Peak Medical and Rescue Limited
Last updated: 6 November 2025
This Privacy Policy explains how Peak Medical and Rescue Limited (“we”, “us”, “our”) collects, uses, and protects personal data when you visit our website, contact us, book a first aid course, receive medical treatment from us, or apply to work with us.
We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Data Controller:
Peak Medical and Rescue Limited
Company No. 15948952
Registered in England
Registered address: 1 Crag Hall Cottage, Wildboarclough, Cheshire, SK11 0BD
Email: info@peak-mr.co.uk
Telephone: 0330 043 6993
Website: peak-mr.co.uk
2. What Personal Data We Collect
We collect personal data in the following situations:
A) General Enquiries
- Name
- Email address
- Telephone number
- Any information you choose to include in your message
B) First Aid Course Bookings
- Name
- Contact information
- Course details
- Payment confirmation (processed by Stripe or PayPal — we do not see or store card details)
C) Medical Treatment / Patient Care
We may collect the following as part of clinical assessment and care:
- Patient name, age, contact information
- Date of birth (including minors under 18)
- Medical history relevant to treatment
- Injury/illness details
- Vital signs, clinical notes, treatment provided
- Emergency contact details
This information may be shared with statutory services (e.g., NHS Ambulance Service, hospital A&E departments) where clinically necessary.
D) Contractors, Clinicians, and Subcontractors
When individuals apply or are engaged to provide services for Peak Medical and Rescue, we may collect:
- Name, address, contact information
- CV and employment history
- Medical qualifications and certificates
- DBS certificate details
- Right-to-work documents (passport, visas, etc.)
- Professional indemnity details (if applicable)
- Training records and onboarding documentation
E) Technical Website Information
We do not use cookies or tracking technologies on our website.
Our hosting provider (Ionos) may collect basic, anonymised server logs for security and performance purposes.
3. How We Use Your Personal Data
We process personal data for the following lawful purposes:
A) Contractual necessity
- Responding to enquiries
- Managing course bookings
- Providing medical treatment
- Engaging contractors
B) Legal obligations
- Maintaining clinical records
- Right-to-work checks
- Insurance and safeguarding requirements
- Incident reporting where required
C) Legitimate interests
- Ensuring safe and effective service delivery
- Maintaining appropriate medical governance
- Managing staffing and deployment
We do not send marketing emails.
4. Sharing Your Information
We only share data where necessary and lawful. This may include:
- NHS services, hospitals, or ambulance trusts when handing over a patient
- Payment processors (Stripe, PayPal)
- Professional regulators if legally required
- Law enforcement or safeguarding authorities where appropriate
- Our website hosting provider (Ionos) for secure technical operation
We do not sell or share data with third parties for marketing.
5. International Transfers
We do not intentionally transfer data outside the UK.
If Ionos, Stripe, or PayPal process data internationally, they do so under approved safeguards such as:
- UK adequacy decisions
- Standard Contractual Clauses (SCCs)
6. Data Retention
We retain data only for as long as necessary:
| Data Type | Retention |
|---|---|
| General enquiries | 12 months |
| Patient medical records | 7 years (or longer if required for legal obligations) |
| First aid course bookings (financial records) | 7 years |
| Contractor applications & onboarding documents | 12 months from last engagement |
| Server logs (Ionos) | As per their standard security retention policy |
After these periods, data is securely deleted or anonymised.
7. How We Protect Your Data
We use a combination of administrative, technical, and physical controls to protect personal data, including:
- Secure email systems
- Access controls for sensitive data
- Encrypted storage for patient and contractor documents
- Secure hosted servers
8. Your Rights Under UK GDPR
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure (where legally permitted)
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent (where consent was relied upon)
To exercise your rights, contact: info@peak-mr.co.uk
If you are unhappy with how we handle your data, you can complain to:
Information Commissioner’s Office (ICO)
www.ico.org.uk
9. Children’s Data
We may collect information relating to children under 18 during the provision of medical treatment. This is processed solely for medical and safeguarding purposes and shared only when necessary with healthcare providers or statutory bodies.
We do not knowingly collect children’s data for any online purpose.
10. Links to External Sites
Our website may contain links to third-party websites. We are not responsible for their content or privacy practices.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service changes. Updates will be posted on this page with a revised “Last updated” date.
12. Contact Us
For questions about this policy or your data, please contact:
Email: info@peak-mr.co.uk
Phone: 0330 043 6993
Address: Peak Medical and Rescue Limited, 1 Crag Hall Cottage, Wildboarclough, Cheshire, SK11 0BD