Data Controller
Nobel Medical LLC ("Nobel Medical", "we", "us", "our") is the data controller for personal data processed through the nobelmedical.co.uk website and associated platforms, including MedicalCert.co.uk.
Registered address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
ICO Registration Number: ZC112101 — verifiable on the ICO register.
What Data We Collect
We may collect and process the following types of personal data:
- Identity data: name, date of birth, gender
- Contact data: email address, phone number, postal address
- Health data: medical history, symptoms, supporting evidence submitted as part of a consultation (special category data under UK GDPR)
- Transaction data: payment details (processed by third-party payment providers — we do not store full card details)
- Technical data: IP address, browser type, device information, cookies
- Usage data: how you use our website and services
How We Use Your Data
We use personal data for the following purposes:
- To facilitate independent clinical assessment by GMC-registered doctors
- To deliver medical certificates and letters as requested
- To process payments and manage refunds
- To communicate with you about your request or account
- To comply with legal obligations and professional regulatory requirements
- To improve our services and website functionality
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: processing necessary to fulfil a service you have requested
- Legitimate interests: improving our services, fraud prevention, operational management
- Legal obligation: complying with regulatory, tax, and legal requirements
- Explicit consent: for processing health data (special category data) — you provide this when submitting a medical consultation
Data Sharing
We may share personal data with:
- Independent GMC-registered doctors for clinical review
- Payment processors for transaction handling
- IT and hosting providers for platform operation
- Professional advisers (legal, accounting) where necessary
- Regulatory bodies or law enforcement where required by law
We do not sell personal data to third parties. We do not share medical data for marketing purposes.
Data Retention
Personal and medical data is retained for as long as necessary to fulfil the purpose for which it was collected, and in accordance with professional regulatory requirements for medical records. When data is no longer required, it is securely deleted or anonymised.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, or damage. These include encryption, access controls, and secure hosting infrastructure.
Your Data, Your Rights
Under UK GDPR you have full control over your personal data. You can request access, correction, deletion, or portability at any time — and we'll respond promptly.
Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal and regulatory retention requirements)
- Object to processing based on legitimate interests
- Request restriction of processing
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, contact us at support@nobelmedical.co.uk.
Cookies
Our websites use cookies and similar technologies for functionality, analytics, and improving user experience. You can manage cookie preferences through your browser settings. For more details, see the cookie consent tools available on our websites.
International Transfers
As Nobel Medical LLC is registered in the United States, some data processing may occur outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available on this page.
Last updated: May 2025