Website and enquiry information
Your name, email address, telephone number, organisation, role and the content of messages you send to us.
Privacy and data protection
This notice explains how Corsalveo handles information through its website and services, including the ROHIT specialist-referral platform.
Last updated: 10 August 2026Scope
This notice applies to visitors to the Corsalveo website, people who contact us, healthcare professionals who use or enquire about our services, and patients whose information may be processed through ROHIT.
It explains Corsalveo’s use of personal information and the circumstances in which Corsalveo acts on behalf of a healthcare organisation.
A healthcare organisation using ROHIT should also provide its own patient privacy information. That organisation’s notice explains how it uses patient information in delivering care.
Data-protection roles
Corsalveo is the controller for personal information it collects for its own business purposes. This includes website enquiries, correspondence, supplier and customer contacts, professional-user administration and service-management information.
The relevant healthcare organisation is normally the controller for patient information entered into ROHIT as part of a referral, clinical review, transfer or related care process.
The healthcare organisation determines why patient information is used, the lawful basis for its use, who may access it and how long the clinical record must be retained.
When Corsalveo provides ROHIT to a healthcare organisation, Corsalveo processes patient information on that organisation’s documented instructions and under the applicable contractual and data-processing arrangements.
Information we handle
Your name, email address, telephone number, organisation, role and the content of messages you send to us.
Identity, professional role, organisation, work contact details, account information, access history and relevant training or support records.
Internet Protocol address, browser or device information, dates and times of access, security logs and information required to maintain and protect the service.
Information required for a referral or clinical pathway may include identifiers, contact details, relevant medical history, investigations, clinical findings, treatment, advice, outcomes and transfer information.
Health information is special-category personal data and receives additional legal protection.
Purpose and lawful basis
| Information | Purpose | Basis used by Corsalveo |
|---|---|---|
| Website enquiries and correspondence | To respond to questions, arrange demonstrations and manage professional or commercial relationships. | Legitimate interests, steps requested before entering a contract, or performance of a contract. |
| Customer, supplier and professional-user details | To administer services, user access, implementation, training, support, billing and contractual relationships. | Legitimate interests, contractual necessity and compliance with legal obligations. |
| Technical, access and security records | To operate, monitor, troubleshoot and protect the website and services, and investigate inappropriate use or security incidents. | Legitimate interests and compliance with legal obligations. |
| Patient and clinical information in ROHIT | To support specialist referral, advice, clinical communication, handover and inter-hospital transfer. | The healthcare organisation determines the applicable lawful bases. Corsalveo processes this information on the controller’s instructions rather than selecting an independent lawful basis for the care activity. |
Corsalveo does not rely on patient consent as its basis for processing clinical information on behalf of a healthcare organisation. Consent to treatment and the lawful basis for processing personal information are separate matters.
Sharing and service providers
Information may be available to authorised healthcare professionals and to organisations involved in providing, securing or supporting the relevant service.
Authorised professionals at referring, reviewing or receiving organisations may use information where necessary for the patient’s care and the relevant pathway.
Corsalveo uses contracted technology providers for secure database hosting, communications, website operation and technical support. Access is limited according to service need and contractual arrangements.
Information may be disclosed to professional advisers, regulators, courts or public authorities where necessary to meet a legal obligation, establish legal rights or respond to a lawful request.
Corsalveo does not sell patient, professional-user or website-enquiry information.
Some website or technology providers may process limited professional, technical or administrative information outside the UK. Where data-protection law restricts a transfer, an applicable adequacy decision or contractual safeguard is required.
ROHIT does not make clinical decisions. Corsalveo does not use personal information to make solely automated decisions that produce legal or similarly significant effects on individuals.
Patient-identifiable information is not intended to be included in routine SMS alerts. Users must not enter patient information into general website contact forms.
Website technology
The Corsalveo website is delivered using Weebly. Weebly and related infrastructure may process technical information required to deliver and secure the website.
General website contact forms must not be used to submit patient-identifiable or confidential clinical information. Clinical referrals should be submitted only through the designated ROHIT referral pathway.
The website may use essential technologies needed for operation and security. Where non-essential cookies or analytics are enabled, appropriate information and choices should be provided through the website’s cookie controls.
Retention
Information is retained only for as long as it is needed for the purpose for which it was collected and to meet applicable clinical, contractual, regulatory and legal requirements.
Retention is determined by the relevant healthcare organisation’s records-management policy and the applicable service agreement.
Account information is retained while access is required. Relevant audit, safety and security records may be retained after access ends where necessary for governance, investigation or legal purposes.
Correspondence is retained for as long as reasonably necessary to deal with the enquiry and manage any resulting professional, contractual or legal relationship.
Information is deleted, anonymised or securely disposed of when it is no longer required, subject to backup, evidential and legal-retention requirements.
Security
Corsalveo applies measures intended to protect personal information against unauthorised access, inappropriate use, alteration, loss or disclosure. These include access controls, authentication, encrypted transmission, audit logging, system monitoring, supplier controls, incident management and business-continuity arrangements.
No system can eliminate every risk. Security controls are therefore reviewed and developed in response to service changes, identified hazards, incidents and emerging threats.
Your rights
Depending on the circumstances and the lawful basis for processing, you may have the following rights.
Ask whether your information is being used and request a copy of relevant personal information.
Ask for inaccurate or incomplete personal information to be corrected.
Ask for information to be deleted where the right applies. This right is not absolute, particularly for clinical records.
Ask for use of your information to be restricted in specified circumstances.
Object to particular processing where the right applies, including certain processing based on legitimate interests.
Request certain information in a portable format where the legal conditions for this right are met.
Where Corsalveo relies on legitimate interests, you may object to the processing of your personal information. Corsalveo will consider the circumstances and whether there are compelling legitimate grounds for the processing to continue.
If your request concerns a clinical record, referral or care pathway, it will normally need to be addressed to the healthcare organisation responsible for your care. Corsalveo will support that organisation where required.
Questions or concerns
Contact us if you have a question about this notice or Corsalveo’s use of your personal information. Please do not include patient-identifiable or confidential clinical information in a general website enquiry.
You may also complain to the Information Commissioner’s Office. We would welcome the opportunity to consider your concern first, but contacting Corsalveo does not affect your right to approach the ICO.