Privacy Policy
This policy sets out the basic privacy and data protection principles for practices using General Practice in Ireland and the UK.
1. Who we are
General Practice is a digital service used by doctor surgeries to manage appointments, repeat prescriptions, and practice communications with patients. The practice is the data controller for patient information processed through the service.
2. What information is collected
- Patient identity and contact details
- Appointment requests and booking details
- Repeat prescription requests
- Practice communications by email and SMS
- Administrative and audit information needed to operate the service
3. Why information is used
Information is processed to provide healthcare administration services, respond to patient requests, manage appointments, issue repeat prescriptions, and support safe and effective practice communications.
4. Lawful basis
Practices may rely on consent, contract, legal obligation, vital interests, and/or the performance of a task carried out in the public interest, depending on the specific processing activity. Special category health data is handled only where permitted under applicable data protection law.
5. Sharing information
Patient information is only shared with authorised practice staff, relevant healthcare professionals, and service providers who support the operation of the platform, where necessary and lawful. Data is not sold or shared for unrelated marketing purposes.
6. Retention
Information is retained only for as long as needed for the purposes for which it was collected, or for the periods required by clinical, legal, and regulatory obligations.
7. Security
Appropriate technical and organisational measures should be used to protect patient information, including access control, authentication, audit logging, encryption where appropriate, and secure communication channels.
8. International use and legal compliance
Practices using the service should comply with the UK GDPR, the Data Protection Act 2018, the EU GDPR where applicable, and Irish data protection law. If information is transferred outside the UK or EEA, appropriate safeguards should be in place.
9. Your rights
Depending on the legal basis for processing, patients may have rights of access, rectification, restriction, objection, portability, and erasure. Requests should normally be made to the relevant practice.
10. Contact
For privacy questions, contact the practice directly. If your request relates to the app or service provider, the practice can direct you to the appropriate contact details.