Social media
Contact information
Address

Sunrise House, Post Office Lane, Beaconsfield,Buckinghamshire, HP9 1FN

Email

customercare@gracewell.co.uk

Telephone

01494 739 080

Website

www.gracewell.co.uk

Privacy Policy

INTRODUCTION

Sunrise Senior Living Ltd and Gracewell Healthcare Ltd (collectively, “Sunrise”) provide quality private residential and assisted living services including access to nursing, respite and dementia care.

This notice describes how Sunrise collects, uses and manages the information it holds about you, including how the information may be shared and how the confidentiality of personal information is maintained.

The “At a Glance” section contains some very important information that will help explain what information we process and why.

AT A GLANCE

When do we collect personal data about you?

When we refer to personal data in this notice, we mean information that can or has the potential to identify you as an individual. 

We will collect and process personal data about you at the following stages:

  1. Stage

    Description

    Enquiry

    When you enquire about a potential vacancy by visiting one of our websites, speaking to us over the telephone or visiting us at one of our residential homes

    Application

    When you submit an application for consideration and an assessment of your suitability is undertaken

    Contract

    When you have successfully passed the vetting and on boarding process and have signed a contract of employment 



What personal data may we collect from you and why?

Enquiry
We will largely rely on our ‘legitimate interests’ to process your personal data with the exception of those areas marked with an (*) below where we will require your ‘consent’.

Data Category 

Reason for Processing

Personal Identifiers

Contact Details

Personal Information

To communicate with you regarding your initial enquiry

*Personal Identifiers

*Contact Details

Personal Information

To retain your personal information and to contact you regarding future career opportunities

Personal Identifiers

Contact Details

Internal record keeping and administration

 

Application

We will largely rely on our ‘legitimate interests’ to process your personal data with the exception of those items marked with an (#) below where we will rely on ‘compliance with a legal obligation’ and items marked with a (*) below where we will require your ‘consent’

Data Category 

Reason for Processing

Personal Identifiers

Contact Details

To communicate with you regarding your application for employment

Personal Identifiers

Contact Details

Personal Information

To assess your suitability (skills, strengths, behaviours for the role)

*Personal Identifiers

*Contact Details

*Third Party Information

To verify the information that you have provided, in particular relating to your previous work history, education and professional qualifications

#Personal Identifiers

#Contact Details

Personal Information

Special Category Information

To undertake activities needed to complete the on-boarding and screening process should your application be successful


Contract

We will largely rely on ‘contractual necessity’ to process your personal data with the exception of those areas marked with an (#) below where we will rely on ‘legal obligation’ 

Data Category 

Reason for Processing

Personal Identifiers

Contact Details

General management of personnel and work activities inc. appraisals, performance management, managing disciplinary matters, grievances and terminations, planning and monitoring of training requirements and career development activities and creating and maintaining one or more internal employee directories etc

Personal Identifiers

Contact Details

Personal Information

Financial Information

Employment Information

Special Category Information

Third Party Information

To carry out our obligations and benefits to you arising from any contract inc. payroll processing, healthcare, pensions, loans, business expenses and reimbursements etc

Personal Identifiers

Contact Details

Personal Information

Financial Information

Special Category Data

Third Party Information

Other Information

For internal audit and accounting purposes together with the preparation and review of management information

#Personal Identifiers

#Contact Details

To comply with legal and other requirements, such as income tax and national insurance deductions, record-keeping and reporting obligations, physical access policies, conducting audits, management and resolution of health and safety matters, such as accident and insurance claims, compliance with government inspections and other requests from government or other public authorities, responding to legal process such as subpoenas, pursuing legal rights and remedies, defending litigation and managing any internal complaints or claims, conducting investigations and complying with internal policies and procedures

 

For further details of the data types contained within each category please refer to the Annex of Personal Data Types which can be found in section 1.10

 Your decision to provide any personal data described above to us is voluntary.  In addition, we will only contact third party referees if you give consent for us to do so.  If you chose not to provide any of the personal data requested, or do not consent to us contacting third party referees regarding your application, our ability to consider you as a candidate may be limited. 

If you are offered a position at Sunrise, you will be required to complete an application form for the Disclosure and Barring Service, and to provide a copy of any certificate conferred by the Disclosure and Barring Service to us.  If you fail to provide a satisfactory certificate issued by the Disclosure and Barring Service to us, this may lead to rejection of your application for employment or immediate termination of your employment if it has already commenced.

 

FURTHER DETAILED INFORMATION 

Data sharing and transfers

In the usual course of business Sunrise may disclose your personal data (to the extent necessary) to (i) its affiliates and certain third-party processors Sunrise has retained to perform services on its behalf and pursuant to its instructions, and the operating companies.  This may include the following:

  • Sunrise Senior Living, LLC (U.S.) and Sunrise Senior Living Management, Inc for the provision and delivery of services, IT application support, internal audit reviews and investigations, quality assurance, program monitoring, management reporting and other internal purposes
  • Operating companies for internal audit, reviews, management information and reporting.  Full details of the operating companies can be found in the glossary.
  • business partners, suppliers and sub-contractors for the provision of the contracted services,
  • organisations providing IT systems support and hosting in relation to the IT systems on which your information is stored
  • third party service providers who perform services on our behalf based on our instructions, for instance, for the purposes of storage of information and confidential destruction.  We do not authorise these service providers to use or disclose the information except as necessary to perform services on our behalf or comply with applicable legal obligations.
Where a third-party data processor is used, we ensure that they operate under contractual restrictions with regard to confidentiality and security, in addition to their obligations under Data Protection Laws.

Sunrise may also disclose your personal data (ii) if it is required to do so by law or legal process, or (iii) in response to lawful requests from public authorities, including to meet national security, public interest or law enforcement requirements.  Sunrise also reserves the right to transfer Personal Data in the event of an audit or if the company sells or transfers all or a portion of its business or assets (including in the event of a merger, acquisition, joint venture, reorganization, dissolution or liquidation).

Third Country Data Transfer

Due to the global nature of our operations, we may transfer the personal data we collect about you to recipients in countries other than the country in which the information originally was collected.  For example, we may disclose your personal data to Sunrise Senior Living, LLC and Sunrise Senior Living Management, Inc in the U.S. Access to your personal data will be limited to individuals who have a need to know the information for the purposes described in this Notice, and may include personnel in the HR, IT, compliance, legal, finance, accounting and internal audit, marketing and risk management functions.

Where we transfer your personal data to a country which may not have the same data protection laws as the country in which you initially provided the information (such as the U.S.), we will protect that information as described in this Privacy Notice and will comply with applicable legal requirements providing adequate protection for the transfer of personal information to recipients in countries other than the one in which you provided the information. Your information will also be transferred to our third-party service providers in the U.S. We have implemented appropriate safeguards to ensure an adequate level of data protection, including by concluding data transfer agreements incorporating the European Commission’s Standard Contractual Clauses under Article 46 of the EU General Data Protection Regulation (GDPR). You may contact the Data Protection Officer as indicated below to obtain further information on the transfer mechanism. 

How we protect your personal data

We maintain appropriate technical and organisational measures designed to protect your personal data against loss or accidental, unlawful or unauthorised, alteration, access, disclosure or use.
We retain personal information for as long as we reasonably require it for legal and business purposes. In determining data retention periods, Sunrise also takes into consideration local laws, relevant regulations and contractual obligations.

At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:

  •   Right of access – you have the right to request a copy of the information that we hold about you.  Sunrise reserves the right to charge a reasonable fee based on our administration costs where further copies are requested.
  •   Right of rectification – you have the right to correct data that we hold about you that is inaccurate or incomplete.
  •   Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
  •   Right to restriction of processing – where certain conditions apply you have the right to request that we restrict the processing.
  •   Right of portability – in certain circumstances you have the right to have the data we hold about you transferred to another organisation.
  •   Right to object – you have the right to object to certain types of processing such as direct marketing.
  •   Right to object to automated processing and profiling
All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.
If you would like to exercise any of your data subject rights, please contact us using one of the methods highlighted below.

Please contact us if you have any questions about our privacy notice or information we hold about you:
  • By email at dpo@sunriseseniorliving.uk.com
  • By writing to us at Data Protection Officer, Sunrise House, Post Office Lane, Beaconsfield, Buckinghamshire HP9 1FN
Complaints
In the event that you wish to make a complaint about how your personal data is being processed by us (or third parties as described in 1.3 & 1.4 above) please contact the data protection officer at the address detailed above. 

If you are not satisfied with how your complaint has been handled you have the right to lodge a complaint directly with the supervisory authority at the Information Commissioner's Office (ICO) Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Tel 0303 123 1113 or 01625 5457

Personal data types & items

Data Type

Data Items

Personal Identifiers

National Insurance Number

NHS Number

Online Identifiers (IP Address)

Passport Number

Contact Information

Name

Address

Email

Telephone

Room Number

Community Name

Personal Information

Date of Birth

Gender

Marital Status

Photograph

Nationality

Financial Information

Bank Details

Employment Loan Details

Life Assurance Details

Pension Details

PMI Details

Tax Details

Employment Information

Absence Details

Employment Details (Current)

Employment Details (Historic)

Maternity Details

Performance Details

Qualification Details

Reference Details

Remuneration Details

Special Category Information

Ethnic Origin

Health Information

Race

Religion

Third Party Information

Children’s Details

Dependent Details

Guarantor Details

NOK Details

Reference Details

Spouse Details


Use of cookies
You can read more about our use of cookies on our Cookies page

In certain circumstances, we are required to obtain your consent to the processing of your personal data in relation to certain activities.

Article 4 of the GDPR states that (opt-in) consent is "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." In plain language, this means that:
  • you have to give us your consent freely;
  • you have to know what you are consenting to;
  • you should have choice over which processing activities you consent to and which you don’t; and
  • you need to take positive and affirmative action in giving us your consent

We will keep records of the consents that we have received from you. 

You have the right to withdraw your consent to these activities. You can do so at any time, and details of how to do so can be found in section 1.8

Contractual necessity

Article 6 of the GDPR states that we can process your data on the basis that such processing is necessary in order to enter into or perform a contract with you. 

The "contractual performance" lawful basis permits the processing of personal data in two different scenarios:

  • Situations in which processing is necessary for the performance of a contract to which you, the data subject, is a party. This may include, for example, processing your health details for the provision of residential care. 
  • Situations that take place prior to entering into a contract such as pre-contractual relations. For example, a formal review of the health confirmation collected during the care package assessment to determine the level of care required and the associated residential costs.

From the point at which contract negotiations commence and throughout your stay with us we will rely on contractual necessity as the lawful basis for the majority of personal data processing activities.

Compliance with legal obligations

Article 6 of the GDPR states that we can process your data on the basis that the we have a legal obligation to perform such processing.  Processing is permitted if it is necessary for compliance with a legal obligation.

Legitimate Interests

Article 6 of the GDPR states that we can process your data where it is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights or freedoms of you which require protection of personal data. 

Operating Companies

Sunrise UK Operations Ltd

Sunrise of Frognal

Sunrise of Virginia Water

Sunrise of Elstree

Sunrise of Banstead

Sunrise of Purley

Sunrise of Bassett

Sunrise of Beaconsfield

Sunrise of Chorleywood

Sunrise of Eastbourne

Sunrise of Edgbaston

Sunrise of Fleet

Sunrise of Guildford

Sunrise of Mobberley

Sunrise of Solihull

Sunrise of Sonning

Sunrise of Southbourne

Sunrise of Tettenhall

Sunrise of Hale Barns

Sunrise Operations Bramhall II Ltd

Sunrise of  Bramhall

Sunrise Operations Cardiff Ltd

Sunrise of  Cardiff

Sunrise Operations Esher Ltd

Sunrise of  Esher

Sunrise Operations Westbourne Ltd

Sunrise of  Westbourne

Sunrise Operations Weybridge Ltd

Sunrise of  Weybridge

Sunrise Operations Bagshot II Ltd

Sunrise of  Bagshot

Sunrise Operations Winchester Ltd

Sunrise of  Winchester

Sunrise UK Holdco

 

 

Gracewell Healthcare 4 Ltd

Holding company for Shelbourne Senior Living

Gracewell Healthcare 3 Ltd

Gracewell of Church Crookham

Gracewell of Edgbaston

Gracewell of Newbury

Gracewell of Adderbury

Gracewell of Sutton

Gracewell of Suuton Coldfield

Gracewell of Bath

Gracewell of Bookham

Gracewell of High Wycombe

Gracewell of Woking

Gracewell Healthcare 2 Ltd

Gracewell of Camberly

Hamilton Court

Gracewell Healthcare 1 Ltd

Gracwell of Fareham

Gracwell of Frome

Gracewell of Horley Park

Gracewell of Salisbury

Gracewell of Weymouth

Shelbourne Senior Living

Gracewell of Sway

Gracewell Newmarket Ltd

Gracewell of Kentford

Maids Moreton Operations Ltd

Gracewell of Maids Moreton

Bayfield Court Operations Ltd

Gracewell of Chingford