How NewGen Solutions Ltd collects, uses, shares and protects personal and health data on the NewGen Occupational Health platform.
NewGen Solutions Ltd (“NewGen“, “we“, “us“, “our“) provides a secure, cloud-based occupational health case management platform (the “Platform“) used by police forces, NHS and healthcare bodies, and other regulated-sector organisations and their occupational health (OH) providers.
This Privacy Policy explains how we collect, use, store, share and protect personal data — including special category health data — in connection with the Platform, our website, and our wider business activities. It is written to comply with the UK General Data Protection Regulation (“UK GDPR“) and the Data Protection Act 2018 (“DPA 2018“).
This policy is aimed at three audiences, who should read the sections most relevant to them: (a) employees and service users whose OH data is processed through the Platform on behalf of a client organisation; (b) authorised users of the Platform (clinicians, OH administrators and case managers) acting on behalf of a client organisation; and (c) visitors to our public website.
Data protection responsibility depends on whose data is being processed, and for what purpose. This distinction matters and is explained below rather than glossed over, because it determines who you should contact with a query or request.
For the core occupational health case data held within the Platform (referral records, medical assessments, surveillance results, incident reports, case notes and related documents), our client organisation — typically the police force, NHS trust, shared OH service, or independent OH provider that has contracted with us — is the Data Controller. NewGen acts as a Data Processor, processing that data strictly on the Controller’s documented instructions, under a data processing agreement (“DPA“) entered into with each client.
What this means for you
If your health or employment data is held on the Platform because your employer or referring organisation uses NewGen, that organisation is responsible for your data as Controller, and is your first point of contact for exercising your data protection rights. We support our clients in responding to these requests but do not make independent decisions about your data outside their instructions.
We act as Data Controller in our own right for: (a) personal data of individuals who use our public website (see the Cookies section below); (b) contact details of prospective and existing client organisation staff who engage with our sales, support or marketing activities; and (c) account credentials, login activity and audit logs of authorised Platform users, which we process to maintain the security and integrity of the service.
The categories of information processed through the Platform depend on the modules a client organisation has configured, but typically include:
We do not require special category data to be provided through the website itself, and no health information is collected via public-facing marketing forms.
Where NewGen processes data as Processor, the lawful basis for processing is determined and documented by the Controller organisation. Where we process data in our own right as Controller, we rely on the following lawful bases:
| Purpose | Data category | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Providing and maintaining the Platform for authorised users | Account data, usage logs | Performance of a contract (Art. 6(1)(b)) |
| Maintaining Platform security, preventing unauthorised access | Login/audit logs, IP address | Legitimate interests (Art. 6(1)(f)) |
| Responding to sales and support enquiries | Name, work email, organisation | Legitimate interests / pre-contract steps (Art. 6(1)(b)/(f)) |
| Sending product updates to subscribed contacts | Name, work email | Consent (Art. 6(1)(a)) |
| Complying with legal and regulatory obligations | Contractual and billing records | Legal obligation (Art. 6(1)(c)) |
Occupational health case data inherently includes special category data concerning health, as defined in Article 9 UK GDPR. Where NewGen processes this data as a Processor, the applicable Article 9 condition is identified and documented by the Controller client — typically Article 9(2)(h) (medical assessment / occupational medicine, subject to conditions in the DPA 2018) or Article 9(2)(b) (employment, social security and social protection law obligations).
Access to health data within the Platform is restricted through role-based permissions, so that clinical notes and assessment results are visible only to appropriately qualified and authorised users, in line with each client’s own configuration and confidentiality policies.
We do not sell personal data. Data may be shared in the following limited circumstances:
An up-to-date list of sub-processors is available to client organisations on request.
Platform data — including all occupational health case data — is hosted on infrastructure located in the United Kingdom. We do not transfer personal data processed through the Platform outside the UK.
Where a limited sub-processor (such as an email delivery or monitoring tool used for non-clinical, operational purposes) is located outside the UK, any such transfer is protected by an appropriate safeguard recognised under UK GDPR Chapter V, such as the UK International Data Transfer Agreement (IDTA) or a UK Addendum to the EU Standard Contractual Clauses.
Retention periods for occupational health case data are set by the Controller client in line with their own record-retention schedule, applicable employment law, and relevant clinical retention guidance (for example, guidance issued by the Faculty of Occupational Medicine). Typical default periods, absent a specific client instruction, are set out below.
| Data type | Typical retention period |
|---|---|
| General OH case records | 6 years after the end of the employment relationship |
| Health surveillance records (e.g. COSHH-related) | Up to 40 years, per HSE guidance, where applicable to the exposure type |
| Incident and RIDDOR records | 3 years from the date of the incident, or longer where litigation is reasonably anticipated |
| Platform account & audit logs | 12 months on a rolling basis |
| Website enquiry and marketing contact data | 24 months from last engagement, or until consent is withdrawn |
At the end of the applicable retention period, data is securely deleted or irreversibly anonymised.
We maintain technical and organisational measures appropriate to the sensitivity of the data we process, including: encryption of data in transit and at rest; role-based access controls and least-privilege permissions; multi-factor authentication for administrative access; continuous audit logging of access to clinical records; regular vulnerability testing; and staff training on data protection and confidentiality obligations.
No system can be guaranteed 100% secure, and we maintain a documented incident response process, including obligations to notify affected Controller clients and, where legally required, the ICO, without undue delay.
Subject to certain exemptions and conditions, UK data protection law gives you the following rights in relation to your personal data:
If your data is held on the Platform on behalf of an employer or referring organisation, please direct your request to that organisation in the first instance, as they are the Data Controller. If you are unsure who to contact, or your enquiry relates to our own activities as Controller, contact us using the details in Section 14.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk, or by calling 0303 123 1113.
Our public website uses a limited number of essential cookies required for the site to function, and, where you consent, analytics cookies to help us understand site usage. The Platform itself (the authenticated application used by OH teams) uses strictly necessary session cookies required for secure login and does not use tracking or advertising cookies.
You can control or disable non-essential cookies through your browser settings at any time. Disabling essential cookies may affect the functionality of the website or Platform.
The Platform and our website are intended for use by adults acting in a professional or employment capacity. We do not knowingly collect personal data from children. Occupational health assessments processed through the Platform relate to individuals of working age, in accordance with client organisations’ employment and referral policies.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Platform’s functionality. Material changes will be notified to client organisations and, where appropriate, highlighted on our website. The “Last updated” date at the top of this page indicates when it was last revised.
Questions, concerns or requests relating to this Privacy Policy, or to our handling of personal data as a Controller, can be directed to:
Data protection contact
NewGen Solutions Ltd
Email: privacy@newgensolutions.co.uk
General enquiries: demo@newgensolutions.co.uk
Registered in England and Wales. Company No. [Company registration number]
Registered office: [Registered office address]
ICO registration reference: [ICO registration number]