Legal
Privacy Policy
How R A Medical Services Ltd collects, uses, stores and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: 11 June 2026
Introduction
R A Medical Services Ltd is committed to protecting the privacy and personal data of everyone who interacts with us. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and the rights you have over your data.
We process your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and the new requirements introduced by the Data (Use and Access) Act 2025 which came into force on 19 June 2026.
Who we are
R A Medical Services Ltd is the data controller for the personal data described in this policy. We are a UK company registered in England and Wales, supplying and maintaining inhalation sedation and medical gas equipment to NHS Trusts, dental practices and medical aesthetics clinics.
Data controller: R A Medical Services Ltd
Registered office: Sandylands Business Centre, Carleton New Road, Skipton, North Yorkshire, BD23 2AA
Company number: 02190602
ICO registration: ZA794446
Data Protection lead: info@ramedical.com
General contact: info@ramedical.com · 01535 652 444
We have not appointed a formal Data Protection Officer as our processing activities do not meet the Article 37 criteria that would require one. The Data Protection lead above is your point of contact for all data protection enquiries and individual rights requests.
What personal data we collect
We collect only the personal data we need to provide our services and run our business. This falls into the following categories:
- Identity data: name, job title, role.
- Contact data: business address, email address, telephone number.
- Enquiry data: the information you provide when you contact us (e.g. a question about a product, a service request, a quote enquiry).
- Transaction data: order details, equipment serial numbers, installation and service records.
- Technical data: basic server logs (IP address, browser type, pages visited, timestamps) collected automatically when you visit our website.
- Marketing data: your preferences for receiving marketing communications from us.
We do not knowingly collect special-category data (such as health, biometric or genetic data) through this website. We do not collect payment card details — payments are handled by secure third-party processors who are themselves data controllers.
How we collect your data
We collect personal data directly from you when you:
- Submit an enquiry through our website contact form, email, or telephone.
- Request a quote, demo, or product specification.
- Place an order for products or services.
- Subscribe to our marketing communications.
- Apply for a job with us.
- Visit our website (technical/usage data via server logs).
We may also receive limited contact data from third parties (e.g. when an existing customer refers you, or from publicly available business directories) — in which case we will provide you with a copy of this privacy information within one month of receiving your data.
Why we use your data (purposes and lawful basis)
Under the UK GDPR we must always have a valid lawful basis for any processing. The table below explains what we use your data for and which basis applies.
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| Responding to enquiries | Identity, contact, enquiry | Legitimate interest |
| Quoting, supplying, and servicing equipment | Identity, contact, transaction | Contract |
| Accounting, tax, regulatory record-keeping | Identity, contact, transaction | Legal obligation |
| Product safety notifications and recalls | Identity, contact, transaction | Legal obligation |
| Email newsletters and product updates | Identity, contact, marketing | Consent (you can withdraw at any time) |
| Website security and basic analytics | Technical | Legitimate interest |
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
International transfers
Some of our IT service providers (for example, our website hosting and email platform) may store data on servers located outside the UK. Wherever we transfer your personal data outside the UK, we rely on one of the lawful transfer mechanisms recognised under the UK GDPR — typically the UK International Data Transfer Agreement (IDTA), the UK–US Data Bridge, or adequacy regulations issued by the UK government. A copy of the relevant safeguards can be provided on request.
How long we keep your data
We will only keep your personal data for as long as is reasonably necessary to fulfil the purpose for which we collected it, including to satisfy any legal, accounting, or reporting requirements.
- Quotation and enquiry records: up to 2 years from last contact.
- Sales and service records: 7 years from the date of the transaction (HMRC and ISO 13485 record-keeping requirements).
- Medical device installation and service records: 15 years from the date of installation, or the lifetime of the equipment, whichever is longer, in line with MHRA guidance on medical-device traceability.
- Marketing subscription data: until you unsubscribe, plus a brief suppression list to ensure we do not re-contact you.
- Job applications (unsuccessful): 6 months from the closing date, unless you ask us to retain your CV for longer.
Your rights
Under the UK GDPR you have the following rights. To exercise any of them, contact us using the details at the bottom of this page — we will respond within one month.
- Right of access — to request a copy of the personal data we hold about you.
- Right of rectification — to ask us to correct data that is inaccurate or incomplete.
- Right of erasure — also known as the "right to be forgotten" — to ask us to delete your data in certain circumstances.
- Right to restrict processing — to ask us to suspend processing of your data in certain circumstances.
- Right to data portability — to ask us to provide your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interest or to direct marketing.
- Right to withdraw consent — where our lawful basis is consent (e.g. marketing), you can withdraw it at any time without affecting earlier processing.
- Rights related to automated decision-making — we do not carry out any automated decision-making that has legal or similarly significant effects on you, so these rights do not currently apply.
How to complain
We would always prefer to resolve any concern directly. Please contact our Data Protection lead first using the details at the bottom of this page and we will:
- Acknowledge your complaint within 30 days of receipt.
- Investigate without undue delay and keep you informed of progress.
- Tell you the outcome of our investigation in writing.
This complaints process is provided in accordance with the new requirements of the Data (Use and Access) Act 2025, in force from 19 June 2026.
If you remain dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
Make a complaint: ico.org.uk/make-a-complaint
How we protect your data
We take the security of your personal data seriously. Our technical and organisational measures include:
- Encryption in transit (HTTPS/TLS) for all website traffic.
- Access controls so that only staff who need your data to do their job can see it.
- ISO 13485:2016 certified quality-management system covering our service operations.
- Regular staff training on data protection and information security.
- Pseudonymisation and minimisation of personal data wherever practical.
- Documented procedures for handling personal-data breaches, with notification to the ICO within 72 hours where required.
No method of transmission over the internet, however, is 100% secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
Children's privacy
Our website and services are not directed at children under the age of 18, and we do not knowingly collect personal data from children through this website. If you believe a child has provided us with personal data, please contact us and we will delete the information promptly.
Third-party links
Our website may contain links to external websites we do not control, such as the BDIA or our OEM partners. This Privacy Policy does not cover those sites. We encourage you to read the privacy notice of every website you visit.
Changes to this policy
We may update this Privacy Policy from time to time. The most current version will always be published on this page, with the "Last updated" date above. If we make material changes that affect how we handle your data, we will take reasonable steps to bring those changes to your attention.
Contact us
For any questions about this policy, to exercise your rights, or to raise a data protection complaint, please contact us:
R A Medical Services Ltd
Sandylands Business Centre, Carleton New Road, Skipton, North Yorkshire, BD23 2AA
Data Protection lead: info@ramedical.com
General enquiries: info@ramedical.com
Telephone: 01535 652 444
See also our Cookie Policy.
