Who we are
This Privacy Policy explains how HealthCore LTD (“HealthCore”, “we”, “us” or “our”) processes personal data in connection with ReflectRN (the “Service”).
HealthCore LTD is a private limited company incorporated in England and Wales under company number 16714575. Registered office: HealthCore LTD, Hucknall Business Hub, Unit 2 The Byron Centre, Ogle Street, Hucknall, Nottingham, NG15 7FQ.
For most account, billing, security and website data, HealthCore is the data controller. For portfolio content that Account Holders collect from colleagues and others (feedback, skills sign-offs and similar), the Account Holder is typically the data controller and HealthCore acts as their data processor.
Contact for privacy queries: hello@reflectrn.co.uk (or hello@reflectrn.co.uk).
Scope
This Policy applies to visitors to reflectrn.co.uk, Account Holders, Respondents who submit feedback or sign-offs, and organisation managers using organisational features. It should be read with our Terms & Conditions.
What we collect
- Account data: name, email address, password hash (if set), optional NMC PIN, organisation code / membership status, preferences, profile photo, homepage photo opt-in, terms acceptance timestamp, and email verification status.
- Authentication data: when you use Google or Microsoft sign-in, we receive identifiers and profile fields those providers share (typically name and email) and store a linked OAuth account record.
- Portfolio Data: feedback requests and responses, skills requests and sign-offs, CPD entries, practice hours, exports you generate, and related metadata (dates, tokens, status).
- Organisation data: organisation codes, invites, join requests, manager flags and related approval records.
- Billing data: ReflectRN+ subscription status, Stripe customer/subscription identifiers, plan interval, and payment-related events. Card details are handled by Stripe and are not stored in full on our servers.
- Technical and security data: IP address, device/browser information, approximate location derived from IP where relevant, login success/failure logs, session data, cookies or similar technologies, diagnostic logs and abuse-prevention signals.
- Communications: support emails, contact-form messages, and transactional or service emails we send you.
Homepage photos
If you upload a profile photo, you can choose in My account whether it may appear on the public ReflectRN homepage alongside other opted-in members. Only photos where you have turned on Include my photo on the homepage are used. You can withdraw this at any time; we will stop featuring newly rendered homepage views accordingly, subject to caching delays.
How we use your data and lawful bases
We process personal data for the following purposes:
- Providing the Service (creating accounts, storing portfolio records, sharing invite links, exports, organisation features) - contract performance and/or legitimate interests in operating ReflectRN.
- Processing Portfolio Data on behalf of Account Holders - our processing as processor is based on the Account Holder’s instructions and their own lawful basis (often legitimate interests in professional development / revalidation evidence, or consent where they rely on it).
- Billing and ReflectRN+ - contract performance and legal obligation (tax/accounting).
- Security, fraud prevention, misuse detection and service integrity - legitimate interests and, where applicable, legal obligation.
- Service communications (verification, password reset, security alerts, subscription notices, product changes) - contract performance and legitimate interests.
- Optional product emails (for example feedback or skills notifications you enable) - consent and/or legitimate interests, with controls in account settings where offered.
- Improving and troubleshooting the Service (aggregated analytics, diagnostics) - legitimate interests.
- Legal compliance and dispute handling - legal obligation and legitimate interests.
- Marketing our Service to businesses or professionals where permitted - legitimate interests or consent, with opt-out.
We do not sell your personal data. We do not use Portfolio Data to train public generative AI models.
Special category and clinical data
ReflectRN is not designed for patient records. You must not upload patient-identifiable information or special category data about patients. If such data is submitted in error, we may delete it and may suspend accounts that repeatedly breach this rule. Account Holders remain responsible for preventing unlawful clinical data entry.
Who we share data with
We share personal data only as needed with:
- Infrastructure and operations providers (for example cloud hosting, storage, backups, email delivery, error monitoring, content delivery / security such as Cloudflare);
- Stripe for payment processing and subscription management;
- Google and/or Microsoft when you choose to sign in with those providers (they act as independent controllers of your identity-provider account);
- Organisation managers where your account is linked to an organisation feature and that feature necessarily exposes limited membership information;
- Respondents and invitees only to the extent an Account Holder’s invitation reveals necessary context (for example the inviting nurse’s name);
- Professional advisers (legal, accounting) under confidentiality;
- Authorities or claimants where required by law, court order, or to protect rights, safety and security; and
- A buyer or successor in a merger, acquisition or asset transfer, subject to appropriate safeguards.
Processors are bound by contract to process data only on our instructions (or the Account Holder’s instructions where we are processor) and to implement appropriate security measures.
International transfers
Some providers may process data outside the United Kingdom. Where we transfer personal data internationally, we implement appropriate safeguards required by UK data protection law (such as the UK International Data Transfer Agreement / Addendum or adequacy regulations), unless a derogation applies.
Retention
We retain account and Portfolio Data while your account is active and as needed to provide the Service. After deletion requests or account closure, we delete or anonymise personal data within a reasonable period, unless we must retain it longer for legal claims, security logs, tax/accounting, or backup integrity. Security logs are typically retained for a limited period appropriate to incident investigation. Billing records may be retained for statutory periods.
Security
We implement technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), access controls, password hashing, monitoring and backups. No method of transmission or storage is completely secure; you use the Service at your own risk to that extent permitted by law. You must use strong credentials and protect devices used to access ReflectRN.
Cookies and similar technologies
We use cookies and similar technologies that are necessary for authentication, security, load balancing and remembering settings. We may use analytics tools to understand aggregated usage. Where non-essential cookies require consent under applicable law, we will request it. You can control cookies via browser settings, noting that blocking necessary cookies may break sign-in.
Your rights
Under UK GDPR you may have rights to access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where processing is consent-based. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
To exercise rights, contact hello@reflectrn.co.uk. We may need to verify your identity. Where we act only as processor of Portfolio Data, we may redirect requests to the relevant Account Holder or handle them according to that Account Holder’s instructions and applicable law.
Children
The Service is not directed at children under 18, and we do not knowingly collect their personal data.
Automated decision-making
We do not use personal data for automated decisions that produce legal or similarly significant effects about you without human involvement.
Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Material changes may be notified via the Service or email.
Contact
HealthCore LTD, Hucknall Business Hub, Unit 2 The Byron Centre, Ogle Street, Hucknall, Nottingham, NG15 7FQ.
Privacy email: hello@reflectrn.co.uk.
This Policy is intended to describe ReflectRN processing practices clearly under UK data protection law. It is not legal advice to HealthCore LTD; consider solicitor review for regulated healthcare contexts.