Please complete the form below and one of our team will be in touch.
1. Introduction:
PCMIS Health Technologies Limited (“PCMIS”, “we”, “us” or “our”) provides the Patient Portal mobile application (“the App”).
The App allows patients to securely complete questionnaires and provide information requested by their healthcare provider, including information relating to their health and treatment.
We take the privacy and security of personal information seriously. This Privacy Policy explains:
what information the App accesses, collects and processes;
- why that information is processed;
- who it may be shared with;
- how information is protected;
- how long information is retained; and
- how you can request access to or deletion of your information.
The healthcare organisation providing your care will normally be the data controller for information relating to your healthcare. PCMIS will normally process this information on that organisation’s behalf as a data processor.
Your healthcare provider may have its own privacy notice explaining in more detail how it uses your health information. You should read that notice alongside this Privacy Policy.
2. Who provides the App?
The App is provided by:
PCMIS Health Technologies Limited
Heslington Hall
Heslington
York
YO10 5DD
United Kingdom
Email: support@pcmis.com
App support: apps@pcmis.com
The Google Play application is published under the developer name PCMIS Health Technologies Limited.
3. Information processed through the App
The information processed will depend upon how your healthcare provider has configured and uses the Patient Portal.
It may include the following categories of information.
Personal information – this may include:
- date of birth;
- service identifiers;
- information to authenticate you; and other information provided by your healthcare organisation.
Health information:
The App is designed for use in connection with healthcare services and may therefore process sensitive health information, including:
- answers to clinical or health questionnaires;
- questionnaire scores;
- Health information is treated as sensitive personal information and receives additional protection under applicable data protection legislation.
We may also process limited technical information required to operate, secure and support the App, such as:
- application version;
- operating system and device type;
The App does not access any other information on your device that is unrelated to the operation of the App unless this is specifically disclosed to you and, where required, your permission is obtained.
4. How we obtain your information
Information may be:
- provided to the App by your healthcare provider;
- entered directly by you when completing a questionnaire or using the App;
- generated automatically as part of the secure operation of the App; or
- generated when we diagnose errors, investigate security incidents or provide technical support.
5. How your information is used
Information processed through the App may be used to:
- authenticate you and provide secure access to the App;
- display questionnaires assigned to you by your healthcare provider;
- allow you to complete and submit questionnaires;
- securely provide questionnaire responses to your healthcare provider;
- support your healthcare provider in delivering your care;
- operate and maintain the App;
- diagnose technical problems;
- maintain the security and integrity of the service;
- prevent unauthorised access, misuse and fraud;
- comply with legal and regulatory obligations; and
provide technical support.
PCMIS does not use health information submitted through the Patient Portal for advertising or targeted marketing.
PCMIS does not sell your personal or health information.
6. Healthcare information and your healthcare provider
Questionnaire information submitted through the App forms part of the information processed by your healthcare provider in connection with the healthcare services it provides to you.
Your healthcare provider determines why this information is collected, how it is used as part of your care and how long it must be retained.
PCMIS provides the technical system through which that information is processed.
Questions concerning your clinical record, including requests to access, correct or erase healthcare information, should normally be directed to the healthcare organisation providing your care.
7. Sharing of Information
Information may be made available to or shared with the following categories of recipients where necessary.
Your healthcare provider:
Information submitted through the App is provided to the healthcare organisation responsible for your care and authorised members of its workforce.
PCMIS:
Authorised PCMIS support staff may have limited access to information where this is necessary to provide technical support, maintain the service, investigate an incident or fulfil our contractual, security or legal obligations.
Access is limited according to role and operational need.
Service providers
We may use carefully selected service providers to provide infrastructure, hosting, technical support, security or other services required to operate the App.
Where these organisations process personal information on our behalf, appropriate contractual and security safeguards are used.
Legal requirements
Information may also be disclosed where required by law, court order or an authorised regulator or public authority.
We do not share personal or health information with advertising networks or data brokers.
8. International transfers
Personal information is not processed outside the United Kingdom. PCMIS and/or your healthcare provider ensures that appropriate safeguards are in place as required by applicable data protection law.
9. Data security
PCMIS uses technical and organisational measures designed to protect personal and sensitive information against unauthorised access, loss, alteration or disclosure.
These measures include, where appropriate:
- encryption of data while being transmitted between the App and supporting services;
- secure authentication and access controls;
- access restrictions based upon operational need;
- monitoring and logging of security-related events;
- secure software development and testing processes;
- vulnerability and security management processes; and contractual controls applying to organisations processing information on our behalf.
No internet-based system can be guaranteed to be completely secure. Users should also take reasonable precautions to protect access to their mobile device.
10. Data stored on your device
The App may temporarily store information on your device where necessary to provide its functionality.
Where possible, sensitive information is not retained on the device for longer than required for the operation of the App.
Signing out of the App and/or removing the App from your device may remove locally stored App information.
Removing the App from your device does not automatically delete information that has already been submitted to your healthcare provider.
Questionnaire scores are required to be stored on your device for the App to function.
11. Data retention
PCMIS does not retain personal information for longer than is necessary for the purposes for which it is processed.
Healthcare and questionnaire information
Questionnaire responses and other information submitted to your healthcare provider may form part of your healthcare record.
The healthcare organisation providing your care determines the retention period for that information in accordance with its legal, regulatory, clinical and organisational requirements.
PCMIS retains or processes that information on behalf of the healthcare provider for the period specified by that healthcare provider and/or for the duration required under our agreement with that organisation.
Technical, audit and security records
Technical, audit and security information is retained only for as long as reasonably necessary for purposes including:
- maintaining the security of the service;
- investigation of errors or security incidents;
- audit requirements;
- contractual requirements; and
- applicable legal or regulatory obligations.
Data stored on the App is retained for 30 days
Information stored locally by the App:
Temporary App information stored on your device is retained only for as long as required to operate the relevant App functionality and may be removed when you sign out, clear the App’s data or uninstall the App.
12. Requesting deletion of your data
You have the right, in certain circumstances, to request deletion of your personal information.
Healthcare information
Because information submitted through the App may form part of your healthcare record, requests to delete questionnaire responses or other healthcare information should be submitted directly to the healthcare organisation providing your care.
The healthcare provider will determine whether information can be deleted in accordance with applicable data protection law and its legal and clinical record-retention obligations.
Healthcare information cannot always be deleted immediately simply because a deletion request has been made. For example, a healthcare provider may be legally required to retain parts of a medical record.
Please do not include unnecessary health or medical information in your email.
The healthcare organisation is the data controller.
Deleting information from your device
You can delete locally stored App data by using Android’s application storage controls and/or by uninstalling the Patient Portal App.
This does not delete information previously submitted to your healthcare provider.
13. Account Deletion
The the account is managed by your healthcare provider, the request will need to be completed by that healthcare provider.
Deleting an App account will not necessarily result in deletion of information that has already become part of your healthcare record where the healthcare provider has a legal or clinical requirement to retain it.
14. Your data protection rights
Depending on the circumstances and applicable law, you may have rights relating to your personal information including the right to:
- be informed about how your information is used;
- request access to your personal information;
- request correction of inaccurate information;
- request deletion of information;
- request restriction of processing;
- object to certain forms of processing; and
- request transfer of your information where applicable.
Your healthcare provider is the data controller for healthcare information processed through the Patient Portal, therefore these rights should be exercised by contacting your healthcare provider.
15. Children
This App is intended for adult use only.
The Patient Portal is a healthcare application and is not designed as a general-purpose application directed at children.
16. Permissions
The App will only request device permissions necessary to provide its functions.
17. Analytics, advertising and tracking
The App does not use third-party advertising or behavioural tracking technologies and does not use third-party analytics services to profile users.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to the Patient Portal;
- changes to our data-processing practices;
- changes to third-party services used by the App; or
- changes to legal or regulatory requirements.
When this Privacy Policy is updated, the revised version will be published at the same location and the “Last updated” date at the base of the policy will be changed.
Where a material change affects how personal information is processed, additional notice will be provided where appropriate.
19. Contact us
Questions about this Privacy Policy or the Patient Portal can be sent to:
PCMIS Health Technologies Limited
Heslington Hall
Heslington
York
YO10 5DD
United Kingdom
General/privacy enquiries: support@pcmis.com
Where your enquiry relates to information contained in your healthcare record, please contact directly the healthcare organisation providing your care.
20. Complaints
If you have concerns about how your personal information has been handled, please contact the healthcare organisation providing your care.
You also have the right to raise a concern with the UK’s data protection regulator, the Information
Commissioner’s Office (ICO).
Further information is available from the Information Commissioner’s Office at ico.org.uk.
Publication Date: 28 August 2026