logo
  • Platform
  • Capabilities
  • Why NewGen
  • FAQ
Explore Book a Demo
  • Platform
  • Capabilities
  • Why NewGen
  • FAQ
Explore Book a Demo
Legal

Privacy Policy

How NewGen Solutions Ltd collects, uses, shares and protects personal and health data on the NewGen Occupational Health platform.

Last updated:  24 July 2026 Applies to:  newgensolutions.co.uk and the NewGen platform Related document:  Terms of Use
1. Introduction 2. Who we are: Controller and Processor roles 3. Information we collect 4. How we use your information & lawful bases 5. Special category (health) data 6. Sharing your information 7. International transfers & UK hosting 8. Data retention 9. Security measures 10. Your rights 11. Cookies 12. Children’s information 13. Changes to this policy 14. Contact us & Data Protection Officer

1. Introduction

NewGen Solutions Ltd (“NewGen“, “we“, “us“, “our“) provides a secure, cloud-based occupational health case management platform (the “Platform“) used by police forces, NHS and healthcare bodies, and other regulated-sector organisations and their occupational health (OH) providers.

This Privacy Policy explains how we collect, use, store, share and protect personal data — including special category health data — in connection with the Platform, our website, and our wider business activities. It is written to comply with the UK General Data Protection Regulation (“UK GDPR“) and the Data Protection Act 2018 (“DPA 2018“).

This policy is aimed at three audiences, who should read the sections most relevant to them: (a) employees and service users whose OH data is processed through the Platform on behalf of a client organisation; (b) authorised users of the Platform (clinicians, OH administrators and case managers) acting on behalf of a client organisation; and (c) visitors to our public website.

2. Who we are: Controller and Processor roles

Data protection responsibility depends on whose data is being processed, and for what purpose. This distinction matters and is explained below rather than glossed over, because it determines who you should contact with a query or request.

2.1 When NewGen acts as a Data Processor

For the core occupational health case data held within the Platform (referral records, medical assessments, surveillance results, incident reports, case notes and related documents), our client organisation — typically the police force, NHS trust, shared OH service, or independent OH provider that has contracted with us — is the Data Controller. NewGen acts as a Data Processor, processing that data strictly on the Controller’s documented instructions, under a data processing agreement (“DPA“) entered into with each client.

What this means for you

If your health or employment data is held on the Platform because your employer or referring organisation uses NewGen, that organisation is responsible for your data as Controller, and is your first point of contact for exercising your data protection rights. We support our clients in responding to these requests but do not make independent decisions about your data outside their instructions.

2.2 When NewGen acts as a Data Controller

We act as Data Controller in our own right for: (a) personal data of individuals who use our public website (see the Cookies section below); (b) contact details of prospective and existing client organisation staff who engage with our sales, support or marketing activities; and (c) account credentials, login activity and audit logs of authorised Platform users, which we process to maintain the security and integrity of the service.

3. Information we collect

The categories of information processed through the Platform depend on the modules a client organisation has configured, but typically include:

  • Identity and contact data: name, date of birth, employee/warrant number, job role, work location, contact details.
  • Employment and referral data: referral reason, sickness absence records, role requirements, fitness-for-work assessments, return-to-work plans.
  • Health surveillance data: audiometry, spirometry, HAVS, skin and vision screening results, vaccination and immunity records, night-worker assessments.
  • Incident and safety data: workplace incident reports, RIDDOR-reportable event details, investigation findings and corrective actions.
  • Clinical case notes and correspondence recorded by treating clinicians and OH advisors within the Platform.
  • Platform usage data: login timestamps, IP address, device/browser type, and in-platform activity logs, collected for security and audit purposes.

We do not require special category data to be provided through the website itself, and no health information is collected via public-facing marketing forms.

4. How we use your information & lawful bases

Where NewGen processes data as Processor, the lawful basis for processing is determined and documented by the Controller organisation. Where we process data in our own right as Controller, we rely on the following lawful bases:

PurposeData categoryLawful basis (UK GDPR Art. 6)
Providing and maintaining the Platform for authorised usersAccount data, usage logsPerformance of a contract (Art. 6(1)(b))
Maintaining Platform security, preventing unauthorised accessLogin/audit logs, IP addressLegitimate interests (Art. 6(1)(f))
Responding to sales and support enquiriesName, work email, organisationLegitimate interests / pre-contract steps (Art. 6(1)(b)/(f))
Sending product updates to subscribed contactsName, work emailConsent (Art. 6(1)(a))
Complying with legal and regulatory obligationsContractual and billing recordsLegal obligation (Art. 6(1)(c))

5. Special category (health) data

Occupational health case data inherently includes special category data concerning health, as defined in Article 9 UK GDPR. Where NewGen processes this data as a Processor, the applicable Article 9 condition is identified and documented by the Controller client — typically Article 9(2)(h) (medical assessment / occupational medicine, subject to conditions in the DPA 2018) or Article 9(2)(b) (employment, social security and social protection law obligations).

Access to health data within the Platform is restricted through role-based permissions, so that clinical notes and assessment results are visible only to appropriately qualified and authorised users, in line with each client’s own configuration and confidentiality policies.

6. Sharing your information

We do not sell personal data. Data may be shared in the following limited circumstances:

  • Sub-processors: vetted, contracted infrastructure and software providers (for example, cloud hosting, email delivery and error-monitoring providers) who process data solely on our documented instructions and under written data processing terms consistent with UK GDPR Article 28.
  • Your organisation: data you provide is visible to authorised individuals within the relevant Controller organisation, according to the roles and permissions that organisation has configured.
  • Regulators and authorities: where required by law, for example in connection with a RIDDOR report, a court order, or a request from the Information Commissioner’s Office (“ICO“).
  • Corporate transactions: in the event of a merger, acquisition or restructuring, subject to equivalent confidentiality and security protections.

An up-to-date list of sub-processors is available to client organisations on request.

7. International transfers & UK hosting

Platform data — including all occupational health case data — is hosted on infrastructure located in the United Kingdom. We do not transfer personal data processed through the Platform outside the UK.

Where a limited sub-processor (such as an email delivery or monitoring tool used for non-clinical, operational purposes) is located outside the UK, any such transfer is protected by an appropriate safeguard recognised under UK GDPR Chapter V, such as the UK International Data Transfer Agreement (IDTA) or a UK Addendum to the EU Standard Contractual Clauses.

8. Data retention

Retention periods for occupational health case data are set by the Controller client in line with their own record-retention schedule, applicable employment law, and relevant clinical retention guidance (for example, guidance issued by the Faculty of Occupational Medicine). Typical default periods, absent a specific client instruction, are set out below.

Data typeTypical retention period
General OH case records6 years after the end of the employment relationship
Health surveillance records (e.g. COSHH-related)Up to 40 years, per HSE guidance, where applicable to the exposure type
Incident and RIDDOR records3 years from the date of the incident, or longer where litigation is reasonably anticipated
Platform account & audit logs12 months on a rolling basis
Website enquiry and marketing contact data24 months from last engagement, or until consent is withdrawn

At the end of the applicable retention period, data is securely deleted or irreversibly anonymised.

9. Security measures

We maintain technical and organisational measures appropriate to the sensitivity of the data we process, including: encryption of data in transit and at rest; role-based access controls and least-privilege permissions; multi-factor authentication for administrative access; continuous audit logging of access to clinical records; regular vulnerability testing; and staff training on data protection and confidentiality obligations.

No system can be guaranteed 100% secure, and we maintain a documented incident response process, including obligations to notify affected Controller clients and, where legally required, the ICO, without undue delay.

10. Your rights

Subject to certain exemptions and conditions, UK data protection law gives you the following rights in relation to your personal data:

  • Right of access — to obtain a copy of the personal data we (or the relevant Controller) hold about you.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to request deletion of your data in certain circumstances.
  • Right to restrict processing — to limit how your data is used while a query is resolved.
  • Right to data portability — to receive certain data in a structured, commonly-used format.
  • Right to object — to processing based on legitimate interests, or to direct marketing.
  • Rights related to automated decision-making — the Platform’s AI-assisted drafting features never make autonomous clinical decisions; all AI-generated outputs require explicit clinician review and sign-off before release, so no solely automated decision with legal or similarly significant effect is made about you.

If your data is held on the Platform on behalf of an employer or referring organisation, please direct your request to that organisation in the first instance, as they are the Data Controller. If you are unsure who to contact, or your enquiry relates to our own activities as Controller, contact us using the details in Section 14.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk, or by calling 0303 123 1113.

11. Cookies

Our public website uses a limited number of essential cookies required for the site to function, and, where you consent, analytics cookies to help us understand site usage. The Platform itself (the authenticated application used by OH teams) uses strictly necessary session cookies required for secure login and does not use tracking or advertising cookies.

You can control or disable non-essential cookies through your browser settings at any time. Disabling essential cookies may affect the functionality of the website or Platform.

12. Children’s information

The Platform and our website are intended for use by adults acting in a professional or employment capacity. We do not knowingly collect personal data from children. Occupational health assessments processed through the Platform relate to individuals of working age, in accordance with client organisations’ employment and referral policies.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Platform’s functionality. Material changes will be notified to client organisations and, where appropriate, highlighted on our website. The “Last updated” date at the top of this page indicates when it was last revised.

14. Contact us & Data Protection Officer

Questions, concerns or requests relating to this Privacy Policy, or to our handling of personal data as a Controller, can be directed to:

Data protection contact

NewGen Solutions Ltd
Email: privacy@newgensolutions.co.uk
General enquiries: demo@newgensolutions.co.uk
Registered in England and Wales. Company No. [Company registration number]
Registered office: [Registered office address]
ICO registration reference: [ICO registration number]

NewGen

Occupational Health, built around how your organisation works. One secure platform for end-to-end OH service delivery.

Platform
  • Referral & Case Management
  • Medicals & Surveillance
  • Incidents & RIDDOR
  • Documents & Compliance
  • Recall Engine
  • Reporting & AI
Sectors
  • NHS & Healthcare
  • Rail & Transport
  • Construction
  • Public Sector
  • Utilities
  • Manufacturing
Company
  • About NewGen
  • Book a demo
  • FAQ
  • Contact
  • Privacy policy
  • Terms of use
© Ranka Limited trading as NewGen OHS
Privacy Policy Terms of Use