Privacy Policy

Last updated: January 2025

Greenstaff Medical Limited is part of ICG Medical Group. ICG Medical Group ("ICG Medical", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your data, and outlines your rights under global data protection laws. It applies across all ICG Medical brands and global operations. This policy applies to all individuals engaging with us as candidates, clients, suppliers, website or app users.

1 – Who We Are

ICG Medical Group is a global provider of healthcare workforce solutions. While each of our brands may act as a data controller, this group-level policy governs the overarching data protection standards applied across all group entities.

Postal Address:
Suite 1, Wrest Park Business Centre, Capability House, Wrest Park, Silsoe, Bedfordshire, MK45 4HR, United Kingdom

2 – Scope of This Policy

This Privacy Policy applies when you:

  • Visit our websites or use our applications
  • Apply for or register interest in roles
  • Communicate with us via email, phone or in person
  • Are referred to us by a third party (with your permission)
  • Engage with us as a supplier, contractor or client

This policy does not apply to third-party services or platforms linked to our websites or applications.

3 – Types of Data We Collect

Depending on your interaction, we may collect:

  • Identity & Contact Data – Name, address, email, phone number
  • Professional Data – CV, qualifications, references, employment history
  • Compliance Data – Identity checks, background screening, licences, health records
  • Account Data – Usernames, passwords, log data
  • Financial Data – Payment information, tax references
  • Behavioural & Technical Data – Device information, IP, usage data
  • Sensitive Data – Health or criminal background (where required and legally justified)

4 – How We Collect Your Data

  • Directly from You – Via applications, forms, surveys, or direct contact
  • Automatically – Using cookies or analytics tools on websites and apps
  • Third Parties – Background screening services, referees, regulatory bodies
  • Referral – By others, with your prior consent

5 – Cookies and Tracking

We use cookies to:

  • Enable site functionality
  • Analyse usage behaviour
  • Customise user experience
  • Deliver targeted advertising

You may manage or disable cookies in your browser or using our cookie preference tool. See our full Cookie Policy for details.

6 – Lawful Use of Your Data

We use your personal data only when permitted by law. Lawful bases include contract, legal obligation, legitimate interest, and consent. You may withdraw consent at any time.

7 – Sharing Your Data

We only share data when necessary and with appropriate safeguards in place, including with:

  • Other ICG Medical brands providing related services
  • Third-party processors (e.g. payroll, IT, compliance services)
  • Clients for service fulfilment
  • Regulators, auditors and legal advisers
  • Authorities or acquiring companies where legally required

All sharing is governed by data processing agreements or equivalent safeguards.

8 – International Data Transfers

Your data may be transferred outside your jurisdiction. We apply:

  • UK/EU adequacy decisions
  • Standard contractual clauses (SCCs)
  • Government-approved safeguards where applicable

9 – Data Retention

Data is retained only for as long as necessary for contractual and legal compliance, operational support, or audit purposes. Secure deletion or anonymisation follows expiry of the relevant period.

10 – Data Security

We apply strong protections aligned with ISO/IEC 27001 principles, including:

  • Encryption
  • Role-based access controls
  • Intrusion detection and monitoring
  • Security training
  • Incident response protocols

If you suspect misuse or breach, please contact us immediately.

11 – Your Rights

Depending on your location, you may exercise:

  • Right of access
  • Right to correct inaccurate data
  • Right to erasure
  • Right to restrict processing
  • Right to object to certain uses (including profiling)
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge complaints with your data protection authority

Contact DPO@icgmedical.co.uk to exercise your rights.

12 – Marketing Preferences

You can opt out of marketing by clicking 'unsubscribe' in emails, contacting us directly, or via account settings on our platforms. We never sell your data.

13 – Policy Changes

This policy may be updated periodically. We will provide notice where material changes occur.

14 – Contact

Global Data Protection Officer

Email: DPO@icgmedical.co.uk
Post: Suite 1, Wrest Park Business Centre, Capability House, Wrest Park, Silsoe, Bedfordshire, MK45 4HR, United Kingdom

Appendix A – Asia-Pacific Compliance

China – Personal Information Protection Law (PIPL)

  • Formal compliance audits every two years where required
  • Cross-border transfer mechanisms including CAC security assessments and Standard Contracts
  • Data localisation respected where required by law
  • Contracts with processors incorporate Article 59 requirements
  • Data subject requests actioned within 15 business days

Japan – Act on the Protection of Personal Information (APPI)

  • AI model training uses only pseudonymised data with opt-out
  • Explicit opt-in for biometric and children's data
  • Breach notification within 30–60 days for certified entities
  • Full record of processing activities maintained

Australia – Privacy Act Reforms (Effective June 2025)

  • Privacy Impact Assessment register maintained
  • Consent is freely given, informed, specific and unambiguous
  • Penalties up to AU$50 million for serious breaches
  • Binding clauses used for overseas transfers

India – Digital Personal Data Protection Act (DPDP 2023)

  • Processing based on free, informed, specific and revocable consent
  • Integration with authorised Consent Manager Platforms
  • Data transferred only to government-approved countries
  • Parental consent required for individuals under 18

Appendix B – European and UK Compliance

Lawful Basis for Processing

ICG Medical ensures all processing meets at least one lawful basis under Article 6 GDPR: consent, contractual necessity, legal obligation, legitimate interests, vital interests, or public interest.

Data Subject Rights

EU and UK data subjects are entitled to the full suite of rights under Articles 12–22 GDPR. Requests are processed within one calendar month.

Record of Processing Activities (ROPA)

A Group-wide ROPA is maintained and updated quarterly per Article 30.

International Data Transfers

  • Adequacy decisions by the European Commission or UK Secretary of State
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs) – under development

UK-specific Measures

  • Appropriate Policy Documents maintained for criminal conviction data
  • Additional safeguards for children's data under 13
  • UK Representative appointed where required under UK GDPR Article 27

Appendix C – Americas Compliance

United States – Multi-State Privacy Framework

ICG applies a high-water mark approach across all US states, honouring data minimisation, transparency, opt-out rights, and access/correction/deletion/portability rights.

Canada – PIPEDA and Bill C-27

Consent is express or implied depending on sensitivity. Individuals have the right to explanation for automated decisions. Anonymised and de-identified data are classified and treated accordingly.

Mexico – LFPDPPP

ARCO rights (Access, Rectification, Cancellation, Opposition) are actioned within 20 days acknowledgement and 15 days fulfilment. Privacy notices delivered at point of data collection.

Appendix D – Africa Compliance

South Africa – POPIA

  • Eight processing conditions applied as foundation of South African operations
  • Data transferred outside SA only where equivalent protection or binding agreements exist
  • Information Officer registered with the Regulator
  • Data subject access/correction/deletion requests fulfilled within 21 business days
Fault Ring

Fraud Alert - Greenstaff Medical HomeCare is a trusted business and will never ask candidates for payment in exchange for a job anywhere in the world. If you're asked to pay, it's a scam. Verify any communication by contacting us directly through our official website. Stay vigilant and only engage with official Greenstaff Medical HomeCare representatives.