RF Healthcare Ltd

Privacy Policy

Last reviewed: September 2026

RF Healthcare Ltd is committed to protecting your privacy and handling personal information lawfully, fairly and transparently.

1. Website discovery and requirements

When a person starts a Website Discovery, we collect their contact and organisation details and send a private, time-limited link so the questionnaire can be saved and resumed. Discovery responses may cover business goals, audiences, the current website and suppliers, requested pages and functions, brand information, integrations, accessibility, security, data-handling needs, timescale, budget range and approval arrangements.

Supporting files such as logos, brand guidelines, example content or page lists may be uploaded where useful. Uploads undergo the same file-type, content-signature and configured malware-scanning controls used for secure project documents. Users are told not to upload passwords, access codes or unnecessary personal information.

RF Healthcare uses this information to clarify needs, prepare and approve a structured requirements document, develop scope and pricing, create a draft Xero quote where instructed, and convert approved work into a My RF project. Discovery activity and administrative review decisions are recorded for audit and delivery continuity.

2. Community website giveaway

When an authorised representative enters the RF Healthcare community website giveaway, we collect the organisation name and type, area served, contact name and email address, and any optional telephone number, charity number, existing website or background information they choose to provide. We also record the confirmations required to administer the entry and whether separate optional marketing consent was given.

We use giveaway information to receive and de-duplicate entries, check eligibility, administer the random draw, keep an audit of the selected winner and contact the organisation about the giveaway. Optional background information is not used to judge or weight the random selection. Giveaway administration does not require the entrant to agree to marketing.

If an entrant separately gives marketing consent, RF Healthcare may use the contact details for occasional relevant updates until that consent is withdrawn. Giveaway records are retained only for as long as reasonably needed to administer the campaign, evidence how the draw was conducted and deal with any resulting website work or queries.

3. Who we are

RF Healthcare Ltd provides healthcare consultancy, training, IT and digital support, and related professional services across the UK. We are the controller for personal information collected through this website and our direct business relationships where we determine how and why that information is used.

4. Information we collect

  • Contact, organisation and role details provided through enquiries, quotations, training bookings and IT-service orders
  • Purchaser and attendee details used to manage course places, registers, joining information and certification
  • IT order details including the package selected, configuration options, customer notes, delivery status and subscription information
  • My RF client-portal information including account invitations, activation and sign-in records, linked orders, projects, service status, project milestones, client-visible updates and actions, secure project documents, Xero billing links and support requests raised through the portal
  • Project and service-delivery records, including agreed scope, progress, target dates, milestones, client actions and appropriate internal delivery notes needed to manage an engagement
  • Secure document records including file versions, document categories, access settings, review comments and replies, approval or change-request decisions, client uploads, review deadlines, payment-release conditions and document access audit events
  • Commercial records displayed from Xero, including linked customer/contact identifiers, quote and invoice identifiers, values, VAT, dates, status, amount paid and amount outstanding, together with quote acceptance or decline decisions submitted through My RF
  • Booking, payment and refund records, including transaction references and payment status. We do not receive or store full card details
  • Billing-address information handled by Stripe as part of checkout where required
  • Information provided when applying to work with us as an associate trainer or consultant, including qualifications, professional experience, location and availability
  • Where relevant to onboarding or deployment, evidence relating to identity, right to work, employment history, references, DBS status, professional registration, qualifications, training, insurance, contracts, declarations and fitness or occupational-health requirements
  • For Workforce external checks, professional-registration identifiers and, where a DBS Update Service check is required, DBS certificate identifiers, certificate surname, date of birth, certificate level and workforce, together with records showing consent, original-certificate sighting, identity checking and legal entitlement to perform the status check
  • Associate portal account information such as invitation, activation and sign-in records used to secure and administer self-service access
  • Correspondence, project records and information required to deliver an agreed consultancy, training, IT or digital service
  • Technical, account, domain, hosting or configuration information supplied by a client where it is necessary to deliver agreed IT or digital work
  • Limited technical information collected through essential website functions and, where consent is provided, analytics or similar non-essential technologies

5. How we use information

  • To respond to enquiries and provide quotations
  • To create and manage training bookings, take payment, process refunds, issue joining information and support certification
  • To create and manage IT-service orders, monthly subscriptions, onboarding and delivery progress
  • To provide My RF client self-service access to projects, milestones, client actions, secure documents, Xero quotes and invoices, orders, service status, subscription billing links and support requests
  • To present Xero quote and invoice information to the correct authenticated client, record quote acceptance or decline decisions and direct clients to Xero's official online invoice experience
  • To exchange controlled project files, request evidence, manage document versions, conduct client reviews, respond to review comments and record approval or change-request decisions
  • To release a protected document where an administrator has linked its release to a Xero invoice and Xero reports that invoice as paid
  • To plan, record and communicate delivery progress for consultancy, IT, digital and other agreed client work
  • To maintain accounting, tax and financial records
  • To assess trainer and consultant applications, complete appropriate safer-recruitment and compliance checks, manage associate onboarding and determine deployment readiness
  • To make lawful status enquiries to professional regulators or public-authority services such as the HCPC and DBS Update Service, record the outcome of the check and maintain an auditable check history
  • To provide secure associate self-service access for profile updates, evidence submission and assignment information
  • To maintain evidence that required checks were completed and remain in date
  • To deliver consultancy, training, IT, website, hosting and related services
  • To configure, maintain or support client systems where this forms part of an agreed IT or digital engagement
  • To meet legal, regulatory, accounting and safeguarding obligations
  • To improve our services and website
  • To communicate relevant service information where permitted

6. Payments, subscriptions, accounting and email

Card payments and online IT subscriptions are handled through Stripe. RF Healthcare receives transaction references, payment status, subscription identifiers and other information needed to link a payment, renewal or refund to the relevant booking or IT order, but does not receive or store full card numbers or security codes.

Where a My RF account is linked to a Stripe customer record, the client portal may provide a secure hand-off to Stripe's hosted billing portal for Stripe-managed subscriptions and payment methods without RF Healthcare receiving card credentials.

RF Healthcare uses Xero as an accounting system and may link a My RF account to the corresponding Xero contact. My RF may then retrieve and display that client's Xero quotes, invoices, due dates, payment status and outstanding balances. If a client accepts or declines a Xero quote through My RF, the decision is sent to Xero and an RF Healthcare audit record is retained. When a client opens an invoice from My RF, the portal uses Xero's official online invoice link, where the payment methods RF Healthcare has enabled in Xero, such as bank transfer or Direct Debit through a connected provider, may be available.

Booking and IT-order payment information may also be transferred to Xero for accounting and reconciliation. Transactional emails such as booking confirmations, IT-order confirmations, refund notices, joining information, project updates, client actions, secure-document review notifications and portal messages are delivered through our email service provider. These providers process information only for the relevant service and under their own security and data-protection obligations.

7. Tender Alerts

If you subscribe to RF Healthcare Tender Alerts, we process the email address you provide and, where supplied, your name, together with subscription, consent, unsubscribe and delivery records needed to operate the service.

We use this information to send the Tender Alerts you requested. The lawful basis for these alert emails is consent. You can withdraw that consent at any time using the unsubscribe link included in every Tender Alert email.

After you unsubscribe, we stop sending alerts. We retain only the minimum suppression and audit information reasonably needed to respect your choice and demonstrate how the subscription was managed. Tender Alert email delivery is handled through Resend as our email service provider.

8. IT, website and hosting engagements

Some IT or digital projects may require temporary or ongoing access to client systems, domains, hosting platforms, user accounts or technical configuration. We only request access reasonably needed for the agreed work and expect clients to avoid sending passwords or other credentials through insecure channels.

Where RF Healthcare processes personal information solely on a client's documented instructions while delivering hosting, website or IT support, the respective controller and processor responsibilities may be set out in the relevant quotation, agreement or data-processing terms.

9. Our lawful bases

Depending on the activity, we process information because it is necessary to take steps before or perform a contract, because we have a legal obligation, because it supports our legitimate business interests, or because you have provided consent. We assess the appropriate basis for each activity rather than relying on consent where another lawful basis applies.

10. Cookies and consented analytics

Essential cookies support secure sign-in, booking, payment and other functions that cannot operate without them. Optional analytics are activated only when a visitor chooses Accept all in the cookie banner.

Our website analytics records aggregate daily counts for a small set of journey events, such as viewing training, selecting a course date, reaching a payment step or opening an IT checkout. The analytics table does not store visitor names, email addresses, IP addresses, device identifiers, user-agent strings or session identifiers. Aggregate counts are retained for up to 400 days. Choosing Essential only prevents these optional events from being recorded.

11. Special-category and criminal-offence information

Some associate roles may require information that receives additional protection under data-protection law, for example occupational-health information or evidence connected with DBS checks. We only request this where it is relevant and proportionate to the role, and only process it where an appropriate UK GDPR and Data Protection Act 2018 condition applies.

When RF Healthcare uses the DBS Update Service, we record the certificate identifiers and identity information required to make the lawful status enquiry, the prerequisite attestations and the status-check outcome. The Workforce integration does not import or store the underlying criminal-record, conviction, offence or barring content from a DBS certificate.

12. Associate applications and onboarding

If you apply to work with RF Healthcare, we use the information you provide to assess suitability for associate work, contact you about your application and, if approved, support onboarding and future work allocation. Depending on the work, we may ask for evidence needed to verify identity, right to work, references, qualifications, professional registration, DBS status, insurance, training or other deployment requirements. Application and compliance information is accessible only to people who need it for recruitment, onboarding, compliance or operational management. Approval into our associate pool does not guarantee work.

Where a role requires an external status check, authorised RF Healthcare users may query an appropriate regulator or public-authority service using the minimum information needed for that check. DBS Update Service checks are only made after RF has recorded the individual's consent, checked identity, seen the original certificate in person and confirmed legal entitlement to the relevant certificate level and workforce.

Approved or invited associates may be given access to a secure self-service portal. Information submitted through the portal remains subject to RF Healthcare review and does not itself mean a compliance check has been verified or that the associate is cleared for deployment.

Evidence documents uploaded to our onboarding system are held within our secured application environment and are not made publicly accessible. Access is restricted to the associate concerned and authorised RF Healthcare administration users with the relevant permissions.

13. Client portal, projects, documents and support

Eligible customers may be invited to a My RF account whether their work was purchased online or agreed directly with RF Healthcare. We use the account to show information connected with that customer's projects, orders and service delivery, including progress, milestones, client-visible updates and actions, Xero commercial records where linked, available Stripe subscription-management functions where applicable, secure project documents, and support requests. Client-portal access is authenticated and information is linked to the relevant customer account.

Secure project documents may include multiple file versions, review comments and replies, client uploads, deadlines and review decisions. RF Healthcare may restrict a document to authenticated viewing or review rather than allowing download. Restricted review copies may be individually watermarked with account or user information and access may be logged to support confidentiality, document control and audit requirements. Where RF Healthcare configures an invoice-based release condition, the document may remain protected until Xero reports the linked invoice as paid.

RF Healthcare may keep internal project-delivery notes that are not displayed in My RF where these are reasonably required to coordinate or document the agreed service. Access to those notes is restricted to authorised RF Healthcare administration users.

Support requests, project updates, document comments, client actions and uploaded files should not contain passwords, recovery codes or other secret credentials unless RF Healthcare has explicitly agreed an appropriate secure method for that information.

14. Who we share information with

We share information only where necessary and proportionate. Recipients may include payment and accounting providers such as Stripe and Xero, connected payment providers used through Xero, transactional-email, cloud, domain, hosting and website infrastructure providers, professional advisers, awarding or certification bodies, clients where deployment information is legitimately required, professional regulators and public authorities used for lawful status checks, and regulators or public authorities where we have another lawful reason to disclose it.

Where a service provider processes personal information outside the UK, we expect an appropriate lawful transfer mechanism and contractual safeguards to be in place.

15. Retention

We keep personal information only for as long as it is needed for the purpose for which it was collected and for any legal, contractual, safeguarding, insurance, tax or regulatory requirement. Retention is based on the type of record and the reason it is held. For example, financial, quotation, booking, IT-order, project-delivery and controlled document-review records may need to be kept for contractual, evidential or statutory periods, while application and compliance evidence is reviewed when an application is unsuccessful, an associate becomes inactive or the relevant deployment requirement ends. External-check identifiers and prerequisite records are reviewed when the underlying deployment requirement ends; the minimum check-history information reasonably required to show that RF performed a lawful compliance check may be retained for an appropriate evidential period. Information that is no longer reasonably required is deleted or securely disposed of.

16. Security

We use access controls, authenticated administration, associate and client portals, non-public access to secure client documents, controlled download permissions, document versioning and review audit records, encrypted storage for uploaded compliance evidence, encrypted storage for sensitive Workforce external-check inputs, encrypted storage of sensitive integration credentials, and other proportionate technical and organisational safeguards. Sensitive Workforce identifiers are masked when displayed back to authorised users and are not written to application logs. Restricted client-document viewers may use individual watermarking, rasterised review copies and no-cache controls as additional deterrents to unauthorised redistribution. No online system can be guaranteed completely secure, and we review controls as the service develops.

17. Your rights

  • Ask for access to your personal information
  • Ask us to correct inaccurate information
  • Ask for deletion or restriction where applicable
  • Object to certain processing
  • Ask for information about how your data is used or shared
  • Withdraw consent where processing relies on consent
  • Raise a concern with the Information Commissioner's Office

18. Contact

For privacy questions or to exercise your rights, email info@rfhealthcare.co.uk or write to RF Healthcare Ltd, Office 1, Izabella House, 24–26 Regent Place, Birmingham, B1 3NJ.