ISOSTOCK PRIVACY AND CONSENT STATEMENT (UK GDPR)
INTRODUCTION
This statement explains how personal information held within IsoStock Cloud is handled. It relates specifically to the cloud service and should be read alongside our Company GDPR Statement, which explains Gillett Limited's separate use of business contact and administration information.
We respect data privacy and are committed to protecting personal information in accordance with the UK GDPR and the Data Protection Act 2018. The latest revision of this statement is available on this page and may be updated from time to time.
SCOPE
This statement covers personal information that customer organisations and their authorised users enter into IsoStock Cloud, or that is generated through use of the service, and information supplied for its configuration and support. IsoStock Cloud is a browser-based service for managing and reporting the lifecycle of radioactive materials. Information collected through our public websites, sales enquiries and other business activities is addressed in the Company GDPR Statement.
DEFINITIONS
'Data' means information about an identifiable person that the Organisation enters into IsoStock Cloud, that the service records during use, or that the Organisation provides to us for setup or support.
'End User' means a person authorised by the Organisation to use IsoStock Cloud. Other individuals whose information may be held, including patients, are data subjects even if they do not use the service.
'UK GDPR' means the UK General Data Protection Regulation.
'IsoStock Cloud' means the cloud-based service provided by Gillett Limited.
'Organisation' means the customer organisation using the service. It acts as the data controller for personal information it enters into the service or asks us to process on its behalf.
'We', 'us' and 'our' mean Gillett Limited, the service provider and data processor for that customer-controlled information.
End Users and other individuals should also read the Organisation's own privacy information to understand its purposes, lawful bases and retention arrangements.
PRIVACY INFORMATION
The Organisation and its authorised users enter and manage information within IsoStock Cloud. We host and process that service information on the Organisation's behalf to provide and support the agreed service under the applicable service agreement and IsoStock Cloud Data Processing Addendum.
We do not sell customer service data or use it for our own sales, marketing, profiling or advertising. We process it to operate, secure, maintain and support IsoStock Cloud. The Organisation determines the information entered and who may access it through the service.
Gillett Limited is the developer and service provider of IsoStock Cloud, based at Aizlewood's Mill, Nursery Street, Sheffield S3 8GG, UK.
IsoStock Cloud is hosted on Microsoft Azure in the UK. The service's customer data is hosted in Azure UK South, with geo-redundant SQL backups in UK West. Microsoft provides the hosting infrastructure and acts as a sub-processor; storage by a hosting provider is itself processing of personal information. Our supplier arrangements include data protection, confidentiality and security requirements. The use of sub-processors is subject to the applicable Data Processing Addendum.
UK hosting does not by itself exclude access from another country. Where access or another activity constitutes a restricted international transfer, it must comply with the Organisation's instructions and applicable UK data protection law, using an appropriate safeguard or other lawful transfer mechanism where required. Contact privacy@gillett.co.uk for information about safeguards applicable to your data.
Our separate handling of business contacts, sales enquiries, billing and administration information is explained in the Company GDPR Statement.
DATA PROTECTION BY DESIGN
IsoStock Cloud incorporates access controls appropriate to the service. The Organisation and its users access information through IsoStock Cloud's functionality rather than by direct access to the underlying database.
Access uses Microsoft Entra ID accounts. Users must also be registered in the Organisation's IsoStock Cloud instance and assigned appropriate permissions. Multi-factor authentication is required. IsoStock Cloud does not request or store users' Microsoft account passwords.
The Organisation manages its authorised users, roles and permission levels. Where access to customer data is needed for support, customer-granted support access is role-based, time-limited and audit logged; the Organisation can grant and revoke that access. Appropriate authorised administration remains subject to our security controls.
INFORMATION HELD WITHIN ISOSTOCK
IsoStock Cloud helps Organisations manage and report records concerning radioactive materials, including use relevant to their own regulatory and operational requirements. Most service data is operational and does not identify an individual.
Where the Organisation enters personal information, or the service records use and security activity, that information may include:
- User names, work email addresses, roles and permissions.
- Login dates and times, IP addresses, account identifiers and audit activity.
- Patient names or identifiers, where the Organisation chooses to record them.
- The radionuclide administered and an investigation or therapy reference linked to a patient, where entered.
- Notes or other references entered by authorised users. The content of free-text fields depends on what the Organisation enters.
Patient names and identifiers are not required to use IsoStock Cloud. Some Organisations choose to enter them because they find them helpful for their records. The standard service does not require diagnoses, clinical indications, clinical results, treatment plans, medical histories or imaging records. The Organisation should avoid adding unnecessary clinical detail to notes or other fields. Patient-linked records can reveal information about an individual's health even where they do not include a diagnosis; such information is treated as special category personal data where applicable. The Organisation controls any patient information it chooses to enter, and we process it on its behalf.
Information exchanged with us in ordinary service and support communications, including email or other electronic messages, is handled according to its purpose and the applicable processing arrangements. We will review this statement if changes to the service alter the categories of information processed.
HOW THE DATA IS COLLECTED
The Organisation may supply initial data to configure IsoStock Cloud. Thereafter, it and its authorised users enter and amend service information. The service also creates access and audit records through normal use.
We do not routinely access customer service data for our own purposes. Access may be needed to configure, provide, maintain or support the service, for example at the Organisation's request, to investigate a fault or to implement an update, or where required by law. Customer-granted support access is controlled as described above.
The Organisation is responsible for the accuracy and relevance of information it enters and can correct records through authorised users, subject to their permissions. We assist where necessary under the service agreement and Data Processing Addendum and remain responsible for our own obligations as processor.
LEGAL BASIS AND CONSENT
The Organisation is responsible for identifying an appropriate lawful basis for the personal information it enters into IsoStock Cloud and, where health information or other special category data is involved, an additional condition under the UK GDPR. The basis and condition depend on the Organisation's own purposes and circumstances.
We process this customer-controlled information on the Organisation's behalf to provide and support the service under the applicable service agreement and Data Processing Addendum. Choosing to use IsoStock Cloud or entering information into it does not, by itself, constitute consent from the individuals concerned. Where the Organisation relies on consent for any of its processing, it is responsible for ensuring that consent is valid and can be withdrawn.
The Organisation's own privacy information should explain its purposes, lawful bases and retention arrangements. Requests to exercise data protection rights concerning information held on its behalf should normally be made to the Organisation. If we receive such a request directly, we will refer it to the Organisation without undue delay and assist it in responding. Questions about personal information that Gillett Limited controls for its own business purposes may be sent to privacy@gillett.co.uk.
If you have a complaint about how Gillett Limited handles personal information, contact privacy@gillett.co.uk, use our website contact form or write to our address above. We also accept complaints through other communication channels. We will acknowledge your complaint within 30 days, make appropriate enquiries, keep you informed and explain the outcome without undue delay. Where the complaint concerns information controlled by the Organisation, we will refer it to the Organisation and assist as appropriate. You may also complain to the Information Commissioner's Office.
oner's Office.CHILDREN
IsoStock Cloud is supplied to Organisations and is not directed at children under 16. However, information the Organisation enters may concern a child, including a patient. The Organisation is responsible for deciding whether that information is necessary and for meeting its data protection obligations. We process it on the Organisation's behalf under the applicable Data Processing Addendum.
DATA BREACH
If we become aware of a personal data breach affecting information processed on the Organisation's behalf, we will notify it without undue delay, investigate, take appropriate steps to contain and mitigate the breach, and provide available information and assistance as the investigation progresses.
The Organisation, as controller, assesses whether the breach must be reported to the ICO or affected individuals, with our assistance. We assess our own notification obligations for personal information that Gillett Limited controls for its separate business purposes.
RETENTION OF DATA
Service information is accessible during the Organisation's use of IsoStock Cloud, subject to its user permissions and applicable service arrangements. The Organisation determines how long information is needed for its purposes.
When the Organisation stops using the service, we contact it to confirm arrangements for return or deletion of its service data. Data is returned or deleted in accordance with the Organisation's instructions and the applicable Data Processing Addendum, unless retention is required by law. We delete live service data as soon as reasonably practicable and within 30 days of receiving an authorised deletion request, or within 30 days of a future deletion date agreed with the Organisation. Any earlier contractual deadline continues to apply. Pending deletion cases are reviewed as part of our monthly ISMS review. Deletion is managed through our Azure environment.
Routine SQL backups are retained for up to 35 days. Following deletion of live service data, existing backup copies remain until they expire under this backup cycle. Any separately retained support or archive copies are managed in accordance with the applicable Data Processing Addendum and agreed retention arrangements.
Gillett Limited's own business contact, support administration and accounting records are subject to separate arrangements explained in the Company GDPR Statement.
USE OF COOKIES
IsoStock Cloud uses cookies and similar technologies to support access to the authenticated service. Please see the IsoStock Cloud Cookie Policy for further information.
DATA PROCESSING ADDENDUM
This statement should be read in conjunction with the IsoStock Cloud Data Processing Addendum (DPA).