Protecting your health data is central to everything we do at CPEP. This page summarises how we safeguard your information in line with UK GDPR and data protection law.
Our commitments
- End-to-end encryption for data in transit
- Secure, access-controlled storage for health information
- GDPR-compliant processing and governance
- We never sell your data to third parties
Lawful basis for processing
We process personal and health data where necessary to deliver our services, with your consent where required, and to meet legal and regulatory obligations.
Access controls
Only authorised clinical and operational staff with a legitimate need can access your health information. Access is logged and reviewed.
Data hosting
Your data is stored on secure infrastructure with appropriate technical and organisational safeguards.
Your rights
You have the right to request access to your data, ask for corrections, object to certain processing, and request erasure where applicable. Contact [email protected] to make a request.
Last updated: 7 July 2026