Braemar medical
Privacy Policy
BRAEMAR MEDICAL LIMITED
PRIVACY NOTICE
Last updated: 2 September 2026
Braemar Medical Limited (“Braemar Medical”, “we”, “us” or “our”) is committed to protecting the privacy and security of the personal information we process.
We are a healthcare recruitment agency supplying qualified healthcare professionals, including GPs and nurses, to primary care organisations and other healthcare clients.
This Privacy Notice explains how we collect, use, store and share personal information, the legal bases we rely on, how we protect information and the rights individuals have under UK data protection law.
For the purposes of applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Braemar Medical Limited is generally the data controller for the personal information described in this notice.
1. Who we are
Braemar Medical Limited
32 Braemar Road
Worcester Park
KT4 8SW
United Kingdom
Email: info@braemarmedical.co.uk
Telephone: 020 3907 8570
Website: braemarmedical.co.uk
If you have any questions about how we use your personal information, please contact us using the details above.
2. What information do we collect?
The information we collect depends on your relationship with Braemar Medical and the services we provide.
Candidates and healthcare professionals
If you register with us or apply for a position or placement, we may collect:
- name and title;
- address and contact details;
- date of birth where necessary;
- CV and employment history;
- qualifications and professional experience;
- GMC, NMC or other relevant professional registration information;
- professional references;
- right-to-work information;
- identity verification information;
- availability and placement preferences;
- information relating to bookings and placements;
- communication records;
- training and compliance information;
- DBS information where required for a role;
- information relating to health or fitness to work where necessary and lawful; and
- other information reasonably required to assess suitability for healthcare work.
We will seek to collect only information that is relevant and necessary for the recruitment, compliance and placement process.
Clients and their representatives
For GP practices, primary care organisations and other clients, we may collect:
- name;
- job title;
- business email address;
- business telephone number;
- organisation details;
- placement requirements;
- contractual information;
- correspondence and communication records; and
- information relating to bookings and services.
Workers and contractors
Where you work through Braemar Medical, we may also process:
- timesheets;
- booking and placement information;
- payment and bank details;
- tax and payroll information; and
- records required for contractual, accounting or legal purposes.
Website users
When you use our website, we may collect information such as:
- IP address;
- browser and device information;
- pages visited;
- information submitted through contact or enquiry forms;
- technical and usage information; and
- cookie and similar technology information.
Where website analytics are enabled, information about your use of our website may also be collected through Google Analytics as described in Section 13.
3. Special category and criminal offence information
Some information processed by a healthcare recruitment agency requires additional protection.
Special category data
Special category data includes information concerning health and certain other sensitive categories of personal information.
Depending on the circumstances, Braemar Medical may process special category information, for example:
- health or occupational health information where necessary for a placement or compliance requirement;
- information relating to disability or reasonable adjustments; and
- other special category information where it is necessary and lawful to process it.
We may also process criminal offence information, for example where DBS or other legally permitted checks are required for a healthcare role.
Special category and criminal offence information will only be processed where we have an appropriate lawful basis and, where required, an additional condition under data protection law.
We take additional care with this information and restrict access to authorised individuals who need it for legitimate business or compliance purposes.
We do not collect special category information simply because it is available. We aim to collect only information that is necessary and proportionate for the relevant purpose.
4. How do we use personal information?
We may use personal information for the following purposes.
Recruitment
To:
- register candidates;
- assess qualifications and experience;
- identify suitable vacancies and placements;
- communicate with candidates;
- arrange interviews or discussions; and
- maintain recruitment records.
Compliance and credentialing
To:
- verify professional registration;
- verify qualifications and experience;
- obtain and check references;
- undertake right-to-work checks;
- undertake DBS or other appropriate checks where required;
- confirm suitability for healthcare placements; and
- meet contractual, regulatory or legal requirements.
Placement management
To:
- introduce healthcare professionals to clients;
- arrange placements and bookings;
- communicate with GP practices and primary care organisations;
- manage availability;
- manage shifts and assignments; and
- resolve queries relating to placements.
Financial and administrative purposes
To:
- process payments;
- process invoices and timesheets;
- maintain accounting records;
- communicate with accountants or payroll providers where applicable; and
- comply with tax and other legal obligations.
Client management
To:
- manage client relationships;
- understand staffing requirements;
- arrange healthcare professional placements;
- manage contracts; and
- communicate regarding services.
Security and legal compliance
To:
- protect our systems and information;
- investigate suspected misuse or security incidents;
- prevent fraud or unlawful activity;
- comply with legal obligations; and
- establish, exercise or defend legal claims.
Marketing
Where permitted by law, we may use contact information to communicate information about our recruitment services or opportunities.
We will comply with applicable electronic marketing and privacy rules, including the Privacy and Electronic Communications Regulations (PECR).
5. What lawful bases do we rely on?
We do not rely on consent for every type of processing.
Depending on the circumstances, our lawful bases under the UK GDPR may include:
Contract
We may process information where it is necessary to enter into or perform a contract or to take steps at an individual’s request before entering into a contract.
Legal obligation
We may process information where necessary to comply with a legal obligation, for example certain employment, tax, accounting, safeguarding or regulatory requirements.
Legitimate interests
We may process information where necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by the individual’s rights and interests.
Examples may include:
- operating our recruitment business;
- managing client relationships;
- maintaining appropriate business records;
- preventing fraud; and
- maintaining information security.
Where we rely on legitimate interests, we will consider whether the processing is necessary and proportionate and whether the individual’s interests and rights are adequately protected.
Consent
Where consent is the appropriate lawful basis, we will ask for consent in a clear and specific manner.
This includes, where applicable, consent for non-essential cookies and website analytics.
We will keep an appropriate record of consent where we rely on it.
Individuals may withdraw consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn. It also does not affect processing that is lawfully carried out under another legal basis.
We do not use consent as a substitute for another lawful basis where another lawful basis is more appropriate.
6. Additional conditions for special category information
Where we process special category information, we will identify both:
- an appropriate lawful basis under Article 6 UK GDPR; and
- an appropriate condition under Article 9 UK GDPR.
Where criminal offence information is processed, we will also comply with the additional requirements applicable under Article 10 UK GDPR and the Data Protection Act 2018.
We will document the relevant conditions where required.
7. Information obtained from other sources
We may obtain information from sources other than the individual where this is necessary and lawful.
These sources may include:
- referees;
- professional registration organisations such as the GMC or NMC;
- qualification or training providers;
- DBS or other authorised checking services;
- previous employers;
- organisations involved in right-to-work or identity verification;
- healthcare clients; and
- authorised service providers.
Where we obtain personal information from another source, we will provide the required privacy information unless an applicable legal exception applies.
Recruitment organisations should take particular care where information is obtained from sources other than the candidate, and we will seek to handle such information lawfully and fairly.
8. Who do we share information with?
We only share personal information where there is a legitimate and lawful reason to do so.
Depending on the circumstances, information may be shared with:
- GP practices;
- primary care networks;
- NHS or other healthcare organisations;
- healthcare clients requiring staffing services;
- referees;
- professional registration or verification bodies;
- DBS or other appropriate checking providers;
- payroll providers;
- accountants;
- banks/payment providers;
- IT and software service providers;
- professional advisers;
- insurers;
- regulators or public authorities where required; and
- law enforcement agencies where legally required.
For example, information about a GP or nurse may need to be shared with a healthcare client where this is necessary to assess or arrange a placement.
We will not share more information than is reasonably necessary for the relevant purpose.
Where we use third-party service providers to process personal information on our behalf, we will seek to ensure that appropriate contractual and data protection arrangements are in place.
9. Our main systems and service providers
Braemar Medical uses business systems to manage recruitment, communications and financial administration.
These include:
Firefish CRM
We use Firefish as our recruitment CRM. Candidate, worker, client and placement information may be stored and processed within the system.
We will maintain appropriate contractual and data protection arrangements with the supplier and review its security and data processing arrangements as appropriate.
Microsoft 365
We use Microsoft 365 for business email, documents and other business functions.
Personal information may therefore be contained within emails, documents, spreadsheets, calendars and other Microsoft 365 services.
We apply appropriate access and security controls to our Microsoft 365 environment.
Xero
We use Xero for accounting and financial administration.
Financial and payment information may therefore be processed through Xero where necessary for accounting, invoicing and payment purposes.
We will maintain appropriate contractual and data protection arrangements with relevant suppliers.
Google Analytics
We use Google Analytics to understand how visitors use our website and to help us monitor website performance and improve our online services.
Google Analytics is subject to the cookie and consent arrangements described in Section 13.
We will review the services we use and maintain appropriate information governance arrangements in relation to relevant suppliers.
10. How do we protect personal information?
We take appropriate technical and organisational measures to protect personal information against:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- inappropriate disclosure; and
- other unlawful or unauthorised processing.
Our measures may include:
- access controls;
- user permissions based on job responsibilities;
- strong passwords;
- multi-factor authentication where available and enabled;
- secure cloud services;
- device security;
- secure handling of email and documents;
- staff confidentiality obligations;
- staff data protection awareness and training;
- secure disposal of information;
- backup and recovery arrangements; and
- incident and data breach procedures.
Because sensitive information requires greater protection, we apply additional care when handling special category and criminal offence information.
11. How long do we keep information?
We retain personal information only for as long as necessary for the purposes for which it was collected, unless we are required or permitted by law to retain it for longer.
Retention periods depend on the type of information and the reason for processing.
For example, different retention requirements may apply to:
- candidate records;
- successful worker records;
- DBS and compliance information;
- placement records;
- financial and accounting records;
- contractual records; and
- marketing information.
Braemar Medical maintains an internal Data Retention Schedule setting out the appropriate retention periods for different categories of information.
When information is no longer required, we will securely delete it, anonymise it where appropriate, or securely archive it where a legal or business requirement requires continued retention.
12. International transfers
Some of our technology and service providers may process information outside the United Kingdom.
Where personal information is transferred outside the UK, we will ensure that the transfer is made in accordance with applicable UK data protection requirements and that appropriate safeguards are in place where required.
This may include using an applicable adequacy regulation, appropriate contractual safeguards or another lawful transfer mechanism.
Details of relevant international transfers and safeguards will be maintained as part of our information governance records.
13. Cookies and website analytics
Our website uses cookies and similar technologies.
Cookies are small files or similar technologies that may be placed on your device when you visit a website. They can help websites operate, remain secure, remember preferences and understand how visitors use them.
We use cookies and similar technologies for purposes including:
- essential website functionality;
- security;
- performance;
- analytics; and
- understanding how visitors use our website.
Google Analytics
We use Google Analytics, a web analytics service provided by Google, to help us understand how visitors use our website.
Google Analytics may collect information relating to website visits and usage, which may include information such as:
- pages visited;
- how visitors arrived at our website;
- browser and device information;
- approximate location information;
- information about interactions with the website; and
- technical information relating to website usage.
We use Google Analytics to understand website traffic and usage, monitor website performance, identify areas for improvement and improve the experience we provide to website visitors.
Google Analytics uses cookies and similar technologies to collect analytics information.
Where consent is required for analytics cookies or similar technologies, we will obtain that consent before using them for those purposes.
Cookie consent and managing your preferences
When you first visit our website, our cookie consent mechanism allows you to manage your preferences for non-essential cookies and similar technologies.
You can use the cookie consent mechanism to accept or refuse non-essential cookies where the relevant options are provided.
You may also be able to control or delete cookies through your browser settings. Blocking or deleting cookies may affect how some websites function.
Where we rely on consent for analytics or other non-essential cookies, you may withdraw your consent through our cookie consent mechanism.
You can also use the controls and opt-out mechanisms made available by Google in relation to Google Analytics.
Further information about Google Analytics and Google’s privacy practices is available through Google’s own privacy resources.
Third-party services
Our website may use third-party services such as Google Analytics and website hosting or other technical service providers.
These providers may process information in accordance with their own terms and privacy information and, where applicable, on our behalf.
We will keep the cookies and tracking technologies actually used on our website under review and will update our cookie information and this Privacy Notice where necessary.
14. Your data protection rights
Under applicable UK data protection law, you may have rights including:
- the right to be informed about how your information is used;
- the right to request access to your personal information;
- the right to request correction of inaccurate information;
- the right to request deletion in certain circumstances;
- the right to request restriction of processing in certain circumstances;
- the right to object to certain processing;
- the right to data portability in applicable circumstances;
- rights relating to automated decision-making and profiling where applicable; and
- the right to withdraw consent where we rely on consent.
These rights are subject to certain legal exceptions and limitations.
15. How to exercise your rights
To exercise your rights, please contact:
Braemar Medical Limited
Email: info@braemarmedical.co.uk
You may also write to us at:
Braemar Medical Limited
32 Braemar Road
Worcester Park
KT4 8SW
United Kingdom
We may need to verify your identity before dealing with your request.
We will respond to requests within the timescales required by applicable data protection law.
16. Data breaches
We maintain procedures for identifying, managing and responding to personal data breaches.
If you believe that your personal information has been lost, disclosed incorrectly or accessed without authorisation, please contact us immediately at:
We will assess the incident and take appropriate action in accordance with our Data Breach Procedure.
Where required by law, we will notify the Information Commissioner’s Office (ICO) and/or affected individuals.
17. Data protection complaints
If you have concerns about how we have handled your personal information, please contact us first so that we have the opportunity to investigate and resolve your concern.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office (ICO)
Website: ico.org.uk
The ICO is the UK’s independent regulator for data protection and information rights.
18. Children
Our recruitment services are intended for adults.
We do not knowingly recruit or provide healthcare placements to individuals under 18 through our normal recruitment services.
If we become aware that we have collected personal information from a child where this was not appropriate, we will take reasonable steps to address the situation.
19. Automated decision-making and profiling
Braemar Medical does not currently make decisions about candidates using solely automated decision-making that produces legal or similarly significant effects.
Where technology is used to assist recruitment activities, appropriate human oversight will be maintained.
If this changes, we will review our data protection obligations and update this Privacy Notice where required.
20. Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect:
- changes to our services;
- changes to our systems or suppliers;
- changes in how we process personal information;
- changes in applicable law or regulatory guidance; and
- improvements to our information governance arrangements.
The latest version will be published on our website with the date it was last updated.
We recommend checking this page periodically.
21. Contact us
If you have any questions about this Privacy Notice or how Braemar Medical processes personal information, please contact:
Braemar Medical Limited
32 Braemar Road
Worcester Park
KT4 8SW
United Kingdom
Email: info@braemarmedical.co.uk
Telephone: 020 3907 8570
Website: braemarmedical.co.uk
Privacy Notice version: 1.1
Last reviewed: 2 September 2026
Next review: 2 September 2027