Legal
Data Protection Statement
Preventra's public commitments for personal and health information used in programmes
Effective date: 10 August 2026
Organisation: Preventra (SMC-Private) Limited, registered in Pakistan
Contact: info@preventra.co.uk
1. Our commitment
Preventra designs and delivers preventive health, screening, patient navigation and managed care programmes. These activities may involve personal information and, where approved, health information. We treat that information as confidential and use it only for defined, lawful and documented programme purposes.
2. Our role
Preventra's legal role depends on the programme. We may act as a data controller for information we determine how and why to use, or as a data processor or service provider acting on documented instructions from an employer, pharmaceutical organisation, insurer, public institution or other client. The applicable agreement and participant notice will define responsibilities for each programme.
3. Purpose limitation and product neutrality
We collect and use only the information needed to register participants, assess agreed risk factors, deliver screening, provide follow-up, support navigation, manage cases, handle safety escalation, communicate with consent, evaluate programme performance and meet legal or contractual duties.
Where a programme is sponsored by a pharmaceutical or commercial organisation, clinical screening and navigation must follow an approved, product-neutral pathway. Rewards, eligibility and support must not depend on diagnosis, treatment selection, prescription, referral acceptance or purchase of a product.
4. Lawful and fair processing
We provide clear information before or when data is collected. Where consent is the appropriate basis, consent must be informed, specific and capable of withdrawal. We do not use consent to remove rights that apply under law or contract. Health information is processed only under an additional lawful condition and approved programme governance.
5. Data minimisation and quality
Programme forms, questionnaires and reports are limited to approved fields. We take reasonable steps to keep information accurate, relevant and up to date. Optional information is identified where practical. We do not collect information merely because it may be useful later.
6. Access and confidentiality
Access is limited according to job responsibility and programme need. Personnel and approved partners are subject to confidentiality duties and appropriate training. Access rights are reviewed and removed when no longer required.
7. Security
We apply proportionate technical, physical and organisational controls. These may include secure transmission, access controls, authentication, role-based permissions, audit records, managed devices, secure backups, supplier controls, confidentiality requirements and incident response procedures. Safeguards are reviewed according to the sensitivity and scale of each programme.
8. Sharing and service providers
Information is shared only with authorised recipients for an approved purpose. Identifiable information is not disclosed to an employer, sponsor or other client unless the programme documents, law and participant information clearly allow it. Clients receive de-identified participant information and aggregated reporting by default where identifiable data is not required.
Service providers and delivery partners must be assessed, contractually restricted and given only the information needed for their task. We do not sell participant information.
9. Clinical records and communications
Health measurements do not by themselves constitute a diagnosis. Clinical decisions and escalation remain with appropriately qualified healthcare professionals acting within the approved scope. Participant communications use approved channels and content. Contact frequency and channel reflect consent, participant preference, risk and programme rules.
10. Children and vulnerable participants
Programmes involving children or vulnerable people require additional safeguards, appropriate consent or authorisation, age-appropriate information, restricted access, safeguarding procedures and approved escalation routes.
11. Retention and disposal
Each programme uses an approved retention schedule based on purpose, client instructions, legal requirements, clinical needs and dispute periods. Information is securely deleted, anonymised or returned when the retention period ends, subject to lawful exceptions. Rented physical records or equipment are handled under the applicable agreement and secure return process.
12. International transfers
If information is stored or accessed outside the country of collection, Preventra applies appropriate contractual, technical and organisational safeguards and follows applicable transfer requirements.
13. Individual rights
Participants may request access, correction, deletion, restriction, objection, consent withdrawal or another right available under applicable law. Some requests may be referred to the client where the client controls the information. We explain any lawful limitation and do not disadvantage a person for making a privacy request.
14. Incidents
Suspected loss, misuse or unauthorised access is escalated promptly under Preventra's incident response process. We contain and assess the incident, preserve relevant evidence, take corrective action and notify the responsible client, affected individual or authority where required.
15. Automated decisions and public reporting
Preventra does not make solely automated decisions that produce legal or similarly significant effects unless specifically authorised, lawfully governed and clearly explained. Public leaderboards or recognition require separate optional consent, use an approved display name or unique identifier, and remove the public listing following withdrawal. Health, weight, BMI, risk, referral and treatment information must never appear publicly.
16. Governance and contact
Programmes are governed through approved scope, documented roles, data fields, access rules, retention, reporting, supplier controls and escalation procedures. Questions, concerns or rights requests may be sent to info@preventra.co.uk or to Preventra (SMC-Private) Limited, Office No. 301, 3rd Floor, Plot No. 8-C, Lane No.1, Ittehad Commercial, Phase-VI, DHA, Karachi.