MEDI ALARM 247
PRIVACY POLICY
Last updated: 17 July 2026
Medi Alarm 247 Limited respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains:
- what personal information we collect;
- how and why we use it;
- who we may share it with;
- how long we keep it;
- how we protect it; and
- the rights you have in relation to your information.
This policy applies to information collected through:
- our website;
- online enquiry and contact forms;
- Facebook and Instagram lead forms;
- telephone calls;
- email, SMS and WhatsApp;
- personal alarm devices;
- our monitoring and response services;
- our customer relationship management systems;
- subscription and payment arrangements;
- customer-support activity;
- cookies, analytics and advertising technologies; and
- communications with Customers, Users, relatives, carers, Emergency Contacts and representatives.
This policy should be read alongside our Customer Terms and Conditions, Cookie Policy and any additional privacy information provided when we collect personal information.
1. WHO WE ARE
Medi Alarm 247 is operated by:
Medi Alarm 247 Limited
Company number: 13634557
Postal and correspondence address:
Medi Alarm 247 Limited
Unit 5
17 Cobham Road
Ferndown
Dorset
BH21 7PE
Telephone: 0800 688 9961
Email: hello@medialarm247.com
Website: www.medialarm247.com
Medi Alarm 247 Limited is the data controller for the personal information described in this policy. This means that we determine why and how that information is used, except where another organisation acts as an independent or joint controller for a particular service.
Questions or requests concerning personal information should be sent to:
Privacy Team
Medi Alarm 247 Limited
Unit 5
17 Cobham Road
Ferndown
Dorset
BH21 7PE
Email: hello@medialarm247.com
Telephone: 0800 688 9961
2. DATA-PROTECTION LAW
We process personal information in accordance with applicable UK data-protection and privacy legislation, including:
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- the Data (Use and Access) Act 2025; and
- the Privacy and Electronic Communications Regulations 2003, as amended.
In this policy, “personal information” means information relating to an identified or identifiable living person.
Certain information, including health information, is classed as special-category personal data and receives additional legal protection.
3. PEOPLE COVERED BY THIS POLICY
This policy may apply to:
- people enquiring about our products or services;
- Customers who purchase or pay for a Service;
- Users who wear or use alarm Equipment;
- relatives, carers or representatives acting for a User;
- nominated Emergency Contacts;
- keyholders;
- people who contact our customer-service team;
- website visitors;
- prospective Customers;
- former Customers;
- complainants;
- people who leave reviews or provide feedback; and
- other people whose information is provided in connection with an alarm account.
The person paying for the Service and the person using the Equipment may be different people. Where this occurs, we may hold separate information about the Customer and the User.
4. INFORMATION WE COLLECT
4.1 Identity and contact information
We may collect:
- title;
- full name;
- date of birth;
- postal address;
- service address;
- previous address where relevant;
- email address;
- landline number;
- mobile telephone number;
- preferred contact method;
- account number;
- customer reference;
- relationship to the User; and
- details of an authorised representative.
4.2 User profile and Service information
We may collect information needed to configure and provide the alarm Service, including:
- the User’s name and date of birth;
- the User’s home address;
- whether the User lives alone;
- communication needs;
- mobility information;
- relevant risks;
- support requirements;
- preferred response instructions;
- language requirements;
- access requirements;
- whether a carer or relative is involved;
- alarm-device details;
- device serial number;
- SIM or telecommunications identifiers;
- activation date;
- selected monitoring Plan; and
- test-call information.
4.3 Health, medical and vulnerability information
Where relevant to providing an appropriate alarm response, we may collect:
- medical conditions;
- disabilities;
- allergies;
- medication information;
- history or risk of falls;
- epilepsy or seizure information;
- dementia or cognitive-impairment information;
- communication difficulties;
- mobility limitations;
- sensory impairments;
- recent illness, injury or surgery;
- relevant mental or physical health information;
- vulnerability information;
- emergency-care instructions; and
- other information that may help an operator respond safely.
We will only request information that is relevant to providing the Service.
Our alarm devices and operators do not provide a medical diagnosis. Health information is used to support alarm monitoring and emergency response.
4.4 Emergency Contact and keyholder information
We may collect the following information about Emergency Contacts, carers and keyholders:
- name;
- relationship to the User;
- telephone number;
- email address;
- home or work address where relevant;
- availability;
- preferred contact order;
- whether the person holds a key;
- whether the person is willing to attend;
- communication history; and
- notes relevant to responding to an alert.
The Customer should obtain permission before giving us another person’s information.
Where appropriate, we may contact an Emergency Contact to confirm their details and explain how their information will be used.
4.5 Property-access information
Where relevant to emergency response, we may collect:
- key-safe location;
- key-safe access code;
- keyholder details;
- entry codes;
- property-access instructions;
- building-entry information;
- details about pets;
- hazards at the property; and
- other information needed to gain safe access.
Access information is treated as confidential and is only made available to authorised people where reasonably necessary.
4.6 Alarm-device and monitoring information
When an alarm device is active, we may collect:
- SOS activations;
- automatic fall alerts;
- cancelled or accidental alerts;
- the date and time of alerts;
- GPS location;
- mobile-network location;
- location history where the selected Service provides it;
- safety-zone or geofence events;
- device connection status;
- signal information;
- battery level;
- charging status;
- device faults;
- online and offline status;
- test-call records;
- Monitoring Centre notes;
- response action taken;
- Emergency Contacts contacted;
- emergency-services escalation;
- operator notes;
- alert outcome; and
- technical diagnostic information.
Depending on the device and selected Service, location information may be collected continuously, periodically, when requested through an authorised portal or when an alert is activated.
4.7 Call recordings and communications
We may record or retain:
- Monitoring Centre calls;
- inbound and outbound customer-service calls;
- sales and onboarding calls;
- telephone notes;
- voicemail messages;
- emails;
- SMS messages;
- WhatsApp messages;
- webchat messages;
- contact-form submissions;
- appointment records;
- complaint communications; and
- communications with Emergency Contacts or representatives.
Where calls are recorded, recordings may be used for:
- responding to incidents;
- confirming what was agreed;
- safeguarding;
- staff training;
- service-quality monitoring;
- complaint investigation;
- resolving disputes;
- fraud prevention;
- evidential purposes; and
- legal or regulatory compliance.
4.8 Payment and subscription information
We may collect:
- payer name;
- billing address;
- payment method;
- Direct Debit status;
- bank-account information provided through a payment provider;
- card-payment status;
- payment references;
- transaction dates;
- subscription Plan;
- amounts charged;
- payment frequency;
- failed-payment information;
- refunds;
- arrears;
- cancellation information; and
- relevant correspondence.
Full card details are normally collected and processed directly by an authorised payment provider and are not stored in full on our own systems.
4.9 Enquiry, marketing and CRM information
We may collect:
- enquiry source;
- products or services of interest;
- lead-form answers;
- appointment information;
- call status;
- communication preferences;
- marketing-consent records;
- opt-out records;
- sales and customer-service notes;
- previous communications;
- campaign information;
- advertisements clicked;
- pages viewed before submitting an enquiry;
- enquiry outcome;
- reason for not proceeding where voluntarily supplied; and
- information generated through our CRM workflows.
4.10 Website, cookie and technical information
When someone visits our website, we may collect:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location;
- referring website;
- pages visited;
- time spent on pages;
- buttons or links selected;
- website-session information;
- cookie identifiers;
- analytics identifiers;
- advertising identifiers;
- consent preferences; and
- error or security logs.
More information is provided in section 19 and our Cookie Policy.
4.11 Complaints, rights requests and legal information
We may collect:
- details of a complaint;
- information included in a data request;
- identity-verification information;
- correspondence with representatives;
- legal advice;
- dispute information;
- evidence;
- investigation notes;
- insurance information;
- information provided by a regulator; and
- information needed to establish, exercise or defend legal claims.
4.12 Reviews and feedback
Where a person chooses to provide a review, testimonial, survey response or other feedback, we may collect:
- name;
- rating;
- review text;
- image or video where supplied;
- customer status;
- survey answers; and
- permission to publish the feedback.
We will obtain appropriate permission before using an identifiable testimonial in advertising.
5. HOW WE COLLECT INFORMATION
We may collect personal information directly from you when you:
- visit our website;
- complete an enquiry form;
- submit a Meta lead form;
- telephone us;
- send an email, SMS or WhatsApp message;
- place an order;
- enter into a Service agreement;
- set up a payment arrangement;
- activate or test a device;
- use an alarm;
- speak to the Monitoring Centre;
- update Emergency Contact information;
- make a complaint;
- exercise a data-protection right; or
- provide feedback.
We may also receive information from:
- a family member;
- a carer;
- an attorney or deputy;
- an authorised representative;
- the person paying for the Service;
- an Emergency Contact;
- a keyholder;
- our Monitoring Centre;
- our alarm-device and location platform;
- a payment or Direct Debit provider;
- Meta lead forms;
- advertising and analytics providers;
- delivery and returns providers;
- a care organisation or business customer;
- emergency services;
- professional advisers;
- regulators; and
- publicly available sources where lawful and appropriate.
Where information is provided to us about another person, the person supplying it should make them aware of this Privacy Policy.
Where we obtain personal information from somebody other than the person it concerns, we will provide appropriate privacy information within the period required by law unless an exemption applies.
6. WHY WE USE PERSONAL INFORMATION
We use personal information to:
- respond to enquiries;
- recommend an appropriate alarm Service;
- provide quotations;
- arrange appointments;
- create and manage accounts;
- verify Customer and User details;
- deliver and activate Equipment;
- provide alarm monitoring;
- locate a User following an alert;
- assess and respond to an emergency;
- communicate with a User;
- contact Emergency Contacts;
- provide relevant information to emergency services;
- manage key-safe and property-access information;
- test and maintain Equipment;
- investigate device faults;
- provide technical support;
- process payments;
- manage Direct Debits;
- manage money-back guarantees and subscriptions;
- issue reminders and service notifications;
- manage cancellations, returns and refunds;
- identify dormant or disconnected devices;
- handle complaints;
- investigate incidents;
- respond to data-protection requests;
- prevent fraud and misuse;
- maintain system and information security;
- train staff;
- monitor service quality;
- comply with legal obligations;
- establish, exercise or defend legal claims;
- maintain appropriate business records;
- improve our products and services;
- measure website and advertising performance;
- provide relevant marketing where permitted; and
- suppress marketing to people who have opted out.
We will not use personal information for a purpose that is incompatible with the purpose for which it was collected unless permitted or required by law.
7. OUR LAWFUL BASES
UK data-protection law requires us to identify a lawful basis before processing personal information. The lawful basis depends on the purpose and circumstances.
7.1 Enquiries, quotations and pre-contract communications
We may rely on:
- steps requested before entering into a contract, where someone asks for information, a quotation or an appointment; and
- legitimate interests, including responding to genuine enquiries, managing prospective-customer relationships and operating our business effectively.
7.2 Creating and managing a customer account
We may rely on:
- contractual necessity, where processing is needed to enter into or perform our agreement with the Customer; and
- legitimate interests, where the User is different from the Customer or where processing is needed to administer the wider Service relationship.
7.3 Providing alarm monitoring and technical support
We may rely on:
- contractual necessity;
- legitimate interests, including operating a reliable and safe monitoring Service;
- vital interests, where processing is necessary to protect somebody’s life or physical safety; and
- legal obligation, where a specific legal requirement applies.
7.4 Emergency response
Where an alarm indicates a possible emergency, we may use and disclose relevant personal information on the basis of:
- vital interests;
- contractual necessity;
- legitimate interests, including protecting the User and enabling an appropriate response; and
- legal obligation, where applicable.
In an emergency, it may not be possible or appropriate to obtain consent before contacting Emergency Contacts or emergency services.
7.5 Payments, accounting and financial administration
We may rely on:
- contractual necessity;
- legal obligation, including tax and accounting requirements; and
- legitimate interests, including preventing fraud, managing debts and maintaining accurate financial records.
7.6 Service calls and call recordings
We may rely on:
- contractual necessity;
- legitimate interests, including quality assurance, training, incident investigation, fraud prevention and confirming what was agreed;
- legal obligation, where applicable; and
- vital interests for emergency monitoring calls.
7.7 Complaints, disputes and legal claims
We may rely on:
- legal obligation;
- legitimate interests, including investigating concerns and protecting our legal position; and
- processing necessary to establish, exercise or defend legal claims.
7.8 Security, misuse and fraud prevention
We may rely on:
- legitimate interests, including protecting Customers, Users, employees, systems and the Service; and
- legal obligation, where applicable.
7.9 Service-related communications
We may rely on:
- contractual necessity; and
- legitimate interests.
Service messages can include:
- alarm notifications;
- device-status warnings;
- test reminders;
- battery warnings;
- billing notices;
- guarantee period reminders;
- renewal information;
- safety communications;
- changes to the Service; and
- account-administration messages.
These are not marketing messages.
7.10 Marketing
For email, SMS and WhatsApp marketing, we normally rely on:
- consent; or
- another permission available under electronic-marketing law, where applicable.
For limited telephone or postal marketing, we may rely on:
- consent; or
- legitimate interests, where the contact is lawful, proportionate and reasonably expected.
We will respect applicable preference services and previous objections.
7.11 Cookies and advertising technology
We may rely on:
- consent for non-essential analytics, advertising and remarketing technologies; and
- legitimate interests or a permitted statutory exemption for essential or other qualifying low-risk technologies where the law allows.
8. SPECIAL-CATEGORY PERSONAL DATA
Health and medical information is special-category personal data.
Before processing this information, we must identify:
- a lawful basis under Article 6 of the UK GDPR; and
- an additional condition under Article 9.
Depending on the circumstances, we may rely on the following conditions.
8.1 Explicit consent
We will normally request the User’s explicit consent to collect and use relevant health, medical and vulnerability information for:
- configuring the alarm account;
- informing operators about relevant risks;
- assisting the Monitoring Centre;
- providing relevant information to Emergency Contacts; and
- supporting an appropriate emergency response.
Consent may be recorded in writing, electronically or through an appropriately documented verbal process.
A person may withdraw consent at any time.
However, where essential health information is removed, we may be unable to provide the same level of informed emergency response. In some cases, we may be unable to continue providing the Service safely.
8.2 Vital interests
In an emergency, we may process health information where this is necessary to protect life and the individual is physically or legally incapable of giving consent.
This may include providing relevant information to:
- the Monitoring Centre;
- ambulance services;
- police;
- fire and rescue services;
- Emergency Contacts;
- carers; or
- another person responding to the incident.
8.3 Legal claims
We may retain and use health information where necessary to establish, exercise or defend a legal claim.
8.4 Legal and safeguarding requirements
Where another condition is available under data-protection law, we may process special-category information to meet an applicable legal or safeguarding requirement.
We do not use health or medical information for advertising, audience targeting or unrelated marketing.
9. INFORMATION ABOUT EMERGENCY CONTACTS
A Customer or User may nominate another person as an Emergency Contact.
We may use an Emergency Contact’s information to:
- confirm that they are willing to act as a contact;
- add them to the User’s alarm profile;
- contact them following an alert;
- provide information needed for them to help the User;
- ask whether they can attend;
- confirm an incident outcome;
- update contact details;
- test emergency-response arrangements; and
- maintain appropriate records.
Our lawful basis will normally be our legitimate interests in operating the alarm Service and protecting the User.
In an emergency, we may also rely on vital interests.
Emergency Contacts may ask us to correct or remove their information. Removing an Emergency Contact will not affect information already recorded in an incident report where retention remains necessary.
The Customer or User must provide a replacement Emergency Contact where this is necessary for their selected response plan.
10. LOCATION INFORMATION
Location information is an important part of some alarm services.
Depending on the Equipment and Plan, we may process location information:
- when the User presses the SOS button;
- when automatic fall detection activates;
- when the Monitoring Centre requests a location;
- when an authorised family or carer portal requests a location;
- when a safety-zone event occurs;
- at periodic intervals needed to provide a connected-device function;
- during device testing;
- when investigating a fault; or
- where necessary to protect the User.
GPS information is not always exact and may be affected by:
- buildings;
- indoor use;
- satellite availability;
- network coverage;
- geographic conditions; and
- device status.
Location information will only be made available to:
- authorised staff;
- the Monitoring Centre;
- authorised portal users;
- Emergency Contacts where necessary;
- emergency services; and
- relevant technology providers acting on our behalf.
The Customer is responsible for ensuring that family or carer portal access is only provided to appropriate and authorised people.
11. WHO WE SHARE INFORMATION WITH
We only share personal information where there is a lawful reason and the disclosure is reasonably necessary.
Recipients may include the following.
11.1 Monitoring and emergency-response providers
We share relevant account, health, location, access and Emergency Contact information with our Monitoring Centre so that operators can respond to alerts.
11.2 Emergency services
We may provide information to:
- ambulance services;
- police;
- fire and rescue services;
- coastguard services; and
- other emergency responders.
Information shared may include:
- the User’s name;
- location;
- address;
- nature of the alert;
- medical information;
- access information;
- communication history; and
- relevant risk information.
11.3 Emergency Contacts, carers and authorised representatives
We may share information needed to explain an alert and enable an appropriate response.
11.4 Alarm-device and telecommunications providers
We may use technology suppliers to provide:
- mobile connectivity;
- SIM management;
- device platforms;
- GPS location;
- alert routing;
- equipment registration;
- remote configuration;
- firmware updates; and
- technical diagnostics.
11.5 CRM and communications providers
We use service providers to manage customer information and communications, including:
- GoHighLevel;
- Twilio;
- email providers;
- telephone providers;
- SMS providers;
- WhatsApp service providers; and
- workflow and automation services.
These providers may process communications and account information on our behalf.
11.6 Payment and Direct Debit providers
We may share payment and account information with:
- payment processors;
- card-acquiring services;
- Direct Debit facilities-management providers;
- banks;
- accounting providers;
- refund providers; and
- lawful debt-recovery providers.
11.7 Delivery and returns providers
We may share delivery details with:
- Royal Mail;
- courier companies;
- fulfilment providers;
- returns providers; and
- equipment suppliers.
11.8 Website, analytics and advertising providers
Subject to consent and applicable law, we may use:
- Meta;
- Google;
- website-hosting providers;
- analytics providers;
- cookie-consent providers; and
- advertising-measurement providers.
We do not provide health information, alarm-event information, emergency notes or key-safe information to advertising platforms.
11.9 Professional advisers and insurers
We may share information with:
- solicitors;
- accountants;
- auditors;
- insurers;
- insurance brokers;
- compliance advisers; and
- other professional advisers.
11.10 Regulators, authorities and courts
We may disclose information to:
- the Information Commissioner’s Office;
- law-enforcement agencies;
- courts;
- government bodies;
- tax authorities;
- Trading Standards;
- consumer-protection bodies; and
- another regulator or authority where legally required.
11.11 Business transfers
If our business, assets or Service are sold, transferred, merged or reorganised, relevant information may be disclosed to:
- prospective purchasers;
- advisers;
- funders; and
- the acquiring organisation.
We will take reasonable steps to protect personal information and ensure that continuing use remains consistent with applicable law.
12. SERVICE PROVIDERS AND CONTROLLERS
Some recipients process personal information solely on our instructions and act as our processors.
Other organisations may act as separate or joint controllers because they determine some of their own purposes and methods.
For example:
- emergency services act independently when deciding how to respond;
- banks and payment providers may have independent legal obligations;
- Meta and Google may act as controllers for some advertising and platform activities;
- WhatsApp and telecommunications providers may process certain information under their own terms; and
- professional advisers act under their own professional duties.
Where we appoint a processor, we require appropriate contractual and security protections.
A current list of key supplier categories can be requested by contacting hello@medialarm247.com.
We may withhold commercially sensitive or security-related information where appropriate, but will provide the information required by law.
13. INTERNATIONAL TRANSFERS
Some technology, communications, CRM, hosting and advertising providers may process personal information outside the United Kingdom.
Where personal information is transferred internationally, we will use a lawful transfer mechanism where required.
This may include:
- a UK adequacy regulation;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission’s Standard Contractual Clauses;
- another approved transfer safeguard; or
- a permitted legal exception.
Where appropriate, we will assess the laws and practices of the destination country and apply supplementary technical, contractual or organisational protections.
Further information about the safeguards used for a particular transfer may be requested from hello@medialarm247.com.
14. DATA RETENTION
We do not keep personal information for longer than reasonably necessary.
Retention depends on:
- the purpose for which the information was collected;
- whether the account remains active;
- legal and accounting requirements;
- the sensitivity of the information;
- the risk of harm from continued retention;
- limitation periods for legal claims;
- complaints or investigations;
- contractual requirements; and
- the retention capabilities of relevant systems.
Our normal retention periods are set out below.
14.1 Unsuccessful enquiries
Enquiry and CRM information will normally be retained for up to 12 months after the last meaningful interaction.
Information may be deleted earlier where:
- the person asks us to delete it;
- there is no continuing lawful purpose;
- consent is withdrawn; or
- the information is clearly no longer relevant.
14.2 Marketing-consent records
Consent records will be kept for as long as reasonably necessary to demonstrate that marketing was lawful.
Where a person opts out, we may retain limited suppression information for as long as necessary to ensure that we do not contact them again against their wishes.
14.3 Customer account and contract records
Core customer, order, contract, cancellation and account-administration records will normally be retained for the duration of the Service and for up to six years afterwards.
14.4 Financial records
Invoices, transactions, payment records and relevant accounting records will normally be retained for six years after the relevant accounting period or transaction, or longer where legally required.
14.5 Health and emergency-profile information
Current health, vulnerability, access and emergency-profile information will normally be retained for the duration of the active Service.
After the Service ends, operational copies will normally be deleted or de-identified within 90 days, unless:
- the information forms part of an incident record;
- there is an unresolved complaint;
- there is a safeguarding concern;
- a legal claim is anticipated or ongoing;
- continued retention is required by law; or
- another lawful reason applies.
14.6 Emergency Contact information
Emergency Contact and keyholder information will normally be retained for the duration of the active account and removed or de-identified within 90 days after the Service ends, subject to incident, complaint and legal-record requirements.
14.7 Alarm, location and device logs
Alarm-event, GPS, device-status and technical records will normally be retained for up to 12 months, unless a longer period is necessary for:
- incident investigation;
- safeguarding;
- a complaint;
- quality assurance;
- fraud prevention;
- a legal claim; or
- another documented operational or legal reason.
Some technical logs may be retained for a shorter period.
14.8 Call recordings
Call recordings will normally be retained for up to 12 months.
A relevant recording may be kept for longer where needed for:
- an incident investigation;
- a complaint;
- safeguarding;
- a legal claim;
- fraud prevention;
- insurance; or
- a regulatory matter.
14.9 Complaints and rights requests
Complaints, data-rights requests and related correspondence will normally be retained for up to six years after closure where necessary to demonstrate compliance or manage a potential claim.
Identity documents collected solely to verify a request will be deleted as soon as reasonably possible after verification, unless continuing retention is necessary.
14.10 Website and cookie information
Website and cookie information is retained according to the purpose and lifespan of the relevant cookie or technology.
Specific periods should be displayed in our Cookie Policy or cookie-preference centre.
When information is no longer required, we will securely delete, anonymise or otherwise place it beyond use.
15. DATA SECURITY
We use proportionate technical and organisational measures designed to protect personal information.
These may include:
- access controls;
- user authentication;
- password controls;
- encryption in transit and, where appropriate, at rest;
- secure hosting;
- role-based system permissions;
- audit logs;
- device and account-management controls;
- staff confidentiality requirements;
- data-protection training;
- supplier checks;
- processor agreements;
- system monitoring;
- incident-response procedures;
- backups;
- business-continuity arrangements; and
- periodic reviews of access and security.
Access to health, location, key-safe and alarm-event information is limited to people who reasonably require it for their work.
No internet-based or electronic system can be guaranteed to be completely secure. We continually review risks and update protections where appropriate.
16. PERSONAL-DATA BREACHES
A personal-data breach can include:
- loss of information;
- unauthorised access;
- accidental disclosure;
- alteration;
- destruction;
- ransomware;
- sending information to the wrong person; or
- loss of availability.
Where we become aware of a suspected breach, we will:
- investigate it;
- take steps to contain it;
- assess the likely consequences;
- document the incident;
- take remedial action;
- notify the Information Commissioner’s Office where legally required; and
- notify affected people where the breach is likely to create a high risk to their rights and freedoms.
Anyone who believes that Medi Alarm 247 information has been lost, disclosed or accessed improperly should contact us immediately at hello@medialarm247.com or 0800 688 9961.
17. AUTOMATION, AI AND PROFILING
We use CRM, scheduling and automation tools to help us:
- record enquiries;
- send appointment reminders;
- route messages;
- organise follow-up activity;
- identify whether an enquiry has been answered;
- allocate tasks;
- send service communications;
- record communication preferences;
- identify disconnected devices;
- prioritise urgent customer-service matters; and
- manage customer journeys.
We may also use automated conversational tools to:
- answer common questions;
- collect basic enquiry information;
- identify the product a person is interested in;
- arrange a call; and
- direct the person to human support.
A human-support option is available.
We do not currently use solely automated processing to make decisions that produce legal or similarly significant effects, such as automatically refusing a person a Service based solely on an algorithm.
An employee may review and change an automated categorisation or recommendation.
We do not use medical information to train public or third-party generative artificial- intelligence models.
We will update this policy and provide appropriate information before introducing significant automated decision-making that affects individuals.
18. MARKETING COMMUNICATIONS
We may send marketing about Medi Alarm 247 products or services where we have an appropriate legal basis.
Marketing may be sent by:
- email;
- SMS;
- WhatsApp;
- telephone;
- post; or
- online advertising.
Electronic marketing will normally only be sent where:
- the person has actively requested information;
- valid consent has been provided;
- an existing-customer permission applies; or
- another lawful permission is available.
Consent is optional and is not a condition of receiving emergency monitoring.
A person may opt out at any time by:
- replying STOP to an applicable SMS or WhatsApp message;
- using an unsubscribe link;
- emailing hello@medialarm247.com; or
- calling 0800 688 9961.
We will action marketing objections as soon as reasonably possible.
Opting out of marketing does not stop essential service messages.
We may retain limited information on a suppression list to ensure that the person’s objection continues to be respected.
We do not sell personal information or mobile-marketing consent to other businesses.
19. COOKIES, ANALYTICS AND ADVERTISING
Our website uses storage and access technologies, including cookies.
Cookies may be used for:
- essential website functions;
- security;
- remembering privacy choices;
- form functionality;
- website performance;
- analytics;
- advertising measurement;
- conversion tracking;
- remarketing; and
- displaying more relevant content.
Non-essential cookies will normally only be used after the visitor has provided consent through our cookie-control tool, except where a specific statutory exemption applies.
Visitors should be able to:
- accept non-essential cookies;
- reject non-essential cookies;
- select cookie categories; and
- change their preferences later.
Rejecting non-essential cookies should not prevent access to the main information on our website, although some optional functions may be affected.
We may use Meta and Google technologies to:
- measure advertising results;
- understand whether an advertisement led to an enquiry;
- create advertising audiences;
- exclude existing Customers from certain campaigns; and
- present relevant advertising.
We do not upload health information, alarm-event information, emergency notes or key-safe information to advertising platforms.
More detailed information about individual cookies, providers, purposes and durations should be provided in our Cookie Policy or cookie-preference centre.
20. SOCIAL MEDIA AND EXTERNAL WEBSITES
Our website and communications may contain links to:
- Facebook;
- Instagram;
- Google;
- WhatsApp;
- review websites; and
- other external services.
These organisations control how they use information collected through their own websites, applications and accounts.
This Privacy Policy does not replace the privacy policies of those organisations.
Information posted publicly on social media may be visible to other users. Customers should not publish medical, key-safe, payment or other sensitive information on a public social-media page.
21. CHILDREN AND VULNERABLE PEOPLE
Our consumer contracts must be entered into by an adult.
Where an alarm is used by a child, the Customer must be:
- the child’s parent;
- the child’s legal guardian; or
- another appropriately authorised adult or organisation.
We will process a child’s information only where necessary to provide the requested Service and with appropriate involvement from the responsible adult.
We recognise that many Users may be older, disabled, unwell or otherwise vulnerable.
We will take reasonable steps to:
- explain clearly how information is used;
- identify an appropriate representative;
- avoid collecting unnecessary information;
- protect health and location information;
- offer human assistance;
- respect the User’s rights and preferences; and
- involve an attorney, deputy, guardian or representative only where appropriate.
Vulnerability does not automatically mean that somebody lacks mental capacity.
Where a person lacks capacity, we will take reasonable steps to verify the authority of the person acting on their behalf.
Further information is available in our Vulnerable Customer and Reasonable Adjustments Policy.
22. IF YOU DO NOT PROVIDE INFORMATION
Some information is optional.
However, we need certain information to:
- identify the Customer and User;
- enter into the contract;
- take payment;
- configure the alarm;
- contact the User;
- locate the User;
- contact Emergency Contacts; and
- respond safely to an alert.
Where required information is not provided, we may be unable to:
- accept an order;
- activate the Service;
- provide a particular feature;
- give operators relevant information;
- contact the appropriate person; or
- continue providing the Service safely.
Marketing consent is not required to purchase or use the Service.
23. YOUR DATA-PROTECTION RIGHTS
Depending on the circumstances and lawful basis, you may have the following rights.
23.1 Right of access
You may request confirmation that we process your personal information and ask for a copy of that information.
23.2 Right to correction
You may ask us to correct incomplete or inaccurate information.
Customers should contact us promptly when contact, health, location or Emergency Contact information changes.
23.3 Right to erasure
You may ask us to delete personal information in certain circumstances.
This right is not absolute. We may retain information where it remains necessary for:
- a contract;
- legal compliance;
- a legal claim;
- a complaint;
- safeguarding;
- fraud prevention; or
- another lawful purpose.
23.4 Right to restrict processing
You may ask us to limit how information is used in certain circumstances.
23.5 Right to object
You may object to processing based on legitimate interests.
We will stop the processing unless we demonstrate compelling legitimate grounds or the information is needed for legal claims.
You have an absolute right to object to direct marketing at any time.
23.6 Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may be entitled to receive information you supplied in a structured, commonly used and machine- readable format.
23.7 Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal will not make earlier processing unlawful.
Withdrawal of consent for essential health information may affect our ability to provide an appropriately informed emergency response.
23.8 Rights relating to automated decisions
You may have rights concerning a decision based solely on automated processing that produces legal or similarly significant effects.
We do not currently use this type of solely automated decision-making for customer eligibility or emergency response.
23.9 Right to complain
You may complain directly to Medi Alarm 247 or to the Information Commissioner’s Office.
24. HOW TO EXERCISE YOUR RIGHTS
Requests may be made using the following details:
Email: hello@medialarm247.com
Telephone: 0800 688 9961
Post:
Privacy Team
Medi Alarm 247 Limited
Unit 5
17 Cobham Road
Ferndown
Dorset
BH21 7PE
Please provide enough information to help us:
- confirm your identity;
- locate the relevant account;
- understand your request; and
- identify the relevant period or communication.
We may request reasonable proof of identity where necessary to protect personal information.
We will not normally charge a fee.
A reasonable fee may be charged, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.
We will respond without undue delay and normally within one month.
Where a request is complex or multiple requests have been made, the response period may be extended where permitted by law. We will explain any extension.
A request can be made through an authorised representative.
We may ask for evidence of their authority and may verify the request directly with the individual.
25. DATA-PROTECTION COMPLAINTS
A person may complain if they believe we have:
- used information unfairly or unlawfully;
- failed to keep information secure;
- retained information for too long;
- failed to correct inaccurate information;
- sent unwanted marketing;
- failed to respond properly to a rights request;
- disclosed information to the wrong person; or
- otherwise failed to comply with data-protection law.
A complaint can be submitted using the following details:
Email: hello@medialarm247.com
Telephone: 0800 688 9961
Post:
Data Protection Complaint
Medi Alarm 247 Limited
Unit 5
17 Cobham Road
Ferndown
Dorset
BH21 7PE
The complaint should include:
- the complainant’s name;
- contact details;
- account or reference number where known;
- what happened;
- relevant dates;
- which information is affected; and
- the outcome being requested.
We will:
- provide a clear method of making a complaint;
- acknowledge the complaint within 30 days;
- investigate the issue to an appropriate extent;
- request additional information where reasonably necessary;
- keep the complainant informed where appropriate;
- communicate the outcome without undue delay; and
- explain any further action that can be taken.
26. COMPLAINTS TO THE INFORMATION COMMISSIONER
You also have the right to complain to the Information Commissioner’s Office.
The Information Commissioner is the UK regulator for data protection.
ICO helpline: 0303 123 1113
Further information is available through the Information Commissioner’s website.
We would appreciate the opportunity to investigate and resolve a concern first, but contacting us does not remove your right to complain to the Information Commissioner.
27. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect:
- changes in law;
- regulatory guidance;
- new products or services;
- changes to suppliers;
- new technology;
- changes to how information is collected; or
- changes to our business.
The latest version will be displayed on our website with its updated date.
Where a change materially affects how we use existing personal information, we will take reasonable steps to bring it to the attention of affected people before the new use begins.
Previous versions may be requested from hello@medialarm247.com.
28. CONTACT US
Questions, concerns and requests concerning personal information should be sent to:
Privacy Team
Medi Alarm 247 Limited
Unit 5
17 Cobham Road
Ferndown
Dorset
BH21 7PE
Telephone: 0800 688 9961
Email: hello@medialarm247.com