Privacy notice

Last updated: 22 August 2026

Introduction

This Privacy Notice gives you information about how Theta Sleep Ltd ("Theta Sleep") collects and uses your personal data through your use of our apps and when you communicate with us in any way, including any data you may provide when you sign up and use our services.

Who we are and how to contact us

Theta Sleep Ltd is a Data Controller and responsible for your Personal Data (collectively referred to as Theta Sleep, "the company", "we", "us" or "our" in this Privacy Notice) provided to us when using our Service. Theta Sleep Ltd is a company registered in England and Wales with company number 16087698 with its registered office at Canterbury House, 1 Royal Street, London, England, SE1 7LL.

Theta Sleep is an independent data controller in respect of the personal data we process to deliver your care. Where you are referred to us by an NHS organisation, a private hospital or an insurer, that organisation is a separate independent data controller for its own purposes. We are not a joint data controller with any of these organisations, and we do not act as any organisation's data processor. Sharing between us and those organisations is governed by written data sharing agreements.

Our Data Protection Officer (DPO) is responsible for monitoring our compliance with data protection legislation. We have also appointed a Caldicott Guardian, who is responsible for protecting the confidentiality of patient information and enabling appropriate information sharing. Our Caldicott Guardian is recorded on the national register held by NHS England.

We carry out a Data Protection Impact Assessment for all high-risk processing before that processing begins.

If you would like to contact us about anything in this Privacy Notice, would like to contact our DPO, or if you have any questions about how we use your information or if you would like to exercise any of your data subject rights, please contact us at privacy@thetasleep.com

The types of personal data we collect about all the users of our apps

Personal data means any information about an individual from which that person can be identified. Certain types of personal data require a higher level of protection such as information about health.

We may collect, use, store and transfer different kinds of personal data about you which are grouped together as follows:

  • Identity data includes names, email addresses, usernames, date of birth, sex, equality data, next of kin details, your GP details, your address, and your healthcare number (for example your NHS number, CHI number or Health and Care number). It also includes demographic details we confirm against NHS records, as described below.
  • Profile data includes your username and password, details of how you were referred to us, purchases or orders made by you, bookings and appointments details, preferences, feedback and survey responses.
  • Contact data includes email addresses, telephone numbers and addresses such as delivery and billing addresses as well as emergency contact details.
  • Transaction data includes details about payments to and from you and other details of products and services you have purchased from us.
  • Technical data includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
  • Usage data includes information about how you interact with and use our website, products and services including administrative details relating to technical support queries you raise so we can resolve issues that arose using our platform.
  • Communications data includes your preferences in receiving communications from us and your communication preferences.
  • Sleep & Health data includes any health data provided to us from third party health care providers (such as your GP, specialist, or health insurance company), any health data we obtain from national NHS records as described below, recordings of your consultations where these are made, and any data about your sleep and your health that you share with us when you express interest in, sign up for, and/or use our services.

We also collect, use and share anonymised aggregated data such as statistical or demographic data which is not personal data as it does not directly (or indirectly) reveal your identity. Please see the section on anonymised data below.

How is your personal data collected?

We use different methods to collect data from and about you. Collectively this data is known as your patient record. Information held in your patient record is used for direct care purposes and to review and improve the quality of care we provide (this is known as audit, service development, and clinical governance). This data may be collected through:

  • Your interactions with us. You may give us your personal data by signing up to use our platform, filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes personal data, including special category health data, you provide when you:
    • Create an account to use the Theta Sleep platform
    • Sign in to use the Theta Sleep platform
    • Utilise features on the platform such as booking a sleep study, giving more information about you and your sleep, uploading documents, or contacting us through the help section
    • Give us feedback, respond to a survey, or contact us
    • Subscribe to our newsletter, publications, or education
  • Automated technologies or interactions. As you interact with our platform, we will automatically collect technical and usage data about your equipment, browsing actions, patterns, and engagement with our platform.
  • Third parties. We will receive personal data about you from the categories of third parties set out below:
    • Other clinical teams who make referrals to us. This may include your general practitioner (GP), other specialist medical teams, or medical insurance companies.
  • National NHS records. As described in the section immediately below.
  • Documentation of your clinical consultation. Clinicians you interact with when receiving clinical care from Theta Sleep will document your consultation and management plans.

Information we obtain from national NHS records

We use national NHS record services to make sure we have identified the right person and are working from accurate and complete information. This applies to all our patients, whether your care is funded by the NHS or paid for privately.

Confirming who you are. We use the National Care Records Service (NCRS) to confirm your identity and demographic details — including your name, date of birth, healthcare number, address and GP registration. We do this when you register with us and at points during your care. This means we can be confident that we are treating the right person and adding information to the correct record. We may decline or suspend your registration where your details cannot be verified or appear inconsistent.

Clinical information from your Summary Care Record. We also access your Summary Care Record (SCR) to see clinical information that helps us care for you safely. This includes core information — your current medications, allergies and any adverse reactions you have had to medicines — and additional information where it is available, such as significant medical history, care plans and immunisations.

Your choice about clinical information. After you have booked with us, we will tell you that we use the SCR for clinical information and give you the opportunity to ask us not to. If you tell us you do not want us to access clinical information in your Summary Care Record, we will not do so. Your care will continue, but we may need to ask you directly for information that we would otherwise have seen, and your record with us may be less complete.

This choice is separate from the National Data Opt-Out, which is explained later in this Notice. The National Data Opt-Out applies to the use of confidential patient information for research and planning. The choice described here applies to whether we look at your Summary Care Record for the purposes of your direct care.

How we use these services. We only read information from these services. We do not add to or change your national NHS records. Access is limited to staff who are involved in your care, is controlled through NHS access mechanisms, and is audited and attributable to individual members of staff.

Our legal basis. Where your care is funded by the NHS, we do this in the exercise of a task carried out in the public interest (Article 6(1)(e) UK GDPR). Where you are paying for your care yourself or through an insurer, we do this because it is necessary to perform our contract with you (Article 6(1)(b) UK GDPR). For the health information itself, we rely on the health and social care condition (Article 9(2)(h) UK GDPR; Data Protection Act 2018 Schedule 1, condition 2). We also owe you a common law duty of confidentiality. For your direct care, that duty is satisfied by your implied consent, and the choice described above is how you can withdraw that implied consent in relation to your Summary Care Record.

Processors and other recipients

We use carefully selected third-party suppliers to process personal data on our behalf and on our instructions. These suppliers act only as our processors. They may not use your data for their own purposes. The categories of processor we use are:

  • cloud hosting and infrastructure
  • video consultation, recording, transcription and secure messaging
  • secure email services compliant with the NHS Secure Email Standard
  • document storage and management
  • sleep diagnostic and treatment equipment supply, data capture and study scoring
  • appointment scheduling and patient communications
  • payment processing
  • website analytics (privacy-preserving, with no tracking cookies)
  • professional services, including accountancy

Every processor is subject to a written contract meeting the requirements of Article 28 UK GDPR, may engage sub-processors only under equivalent obligations, and remains accountable to us. A current list of our processors is available on request from privacy@thetasleep.com.

Our processors are different from the organisations we share information with as separate controllers — such as your GP, the organisation that referred you, or a regulator. Those disclosures are described in the Disclosures section below.

How we use your personal data

Legal basis

The law requires us to have a legal basis for collecting and using your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For information about your health, which is a special category of personal data, we need both a legal basis and an additional condition. We also owe you a common law duty of confidentiality.

Our legal basis (Article 6 UK GDPR) depends on how your care is funded:

  • NHS-funded care: we process your personal data because it is necessary for the performance of a task carried out in the public interest, in delivering NHS-commissioned sleep medicine services (Article 6(1)(e)).
  • Self-pay care: we process your personal data because it is necessary to perform our contract with you (Article 6(1)(b)).
  • Insurer-funded care: you remain the contracting party, so we process your personal data because it is necessary to perform our contract with you (Article 6(1)(b)).

Our condition for processing health and other special category data (Article 9 UK GDPR):

  • For your care: we process your health data for health and social care purposes — including preventive medicine, medical diagnosis, the provision of health care and treatment, and the management of health care services (Article 9(2)(h); Data Protection Act 2018 Schedule 1, condition 2). This processing is carried out by, or under the responsibility of, health professionals who are subject to a professional duty of confidentiality.
  • Where we ask for your consent: for a small number of purposes that are not part of your care — such as sharing your story — we rely on your explicit consent (Article 9(2)(a)).
  • For legal claims: where necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f)).

The common law duty of confidentiality. Separately from data protection law, we owe you a duty of confidentiality. For your direct care this duty is satisfied by your implied consent — you can expect that information about you will be shared between the professionals involved in your care. You can object to that sharing, and we explain how below. For uses beyond your direct care, we rely on anonymised information wherever possible, or on another lawful basis such as your explicit consent or a legal requirement.

We may also rely on the following in more limited circumstances:

  • Legal obligation: where processing is necessary for compliance with a legal obligation we are subject to. We will identify the relevant legal obligation when we rely on this basis.
  • Vital interests: in rare cases, to protect your vital interests or those of another person — for example during a medical emergency (Article 6(1)(d); Article 9(2)(c)).
  • Substantial public interest: for certain safeguarding and crime prevention purposes, as set out in the Disclosures section below (Article 9(2)(g) and the relevant conditions in Schedule 1 of the Data Protection Act 2018).
  • Legitimate interests: we may use your personal data where necessary to conduct our business and pursue our legitimate interests. We consider and balance any potential impact on you and your rights before doing so, and we do not process personal data for purposes where our interests are overridden by the impact on you.

Some of the above grounds will overlap, and there may be more than one justification for a particular use of your personal data.

Purposes for which we will use your personal data

We have set out below a description of the ways we plan to use the various categories of your personal data, the legal basis we rely on, and — where health or other special category data is involved — the additional condition we rely on. We have also identified our legitimate interests where appropriate.

In the cases where we are the data controller, we use your data in the following ways:

Purpose: To register you as a new user and create your account.

Type of personal data:

  • Identity
  • Contact
  • Profile

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Purpose: To confirm your identity and demographic details against national NHS records, so that we can be sure we are treating the right person and working from the correct record.

Type of personal data:

  • Identity

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Purpose: To obtain clinical information from your Summary Care Record, where you have not asked us not to, so that we know about your medications, allergies and relevant medical history.

Type of personal data:

  • Identity
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To collect the clinical information we need to plan and deliver your care, including your sleep history, symptoms, medical history and equality data where clinically relevant.

Type of personal data:

  • Identity
  • Profile
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To deliver your clinical sleep medicine care, including arranging and interpreting your sleep study, holding your consultation, making a diagnosis, recommending and arranging treatment, and communicating with other professionals involved in your care.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Communications
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To make and keep a recording and transcript of your consultation, where you have agreed to this, so that we have an accurate record of what was discussed and agreed, and so that we can review the quality and safety of the care we provide.

Type of personal data:

  • Identity
  • Contact
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Special category condition:

  • Health and social care purposes, including the management of health care services (Article 9(2)(h); Data Protection Act 2018 Schedule 1, condition 2)

We use recordings only for your care and for clinical audit and governance.

Purpose: To supply, track and recover diagnostic and treatment equipment provided to you.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))
  • Necessary for our legitimate interests (to recover equipment belonging to us or our suppliers)

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To identify the payments you have made to us, any refunds you may be due, to identify the products or services you have purchased from us, or to collect money owed to us.

Type of personal data:

  • Identity
  • Contact
  • Transaction

Legal basis:

  • Performance of a contract with you (Article 6(1)(b))
  • Necessary to comply with a legal obligation (tax and accounting records)
  • Necessary for our legitimate interests (to collect money owed to us)

Purpose: To manage our relationship with you, including notifying you about changes to our Terms or this Privacy Notice, dealing with your requests, feedback and queries, and keeping our records up to date.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Communications
  • Usage

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))
  • Necessary to comply with a legal obligation
  • Necessary for our legitimate interests (to keep our records updated and to manage our relationship with you)

Purpose: To handle and investigate complaints, concerns and incidents, and to respond to you about them.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Communications
  • Sleep & Health

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))
  • Necessary to comply with a legal obligation

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To protect you or another person from a risk of serious harm, including safeguarding concerns.

Type of personal data:

  • Identity
  • Contact
  • Sleep & Health

Legal basis:

  • Necessary to comply with a legal obligation
  • Vital interests (Article 6(1)(d))
  • Necessary for the performance of a task carried out in the public interest (Article 6(1)(e))

Special category condition:

  • Vital interests (Article 9(2)(c)) or substantial public interest, including the safeguarding conditions in Schedule 1 of the Data Protection Act 2018 (Article 9(2)(g))

Purpose: To meet our regulatory obligations, including inspection and reporting to the Care Quality Commission and reporting to professional regulators.

Type of personal data:

  • Identity
  • Profile
  • Sleep & Health

Legal basis:

  • Necessary to comply with a legal obligation
  • Necessary for the performance of a task carried out in the public interest (Article 6(1)(e))

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

Purpose: To respond to statutory enquiries, including from the Driver and Vehicle Licensing Agency (DVLA) about your fitness to drive, and to disclose information to the DVLA where there is an overriding public interest in doing so.

Type of personal data:

  • Identity
  • Contact
  • Sleep & Health

Legal basis:

  • Necessary to comply with a legal obligation
  • Necessary for the performance of a task carried out in the public interest (Article 6(1)(e))

Special category condition:

  • Health and social care purposes (Article 9(2)(h); DPA 2018 Schedule 1, condition 2), or substantial public interest (Article 9(2)(g)) where we disclose without your agreement

See the Disclosures section below for more about how we handle fitness to drive.

Purpose: To establish, exercise or defend legal claims.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Transaction
  • Communications
  • Sleep & Health

Legal basis:

  • Necessary for our legitimate interests (to protect our legal position)
  • Necessary to comply with a legal obligation

Special category condition:

  • Legal claims (Article 9(2)(f))

Purpose: To train, teach and support the professional development of our clinicians and staff, including through multidisciplinary team discussion and case review.

Type of personal data:

  • Sleep & Health
  • Identity (where it cannot practicably be removed)

Legal basis:

  • NHS-funded care: performance of a public task (Article 6(1)(e))
  • Self-pay and insurer-funded care: performance of a contract with you (Article 6(1)(b))

Special category condition:

  • Health and social care purposes, including the management of health care services (Article 9(2)(h); DPA 2018 Schedule 1, condition 2)

We use anonymised or pseudonymised information for this purpose wherever practicable. Where a recording of your consultation is used for teaching, we do so only with your consent under the service improvement permission described above.

Purpose: To enable you to complete a survey or user test.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Usage
  • Communications

Legal basis:

  • Consent (Article 6(1)(a))

Purpose: To collect and share your experience of getting your sleep problem identified and managed, so that other patients can learn from it and feel reassured about the process.

Type of personal data:

  • Identity
  • Contact
  • Profile
  • Usage
  • Sleep & Health

Legal basis:

  • Consent (Article 6(1)(a))

Special category condition:

  • Explicit consent (Article 9(2)(a))

We only collect stories from patients who have explicitly told us they want to share their story with others. We will explain how the story will be shared, and you are free to ask for it to be removed at any time.

Purpose: To administer and protect our business and our platforms, including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data.

Type of personal data:

  • Identity
  • Contact
  • Technical

Legal basis:

  • Necessary for our legitimate interests (running our business, provision of administration and IT services, network security, and preventing fraud)
  • Necessary to comply with a legal obligation

Purpose: To understand how our website and platform are used, so that we can keep them working well and improve them.

Type of personal data:

  • Technical
  • Usage

Legal basis:

  • Necessary for our legitimate interests (to keep our website and platform updated, relevant and reliable)

We use a privacy-preserving analytics service that does not set tracking cookies, does not identify individuals, and does not track you across other websites. See the Cookies and analytics section below.

How we communicate with you

In order to provide you with accurate and timely information about your appointments, information relating to your episodes of care, or other enquiries, we will need to contact you.

While we will use our best endeavours to contact you using any preferred method of contact you have expressed, this may not always be possible and will be determined by the reason for our contact. We use text messages, phone calls, emails, letters and messages through our platform to communicate with you. Our email is configured in line with the NHS secure email standard (DCB1596). This ensures your information remains private and protected when we send it. Please be aware that your own email may not be secured to the same standard, so consider the sensitivity of the information you include.

Our communications fall into three types:

  • Clinical and service communications. These include appointment confirmations and reminders, information about your results and your care, equipment and safety information, and information about changes to your care. These are necessary to deliver your care, and you cannot opt out of them while you are receiving care from us. It is important that you keep your contact details up to date, and you should be aware that clinical information may be sent to the contact details we hold for you. Where we are unable to reach you and there is a clinical reason to do so, we may contact your GP or the organisation that referred you, so that your care can continue safely.
  • Service administration. These include notices about changes to our Terms or this Privacy Notice, and security notices. These are necessary and you cannot opt out of them.
  • Optional communications. These include newsletters, patient education, invitations to take part in surveys, user testing or research, and information about services we offer. You can opt out of these at any time, and doing so will not affect your care.

###Recording your consultations Where your consultation is held by video, we may make a recording of it, and produce a written transcript. We will always ask you first, and we will only record if you agree.

You can say no. If you would prefer not to be recorded, simply tell us — at the time, or in advance. Your clinician will write notes in the usual way instead. Declining will not affect your care, your treatment, or how quickly you are seen.

You can change your mind. You can ask us not to record future consultations at any time. Recordings already made form part of your clinical record and are kept in line with the retention periods set out below, in the same way as your other clinical notes.

What we use recordings for. Recordings and transcripts are used to support your care — for example so your clinician can write an accurate note and letter — and to review the quality and safety of the care we provide (clinical audit and governance). Access is restricted to staff involved in your care and to senior clinical staff carrying out audit or investigating a concern. Access is logged.

Other people present. If someone else is with you during the consultation — for example a partner or family member — they may appear in the recording. Please let your clinician know who is with you, and let them know that the consultation is being recorded.

Marketing and communications

We will not share your data with any third party for marketing purposes, nor contact you with direct marketing materials from third parties. We do not send marketing by text message.

Third-party marketing

We do not share your personal data with any third party for their own direct marketing purposes.

Opting out of communications

You can opt out of optional communications at any time by contacting us at privacy@thetasleep.com, by using the preference settings in our platform, or by following the unsubscribe instructions in any email we send you. If you opt out, you will still receive the clinical, service and administration communications described above, because these are necessary for your care and for the operation of our service.

Cookies and analytics

To provide you with the most secure and best possible experience with our services, we only use essential cookies on our website and our apps. These cookies are essential to provide you with the services available through our website and apps and to enable you to use some of their features. They help to authenticate users and prevent fraudulent use of user accounts. Without these cookies, the services that you have asked for cannot be provided.

We do not use any non-essential cookies, and we do not track your activity across other websites.

We use a privacy-preserving website analytics service to understand how our website and platform are used. It does not set tracking cookies, does not identify you as an individual, and does not follow you across other websites.

Disclosures of your personal data

We may share your personal data where necessary with the parties set out below, for the purposes outlined above.

Direct care: who we may receive your information from and share your information with, and why

Safe and effective care relies on the exchange of relevant information among those directly involved in a patient's treatment. Health and adult social care providers have a statutory duty under section 251B of the Health and Social Care Act 2012 to share information about an individual for the purposes of their direct care, where doing so is in the individual's best interests and is likely to facilitate their care. That duty does not apply where the individual objects, or would be likely to object. Any sharing must also comply with the common law duty of confidentiality, the UK GDPR and the Data Protection Act 2018.

Your right to object to sharing for your care. You can ask us not to share your health information with other providers involved in your care. To do so, contact us at privacy@thetasleep.com. We will discuss your objection with you and explain what it may mean for your care, as restricting information sharing can affect how quickly and safely other professionals are able to treat you. We will respect your objection except where we are required or permitted to disclose information without your agreement, which is limited to circumstances where:

  • there is a risk of serious harm to you or to another person;
  • there is a safeguarding concern;
  • we are required to disclose by a court order or another legal obligation; or
  • there is an overriding public interest in disclosure.

We may share your information with organisations and individuals directly involved in your care, in order to provide for your healthcare needs. These include:

  • People and organisations involved in your care at Theta Sleep. Health and care professionals including consultants, resident doctors, nurses, allied health professionals, and administrative staff who support the delivery of your care.
  • External organisations involved in your clinical care. This includes GPs, hospitals, specialists, dentists, community services, Integrated Care Boards and their equivalents in the devolved nations, and other organisations involved in providing your ongoing clinical care.
  • The organisation that referred you or funds your care. Where you were referred to us by an NHS organisation, a private hospital or an insurer, we share information with them about the care we have provided. Each of those organisations is a separate independent data controller for its own purposes, and sharing is governed by a written data sharing agreement.

Note that our diagnostic equipment suppliers act as our processors, not as separate controllers. They are described in the Processors section above.

Fitness to drive

Some sleep disorders can affect a person's ability to drive safely, and there are legal requirements to notify the Driver and Vehicle Licensing Agency (DVLA) in certain circumstances. Your clinician will discuss this with you where it applies to you.

We may share information with the DVLA:

  • where the DVLA contacts us to ask about your diagnosis or treatment, usually after you have notified them yourself; and
  • in limited circumstances, where we consider there is an overriding public interest in disclosure and you have not notified the DVLA yourself. We will tell you before we do this wherever it is safe and practicable to do so, in accordance with General Medical Council guidance.

Third parties whose information we hold

Sometimes the information you give us includes information about other people — for example your next of kin, your emergency contact, your GP, or a family member whose medical history is relevant to your diagnosis.

We hold this information so that we can contact the right person in an emergency and provide you with safe care. We rely on you to tell the people you name that you have given us their details. If you have named someone, please let them know.

If you are named in someone else's record and would like to know what we hold about you, or wish to exercise any of your rights, contact us at privacy@thetasleep.com.

Uses beyond your direct care

As well as using your information to care for you, we use information for a limited number of other lawful purposes that help us run a safe, high-quality service. We use anonymised information wherever possible for these purposes. Where identifiable information is needed, we only use it where we have a lawful basis to do so.

These uses may include:

  • reviewing and improving the quality and safety of the care we provide
  • investigating complaints, claims and incidents
  • auditing our accounts and services
  • preparing performance statistics for our commissioners and regulators
  • assessing future patient needs and planning our services
  • training and supporting our clinicians and staff
  • reviewing our service costs

Research and audit

We may share data with NHS bodies, universities and commercial research partners for research and audit intended to improve care. Wherever possible we share only anonymised data, which is no longer personal data and cannot be traced back to you.

Where a research project requires information that could identify you, it will proceed only with the approvals required by law, including research ethics approval, and the organisation carrying out the research will provide its own privacy information explaining how your data is used and what choices you have. We will tell you if this applies to you.

Anonymised data

Where we anonymise data so that individuals can no longer be identified, in line with Information Commissioner's Office guidance on anonymisation, that data is no longer personal data and falls outside the UK GDPR. We may use, share and publish anonymised and aggregated data — including for internal research, clinical audit, service development, product development (which may involve machine learning and large-scale data analysis), building evidence to support clinical trials and feasibility studies, conference presentations and publication in journals.

Safeguarding and protecting people from harm

Where we believe you or another person is at risk of serious harm, we may share information with the organisations who need it to keep people safe — including local authority safeguarding teams, the police, and health and social care partners. We will tell you where we can, but there are circumstances in which it would not be safe or appropriate to do so.

Legal and regulatory disclosures

We are required to share information in certain circumstances. Where we do, we share only what is necessary and proportionate, and we anonymise or pseudonymise information where we can. We will always have a lawful basis for sharing your information.

  • Professional regulatory bodies. Regulators such as the General Medical Council, the Nursing and Midwifery Council and the Health and Care Professions Council have legal powers to request information for investigations into the fitness to practise of registered professionals. We share only relevant information, and will notify you and anonymise data where possible.
  • The Care Quality Commission. Under the Health and Social Care Act 2008, the CQC can access health records in order to inspect and assess whether we provide safe, high-quality care.
  • The Medicines and Healthcare products Regulatory Agency (MHRA). We share information with the MHRA where it is necessary and proportionate to do so, for example in relation to the safety of a medical device.
  • NHS England, the UK Health Security Agency, the Office for Health Improvement and Disparities, and the Department of Health and Social Care. These organisations may require access to confidential patient information under specific directions or legal powers. Data is usually pseudonymised, with personal identifiers replaced by a code.
  • Law enforcement and other authorities. Agencies such as the police, HM Revenue and Customs, the Ministry of Defence and the Home Office may request information where there is a legal obligation to provide it, or where disclosure is necessary for the prevention or detection of crime or the apprehension or prosecution of offenders. We verify the legal basis for every request.
  • Courts and tribunals. We will disclose information where we are required to do so by a court order or other legal process.
  • Legal claims. Where necessary to establish, exercise or defend legal claims, including sharing with our insurers and legal advisers.
  • Private medical insurers. If your treatment is funded by private insurance, your insurer may carry out audits in accordance with its contractual arrangements. Data is anonymised or pseudonymised wherever possible.
  • Commissioners and funders. Organisations that commission or fund your care may audit the care delivered. Data is anonymised or pseudonymised wherever possible.
  • Someone acting on your behalf. Where you authorise a family member, friend, solicitor, attorney or deputy to access your record, we will confirm your authorisation, or their lawful authority to act for you, before releasing information.

Business transactions

If Theta Sleep is involved in a merger, acquisition or asset sale, your personal data may be transferred to the acquiring organisation. Any such transfer will be managed securely and in accordance with appropriate technical and organisational measures. Any organisation acquiring the business must be appropriately registered and regulated to deliver the care, and the transfer will not reduce your rights. Your records will transfer in accordance with this Privacy Notice, and we will notify you.

International transfers

Your clinical data on the Theta Sleep Platform is hosted on servers in the United Kingdom.

A small number of our processors handle personal data within the European Economic Area, this sometimes includes health data stored by our diagnostics and treatment suppliers. This is permitted under the UK's adequacy regulations for the EEA.

Where any processor, or a sub-processor it engages, may access data from outside the UK or the EEA, we put in place the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and we carry out a transfer risk assessment. You can ask us for details of the safeguards that apply by contacting privacy@thetasleep.com.

Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.

We comply with UK Cyber Essentials and the NHS Data Security and Protection Toolkit, and undertake annual third-party security audits and penetration tests with certified auditors.

We have procedures to deal with any suspected personal data breach, and will notify you and the Information Commissioner's Office where we are legally required to do so.

Data retention

Your information is securely stored, and Theta Sleep will retain your personal data only as long as necessary for the purposes set out in this Privacy Notice.

  • Your patient record, including recordings of consultations. We retain your patient record for up to 20 years after your last interaction with us, or 10 years after death. This is in line with the NHS Records Management Code of Practice retention period for records relating to a long-term illness or an illness that may reoccur, which covers the sleep disorders we treat. Where a recording of your consultation has been made, it is retained as part of your patient record for the same period. Where you withdraw your consent to us using a recording to improve our service, we will stop using it for that purpose immediately, although the recording will remain part of your clinical record.
  • Transaction and payment records. Retained for the period required by tax and accounting law.
  • Technical and usage data. Retained for a shorter period, unless it is needed to maintain security, improve the functionality of our service, or comply with a legal obligation.
  • Complaints records. Retained in line with NHS guidance on the retention of complaints records.
  • Anonymised data. Once data is anonymised it is no longer personal data, and we may retain and use it indefinitely.

When determining how long to retain personal data, we consider the amount, nature and sensitivity of the data, the potential risks from unauthorised access or disclosure, the purposes for which we process it, whether those purposes can be achieved in other ways, and any relevant legal, regulatory, tax or accounting requirements.

Protecting your sensitive data

Theta Sleep follows the information security values of:

  • Confidentiality: making sure your information is kept private;
  • Integrity: ensuring the completeness, consistency and accuracy of data over its lifecycle;
  • Availability: ensuring the right information is available to the right person at the right time.

We use the following techniques and best practices to protect your sensitive data:

  • People. All staff receive dedicated data protection and security training. Senior information governance leads have undergone additional training. Your personal data is only accessed on a strictly need-to-know basis by specific team members, and access is logged.
  • Cyber resilience and business continuity. We use secure and resilient cloud infrastructure and maintain up-to-date servers. Information is held in an encrypted database accessible only from a virtual private cloud. We undertake annual third-party security audits and penetration tests with certified auditors as part of the NHS Data Security and Protection Toolkit requirements.
  • Technology. We adopt Secure by Design principles. Our APIs use authentication and authorisation to ensure data minimisation and prevent unauthorised access. Passwords are stored hashed and undergo quality validation. Data is encrypted in transit and at rest. Our secure software development lifecycle further safeguards your data.

If you would like to know more about how we protect your sensitive data, please contact us at privacy@thetasleep.com

Our standards and safeguards

As well as our obligations under data protection law, we hold ourselves to the standards that apply across health and care in the UK:

  • The NHS Constitution, which sets out the rights of patients, including in relation to the confidentiality and security of their information.
  • The Caldicott Principles, eight principles that ensure people's information is kept confidential and used appropriately. We have appointed a Caldicott Guardian, who is recorded on the national register held by NHS England.
  • The National Data Guardian's standards for data security and protection in health and care.

In practice, this means we have a duty to:

  • keep accurate and up-to-date records about your care, to support safe and effective treatment;
  • keep your information confidential and secure, both during your care and afterwards;
  • ensure that only authorised staff involved in your care, or in the management of our services, can access your information, on a need-to-know basis;
  • use your information to support your care and, where appropriate and lawful, to improve services, monitor quality, and support training and research;
  • share information that identifies you only where it is necessary and lawful to do so; and
  • provide information to you in a way that is accessible, and support you in exercising your rights.

All staff working for Theta Sleep, and any organisations working on our behalf, are required to follow strict confidentiality and data protection requirements.

Your legal rights

You have a number of rights under data protection law in relation to your personal data. Some of these rights are not absolute, and which of them apply depends on the lawful basis we rely on for the processing in question. We will comply with your request where the law allows. Where we are unable to comply, we will tell you why.

You have the right to:

Request access to your personal data (commonly known as a "subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are processing it lawfully. In limited circumstances the law allows us to withhold some health information — where disclosing it would be likely to cause serious harm to your physical or mental health, or to that of another person, or where it identifies a third party who has not consented to disclosure. Where we withhold information, we will tell you that we have done so wherever it is appropriate.

Request correction of the personal data we hold about you. Where information in your record is factually incorrect, we will correct it. Where you disagree with a clinical opinion or assessment, we will review it — but a clinical opinion accurately recorded as the opinion held at the time is not inaccurate data, and we will not change it simply because you disagree. In that case we will record your disagreement in your record so that anyone reading it can see your view, and we will explain our decision to you.

Request erasure of your personal data in certain circumstances. This enables you to ask us to delete personal data where there is no good reason for us to continue processing it, where you have successfully objected to processing, where we have processed your information unlawfully, or where we are required to erase it to comply with the law. We may not always be able to comply, and we will tell you why if that is the case. This right does not apply where processing is necessary for health or social care purposes, including for medical diagnosis, the provision of care and treatment, and the management of health care services. If you believe the right to erasure applies to a particular use of your information, please contact us and we will review your request.

Object to processing of your personal data. You can object where we rely on legitimate interests, or on the performance of a task carried out in the public interest, as our lawful basis. In some cases we may be able to demonstrate compelling legitimate grounds for continuing to process your information, which override your objection. You also have a separate right to object to information being shared for your direct care, which is explained in the Disclosures section above.

Object at any time to processing for direct marketing purposes. This right is absolute.

Request the transfer of your personal data to you or to a third party, in a structured, commonly used, machine-readable format. This right applies only to automated information which you initially provided on the basis of consent, or which we use to perform a contract with you. It does not apply to processing carried out in the performance of a public task, so it will not usually apply where your care is funded by the NHS.

Withdraw consent at any time where we rely on consent to process your personal data — for example the sharing of your story. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew. If you withdraw consent, we may not be able to provide certain optional features, and we will tell you if that is the case.

Request information about automated decision-making and profiling, and object to decisions being made solely on that basis.

Request restriction of processing of your personal data. This enables you to ask us to suspend processing where:

  • you want us to establish the accuracy of the data;
  • our use of the data is unlawful but you do not want it erased;
  • you need us to hold the data even though we no longer require it, because you need it to establish, exercise or defend a legal claim; or
  • you have objected to our use of the data and we need to verify whether we have overriding legitimate grounds.

Rights exercised on your behalf. Someone else can exercise these rights for you — for example an attorney under a lasting or enduring power of attorney, a court-appointed deputy, or a person you have authorised. We will ask for evidence of their authority or your authorisation before we act.

If you wish to exercise any of the rights set out above, please contact us at privacy@thetasleep.com. We have a documented process for handling these requests. More information about your rights can be found on the Information Commissioner's Office website.

No fee usually required

You will not usually have to pay a fee to access your personal data, or to exercise any of your other rights. However, we may charge a reasonable fee, or refuse to comply with your request, where your request is manifestly unfounded or excessive.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data, or to exercise any of your other rights. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request, in order to speed up our response.

Time limit to respond

We aim to respond to all legitimate requests within one month. Where a request is particularly complex, or where you have made a number of requests, we may extend this by up to a further two months. If we need to extend the time limit, we will tell you within one month of receiving your request and explain why.

Contact details

If you have any questions about this Privacy Notice or about the use of your personal data, or if you want to exercise your privacy rights, please contact us:

  • By email: privacy@thetasleep.com
  • By post: Theta Sleep Ltd, Canterbury House, 1 Royal Street, London, England, SE1 7LL

Complaints

If you are unhappy about any aspect of your care or our service, we operate a complaints procedure, which is published on our website. You can complain by emailing help@thetasleep.com. We will acknowledge your complaint within three working days and give you a full response within 30 days. Making a complaint will not affect the care you receive.

If you are not satisfied with our final response:

  • if your care was funded by the NHS, you can refer your complaint to the relevant Ombudsman for the nation in which you live — the Parliamentary and Health Service Ombudsman (England), the Scottish Public Services Ombudsman, the Public Services Ombudsman for Wales, or the Northern Ireland Public Services Ombudsman. You may also raise your complaint with the organisation that referred you or commissioned your care;
  • if you paid for your care yourself or through an insurer, we will refer your complaint to an independent external adjudicator, and will tell you who this is when we send our final response.

If your complaint is about how we have handled your personal data, please contact our DPO at privacy@thetasleep.com in the first instance. You also have the right to complain at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection, at ico.org.uk. We would appreciate the chance to deal with your concerns before you approach the ICO.

Changes to this Privacy Notice and your duty to inform us of changes

We keep this Privacy Notice under regular review. Where we make a material change, we will tell you directly by email or through our platform. Where a change is minor or administrative, we will publish the updated Notice on our website. The version number and date of last update are shown at the top of this Notice, and previous versions are available on request.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us — for example a new address, email address, telephone number, or a change of GP.

Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of the websites you visit.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes, and only permit them to process your personal data for specified purposes and in accordance with our instructions.

Payments

We may provide paid products and services within our service. Where we do, we use third-party payment processors to handle payment. We do not store or collect your payment card details. That information is provided directly to our third-party payment processor, whose use of your personal information is governed by its own privacy notice.

National Data Opt-Out (UK)

The National Data Opt-Out allows you to stop your confidential patient information being used for research and planning purposes.

At this time, we do not share any personal data for research or planning purposes for which the national data opt-out would apply. Any data we share for research or audit is anonymised, which means it is no longer personal data. We review all of the confidential patient information we process on an annual basis to see whether it is used for research and planning purposes. If that changes, we will apply the national data opt-out and update this Notice.

You can find out more about the National Data Opt-Out on the NHS website.

The National Data Opt-Out is different from the choice you have about whether we access your Summary Care Record, which is explained earlier in this Notice.

Children and young people

Our Service is for adults aged 18 and over. We do not knowingly collect personal data about anyone under the age of 18 as a patient of our service.

Where you give us the details of a next of kin or an emergency contact who is under the age of 18, we hold only their name and contact details.

If you believe we hold information about a child, please contact us at privacy@thetasleep.com and we will review it.