Skip to main content
Privacy Notice | Nexus Ambulance Group Ltd

Privacy Notice

Nexus Ambulance Group Ltd • Registered in Scotland No. SC866185
Registered Office: 37h Thistle Industrial Estate, Cowdenbeath, KY4 8LP, Scotland
Last Updated: 14 September 2026

Compliant with UK GDPR • Data Protection Act 2018 • NHS Standards

1. Who We Are

Data Controller Information

Nexus Ambulance Group Ltd is a wholly owned subsidiary of Nexus Networks Group Ltd. We provide event medical cover, private patient transport, urgent care response, and clinical support services throughout Scotland.

We are committed to protecting your privacy and safeguarding your personal and clinical information. This Privacy Notice explains how we collect, use, store, share, and protect your data. It applies to all patients, service users, enquirers, website visitors, contractors, and authorised visitors to our premises.

Our processing practices comply fully with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Common Law Duty of Confidentiality, and NHS Scotland confidentiality and information governance standards.

2. What Information We Collect

We collect and process the following categories of personal information:

  • Personal Identifiers: name, date of birth, address, telephone number, email address, and NHS number where provided.
  • Special Category Data (Health Information): medical history, clinical records, treatment details, and any information relating to your physical or mental health. This information is afforded the highest level of protection under Article 9 UK GDPR.
  • Administrative Data: booking and service request details, invoices, payment records, correspondence, and visitor registration records.
  • Technical Data: IP address, device characteristics, and website usage analytics — collected through cookies and server logs.
  • Site Access Data: visitor identification records, sign-in logs, and communications — collected when entering our premises.

3. How We Collect Your Information

We gather information:

  • Directly from you — when making an enquiry, booking a service, contacting us, or providing information in the course of receiving care.
  • From authorised third parties — such as event organisers, care providers, or commissioners — where you have given consent or where law expressly permits such disclosure.
  • Automatically — through our website, secure contact forms, and electronic communications systems.

4. Why We Use Your Information — Lawful Basis of Processing

We only process your information when a lawful basis applies. The table below sets out our purposes and the legal foundations upon which we rely:

Purpose of Processing Lawful Basis Under UK GDPR
To deliver clinical and ambulance services to you Performance of a contract / provision of health care — vital interests
To manage bookings, schedules, and operational safety Performance of a contract / legitimate interests
To maintain clinical records and ensure continuity of care Substantial public interest / compliance with legal obligations
To communicate with you regarding your care or enquiry Consent / performance of a contract
To comply with laws, regulations, and professional standards Compliance with legal obligations
To investigate incidents, improve safety, and enhance services Legitimate interests — where balanced against your rights

Special Protection for Health Information

Health information is classified as Special Category Data under Article 9 UK GDPR. We process this information only where necessary for medical purposes, carried out under the supervision of a health professional or person bound by an equivalent duty of confidentiality, or with your explicit consent. All clinical information is held in strict confidence in accordance with NHS Scotland information governance guidelines.

5. Who We May Share Information With

We will never sell, rent, or lease your personal information to third parties for commercial purposes. We may share your data only when necessary, proportionate, and lawfully permitted — specifically with:

  • Healthcare professionals directly involved in your care — with your consent or where law permits.
  • Event organisers, commissioners, or contracting authorities — limited to the minimum information required for service administration.
  • NHS Scotland bodies, Police Scotland, or public authorities — where we are legally required or authorised to disclose information.
  • Nexus Networks Group Ltd (our parent organisation) — for governance, insurance, compliance, and administrative purposes, subject to strict data-sharing agreements.
  • Regulators or legal authorities — solely to fulfil statutory obligations.

6. Data Storage & Security

Your personal and clinical information is stored securely within the United Kingdom. We do not transfer personal data outside the UK without your explicit consent, unless required by law.

All data is protected using industry-standard measures including encryption, access controls, secure network architecture, and regular security audits. Access to personal and clinical information is restricted to authorised personnel only, each bound by strict confidentiality obligations.

7. How Long We Retain Information

We retain your data only for as long as necessary to fulfil the purpose for which it was collected. Retention periods follow NHS Scotland and Scottish Government record-keeping standards:

  • Clinical and patient records: retained in accordance with NHS Scotland retention schedules — typically for the duration of care plus up to 25 years, or as otherwise required by law.
  • Administrative, booking, and financial records: retained for 7 years following completion of service or contract.
  • Website enquiries and general correspondence: retained while needed to respond and maintain the relationship, then securely deleted.
  • Visitor registers and site access logs: retained for 12 months, then securely disposed of.

8. Your Rights Under Data Protection Law

Under the UK GDPR and the Data Protection Act 2018, you hold the following rights:

  • Right of Access — request a copy of the personal information we hold about you.
  • Right to Rectification — ask us to correct any information that is inaccurate or incomplete.
  • Right to Erasure — request deletion of your information where no compelling legal reason exists for us to retain it.
  • Right to Restriction of Processing — ask us to limit how we use your information.
  • Right to Data Portability — request transfer of your data to another provider, where processing is based on consent or contract.
  • Right to Object — object to processing based on legitimate interests.
  • Right to Withdraw Consent — where processing is based on consent, you may withdraw it at any time. This does not affect lawfully processed data prior to withdrawal.

How to Exercise Your Rights

To request access to your personal information or to exercise any of your rights, please contact our Data Protection Lead using the details provided below. You will normally receive a full response within one calendar month. We may need to verify your identity before releasing information to ensure privacy and security.

9. Website Cookies & Analytics

Our website uses essential cookies to ensure proper functionality. We do not use profiling, advertising, or third-party tracking cookies. You may manage cookie preferences through your browser settings at any time.

10. Complaints & Concerns

If you are dissatisfied with how we have handled your personal information, please raise it with our Data Protection Lead in the first instance. You also retain the right to lodge a complaint directly with the Information Commissioner’s Office (ICO) — the UK’s independent data protection regulator.

ICO Helpline: 0303 123 1113
Website: ico.org.uk

11. Contact & Data Protection Enquiries

For all privacy-related matters, including Subject Access Requests, consent withdrawals, or data protection queries, please contact our Data Protection Lead via our parent organisation: