Providers that process data on our behalf 


MS Office 365

HIS uses Microsoft 365 services as part of an NHSScotland national contract. 

HIS handles data within the M365 environment. We do this in line with national impact assessments and acceptable use policies. We undertake individual impact assessments where required by data protection legislation related to specific use of the M365 apps. This is for specific purposes related to our work. 

MS Privacy Statement 

MS365 Teams Meetings including recording and transcription.

We may record an event, meeting, or training session you attend using MS Teams. Where we do record and/or transcribed using MS365, you will receive a privacy notice. This will be specific to the purpose of the event, meeting, briefing or training session. 

Personal information recorded or transcribed in the MS365 Teams environment relates either to:

  • directly consenting participants in recorded meetings
  • to data where Healthcare Improvement Scotland has an established legal basis for processing. 

The categories of personal information held in relation to recordings and transcriptions are:

  • name
  • job title
  • organisation
  • image
  • personal contributions to the business
  • professional development event

The recording could contain: 

  • video stream (including images of yourself) if you choose to enable your camera during the meeting. 
  • audio stream, if you choose to enable your microphone during the meeting. This could include any opinions you contribute and anything you say about yourself
  • chat contributions within the meeting could also be captured in the meeting recording

E-Newsletter

We use a third party provider, Mailchimp, to deliver our monthly e-newsletters. We also use it for specific business units such as Community Engagement and iHub.  Mailchimp uses click and open rate monitoring. This monitoring allows us to record:

  • how many of the emails we send are opened
  • how many successfully delivered emails registered at least one click.

 We record and use this data to inform activities at an aggregated level. Individual subscribers to our newsletters are not monitored. Subscriber details are only accessible to the HIS Mailchimp account holders. Further information on click and open rates is available on the Mailchimp site. 

The Mailchimp privacy policy provides wider information the companies handling of information. 

Blog 

Our corporate blog is provided by WordPress. Cookies and anonymised analytics are used on this site. This is to improve the visitors experience and to provide feedback to us on visitors. Automattic Inc. provide WordPress. How they use data is outlined in their corporate privacy policy

Social media

We routinely use social media channels to provide information and communicate, including:

  • Twitter
  • Facebook
  • LinkedIn
  • YouTube
  • Vimeo
  • Wistia

 We do not collect any data from our social media accounts beyond the standard analytics available for each platform. Our policy on how we use social media provides more information.

The standard privacy policies for the social media tools we use are below: 

Event booking

We manage our event bookings through different platforms. These are:

Surveys

We use MS Forms and third party provider Smart Survey to gather feedback. We gather feedback on our work, events and publications. See below for Smart Survey privacy information: