This site uses cookies, by using this site you accept our cookie policy.

Whittington Health NHSUCL

Privacy policy

Welcome to the HeLP-Diabetes website (the "Website").

The Website is owned and controlled by University College London , UCL Research Department of Primary Care & Population Health, Upper 3rd Floor, Royal Free Hospital, Rowland Hill Street, London NW3 2PF ("UCL"), who is data controller in respect of all personal information collected from users of the Website (if any) for the purposes of the Data Protection Act 1998.

The terms "we", "us" and "our" when used in this Privacy policy are references to HeLP-Diabetes. The terms "you", "your" and "yours", when used in this Privacy Policy, mean any user of this Website.

UCL is committed to protecting your privacy online. Please read the following Privacy Policy (which forms part of the Terms and Conditions) to understand how we will treat your personal information. Our separate Cookies policy details about the "cookies" that are used on our site.

1. Your Consent

This Privacy Policy sets out how we use the information that we may obtain from or about you via the Website. On or before registration to use the Website, you will be asked to provide certain personal details, such as your name and email address, for the purposes of the registration process. By registering to use the Website, you agree to this use of your personal details.

In the course of using our Website, you may volunteer sensitive personal data to us, for example, when using the HeLP-Diabetes: Starting Out Pathway. You consent to our use of your sensitive personal data in accordance with the terms of this Privacy Policy.

If at any time you wish to withdraw your consent or unsubscribe from the Website, you can contact us either via the Website or using the contact details in paragraph 11. If you have agreed to take part in research carried out through the Website, anonymised data from your account may be retained.

2. What personal information do we collect?

If you choose to register to use the Website we will collect the following types of personal data about you:

  • name;
  • email address;
  • Postcode
  • Date of birth;
  • Gender;
  • Highest educational qualification;
  • Email;
  • GP Practice

After registration to use the website, you can choose to use the website to record the following sensitive personal data:

  • Ethnic Group;
  • Whether you need to take medicine to control your diabetes;
  • blood glucose levels;
  • blood pressure readings;
  • blood test and other results;
  • a list of your medication;
  • your care plan;
  • medical appointments; and
  • any other sensitive personal data which you may choose to upload and store on the Website.

You do not have to upload sensitive personal data to the Website. If you do so, the data is treated as confidential medical information (see paragraph 4) and will be handled strictly in accordance with the terms of this Privacy Policy.

3. How do we use your personal information?

The data you upload to the Website can be used by you to view historical records and see trends over time so you can understand your condition better and improve your health. It can also be used to set personal reminders that you can turn on or off through the Website. Data which you upload is not shared with any medical professionals and it is your confidential personal record. Your GP, nurse or any other medical professional will not have access to this information unless you give them a copy.

We may use the information that you provide or that is collected by us (provided that is not part of your confidential personal record or GP medical record) in the following ways:

    1. to contact you with Website news and updates;
    2. to keep you informed of our activities and the services provided by us using any of the following methods:
      1. e-mail;
      2. telephone (including automated calls);
      3. SMS text messages and other electronic messages, such as picture messaging;
      4. post; and/or
      5. fax


  1. to allow us to understand who has visited which pages, to determine how frequently particular pages are visited and to determine the most popular areas of our Website.

We may also collect information from our Website by using cookies (see below).

Any personal data we collect or which you provide will be used by us in accordance with this Privacy Policy and current data protection legislation. We may store the information we collect from you and hold it in our computer database or otherwise. All data is held and processed in the UK.

4. Our obligations

We fully comply with all relevant data protection laws, including the Data Protection Act 1998, and protect the security of your information with Secure Sockets Layer (SSL) encryption. We maintain electronic and procedural safeguards in the protection of the personal information that we store. All confidential data and all personal data provided to us as a result of this Website will be handled in accordance with our strict standards of confidentiality. Our legal and professional obligations are guided by the following:

The Caldicott Principles;
Data Protection Act 1998;
Human Rights Act 1998;
Common Law duty of Confidentiality;
NHS Operating Framework 2011/12; and
The NHS Confidentiality Code of Practice.

5. Your obligations

You must take all reasonable precautions to keep your information safe and prevent fraudulent use of your account and protect your confidential information. Your obligations include but are not limited to:

  • never writing down or otherwise recording your security details in a way that can be understood by someone else;
  • not choosing security details that may be easy to guess;
  • taking care to ensure that no one hears or sees your security details when you log in;
  • keep your security details unique to the Website;
  • not disclosing your security details to anyone, including us;
  • changing your security details immediately and telling us as soon as possible if you know or suspect that someone else knows your security details;
  • once you have logged in to HeLP-Diabetes do not leave your device unattended or let anyone else use your device;
  • logging out of HeLP-Diabetes when you have finished using the Website;
  • installing and maintaining appropriate security software on any personal computing devices used to access HeLP-Diabetes; and
  • keeping operating systems and browsers on personal computing devices up to date.

In the event that a failure by you to comply with any of the foregoing obligations leads to a breach of security, we cannot be held accountable for the loss of any personal data, confidential information or otherwise.

6. What are "cookies" and how do we use them?

Similar to other websites, our Website uses a technology called "cookies" and web server logs to collect information about how our Website is used. Data about Website usage may be collected anonymously on an aggregate level and used for Website improvement purposes or health research purposes. Personal data will not be used for research purposes without your explicit consent. For details about how we use cookies, please see our Cookies policy.

7. What information do parties other than HeLP-Diabetes collect?

Some websites that have links from our Website from time to time may collect personal information about you when you access or utilise those links. We do not control the collection or use of such information, and this Privacy Policy does not cover the practices of those websites.

8. With whom do we share your information and for what purpose?

We will only pass on your information to third parties in the following situations:

  1. If we choose to share aggregate anonymised information with business contacts and partners;
  2. Where legally permitted or required;
  3. Where disclosure is made with your consent.

9. General

You have the right to see the personal data (as defined in the Data Protection Act 1998) that we keep about you (if any), on receipt of a written request, verification of your identity, and payment of a fee of £10. If you are concerned that any information we hold on you is incorrect please contact us via the details in paragraph 11 below.

10. Changes to our Privacy Policy

We may modify our Privacy Policy from time to time. If we do so, you will be asked to give your consent to the revised terms. In order to do so, we may contact you through the Website or by way of email or text and we will post a revised version of this Privacy Policy on this webpage.

11. Contact us

If you have queries you can write to us at:

UCL Research Department of Primary Care & Population Health
Upper 3rd Floor, Royal Free Hospital, Rowland Hill Street
London NW3 2PF

© Copyright HeLP-Diabetes - all rights reserved. Reproduction of this Website, in whole or in part, in any form or medium without express written permission from HeLP-Diabetes is prohibited.