, and overall satisfaction feel free to submit them as a review, or in cases where you want to share them privately with us, please contact us on [email protected].
4. Healthcare Provider Information: For healthcare providers, we gather professional information, including qualifications, areas of specialisation, languages spoken, available booking slots and more. Just like with our users, every provider is notified ahead of time regarding the types of information they would have to submit to join our platform. This information helps our users, i.e. the patients find the most suitable, befitting healthcare provider which fits their needs.
Purpose of Data Collection
1. Service Provision: The primary purpose of collecting data is to facilitate the connection between patients and healthcare providers. When you book a consultation with any of the providers listed on our platform, you’ll immediately get a notification that your consultation has been scheduled and your chosen healthcare provider immediately gets the information you provided on your booking form, so they can contact you either the same day, as soon as possible or during your specified availability window.
2. Feedback and Quality Improvement: We constantly use feedback from our users, patients and healthcare providers to improve our service, website and platform. Our mission is to be an unwavering, reliable, helping hand which presents scientific and empirical data, and provides an easy, secure, expedited booking system. That’s why we’re always looking to improve in accordance with what our users, patients and providers want the most.
3. Marketing and Communication: We may use your contact details to send you updates about our services, newsletters, and promotional offers. Of course, you’ll know when you’re opting in for these updates, and if you ever want to opt out, you can do so easily with a few clicks. We use these communications to keep you informed about Resoken.com and to provide you with other relevant health-related data points, research and articles.
Data Collection from Different User Types
1. Patients: For patients using Resoken.com, we may collect health information, insurance details, and feedback on the treatment or services the patient has booked or received. This information is essential for matching you with the most befitting and appropriate healthcare provider, as well as checking whether the treatments the patient has chosen are covered by their insurance.
2. Healthcare Providers: For healthcare providers listed on our platform, we collect professional details the healthcare provider supplies which are necessary to create dedicated Resoken profiles (or pages) that patients can explore, review and if they choose call, email or directly book a consultation. This includes information about qualifications, services offered, patient reviews and more.
Detailed Data Collection and Lawful Basis
At Resoken.com, we collect a variety of personal data types, detailed as follows:
1. Patient Information: This includes full name, age, location, contact details (telephone number, email address, postal address), insurance details (policy number, authorisation code), healthcare provider preferences, appointment details (date, time, location), and other health-related information specific to treatment enquiries. All of this information, the patient, user or individual manually enters themselves and consents prior to submission.
2. Healthcare Provider Information: We collect professional information such as name, contact details, place of work, qualifications, areas of expertise, languages spoken, available booking slots, and patient feedback. All of this information, the provider enters themselves and consents prior to submission.
3. User Account Details: For both patients and providers, we collect data necessary for account creation and management, such as usernames, passwords, and email addresses.
4. Transactional Data: This includes records of appointments booked, services rendered, and any communications exchanged through our platform.
5. Feedback and Reviews: User-generated content like reviews, ratings, and comments about healthcare providers and services.
Lawful Basis for Processing This Data
1. Contractual Necessity: The processing of personal data for booking appointments, managing user accounts, and facilitating the provision of healthcare services is based on the necessity of fulfilling our contractual obligations to you as a user of our platform.
2. Legitimate Interests: We process personal data for the benefit of the entire Resoken community, which includes improving our services, conducting market research and finding new regenerative medicine providers, managing the continuous upkeep of this website and platform, plus the processing of feedback and reviews to enhance service quality.
3. Consent: We rely on your explicit consent for processing data for marketing purposes. You have the right to withdraw your consent at any time.
Use of Data for Bookings, Reviews, Customer Service, and Marketing
1. Bookings: We use your personal data to facilitate the booking process. This includes sharing relevant information with healthcare providers to arrange appointments and manage treatment plans.
2. Reviews: Patient reviews are essential in helping others make informed decisions. We process this data to provide a transparent and trustworthy platform where patients can share their experiences.
3. Customer Service: Personal data is used to address any queries or concerns you may have. This includes providing support and resolving issues related to the use of our services.
4. Marketing: With your consent, we use contact details to send newsletters, updates about our services, and promotional offers. This communication aims to keep you informed about the latest in healthcare options and services available through Resoken.com.
Protecting and Sharing Necessary Information
1. Patient Information Sharing: Patient data is primarily shared with healthcare providers listed on Resoken.com for the purpose of arranging appointments and managing healthcare services. This information includes contact details, insurance information, and specific healthcare needs. Patient consent is obtained before sharing sensitive health-related data.
2. Healthcare Provider Information Sharing: Information about healthcare providers, such as professional qualifications, experience, and patient reviews, is made available on our platform to assist patients in making informed choices. Providers consent to this sharing as part of their agreement to be listed on Resoken.com.
Use of Anonymous Data and Restrictions on Commercialising Identifiable Data
1. Anonymous Data: We may use specific anonymised data. This is data where individual identifiers have been completely and irreversible removed, and there’s no way to trace back any of it to the origin. Such data may be used for internal research, statistical analysis, and improvement of our services. It may also be shared with third parties for similar purposes.
2. Restrictions on Identifiable Data: We strictly prohibit the commercialisation of identifiable patient, user and provider data. Such information is only used for the purposes explicitly outlined in this Privacy Policy. We never sell, trade or transfer such personal data with third parties for any type of commercial purposes.
Data Transfer in Business Sale or Legal Obligations
1. Business Transfers: In the event of a merger, acquisition, or sale of our business, personal data may have to be transferred as part of the business assets. In such cases, we’ll ensure the confidentiality of personal data and inform users that they can delete, modify or download their data before any such data transfer occurs.
2. Legal Obligations: We may be required to disclose personal information in response to lawful requests by public authorities. Such cases may include meeting national security or law enforcement requirements, or as required by law, such as to comply with a subpoena, or similar legal processes.
Role of Third-Party Service Providers in Data Processing
1. Selective Engagement of Third Parties: At Resoken, we strictly limit our engagement with third-party service providers to only essential services. Such services may be hosting providers, upstream infrastructure providers, data analytics providers and more. These providers are meticulously selected by our legislative team, specifically for their clear, transparent and ethical privacy policies plus longitudinal track record of excellent business ethics. Such services are granted limited access to only specific types of personal data which are solely needed for the purpose of performing these critical functions. We have strict security protocols in place to ensure that your data is never sent, sold or transferred to any third-party entity for the purpose marketing, customer service, IT support, or any other secondary purposes.
2. Rigorous Data Processing Agreements: To reinforce our strict privacy protocols, we proactively establish data processing agreements with all third-party service providers. These agreements are created to ensure these providers uphold the same high standards of data protection and security that we at Resoken adhere to. They are legally bound to process data exclusively as directed by us and are required to comply fully with all applicable data protection laws. We genuinely go above and beyond, proactively seeking and implementing measures to safeguarding your personal information against any unauthorised use or disclosure.
Data Retention
1. Contract Termination: We may retain some specific data of this kind for up to a period of 6 years. Since Resoken is based in the United Kingdom and operates in accordance to United Kingdom law, we are obligated to retain some data for up to 6 years. Such data may be, legal working contracts with a healthcare provider, or a unique legal contract with a user, in cases where the users seeks out consultations with our team and prolonged service, and where the user agrees to signing such a contract. Hence, upon the termination of these types of contracts with Resoken, we may retain specific working or personal data for a period of 6 years. This duration is chosen to comply with the United Kingdom legal and regulatory requirements. As well as to address any potential post-contractual issues or queries.
2. Marketing Consent: For user or individuals who have consented to receive marketing, or newsletter communications, we will evidently need to retain their relevant contact details to send them said communication. And we’ll retain these details until the individual opts out or withdraws their consent. We regularly review our marketing and newsletter databases to verify that the user and individual preferences are fully respected and updated.
3. Payment Processing: We may retain some specific data of this kind for up to a period of 6 years. Again, since Resoken is based in the United Kingdom and operates in accordance to United Kingdom law, we are obligated to retain some data for up to 6 years. Such data may be transactional records, transactional dates, invoices, receipts, and more. However, these records are not retained for longer than necessary. Typically for a duration not exceeding 6 years, in accordance with UK data protection standards.
Data Storage and Transfer
1. Location of Data Storage: All user data collected by Resoken.com is stored securely either on servers located within the United Kingdom or for higher-sensitivity data, offline data storage, again located within the United Kingdom. We always adhere to the up-to-date United Kingdom data protection laws and regulations. And we take steps further, proactively securing highly sensitive user data on air-gapped data storage banks which have no connection to the internet. This ensures such data cannot be accessed online, significantly increasing data security.
2. Data Transfer Outside the UK: Any transfer of personal data outside the United Kingdom will be done in strict compliance with UK data protection laws. Transfers will only occur under specific circumstances, such as international users requesting their data to be sent internationally, etc. In such cases, we have strict protocols in place to encrypt the data at rest and send it via an encrypted transfer protocol to the user’s required destination. And in all other cases, such as contractual clauses approved by UK data protection authorities, we implement similar practices.
3. Security Measures for Data Protection: At Resoken, we have robust digital infrastructure and security protocols with multiple layers of built-in redundancy. We use advanced, enterprise-grade encryption, secure server environments, and regular security assessments and updates. Our purpose for doing all of this is to prevent unauthorised access, disclosure, alteration, or destruction of your personal information while also maintaining the integrity and confidentiality of the data we hold.
User Rights under Data Protection Law
As a user, you have rights regarding the personal data we collect and process. In this section we’ll outline those rights, and remind you that you’re always free to exercise these rights.
Resoken operates in accordance with UK data protection laws, including the General Data Protection Regulation (GDPR).
Your rights include, but are not limited to, the right to access, correct, or delete your personal information. Also, the right to restrict or object to processing, and the right to data portability.
You also have the right to withdraw consent at any time where processing is based on consent.
To exercise any of these rights, or if you have any concerns about how we handle your personal data, please contact our Data Protection Officer at [email protected].
We are committed to ensuring that your personal data is handled with the utmost care and in compliance with the law.
User Rights under Data Protection Law
Since Resoken.com operates under UK data protection laws, including GDPR, you (the User) have specific rights, which are:
1. Right to Access: You have the right to request access to the personal data we hold about you.
2. Right to Correction: You have the right to request data correction, if you believe any of the data we hold is incorrect or incomplete.
3. Right to Erasure: You can request the deletion of your personal data from our systems, commonly known as the “right to be forgotten”.
4. Right to Restrict Processing: You have the right to request a restriction on how we process your personal data.
5. Right to Data Portability: You can request a copy of your personal data in a digital format for the purpose of transferring it to another service.
6. Right to Object: You have the right to object to the processing of your personal data in certain circumstances, including for marketing purposes.
To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We will respond to your request in accordance with UK data protection laws.
If you are not satisfied with our response, or believe we are processing your data not in accordance with the law, you have the right to submit a complaint with the Information Commissioner’s Office (ICO).
Contact Information and Feedback
For any privacy-related enquiries, concerns or feedback please reach out to us at [email protected]. Our dedicated team and/or Data Protection Officer and/or GDPR solicitors (depending on the type of enquiry) are always available and will respond within 2-3 business days.
We also welcome and highly value your feedback. If you have any suggestions or comments regarding our Privacy Policy or anything else, please do not hesitate to contact us at the aforementioned email address. We always seek user feedback on how to improve, and genuinely implement viable user suggestions.