logo

Data Protection Policy

Our commitment to safeguarding your privacy and personal information

Key Details

Policy prepared by: Semanu Adoboe
Approved by: HomePack Medical
Operational since: August 30, 2024
Next review date: May 28, 2025

Introduction

HomePack Medical Services gathers and uses certain information about individuals, including customers, suppliers, business contacts, employees, and others. This policy describes how personal data must be collected, handled, and stored to comply with the law and meet the company’s data protection standards.

Why this policy exists

  • Complies with data protection law and follows good practice.
  • Protects the rights of customers, staff, and partners.
  • Is transparent about data storage and processing.
  • Protects against data breach risks.

Data Protection Law

The Data Protection Act, 2012 (Act 843), governs the collection, use, and disclosure of data by data controllers and processors. It sets principles for lawful and fair data processing, ensuring transparency, accuracy, security, and individual rights.

  • Processed lawfully, fairly, and transparently.
  • Collected for explicit and legitimate purposes.
  • Adequate, relevant, and limited to what is necessary.
  • Accurate and kept up to date.
  • Kept no longer than necessary.
  • Processed securely to prevent unauthorized use or loss.
  • The data controller is responsible for and must demonstrate compliance.

People and Responsibilities

Everyone at HomePack Medical Services contributes to data protection compliance. Key decision-makers ensure implementation and accountability.

  • Updating management about data protection risks.
  • Maintaining the data protection policy and related procedures.
  • Embedding privacy measures in corporate policies.
  • Training staff on data protection.
  • Handling data subject requests and queries.
  • Reviewing third-party contracts and data security standards.
  • Conducting regular security checks and scans.
  • Evaluating third-party services for compliance.
  • Developing privacy notices and lawful basis documentation.

Data Protection Officer (DPO): Mr. David Takyi (Head of Medical Team / DPO).

Scope of Personal Data

HomePack Medical Services processes the following data: names, addresses, email addresses, telephone numbers, online identifiers, and sensitive data like medical information. Data is collected directly from individuals and stored securely with periodic checks for accuracy and relevance.

Uses and Conditions

Personal data is processed for patient care, including management of names, contact details, and medical history. Legitimate interests and consent form the lawful basis for processing.

Privacy Impact Assessments (PIAs)

HomePack Medical Services conducts PIAs to identify and address privacy risks early, ensuring compliance and protecting individuals.

Data Sharing

Data may be shared with partner labs and health imaging facilities, ensuring appropriate permissions and data sharing agreements.

Security Measures

HomePack Medical Services implements technical measures (e.g., encryption, VPNs, two-step authentication) and procedural measures (password management, data backup). Breaches are reported promptly to the DPO.

Automated Processing

HomePack Medical Services does not currently use automated processing for significant decisions. If this changes, it will ensure the protection of individual rights.

Subject Access Requests

Individuals can request details about their data, how it’s used, and how to update or delete it.

The Right to Be Forgotten

Requests for data deletion are evaluated to balance compliance with retention requirements and individuals’ rights.

Privacy Notices

Individuals are informed about who processes their data, what data is involved, processing purposes, outcomes, and their rights.

Ongoing Documentation & Compliance

HomePack Medical Services will maintain records of privacy measures, regularly test compliance, and document staff training on data protection.

The company’s privacy statement is available on the HomePack Medical Services website.

Contact Our Data Protection Officer

Mr. David Takyi (Head of Medical Team / DPO)

homepackmedical.services@gmail.com