Data Privacy Notice


Introduction

Scotia Medical Group ("we," "us," "our") is committed to protecting your privacy and ensuring the security of your personal data. This privacy notice explains how we collect, use, store, and

protect your information in compliance with the General Data Protection Regulation (GDPR) and other relevant data protection laws.


Who We Are

Scotia Medical Group is a charity registered in Scotland with OSCR. Our primary mission is to save lives through first aid training, and pre-positioning trained first aid volunteers at events. Our

registered address is 7 Braco Place, Elgin, IV30 4PQ.


What Information We Collect

We may collect and process the following types of personal data:

 Name, address, and contact details (phone number, email address)

 Date of birth and emergency contact details

 Medical information (if required for volunteering purposes)

 Training records and qualifications

 Financial details (for payments and donations)

 Website usage data (such as cookies and analytics)


How We Use Your Information

We process personal data for the following purposes:

 Managing volunteer applications and event deployment

 Delivering first aid training and maintaining training records

 Communicating with you about our activities, events, and services

 Ensuring the safety and wellbeing of volunteers and service users

 Complying with legal and regulatory obligations

 Processing donations and financial transactions


Legal Basis for Processing

Under GDPR, we process personal data based on one or more of the following legal bases:

 Your consent (where required, e.g., marketing communications)

 Performance of a contract (e.g., volunteer agreements, training enrolment, event cover)

 Legal obligations (e.g., health and safety or financial record-keeping)

 Legitimate interests (e.g., ensuring operational efficiency and volunteer safety)


How We Store and Protect Your Data

We implement appropriate technical and organisational measures to secure personal data and prevent unauthorised access, loss, or misuse. Data is stored securely in electronic and physical formats with access restricted to authorised personnel only. We regularly review and update access arrangements.


Data Sharing and Third Parties

We do not sell or rent personal data. However, we may share it with:

 Event organisers and relevant authorities (for safety and compliance purposes)

 Training certification bodies (to issue qualifications)

 IT service providers (to support our systems and operations)

 Legal and regulatory bodies (when required by law)


Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this notice and in accordance with legal and regulatory requirements. Training records, for example, may

be kept for a specified period for certification validation.


Your Rights

Under GDPR, you have the following rights:

 The right to access, correct, or delete your personal data

 The right to restrict or object to processing

 The right to data portability

 The right to withdraw consent (where processing is based on consent)

 The right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data correctly


Cookies and Website Data

Our website may use cookies to improve user experience. You can manage cookie preferences through your browser settings.


Contact Us

If you have any questions about this privacy notice or wish to exercise your rights, please contact us at: contactus@scotiamedicalgroup.org.uk.


This privacy notice may be updated periodically to reflect changes in legal or operational requirements. Please review it regularly for updates.