Privacy Policy
Privacy Policy – Cryo Medical Logistics
Effective Date: 23.13.24
This Privacy Policy explains how Cryo Medical Logistics Ltd, a company registered in the United Kingdom (“we”, “us”, “our”), collects and processes personal information in accordance with:
-
UK General Data Protection Regulation (UK GDPR)
-
EU General Data Protection Regulation (EU GDPR) (for EU-based clients or EU data subjects)
-
The Data Protection Act 2018
-
PECR (Privacy and Electronic Communications Regulations) where applicable
This Privacy Policy applies to visitors of our website, clients, clinics, laboratories, partner organisations, applicants, and anyone who interacts with our cryogenic and medical logistics services.
1. Personal Data We Collect
We collect personal data only when necessary for service delivery, legal compliance, legitimate interests, or when you give clear consent.
1.1 Information You Provide Directly
You may give us personal information when you:
-
Submit a quotation or transport request
-
Download content or request educational materials
-
Fill out our contact form
-
Subscribe to newsletters or updates
-
Communicate with our team
-
Apply for employment or contractor roles
-
Provide details for the carriage of biological samples
-
Request laboratory–clinic–patient liaison services
This may include:
-
Full name
-
Job title
-
Company/clinic details
-
Email address
-
Phone number
-
Postal/collection address
-
Details about your enquiry
-
Documentation required for shipment
-
CV or employment information (if applying)
1.2 Special Category Data (Article 9 GDPR)
Special category data is only collected when strictly necessary, and only with explicit consent.
This may include:
-
Medical information relating to IVF, fertility, gametes, embryos, or cryogenic samples
-
Information relating to treatment cycles
-
Biological sample identifiers
-
Patient or donor ID numbers provided for shipment
Such data is processed under:
-
Article 9(2)(a) – explicit consent
-
Article 9(2)(h) – healthcare/diagnostic purposes, where applicable
-
Article 9(2)(f) – establishment, exercise, or defence of legal claims
We never process special category data without a lawful legal basis.
1.3 Information Collected Automatically
When you browse our website, we may collect:
-
IP address
-
Browser type and version
-
Device information
-
Pages visited and time spent
-
Cookies and analytics data (see Cookies section below)
This helps us enhance website performance and security.
2. Lawful Bases for Processing (Article 6 GDPR)
We process your personal data on one or more of the following legal bases:
2.1 Consent (Art. 6(1)(a))
For:
-
Newsletters
-
Marketing communications
-
Processing special category data
-
Optional form submissions
Consent is freely given, specific, informed, and unambiguous.
You may withdraw consent at any time.
2.2 Contract (Art. 6(1)(b))
When processing is necessary:
-
To provide a quote
-
To fulfil cryogenic shipping services
-
To communicate about logistics or transport schedules
2.3 Legal Obligation (Art. 6(1)(c))
To comply with:
-
Customs and border requirements
-
Regulatory and medical transport laws
-
Financial, audit, and tax obligations
-
Compliance with court orders or law enforcement requests
2.4 Legitimate Interests (Art. 6(1)(f))
Where balanced against your rights, such as:
-
Website optimisation
-
Service improvement
-
Security monitoring
-
Fraud prevention
-
Internal training
A Legitimate Interest Assessment (LIA) is conducted where required.
3. How We Use Your Data
We use your information to:
-
Provide cryogenic transport, logistics, and support services
-
Assess and respond to enquiries
-
Communicate with clinics, labs, and clients
-
Issue invoices, quotes, and documentation
-
Track and monitor shipments
-
Improve our services
-
Provide customer support
-
Maintain regulatory and safety records
-
Protect the security and integrity of our operations
We do not sell your personal data.
4. Sharing Your Data
We only share data when necessary and always under GDPR-compliant agreements.
4.1 Third parties we may share with:
-
Clinics, laboratories, and medical professionals involved in your shipment
-
Partner logistics providers and courier networks
-
Insurers, legal advisers, or accreditation bodies
-
IT, hosting, and software providers
-
Border, customs, or regulatory authorities
-
Auditors and compliance bodies
All third parties must:
-
Comply with UK GDPR/EU GDPR
-
Sign data processing or confidentiality agreements
-
Implement appropriate security measures
4.2 No Unauthorised Third-Party Marketing
We never allow third parties to use your information for their own marketing.
5. International Data Transfers
Because we provide international medical logistics, your data may be transferred outside the UK/EU.
We ensure lawful safeguards, including:
-
UK/EU Standard Contractual Clauses (SCCs)
-
Approved International Data Transfer Agreements (IDTAs)
-
Adequacy regulations
-
Explicit consent, where applicable
All transfers meet GDPR requirements.
6. Data Security Measures
We implement robust physical, technical, and organisational controls, including:
-
Encrypted storage and transfers
-
Role-restricted access
-
Secured documentation handling
-
Cybersecurity monitoring
-
Confidentiality obligations for all staff
-
Secure GPS and shipment tracking systems
-
Regular testing of security processes
Although no system is entirely risk-free, we take all reasonable steps to keep your information safe.
7. Data Retention
We retain personal data only for as long as necessary for:
-
Service delivery
-
Legal and regulatory obligations
-
Clinical documentation requirements
-
Transport record retention laws
-
Accounting and tax compliance
General retention periods:
Type of DataRetention Period
Transport records7 years (regulatory requirement)
​
Special category (medical) dataOnly for the duration of the service + required legal period
Marketing consent recordsUntil consent withdrawn
Employment/CV data12 months unless hired
Backups are deleted on a rolling schedule.
8. Your GDPR Rights
You have the following rights under UK/EU GDPR:
-
Right to access
-
Right to rectification
-
Right to erasure (“right to be forgotten”)
-
Right to restrict processing
-
Right to object
-
Right to data portability
-
Right to withdraw consent at any time
-
Right not to be subject to automated decision-making
To exercise your rights, contact our Data Protection Officer using the details below. Identification may be required.
9. Cookies
Our site uses cookies to:
-
Improve navigation
-
Provide secure login functionality
-
Analyse website performance
-
Personalise your experience
You can disable cookies at any time via your browser settings.
A full Cookies Policy can be added if needed.
10. Complaints and Dispute Resolution
If you have concerns about how your data is handled, please contact us first—we aim to resolve all concerns quickly.
You also have the right to lodge a complaint with:
Information Commissioner’s Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113
EU residents may lodge complaints with their local Data Protection Authority.
11. External Links
Our website may link to external sites. We are not responsible for their privacy practices and recommend reviewing their policies before submitting any information.
12. Changes to This Policy
We may amend this Privacy Policy to reflect:
-
Legal changes
-
Operational updates
-
Industry best practice
We will post all updates on our website. The “Effective Date” at the top will reflect the latest version.
13. Contact Us
Cryo Medical Logistics Ltd
Email: transports@cryomedicallogistics.com
​
.png)