Privacy Notice


Version: 2.1

Effective Date: 30/04/2026


Introduction

COPE Occupational Health Services Limited (“COPE”, “we”, “our”, “us”) is committed to protecting your personal data and respecting your privacy. This Privacy Notice explains how we collect, use, store, and share personal data in connection with:

  • Our occupational health services
  • Our website and communications
  • Recruitment activities
  • Business development and marketing


It also outlines your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

 

Who We Are

COPE provides occupational health services to employers and their employees across the UK. Depending on the context, we act as either:

  • Data Controller – where we determine how and why personal data is processed (e.g. clinical assessments)
  • Data Processor – where we process data on behalf of a client organisation

 

When This Notice Applies

This notice applies when you:

  • Are referred to us for occupational health services
  • Interact with us as a client or prospective client
  • Visit our website or submit an enquiry
  • Receive communications from us (including marketing)
  • Apply for a role with COPE

 

What Data We Collect

  • Personal Data
  • Name, contact details, date of birth, national insurance number
  • Employment information (job role, employer, location)
  • Business contact details (e.g. name, job title, work email)
  • Recruitment information (CV, application data, right to work)
  • Special Category Data (Health Data)
  • Medical history, symptoms, treatments
  • Clinical assessments and fitness for work opinions
  • Health surveillance results


We only collect data that is necessary and relevant for the purposes described in this notice.


How We Collect Your Data

We may collect data from:

  • Your employer (as part of a referral)
  • You directly (consultations, forms, applications)
  • Other healthcare providers (with your consent)
  • Publicly available sources (for business contact data)
  • Reputable third-party data providers (for business-to-business communications)

 

How We Use Your Data

We process personal data to:

  • Deliver occupational health services
  • Conduct consultations and provide reports
  • Support employer compliance with health and safety law
  • Manage recruitment processes
  • Respond to enquiries
  • Improve services through anonymised analysis
  • Send relevant business communications (see Marketing section below)


We will only share clinical information with your employer with your explicit consent, unless an exception applies (e.g. legal obligation or safety-critical circumstances).


Legal Basis for Processing

We rely on the following lawful bases:


For Personal Data (Article 6 UK GDPR):

  • Legitimate Interests – delivering occupational health and business services
  • Legal Obligation – compliance with health & safety or employment law
  • Contract – recruitment and employment processes
  • Consent – where specifically required
  • Vital Interests – emergency situations


For Health Data (Article 9 UK GDPR):

  • Article 9(2)(h) – occupational health and assessment of working capacity

 

Data Sharing

We may share your data with:

  • Your employer (with appropriate consent)
  • Laboratories and healthcare providers supporting your care
  • Approved third-party processors (e.g. IT systems, communication platforms)
  • Regulatory or legal authorities where required


All third parties are subject to confidentiality and data protection obligations. We do not sell your personal data.

 

Marketing Communications

We may use business contact details to send information about our services, updates, and relevant content where this is likely to be of interest to your organisation. This may include contacting individuals using corporate contact details obtained from:

  • Direct interactions with COPE
  • Publicly available sources
  • Reputable third-party data providers


We rely on legitimate interests as our lawful basis for business-to-business marketing communications, in line with UK GDPR and PECR. We ensure that:

  • Communications are relevant and proportionate
  • Recipients are clearly identified
  • A clear opt-out mechanism is always provided


You can opt out at any time by either clicking the unsubscribe link in our emails or by contacting us at: info@copeohs.com. We do not send marketing communications where consent is required, unless that consent has been obtained.

 

International Transfers

COPE does not transfer personal data outside of the United Kingdom. All personal data is processed and stored within the UK. Where third-party providers are used, we ensure that data is hosted and accessed within the UK and subject to appropriate data protection safeguards.

 

Data Security

We implement appropriate technical and organisational measures, including but not limited to:

  • Encryption in transit and at rest
  • Role-based access controls
  • Secure UK-based infrastructure
  • Audit logging and monitoring
  • Paper records, where used, are stored securely with restricted access.

 

Retention Periods

  • We retain personal data only as long as necessary:
  • Health Surveillance Records: up to 40 years (as required by law)
  • Other Clinical Records: typically 7–8 years after last contact
  • Recruitment Records (unsuccessful): up to 12 months
  • Business contact data: retained while relevant for business purposes or until opt-out
  • Website enquiries: retained only as long as necessary for business purposes

 

Your Data Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request erasure (where applicable)
  • Restrict or object to processing
  • Withdraw consent (where applicable)
  • Data portability (in certain cases)
  • You also have the right to lodge a complaint with the Information Commissioner's Office - www.ico.org.uk


To exercise your rights, please use the below data rights form or contact us at: data.protection@copeohs.com

 

Website Usage & Cookies

When you visit our website, we use cookies to:

  • Improve functionality and user experience
  • Contact form data is transmitted securely and not stored on the public website
  • We do not use website data for third-party marketing
  • You can control cookies through your browser settings.

 

Changes to This Notice

We may update this Privacy Notice periodically. The latest version will always be available on our website.

 

Contact Us

If you have any questions about this notice or how your data is handled, please contact:


Post:

COPE Occupational Health Services Limited

5 Castle Quay, Nottingham, NG7 1FW


Email:

info@copeohs.com


Phone

0115 925 9222

Data Rights Form

Contact Us