Privacy Policy
Last updated: January 2025 · Version 1.0
Sams Care (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data — including sensitive health information — with the highest standards of care. This policy explains how we collect, use, store, and share your data when you use our services at samscare.uk.
1. Who We Are
The data controller for your personal data is Sams Care, operated by Sepideh Sadig Baheran, NMC-registered Independent Nurse Prescriber, practising in the United Kingdom.
Contact us regarding data protection matters at: sb.samscare@gmail.com
We are registered with the Information Commissioner’s Office (ICO) as required under the UK Data Protection Act 2018.
2. What Data We Collect
When you submit a prescription request or use our services, we collect:
- Identity data: full name, date of birth
- Contact data: email address, phone number
- Special category health data (Article 9 UK GDPR): medical conditions, known allergies, current medications, relevant clinical history
- Clinical data: details of the medication or treatment requested, indications, red flags declared
- Consent records: GDPR consent timestamp, IP address hash, consent version
- Communications: messages sent between you and our clinical team
- Technical data: IP address (hashed), browser type, access timestamps (for security audit purposes only)
Special category data:Health and medical information is classified as “special category” data under Article 9 of the UK GDPR. We only process this data with your explicit consent, which you provide when submitting a request. You may withdraw consent at any time, though this may prevent us from providing clinical services.
3. How We Use Your Data
We process your data for the following purposes and legal bases:
Providing prescribing services
Explicit consent (Article 9) + contract performance
Assessing your request, conducting clinical review, and issuing prescriptions.
Clinical safety & follow-up
Legitimate interests + legal obligation
Post-prescription follow-ups at 7 and 30 days as required by NMC prescribing standards.
Repeat prescription management
Consent + contract performance
Sending reminders and enabling fast-lane repeat requests using your patient token.
Audit & regulatory compliance
Legal obligation (NMC, CQC)
Maintaining a complete, immutable audit trail of all clinical decisions for 8 years.
Communications
Contract performance + consent
Sending prescription documents, acknowledgements, and clinical correspondence by email.
We do not use your data for marketing, sell your data to third parties, or use it for automated decision-making that produces legal effects without clinical oversight.
4. Data Retention
Medical and clinical records are retained for 8 years from the date of your last interaction with us, in compliance with NMC standards for prescribers and NHS/professional body guidance on medical records retention.
For patients who were under 18 at the time of treatment (note: we do not treat under-18s, but in the event of an error), records would be retained until age 25, or 8 years — whichever is longer.
After the retention period expires, your data will be securely and permanently deleted from all systems including backups.
5. Who We Share Your Data With
We share your data only where necessary with the following trusted third-party processors, all operating under appropriate data processing agreements:
Supabase Inc.
EU/USA (Standard Contractual Clauses apply)Secure database and file storage
Stores all patient records and uploaded documents in encrypted form.
Resend Inc.
USA (SCCs apply)Transactional email delivery
Used to send prescription documents, acknowledgements, and follow-up emails.
Vercel Inc.
EU (London region, lhr1)Application hosting and delivery
Hosts the samscare.uk web application. Application data is processed in the UK.
We may also disclose data where required by law, court order, or to regulatory bodies such as the NMC, CQC, or police in connection with a criminal investigation.
6. Your Rights Under UK GDPR
As a data subject under the UK General Data Protection Regulation and the Data Protection Act 2018, you have the following rights:
Right of access: Request a copy of all personal data we hold about you (Subject Access Request). We will respond within 30 days.
Right to rectification: Request correction of inaccurate or incomplete data.
Right to erasure: Request deletion of your data. Note: clinical records must be retained for 8 years under professional regulations — this right may be limited in those circumstances.
Right to restriction: Request that we limit how we process your data while a dispute is resolved.
Right to data portability: Request your data in a structured, machine-readable format.
Right to object: Object to processing based on legitimate interests.
Right to withdraw consent: Withdraw consent for special category health data processing at any time. This will not affect the lawfulness of prior processing.
To exercise any right, email us at sb.samscare@gmail.com. We may ask you to verify your identity before responding.
7. Right to Complain
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
We would always appreciate the opportunity to address your concerns directly before you approach the ICO.
8. Data Security
All data is encrypted at rest and in transit using industry-standard TLS 1.3 and AES-256 encryption. Access to patient records is restricted to authorised clinical staff only, protected by multi-factor authentication.
Prescription documents and uploaded files are stored in a private, non-public storage bucket. Access is governed by time-limited signed URLs and role-based access controls.
All actions on patient records are recorded in an immutable audit log, including who accessed what and when.
9. Cookies
We use only essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Please see our Cookie Policy for full details.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by updating the “Last updated” date at the top of this page. Continued use of our services after a change constitutes acceptance of the updated policy.
© 2026 Sams Care · United Kingdom