Last Updated: December 2024
This privacy notice is intended for potential and actual clients, suppliers/service providers, healthcare professionals and other experts whom we provide services to or receive services from, website users, alumni network members, research participants, recruitment candidates and work experience students. In this notice, we outline how Costello Medical collects and processes your personal data, whether provided to us by you or a third party.
It is important that you read and understand this privacy notice. Costello Medical is responsible for deciding how we hold and use your personal data; therefore, we are acting as the “data controller”. We are required under data protection legislation to notify you of the information contained in this privacy notice.
We reserve the right to update this privacy notice at any time.
The Costello Medical Group is made up of different legal entities, located in the UK, US, Singapore and China. When we mention “Costello Medical”, “we”, “us” or “our”, we are referring to Costello Medical Consulting Limited, the UK-domiciled parent company of the Costello Medical Group, and also to its subsidiaries.
Our Information Governance Team oversees data protection-related matters and are responsible for ensuring that your personal data is appropriately secure. If you have any questions about this privacy notice or our data protection practices, please contact the Information Governance Team through our contact details listed below.
Costello Medical Consulting Limited
4th Floor, 50/60, Station Road, Cambridge, CB1 2JH
Information Governance Team: InfoGov@costellomedical.com
T: +44 (0)1223 913 020
We will only use your personal data for the purpose for which we collected it and in accordance with your relationship with Costello Medical.
We may also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity.
We may collect, use, store and transfer different kinds of personal data, including those set out below:
We will process your personal data primarily to manage our relationship with you and to enable our provision of services to you, which may include:
We may collect, use, store and transfer different kinds of personal data, including those set out below:
We will use your personal data most commonly for the following purposes:
We may collect, use, store and transfer different kinds of personal data, including those set out below:
We will use your personal data for the following purposes:
We may collect, use, store and transfer different kinds of personal data, including those set out below:
If you register to join the Costello Medical Alumni Network as a former Costello Medical employee, we will use your personal data to:
We may collect, use, store and transfer different kinds of personal data, including those set out below:
We will use your personal data for the following purposes:
We may collect, use, store and transfer different kinds of personal data, including those set out below:
We will use your personal data for the following purposes:
If you participate in a work experience programme at Costello Medical, we may collect, use, store and transfer different kinds of personal data, including those set out below:
We will use your personal data to:
Please be aware that, by consenting to Costello Medical publishing a photograph and/or video in which you feature online and/or in promotional materials, your personal data may be processed by other third parties outside of Costello Medical’s control. Costello Medical’s ability to restrict the processing of your personal data will be limited to Costello Medical-controlled processing only.
We collect personal data from you directly when you get in contact with us and use our services. We may combine the information you provide with other information from other sources, such as professional social media platforms and external third parties.
We will collect additional personal data in the course of our services-related activities throughout the period of our working relationship with you.
If you submit any personal data relating to another individual to us, we expect that you have the requisite authority to do so.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
Costello Medical will not process personal data without having a legal basis for doing so. The legal bases that Costello Medical may rely on include:
Where Costello Medical is relying on legitimate interests to process personal data, we have conducted a legitimate interest assessment. Occasions where we may be relying on legitimate interests as our legal basis for processing personal data include:
We may share your personal data with:
We may additionally share your personal data with third parties where required by law, where it is necessary to fulfil our contractual obligations with you or where we have another legitimate interest in doing so.
The Costello Medical Group operate globally and so we may transfer, store and process your personal data outside of the country where it is collected. If we do transfer data internationally, all transfers will be compliant with applicable data protection legislation.
All entities in the Costello Medical Group adhere to appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
All relevant third-party service providers are assessed and required to have appropriate security measures in place to protect your personal data. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
Under certain circumstances, by law you have the right to:
If you wish to exercise any of the rights listed above, please contact the Information Governance Team in writing (InfoGov@costellomedical.com). We will respond to your request within one calendar month.
In addition, you have the right to make a complaint at any time to your local data protection authority with respect to data protection issues. However, we will endeavour to resolve any complaint you may have in the first instance, and request you contact Costello Medical first to resolve any issues you may have regarding our processing of personal data.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Our website or applications may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website or application, we encourage you to read the privacy policy of every platform you visit.
If you are looking for more information on how we process your personal data including on data security, data retention and lawful processing bases, please email the Information Governance Team using the contact details listed below.
Costello Medical Consulting Limited
4th Floor, 50/60, Station Road, Cambridge, CB1 2JH
Information Governance Team: InfoGov@costellomedical.com
T: +44 (0)1223 913 020
Costello Medical Group:
Processors of your personal data
Below are details of key services providers and group entities; depending on the scope of relevant activities, these suppliers and group entities may be involved in the processing of personal data.
Name | Location of Data Processing | Purpose of Processing |
Costello Medical Inc. | US | To improve business effectiveness across the global organisation, including facilitating day-to-day operations, effective communication, financial administration, supplier management and IT system management |
Costello Medical Singapore | Singapore | |
Costello Medical Shanghai | Shanghai | |
Cubic Interactive Limited | UK | Project and customer relationship management |
Druva Europe Limited | UK | Data backup |
Egnyte, Inc. | UK and EU | Cloud-based file server |
Little Fish (UK) Ltd | UK | IT services provision and administration |
Microsoft Corporation | UK, EU, and US | Productivity applications and services |
Workable | UK, EEA and US | Recruitment management and administration |
HubSpot | EU | Customer relationship management and marketing |