medCrowd requires JavaScript - please enable JavaScript in your browser if you wish to use App.

Skip to Content

  Please use the latest version of a supported browser with JavaScript enabled:     Got it - don't show me this again


SUPPORTED MOBILE BROWSERS
ANDROID AND IOS
  • Chrome
  • Firefox
ANDROID ONLY
  • Android v5.0+
IOS ONLY
  • Safari
WINDOWS 10 MOBILE
  • Edge
SUPPORTED DESKTOP BROWSERS
WINDOWS AND MAC
  • Chrome 12+
  • Firefox 16+
  • Opera 15+
MAC ONLY
  • Safari 6+
WINDOWS ONLY
  • Edge
  • Internet Explorer 10+

Supplier Relationship Policy

Classification Public
Location https://www.medcrowd.com/compliance/iso27001/policies/SupplierRelationship
Author Paul Gardner
Approver Felix Jackson
Approved 14th December 2016
Date Author Changes
19th June 2023 Paul Gardner Periodic review
24th August 2022 Paul Gardner Updated suppliers
6th June 2022 Paul Gardner Periodic review
16th February 2021 Paul Gardner Periodic review
1st May 2020 Paul Gardner Updates for the introduction of Contact Centres
12th February 2020 Paul Gardner Periodic review
25th May 2018 Paul Gardner Minor changes to reflect the new Data Protection Act (2018)
15th May 2018 Paul Gardner Added Twilio as a supplier
5th December 2016 Paul Gardner Initial

Introduction

This policy is part of the medDigital ISMS and must be fully complied with.

This policy ensures that our information assets are protected when processed by suppliers and to maintain an agreed level of information security and service delivery.

Personal Information

Paul Gardner is responsible for reviewing information flows outside of the EEA and the table below must be updated annually.

This table shows the data that flows outside of the EEA, who receives it, why, and how they comply with the Data Protection Act.

Data Purpose Recipient Location Compliance
Name
Telephone Number
Recording of Contact Centre calls
We use Twilio to send text messages to mobile devices and as a carrier for incoming and outbound calls to and from Contact Centres. The recordings of Contact Centre calls are stored on Twilio infrastructure whilst the call is in progress and then deleted. Twilio Inc. California, United States of America Twilio Inc participates in and has certified its compliance with the EU-US Privacy Shield Framework and also has a GDPR compliant data processing contract addendum.

Supplier selection

Suppliers must be based in the EEA or the United States of America. Suppliers outside of these regions cannot be selected.

Suppliers in the USA with access to medCrowd data that may contain personal identifying information must participate in the EU:US Privacy Shield framework and/or have sufficient GDPR compliant agreements.

No supplier can be given access to medCrowd conversation data.

Service delivery

It is the responsibility of the project lead to monitor, review, and audit supplier service delivery where their projects are concerned and to maintain a record of these activities.

Changes to the provision of services by suppliers, including maintaining and improving existing information security policies, procedures and controls, shall be managed, taking account of the criticality of business information, systems and processes involved and re-assessment of risks.