Privacy Policy
Last Updated: November 2025
1. Introduction
NHS Forms ("we", "us", "our", or "Company") operates the NHS Forms website and service. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We use your data to provide and improve the Service. By using NHS Forms, you agree to the collection and use of information in accordance with this policy.
2. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our Service to you.
2.1 Types of Data Collected:
- Personal Data: While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). This may include:
- Email address
- First name and last name
- Phone number
- Address, State, Province, ZIP/Postal code, City
- Cookies and Usage Data
- Usage Data: We may also collect information how the Service is accessed and used ("Usage Data"). This may include:
- Your computer's Internet Protocol address (e.g. IP address)
- Browser type, Browser version
- The pages of our Service that you visit, the time and date of your visit, the time spent on those pages
- The referring/exit pages
- Operating system, device type, unique device identifiers
- Form Data: Data submitted through NHS Forms is encrypted end-to-end and stored securely in UK data centers. This data is only accessible to authorized users within your organization.
3. Use of Data
NHS Forms uses the collected data for various purposes:
- To provide and maintain our Service
- To notify you about changes to our Service
- To allow you to participate in interactive features of our Service when you choose to do so
- To provide customer support
- To gather analysis or valuable information so that we can improve our Service
- To monitor the usage of our Service
- To detect, prevent and address technical and security issues
- To comply with legal obligations
4. Security of Data
The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
All form data is protected by:
- End-to-end encryption using AES-256
- TLS 1.3 for all data in transit
- UK data residency (no data leaves UK servers)
- Regular security audits and penetration testing
- Comprehensive audit logging of all data access
- Role-based access controls
5. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract: Processing is necessary to perform a contract with you
- Consent: You have given clear consent for us to process your personal data
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: The processing is necessary for our legitimate interests or those of a third party
6. Retention of Data
NHS Forms will retain your Personal Data only for as long as necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws).
Form submission data is retained according to your configured retention policies, with a minimum retention period of 7 years for NHS compliance purposes.
7. Transfer of Data
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
If you are located outside United Kingdom and choose to provide information to us, please note that we transfer the data, including Personal Data, to United Kingdom and process it there.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
8. Disclosure of Data
8.1 Business Transaction
If NHS Forms is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data becomes subject to a different Privacy Policy.
8.2 Disclosure for Law Enforcement
Under certain circumstances, NHS Forms may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
8.3 Security of Data
The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
9. Service Providers
We may employ third party companies and individuals to facilitate our Service ("Service Providers"), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
10. Links to Other Sites
Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
11. Children's Privacy
Our Service does not address anyone under the age of 18 ("Children").
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove such data and terminate the child's account.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
13. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: privacy@nhs-forms.com
- Support: support@nhs-forms.com
- Address: NHS Forms, Scotland