Skip to content Book your free call

Last Updated: 13 July 2026

Introduction

Franklyn Health and its affiliates, subsidiaries and related entities (collectively referred to herein as “Franklyn Health”, “we”, “our” or “us”), respects the privacy of our customers, partners and other website visitors (“you” or “your”). This Privacy Notice (“Notice”) describes how we collect, process, share, and safeguard personal data that is collected via our website (www.franklynhealth.com) (“Website”) and when you engage with our services generally (collectively “Services”). It also tells you about your rights and choices with respect to your personal data, and how you can contact us if you have any questions or concerns. 

This Privacy Notice explains how Franklyn Health collects, uses, and protects personal data where it acts as a data controller, in accordance with the UK & EU General Data Protection Regulation (UK GDPR and EU GDPR) and the Data Protection Act 2018, and other data protection laws applicable to our activities in the countries in which we and our partners operate. 

This Notice applies to all websites, apps and services operated by Franklyn Health. This includes: 

  • Visitors to our website(s).
  • Clients, sponsors, suppliers, and other business contacts.
  • Clinical trial participants (volunteers, patients).
  • Healthcare professionals and consultants.
  • Job applicants for roles at Franklyn Health.

This Notice does not apply to: 

  • Employees, as employee data is covered by a separate internal Staff Privacy Notice (see “Your rights in relation to your data – Employees and workers” below).
  • Personal data we process as a processor or service provider on behalf of our customers (for example, sponsors of clinical studies) when providing services to them. For example, if we process your personal data as part of the service we provide to our customers, such customer will act as the controller and its privacy policy will govern the processing of your personal data.

We may revise this Privacy Notice from time to time. Any changes will be posted on this page with an updated date. We advise you to print a copy for your records. 

Applicability 

The table below summarises the categories of individuals covered by this Notice: 

Category of individual  Relationship to Franklyn Health  Is this Privacy Notice applicable?  Relevant UK GDPR Article 
Website visitors  Direct interaction with Franklyn Health websites  Yes  Article 13 
Clients  Direct contractual relationship  Yes  Article 13 
Sponsors  Direct business relationship  Yes  Article 13 
Suppliers & business contacts  Professional or commercial relationship  Yes  Article 13 
Clinical trial participants  Direct interaction where Franklyn Health determines purposes and means  Yes  Article 13 / Article 14* 
Healthcare professionals & consultants  Professional engagement  Yes  Article 13 
Job applicants  Recruitment process  Yes  Article 13 
Employees  Employment relationship  No – separate Staff Privacy Notice  N/A 
Individuals whose data we process for customers  Franklyn Health acts as processor only  No – customer’s privacy notice applies  Article 28 (processor role) 

*Article 14 applies where personal data is obtained indirectly (e.g. via a sponsor or healthcare organisation). 

Who we are 

Franklyn Health Limited (with principal place of business at Lister House, Lister Hill, Horsforth, Leeds, LS18 5AZ, United Kingdom) will be the controller of your personal data in accordance with data protection laws of the European Economic Area and the United Kingdom. 

Franklyn Health Limited is a leading site management service working across the UK & Europe delivering clinical research studies in both NHS and private patient settings. Our purpose is the advancement of health and the relief of patients’ suffering. 

Company details: 

  • Registered in England and Wales.
  • Principal place of business and registered address: Lister House, Lister Hill, Horsforth, Leeds, LS18 5AZ, United Kingdom.
  • ICO Registration Number: ZC010882.
  • Data Protection Authority: Information Commissioner’s Office (ICO).

Our role: controller vs processor 

Franklyn Health acts as a Data Controller for personal data collected and processed in connection with our own business operations, including recruitment, supplier management, website use, and direct engagement with research participants and healthcare professionals as described in this Privacy Notice. 

However, in many clinical research activities, we act as a Data Processor on behalf of a study sponsor, healthcare organisation, or other third party who determines the purposes and means of processing personal data. In these circumstances: 

  • The study sponsor or commissioning organisation is the Data Controller.
  • Franklyn Health processes personal data solely on documented instructions.
  • Processing is governed by a data processing agreement in accordance with UK GDPR Article 28.
  • The applicable Sponsor or Controller privacy notice will apply to that processing.

Where Franklyn Health processes personal data for its own independent purposes (for example, product or service improvement, internal quality improvement, regulatory assurance, or staff management), this Privacy Notice will apply. 

Contact information 

If you have any questions or comments about this Privacy Notice, please submit a request to privacy@franklynhealth.com or contact us through our website contact page. You may also write to us at the address above. We have appointed an external Data Protection Officer (DPO). Any privacy enquiries sent to us will be reviewed internally and, where appropriate, directed to our DPO. Please indicate “For DPO” in the subject line. 

European Union Representative 

Franklyn Health is based outside the EU and under the EU GDPR, we are required to appoint an EU representative. The purpose of an EU representative is to make it easy for people in the EU to contact us should they wish to exercise their rights or make a complaint or enquiry in relation to how we are processing their Personal Data. It is also a contact point for the supervisory authorities located in the EU. You may contact our EU Representative directly at the address below, or you may contact us at privacy@franklynhealth.com and we will ensure your enquiry is forwarded appropriately. 

Contact person: Laura Van Vaeck 

Address: Barcelona Health Hub, Carrer de Sant Antoni Maria Claret, 167, Barcelona, 08025, Spain 

Email: privacy@franklynhealth.com (please indicate “For EU Representative” in the subject line) 

This appointment applies only where EU GDPR obligations are engaged (for example, where individuals located in the EU participate in research activities or access our services). 

What personal data we collect 

We collect personal data from you in the following ways: 

Contact information and communications 

When you request an RFI/RFP, engage with our services as a customer (such as a sponsor) representative or as a supplier representative, or if you have any enquiries, you may provide us with: 

  • Your full name
  • Email address
  • Phone number(s)
  • Address(es)
  • Country
  • Job title and company you work for
  • Selection of which services you are interested in
  • Message in the contact form
  • Details about the clinical study you are engaged with when you communicate with us
  • Information related to the browser or device you use to access our website
  • Internet browser and operating system
  • Any other information you provide

Trial volunteers (research participants) 

We may collect personal data about trial volunteers from the clinical studies we assist as a clinical research organisation (“CRO”), such as full name, email address, phone number, age, and gender. We may also collect sensitive data such as health and ethnicity data. The data collected will vary depending on the nature and requirements of the specific trial, so it is not possible to provide an exhaustive list in this Notice. Study volunteers should refer to the patient information form provided for their specific study for full details on the health data collected by the Sponsor. 

Basic information: 

  • Personal identity (full name, date of birth, NHS number, National Insurance number)
  • Contact details (address, phone numbers, email)
  • Family/emergency contact details

Medical and health information: 

  • Medical history and current health status
  • Treatment and medication records
  • Study-specific data and measurements
  • Test results and treatment responses

Some common examples of special category (sensitive) data that may be collected from trial volunteers are: 

  • Ethnicity
  • Underlying health conditions, allergies, and medical history
  • Medications taken
  • Mental health information
  • Pregnancy and reproductive health
  • Diet, smoking, alcohol consumption, and drug use
  • Lifestyle information (exercise habits)
  • Religion, philosophical beliefs, political opinion, trade union membership, sexual orientation
  • Biometric data and genetic samples (where relevant to the study)

Note that this data is only collected: 

  • With explicit consent, or
  • Where required by law/regulation for scientific research and public health, subject to safeguards.

Please note that as a CRO we mainly act as a data processor for this personal data on behalf of the study Sponsor. Therefore, this Privacy Notice will not apply to such processing, and volunteers should instead refer to the privacy notice referenced in their patient information sheet. However, to the extent that we process this personal data for our own purposes (for example, product or service improvement, internal quality assurance, regulatory assurance), this Privacy Notice will apply. 

Healthcare professionals and consultants (medical staff) 

We may collect and process personal data about medical staff and healthcare professionals from the clinical studies we are engaged to facilitate the conduct of trials and to keep in contact with them: 

  • Professional identity and contact information (full name, email, phone number, and address)
  • Qualifications, registrations, and credentials
  • Professional indemnity insurance details
  • Performance and quality metrics
  • Payment and invoicing information
  • Training and competency records

Suppliers and contractors 

When engaging with suppliers and contractors, we may collect: 

  • Business contact information
  • Financial and payment details
  • Service performance data
  • Due diligence and risk assessment information
  • Insurance and certification details

Marketing information 

We may collect information about your marketing preferences, such as your choices for receiving communications from us via email and your communication preferences. 

Careers (job applicants) 

If you apply for a vacancy with us via our website, we will collect personal data such as: 

  • Your name and contact details (email, phone number, address)
  • Education and employment history
  • Right to work documentation
  • Other information you provide in your CV or application

For more information about how we process applicant and employee personal data, please see our Staff Privacy Notice, which will be provided to applicants during the recruitment process. 

Automatic data collection 

When you interact with our website or services, we and our service providers may automatically log information about you, your computer or mobile device, and our communications with you, including through the use of cookies and similar technologies. This information includes: 

Device Information: the manufacturer and model, operating system, IP address, and unique identifiers of the device, as well as the browser you use to access our services. The information we collect may vary based on your device type and settings. We may also derive a rough estimate of your location from your IP address when you visit our website. 

Usage Information: information about how you engage with our website, such as the types of content that you view, actions you take, the pages you visit, and the time, frequency, and duration of your activities, and navigation patterns. 

Our website uses cookies and similar technologies to: 

  • Enable core functionality.
  • Collect analytics on site usage.
  • Support marketing campaigns (if applicable).

For more information on our use of cookies and similar technologies, please see our Cookie Policy. You can manage cookies via this policy and your browser settings. Non-essential cookies require your consent. 

Personal data we obtain from third parties 

We may also obtain personal data about you from third parties, including: 

Social media platforms: we maintain pages on social media platforms such as LinkedIn, X (Twitter), Facebook, and Instagram. You or the platform providers may provide us with information through your interactions with our pages. When you visit or engage with us on those platforms, the platform provider’s privacy policy will apply to your use of the platform and their collection, use, and processing of your personal data. 

Other sources: we may also receive personal data about you from business partners, sponsors, investigators, or other third parties in connection with clinical trials or business relationships. 

How do we use this information? 

We process the personal information listed above for various purposes: 

To provide and maintain our Services 

We will use your personal data to perform our contractual obligations, when it is in our legitimate business interests or based on your consent, including to: 

  • Provide, operate, maintain, and secure our Services
  • Provide support assistance and troubleshooting
  • Facilitate the conduct of clinical trials
  • Monitor participant safety during studies
  • Provide healthcare services
  • Send you updates about administrative matters such as changes to our terms or policies
  • Provide user support, and respond to your requests, questions and feedback

To improve, monitor, and protect our Services 

It is in our legitimate business interests to improve and keep our Services safe, which includes: 

  • Gathering analysis or valuable information so that we can improve our Services
  • Enriching your user experience and customising your relationship with us
  • Creating and maintaining a database of medical staff and healthcare professionals regarding future clinical trials
  • Protecting the security of our Services
  • Preventing and detecting security threats, fraud or other criminal or malicious activities
  • Administering content, surveys, voting polls and other Website features
  • Monitoring the usage of our Services
  • Improving website performance and user experience

Research and development 

We will use personal data to develop, analyse and improve the Services and our business when it is in our legitimate interests, or where we have your consent (for example to process sensitive data such as health data). As part of these activities, we may process personal data and/or use aggregated, de-identified or other anonymised data from personal data we collect. We anonymise data by removing information that makes the data personally identifiable. We may use this anonymised data and share it with third parties for our lawful business purposes, including to analyse and improve the Services and promote our business. 

For marketing and advertising 

We, our service providers and our advertising partners may use your personal data for the following marketing and advertising purposes: 

Direct marketing: to send you informative newsletters relating to our expertise and services, service updates, research opportunities, or event information. Newsletters will be sent where you have given your consent to receive it, or where this is allowed under soft-opt in (existing customer relationship). You will be given an opportunity to opt-out at each Newsletter and can unsubscribe using links in emails. You will only receive newsletters from Franklyn Health or one of our subsidiary companies. 

Interest-based advertising: we may engage third-party advertising companies, such as Google and Meta, to display our ads on their online services. We may also share information about our users with these companies to facilitate advertising for our services to them or similar users on other online platforms. For more information, or to understand your choices, please visit our Cookie Policy. 

Except where consent is required, we undertake such marketing and advertising on the basis of our legitimate business interests. Where we seek your consent, you may withdraw your consent at any time by contacting us or using the unsubscribe mechanisms provided. 

To comply with legal obligations 

To comply with legal obligations and to defend Franklyn Health against legal claims or disputes, and to meet regulatory requirements (e.g., MHRA, NHS, Research Ethics Committees). 

To facilitate corporate transactions 

We may use your personal data, when it is in our legitimate business interests, when we do a business deal, or negotiate a business deal, involving the sale or transfer of all or a part of our business or assets. These deals can include any merger, financing, acquisition, or bankruptcy transaction or proceeding. 

For recruitment 

When you apply for a job with us, we may use information collected throughout the recruitment process to: 

  • Manage recruitment and selection processes
  • Review our equal opportunities profile in accordance with applicable legislation

We use this information to take steps to enter into a contract with you, to meet a legal obligation or for our legitimate interests in recruitment. 

Professional service management 

For healthcare professionals, consultants, suppliers and contractors: 

  • Managing professional service contracts and agreements
  • Ensuring professional standards and competency
  • Processing payments and invoicing
  • Regulatory reporting and compliance
  • Quality assurance and improvement
  • Conducting due diligence and risk assessments
  • Ensuring service quality and compliance

Legal basis for processing personal data 

If you are located in the European Economic Area (EEA) or the United Kingdom, Franklyn Health’s legal basis for collecting and using the personal data described in this Privacy Notice depends on the type of data we collect and the specific context in which we collect it. Franklyn Health may process your Personal Data on one or more of the following bases: 

Legal Basis  GDPR Article  When This Applies 
Contractual necessity  Art. 6(1)(b)  Processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract 
Consent  Art. 6(1)(a)  You have given clear and informed consent for specific processing activities 
Legitimate interests  Art. 6(1)(f)  Processing is necessary for Franklyn Health’s legitimate interests, provided these are not overridden by your rights and freedoms 
Legal obligation  Art. 6(1)(c)  Processing is required to comply with a legal or regulatory obligation 
Public task / public interest  Art. 6(1)(e)  Processing is necessary for tasks carried out in the public interest, including healthcare provision and scientific research 
Vital interests  Art. 6(1)(d)  Processing is necessary to protect someone’s life or physical safety, particularly participant safety 

For special category data (such as health data and genetic data), we additionally rely on one of the following conditions: 

Condition  GDPR Article  When This Applies 
Explicit consent  Art. 9(2)(a)  You have given explicit consent for the processing of special category data 
Employment and social protection law  Art. 9(2)(b)  Processing is necessary to meet obligations under employment or social protection law 
Vital interests  Art. 9(2)(c)  Processing is required to protect vital interests where consent cannot be obtained 
Healthcare and public health  Art. 9(2)(h)  Processing is necessary for medical diagnosis, healthcare provision, or health system management 
Public health  Art. 9(2)(i)  Processing is required for public health purposes, including protecting against serious cross-border health threats 
Scientific research  Art. 9(2)(j)  Processing is necessary for scientific or research purposes, subject to appropriate safeguards 

Our legitimate interests 

Where we rely on our legitimate interests as a legal basis, we ensure that those interests are balanced against your fundamental rights and freedoms, and we only process personal data where our interests are not overridden by your interests or rights under data protection law. Our legitimate interests include: 

Business Operations: efficient management of our workforce, services, and business relationships 

Safety & Security: protecting staff, patients, research participants, and business premises 

Professional Standards: ensuring competent delivery of healthcare and research services 

Risk Management: preventing fraud, misconduct, and regulatory breaches 

Emergency Response: contacting staff or participants during incidents or emergencies 

Service Improvement: developing and improving our services and user experience 

Automated decision-making and artificial intelligence (AI) 

Franklyn Health does not use personal data for fully automated decision-making, including profiling, that produces legal effects or similarly significant effects on individuals, as defined under Article 22 UK GDPR. 

Where digital tools, analytics, or technology-assisted systems (including those incorporating elements of artificial intelligence or machine learning) are used to support research delivery, operational efficiency, or data quality, such tools are used to assist human decision-making, not replace it. 

Any use of technology involving personal data is subject to: 

  • Human oversight
  • Appropriate technical and organisational safeguards
  • Data minimisation and purpose limitation
  • Where required, Data Protection Impact Assessments (DPIAs)

Where automated processing or AI-enabled tools are introduced that materially affect individuals, additional information will be provided through study documentation, participant information sheets, or supplementary privacy information, as appropriate. 

Data retention 

Franklyn Health will retain your personal data only for as long as necessary to fulfil the purposes described in this Privacy Notice, or as required by law. Retention periods vary depending on the type of personal data and the context of processing. In particular: 

Clinical trial data: retained in accordance with applicable laws and Good Clinical Practice requirements. This typically means at least 15 years after the last subject’s last visit (or as specified in the sponsor’s Data Processing Agreement), or longer where required by law or contractual obligations with the study sponsor (typically 15–25 years depending on sponsor requirements). 

Healthcare records: retained in accordance with the applicable national healthcare records retention requirements (for example, the NHS Records Management Code of Practice in the UK). 

Client and supplier data: retained for the duration of the business relationship and for up to 6 years thereafter, to comply with tax, contractual, and regulatory obligations. 

Website enquiry data: retained for up to 2 years from the last interaction, unless a longer period is required by law. 

Marketing data: retained until you withdraw your consent or opt out of receiving marketing communications, or 2 years of inactivity, after which we will promptly suppress your details from marketing lists. 

Job applicant data: retained for up to 12 months after the recruitment process ends, unless you consent to a longer retention period or we are legally required to keep it for longer. 

Technical and usage data (cookies, logs, analytics): retained in line with our Cookie Policy, generally no longer than 13 months. 

After these periods, data will be securely deleted, anonymised, or pseudonymised to prevent re-identification. Full details are available in our Data Retention Schedule upon request. 

How we share your personal data 

We may share your personal data with the following third parties: 

Service providers: to assist us in meeting business operational needs and to perform certain services and functions, we may share personal data with our vendors and service providers, including providers of hosting services, cloud services, other information technology services providers, event management services, payment services, marketing services and customer support services. Pursuant to our instructions, these parties will access, process, or store personal data while performing their duties for us. 

Research and healthcare partners: for clinical trial participants and healthcare services, we may share personal data with: 

  • Study sponsors and clinical research organisations
  • Regulatory authorities (MHRA, Research Ethics Committees)
  • Your GP or referring clinicians
  • Specialist consultants involved in your care
  • Pathology laboratories for test analysis
  • Data monitoring committees
  • Healthcare insurance providers (with consent)

Advertising partners: third party advertising companies for the interest-based advertising purposes described above. The disclosure of this information may constitute a data “sale” under certain privacy laws. 

Professional advisors: we may share personal data with our professional advisors such as lawyers and accountants where doing so is necessary to facilitate the services they render to us. 

Legal requirements: we do not volunteer your personal data to government authorities or regulators, but we may disclose your personal data where required to do so to comply with laws and regulations applicable to us as described above. 

Business transaction: if Franklyn Health is involved in a merger, acquisition or asset sale, financing due diligence, reorganisation, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your personal data may be sold, transferred, or otherwise shared including as part of any due diligence process. 

Affiliates: we may share your personal data with our affiliated companies. 

International data transfer 

Your information, including Personal Data, may be transferred to, and maintained on, computers or servers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. Our team and service providers are located in the European Union, the United Kingdom and the United States, and other countries in which we or our partners operate. Additionally, personal data is stored on servers located in the EEA, UK, and U.S. 

Personal data may be accessed by our staff or service providers located in the UK, EEA, or other jurisdictions, strictly on a need-to-know basis and subject to contractual confidentiality and security obligations. 

Unfortunately, the process of transmitting information via the internet is not completely secure. While we take appropriate measures to protect your personal data, please note that transmission over the internet carries inherent risks; any transmission is at your own risk. 

Once we have received your information, Franklyn Health will take all the steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Notice. No transfer of your personal data will take place to an organisation or a country unless there are adequate controls in place, including appropriate technical and organisational measures to protect your data and other personal information. 

Where personal data is transferred outside the United Kingdom and/or the European Economic Area (EEA), Franklyn Health ensures that such transfers are carried out in accordance with UK GDPR and EU GDPR requirements. We implement appropriate safeguards to protect personal data, including: 

  • Transfers to countries recognised by the UK Government or European Commission as providing an adequate level of data protection.
  • Use of International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner’s Office.
  • Use of Standard Contractual Clauses (SCCs) issued by the European Commission or the UK Information Commissioner’s Office (“ICO”) as varied, supplemented, amended or replaced from time to time.
  • Supplementary technical and organisational measures where required to ensure equivalent levels of protection.

We do not transfer personal data internationally unless we are satisfied that appropriate safeguards are in place to protect your rights and freedoms. If none of the above situations apply, we will not transfer your personal data unless you have given your express consent to the proposed transfer, after having been informed of the possible risks. 

To learn more about transfer mechanisms implemented, please contact us by email at privacy@franklynhealth.com or through our website contact page. 

Data security 

We apply comprehensive technical and organisational measures to safeguard personal data, including: 

Technical measures: 

  • Encryption and secure data transfer protocols
  • Secure servers with encryption
  • Password protection and unique user access controls
  • Two-factor authentication where available
  • Access controls and role-based permissions
  • Regular security updates and monitoring

Organisational measures: 

  • Regular data protection training for staff
  • Access controls based on job requirements
  • Policies for data handling, breach reporting, and incident management
  • Regular security risk assessments
  • Incident response procedures
  • Secure data disposal processes

Data breach response: if a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law. If you suspect any misuse, loss, or unauthorised access to your data, please contact us immediately at privacy@franklynhealth.com or through our website contact page. 

Your rights in relation to your data 

The law on data protection gives you certain rights in relation to the personal data we hold on you. Under UK GDPR and EU GDPR, you have the following rights: 

The right of access. You have the right to access and request copies of the personal data that we hold on you. After receiving the request, we will tell you when we expect to provide you with the information (if applicable), and whether we require any fee for providing it to you. 

The right for any inaccuracies to be corrected (rectification). If any data that we hold about you is incomplete or inaccurate, you are able to require us to correct it. 

The right to have information deleted (erasure). If you would like us to stop processing your data, you have the right to ask us to delete it from our systems, unless we are required to continue storing it for legal reasons or reasons of public interest. This may limit the service we can provide to you. 

The right to restrict the processing of the data. When you contest the accuracy of your information, believe we process it unlawfully or want to object against the processing, you have the right to temporarily stop the processing of your information to check if the processing was consistent. In this case, we will stop processing your data (other than storing it) until we are able to provide you with evidence of its lawful processing. 

The right to portability. In certain circumstances, you may have the right to require that we provide you with an electronic copy of your personal information either for your own use or so that you can share it with another organisation. Where this right applies, you can ask us, where feasible, to transmit your personal data directly to the other party. This can only be done if the processing is done in accordance with your consent or for the performance of a contract. 

The right to object to processing of your personal data. You have the right to object to the way we use your data where we are using it for our legitimate interests. 

The right to withdraw consent. Where you have provided consent to our use of your data, you also have the unrestricted right to withdraw that consent at any time. Withdrawing your consent means that we will stop processing the data that you had previously given us consent to use. There will be no consequences for withdrawing your consent. However, in some cases, we may continue to use the data where so permitted by having a legitimate reason for doing so. 

Right not to be subject to automated decisions. You also have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. Franklyn Health currently does not use personal data for automated decision-making or profiling that produces legal or significant effects, unless explicitly stated in study documentation and subject to your consent. 

Employees and workers 

Franklyn Health’s current and former employees, workers and contractors have the same data protection rights set out above — including the rights of access, rectification, erasure, restriction, objection, portability (where applicable), the right to withdraw consent, and the right not to be subject to solely automated decisions. These rights apply to the personal data we process about staff in our capacity as employer and data controller. 

Full details of how we collect and use staff personal data — including the categories of data, purposes, legal bases and retention periods specific to the employment relationship — are set out in our separate internal Staff Privacy Notice, which is provided to staff during onboarding and is available on request. To exercise any of your rights as an employee or worker, please contact privacy@franklynhealth.com or speak to the People/HR team. 

Exercising your rights 

  • Contact us at privacy@franklynhealth.com or through our website contact page.
  • We will respond within one month.
  • No charge for most requests.
  • We may need to verify your identity.

Limitations: 

Some rights may be limited where we have overriding legal obligations or legitimate interests, particularly in clinical research contexts. Certain rights may be limited where processing is necessary for scientific research, public health, or regulatory compliance, in accordance with applicable data protection law. 

If you wish to exercise any of the rights explained above, please contact us at privacy@franklynhealth.com or through our website contact page. 

Marketing communications 

We may contact you about our services, research opportunities, or events where you have given your consent or where we have a legitimate interest to do so (existing customer relationship). 

Your choices: 

  • Unsubscribe using links in emails.
  • Contact us directly to opt out at privacy@franklynhealth.com.
  • Update your communication preferences.

Links to other websites 

Our website may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every website you visit. 

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. 

Children 

We do not intend for children to use our website. We do not intentionally gather personal data about visitors who are under the age of 18 or who are considered a minor in the jurisdiction in which you are accessing our website or Services. 

If a child has provided us with personal data, a parent or guardian of that child may contact us to have the information deleted from our records. If you believe we may have any information from a child under age 18 or an individual considered a minor in the applicable jurisdiction, please contact us at privacy@franklynhealth.com. 

If we learn that we have inadvertently collected the personal data of a child under 18 or the equivalent minimum age depending on jurisdiction, we will take steps to delete the information as soon as possible. 

Complaints 

If you wish to lodge a complaint about how we process your personal data: 

Contact us first: please contact us at privacy@franklynhealth.com or through our website contact page. We will endeavour to respond to your complaint as soon as possible. 

Independent review: depending on where you reside, such as if you reside in the European Economic Area or United Kingdom, you may have the right to complain to a data protection regulator where you live or work, or where you feel a violation has occurred. 

For EU residents: EU data subjects can find their supervisory authority here: https://edpb.europa.eu/about-edpb/board/members_en 

For UK residents: if you are based in the United Kingdom, your regulator will be the Information Commissioner’s Office (ICO): 

  • Website: www.ico.org.uk
  • Helpline: 0303 123 1113
  • You can make a complaint via: https://ico.org.uk/make-a-complaint/

The ICO is the UK’s independent data protection regulator. 

If you are located outside the UK or the EEA, you may also have the right to lodge a complaint with the data protection authority in the country where you live or work. 

Changes and updates to this notice 

We will update this Notice from time to time. Updates will be posted on this page with a revised “last updated” date. Please review this Notice periodically for any changes. Changes to this Notice are effective when they are posted on this page. The terms that apply to you are those posted here on our website on the day you use our website. We advise you to print a copy for your records. The date of last revision appears at the top of this notice. 

Contact us 

For questions about this Privacy Notice or how we handle your data: 

Franklyn Health Limited 

Lister House, Lister Hill, Horsforth, Leeds, LS18 5AZ, United Kingdom 

Email: privacy@franklynhealth.com