Data Protection Statement
How ORVIA Healthcare protects your personal data.
Orvia Healthcare Ltd
Last updated: 23 May 2026
Our Commitment to Data Protection
ORVIA Healthcare takes the protection of personal data seriously. We are committed to handling all personal information lawfully, fairly, transparently and securely, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Registration
Orvia Healthcare Ltd is registered with the Information Commissioner’s Office (ICO).
ICO Registration Number: ZC152311
Registration Date: 19 May 2026
Expiry Date: 18 May 2027
Fee Tier: Tier 1
Data Controller
Orvia Healthcare Ltd
Company Registration: 16123685 (England and Wales)
Registered Address: 3rd Floor, 86-90 Paul Street, London, EC2A 4NE
Data Protection Officer: john.mcgill@orviahealthcare.co.uk
How We Protect Data
We protect personal data through:
Secure systems — Microsoft 365 is our primary operating environment, with SharePoint as our controlled document store
Access controls — only authorised team members can access personal data, based on their role and the requirements of the work
Encryption — we use encrypted email and secure communication channels
Regular review — we review our data handling practices regularly to ensure they remain appropriate
Training — team members are expected to understand their data protection responsibilities
Minimal collection — we only collect the personal data we need for a clear, lawful purpose
Data Protection Principles
We follow the six UK GDPR principles. Personal data must be:
Processed lawfully, fairly and transparently
Collected for specified, explicit and legitimate purposes
Adequate, relevant and limited to what is necessary
Accurate and kept up to date
Kept only for as long as necessary
Processed securely
Safeguarding and Data Protection
ORVIA works in safeguarding, governance and operational oversight. This means we may handle information that is sensitive or relates to vulnerable people. We handle all such information with the highest level of care.
Where there is a safeguarding duty to share information with the appropriate statutory authority (such as a local authority safeguarding team or the police), we will do so in line with UK law and professional guidance. Data protection law does not prevent the sharing of information for safeguarding purposes where there is a lawful basis to do so.
Data Protection Impact Assessments (DPIAs)
Where our processing is likely to result in a high risk to the rights and freedoms of individuals, we will carry out a Data Protection Impact Assessment before beginning that processing.
We conduct Data Protection Impact Assessments where processing is likely to result in a high risk to individuals’ rights and freedoms. This includes assessments for our service delivery processes and any technology-assisted features. Our DPIA approach is reviewed regularly.
Subject Access Requests
You have the right to request a copy of the personal data we hold about you. To make a subject access request, contact us at Hello@orviahealthcare.co.uk. We will respond within one calendar month.
Data Breaches
In the event of a personal data breach, we will:
Assess the breach and its likely impact
Report it to the ICO within 72 hours if it is likely to result in a risk to people’s rights and freedoms
Notify affected individuals without undue delay if there is a high risk to their rights and freedoms
Record all breaches, including those that do not require reporting
AI and Technology
ORVIA uses AI tools to support operational efficiency, communication and administrative tasks. We do not use AI to make safeguarding decisions. Human judgement remains the final decision layer in all matters relating to safeguarding, governance and oversight.
Any AI tools we use are subject to our data protection policies and the AI Removal Test™ — every process that uses AI must also work without it.
Your Rights
For full details of your data protection rights, including how to access, correct or delete your data, please see our Privacy Policy.
Complaints
If you have concerns about how we handle your data, please contact us first. You also have the right to complain to the ICO:
Website: ico.org.uk
Helpline: 0303 123 1113
Contact
Orvia Healthcare Ltd
Email: Hello@orviahealthcare.co.uk
Phone: 0114 399 8231
Address: 3rd Floor, 86-90 Paul Street, London, EC2A 4NE
ICO Registration: ZC152311
ORVIA Healthcare Ltd | 3rd Floor, 86-90 Paul Street, London, EC2A 4NE | Company No. 16123685
Contact: hello@orviahealthcare.co.uk | 0114 399 8231