Last Updated: 25 June 2025
QuickSickCert (“we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, store, and share your personal information when you access or use our website and services (“Service”).
To use QuickSickCert, you must agree to the collection and use of information in accordance with this Privacy Policy and our Terms & Conditions.
1. Data Controller Information
QuickSickCert is the data controller for personal data collected through its platform.
2. Types of Data We Collect
2.1 Personal Data
When using our Service, we may collect the following personal data:
- Full name
- Date of birth
- Email address
- Address or postcode (optional)
- Payment information (via third-party processor)
- Device and IP address
- Self-reported medical information (e.g., symptoms, absence dates)
2.2 Technical and Usage Data
- IP address and device information
- Browser type and version
- Time zone settings
- Referral URLs
- Clickstream and usage activity
- Cookies (see Section 7)
3. How We Use Your Data
We use your personal data to:
- Review and issue medical certificates based on your self-declared information
- Communicate with you about your submission
- Deliver your certificate via email
- Process secure payments
- Detect and prevent fraud or misuse
- Maintain legal records and comply with regulatory obligations
- Improve our website and user experience (anonymised data only)
4. Legal Bases for Processing (GDPR)
We rely on the following legal grounds under the General Data Protection Regulation (GDPR):
- Consent – when you provide sensitive health information voluntarily
- Contract – for issuing certificates and processing payments
- Legal obligation – for retaining records or responding to legal authorities
- Legitimate interests – to detect fraud, protect our Service, and analyse user trends
5. Sharing Your Data
We do not sell your personal data. We may share your data only with:
- Clinicians reviewing your submission (bound by confidentiality and professional regulation)
- Payment processors (e.g., Stripe, PayPal) — no payment information is stored by QuickSickCert
- IT and cloud service providers (for secure storage and technical support)
- Regulatory or legal authorities if required by law
- Third parties in the event of business transfer or asset sale (data would remain subject to this policy)
6. Data Retention
We retain personal and health data only as long as necessary to:
- Provide the Service
- Comply with legal obligations
- Defend against legal claims
- Maintain business records
Retention periods:
- Medical certificate records: up to 2 years
- Transaction and support data: up to 6 years (for accounting and tax law)
You can request deletion of your personal data at any time (see Section 9).
7. Where Your Data Is Stored
All information submitted through this website is transmitted securely over SSL and stored on our web servers, which are located in the United Kingdom. Form submissions (including any uploaded documents) are stored in a private, non-public directory and are not accessible via the public internet.
The website database and uploaded files are hosted and managed by RANE Digital as your appointed data processor. Backups of the website may also be stored within the UK for resilience purposes.
You (as the data controller) retain full control over how long your data is kept and how it is used. If you have any questions about how your information is handled, please contact us at info@quicksickcert.com.
8. Cookies and Tracking
Our website uses cookies and similar technologies for:
- Website functionality
- Secure login
- Analytics and traffic patterns
We do not use cookies for advertising. You can control cookie preferences through your browser settings.[Text Wrapping Break]
9. Data Security
We implement strict technical and organisational measures to protect your data, including:
- SSL encryption
- Access controls and role-based restrictions
- Secure storage of sensitive data on UK/EU-based servers
- Regular security audits and data minimisation practices
Despite best efforts, no system can be completely secure. Use of the Service is at your own risk.
10. Your Rights Under GDPR
You have the following rights, which you may exercise by contacting us.
- Access – receive a copy of your data
- Rectification – correct inaccurate or incomplete data
- Erasure – request deletion of your data (“right to be forgotten”)
- Restriction – limit how we process your data
- Objection – object to processing based on legitimate interests
- Data Portability – receive your data in a portable format
- Withdraw Consent – for processing based on consent (e.g., health info)
We respond to all rights requests within one month. If unsatisfied, you may lodge a complaint with the Information Commissioner’s Office (ICO) in the UK or your local data protection authority.
11. International Data Transfers
All data is stored on servers located in the United Kingdom or European Union. We do not transfer your data outside of the UK/EU unless appropriate safeguards are in place (e.g., adequacy decision or standard contractual clauses).
12. Children’s Privacy
QuickSickCert is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted data, contact us immediately for deletion.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a new “Last Updated” date. Continued use of the Service after changes constitutes acceptance.