Privacy Policy
This privacy policy explains how MICES, operated by Phonehub IO Ltd (“we”, “us”, “our”), collects, stores, uses and protects any information that you give MICES when you use this website and our mobile applications.
We are committed to protecting your privacy and handling your personal data transparently and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this policy.
Phonehub IO Ltd may change this policy at a later date. Any changes will be updated on this page. You should check when providing new data to ensure that you are happy with any changes. This policy is effective from 16 February 2026.
Data controller
MICES is operated by Phonehub IO Ltd, which is the data controller responsible for your personal data.
Phonehub IO Ltd is a company registered in England and Wales (Company no. 9568821) with its registered office at:
1-2, The Old Church
St. Matthews Road
Norwich NR1 1SP
United Kingdom
If you have questions about this policy or how we handle your personal data, you can contact our Data Protection Officer at:
Email: privacy@mices.com
Telephone: 01603 361822
Information that we collect
We collect information to provide the services to our users. The information we collect, and how that information is used, depends on how you use our services and how you manage your privacy controls.
When you create a MICES account, you provide us with personal information such as your name, email address, country, phone number, and address details.
We also collect the content that you upload when using our services. This includes things such as photos of yourself or your additional participants, or photos of your identity documents and those of any additional participants you may add to your account.
Information that we collect as you use our services
Your apps, browsers & devices
We collect information about the apps, browsers and devices that you use to access the MICES service, which helps us provide features such as automatic app updates and save your device settings.
The information that we collect includes unique identifiers, operating system and settings, device type and settings, mobile network information including operator name and phone number and application version number. We also collect information about the interaction of your apps, browsers and devices with our services, including IP addresses, crash reports, system activity, and the date, time and referrer URL of your request.
We collect this information when a Phonehub IO Ltd service on your device contacts our servers, for example, when you install our app from the App Store or Play Store, or when you receive a live call. If you’re using our mobile app, your device may periodically contact our servers to provide information about your device and connection to our services. This information includes things like your availability for live calls, your app version, or minutes balance.
We use various technologies to collect and store information, including cookies, local storage, application data caches, databases and server logs.
Why we collect data
We use the information that we collect from all our services for the following purposes:
- Create and manage your account
- Verify your identity
- Provide video call services
- Send service notifications
- Provide customer support
- Improve our services
- Comply with legal obligations
Providing our services
We use your information to provide our services, such as using your app data to allow you to receive video calls.
Maintaining & improving our services
We also use your information to make sure that our services are working as they should be, such as tracking outages, crashes, or troubleshooting issues that you report to us.
Developing new features and services
We use the information we collect in existing services to help us improve new ones. For example, understanding how people use video calls, helped us design the live call feature.
Measuring performance
We may use data for analytics and measurement to understand how our services are used. For example, we analyse call feedback to do things like improve in-call functionality.
Communicate with you
We use information that we collect, such as your email address, to interact with you directly. For example, we may send you a text message, email, or notification if we need to contact you regarding your account or address any issues that you may have raised to us. And if you contact us, we’ll keep a record or copy of your request in order to help solve any issues you might be facing.
Gathered information, usage, and legal basis for processing
Below is a table containing all information which we currently collect regarding personal user data.
| Category | Data Collected | Purpose of Processing | Lawful Basis |
|---|---|---|---|
|
Service Users and/or Patients |
Name (first and last name) |
Identity verification and call management |
Legal obligation / Legitimate interests |
|
Service Users and/or Patients |
Patient number/unique identifier |
Identity verification and linking to NHS systems |
Legal obligation / Legitimate interests |
|
Service Users and/or Patients |
Notes (including safeguarding information) |
Safeguarding, operational management and compliance with NHS requirements |
Legal obligation / Legitimate interests |
|
Service Users and/or Patients |
Restrictions applied to communications |
Security and compliance with NHS rules |
Legal obligation / Public task |
|
Service Users and/or Patients |
Biometric data |
Identity verification and fraud prevention |
Legal obligation / Legitimate interests |
|
Service Users and/or Patients |
Video and audio recordings of calls |
Safeguarding, security monitoring and evidential purposes |
Legal obligation / Legitimate interests |
|
Staff |
Name |
Account management and access control |
Legitimate interests / Contract |
|
Staff |
Email address |
Account management and system communication |
Legitimate interests / Contract |
|
Staff |
Role |
Access control and role-based permissions |
Legitimate interests |
|
Social Contacts (Adults) |
Name |
Identity verification and account management |
Contract necessity |
|
Social Contacts (Adults) |
Date of birth |
Identity verification and safeguarding checks |
Legal obligation / Legitimate interests |
|
Social Contacts (Adults) |
Email address |
Account access and service notifications |
Contract necessity |
|
Social Contacts (Adults) |
Phone number (including country/location) |
Identity verification and communication |
Contract necessity |
|
Social Contacts (Adults) |
Address details |
Identity verification and fraud prevention |
Legitimate interests |
|
Social Contacts (Adults) |
Photo of ID document |
Identity verification |
Legal obligation / Legitimate interests |
|
Social Contacts (Adults) |
Face photo |
Identity verification and biometric comparison |
Legal obligation / Legitimate interests |
|
Social Contacts (Adults) |
Biometric data |
Identity verification and misuse prevention |
Legal obligation / Legitimate interests |
|
Social Contacts (Adults) |
Device metadata (IP, device type, usage data) |
Security monitoring and fraud prevention |
Legitimate interests |
|
Social Contacts (Adults) |
Video and audio call data |
Provision of service, safeguarding and compliance |
Legal obligation / Legitimate interests |
|
Social Contacts (Children / Sub-Accounts) |
Name |
Account management and relationship tracking |
Legal obligation / Legitimate interests |
|
Social Contacts (Children / Sub-Accounts) |
Date of birth |
Age verification and safeguarding |
Legal obligation / Substantial public interest |
|
Social Contacts (Children / Sub-Accounts) |
Relationship to primary account holder |
Account management and safeguarding |
Legitimate interests |
|
Social Contacts (Children / Sub-Accounts) |
Photo of ID document (where required) |
Identity verification |
Legal obligation / Legitimate interests |
|
Social Contacts (Children / Sub-Accounts) |
Face photo |
Identity verification |
Legal obligation / Legitimate interests |
|
Social Contacts (Children / Sub-Accounts) |
Biometric data (where required) |
Identity verification and security |
Legal obligation / Legitimate interests |
We will not sell your personal data to third parties.
Where biometric data is processed for identity verification purposes, this constitutes special category personal data. We process such data only where necessary for identity verification, safeguarding, security and service provision, and in accordance with applicable data protection legislation.
Other ways we may use your data
We may also use all above data for the purpose of debugging problems to provide support. After gaining your consent, we may use your identifiable data for research, to contact you regarding research or to contact you with promotional material. By default, we will assume that you do not consent unless you perform an affirmative action (such as pressing a button).
Automated Decision-Making
We use automated systems to support fraud detection, identity verification, billing, safeguarding alerts and security monitoring.
Some decisions relating to your account may involve automated processing. Where automated processing significantly affects you or your use of the service, you have the right to request human review of the decision.
Sharing your information
We may share your data with:
- The organisation responsible for the care, custody or management of the service user - where applicable, data may be shared for identity verification, safeguarding, security, service provision and appointment management. This may include NHS Trusts, His Majesty's Prison and Probation Service (HMPPS), the Ministry of Justice, prison operators, secure hospitals, mental health providers or other authorised care providers.
- Messaging providers - for SMS, email or notification delivery.
- Hosting and infrastructure providers - for secure storage and operation of the service.
Data retention
We will retain user data throughout the period of providing you with the service.
Retention periods vary depending on the type of data:
- Account information – retained for the duration of your account and for up to 7 years after cancellation for financial record-keeping, fraud prevention and reactivation purposes.
- Identity verification data – retained only as long as necessary to maintain account integrity and comply with NHS service requirements.
- Security logs and technical records (such as IP addresses) – retained for a limited period for fraud prevention and system security monitoring.
Cookies
Cookies are files which are stored on your computer in order to retain information as you browse the website.
We use essential cookies for essential purposes, such as logging you into your account, and other cookies for analytics purposes. Traffic logs from these cookies help identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to your needs. Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. We default to only allowing essential cookies.
By default, most browsers will accept cookies. In the event that you wish to disable all cookies, including essential cookies, please modify your browser settings to decline and remove the cookies. This will prevent you from using the website as intended.
Third parties
Phonehub IO will never provide your information to any other organisation for direct marketing purposes. We will not distribute, sell or lease your personal information to third parties unless we have your permission or are required by law to do so. We may send you promotional information about third parties which we think you may find interesting (unless you have requested no promotional contact).
We will share details for identity verification with the specified NHS establishment upon signing up. We may also provide it to other NHS establishments in the event that the service user/patient changes establishment.
Other third parties may be used strictly for the purpose of providing the service (such as for sending text notifications). They may be international organisations, outside of the United Kingdom.
International Transfers
Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place in accordance with applicable data protection laws, including adequacy regulations or approved contractual protections where required.
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. These measures include:
- Encrypted data transmission
- Secure hosting environments
- Access controls and role-based permissions
- Multi-factor authentication where appropriate
- Audit logging and monitoring
- Regular security reviews and updates
- Access to personal data is limited to authorised personnel who require it for legitimate business purposes.
Safeguarding
Safeguarding all users of the service is of paramount importance to us; some users of the service may be vulnerable individuals. In light of this, we may at the discretion of our directors choose to contact the NHS if we, in the course of providing support or operating the service, become aware of information which we believe could indicate that an individual is at risk of self-harm or other risks of harm.
Application permissions
The Android version of the MICES mobile app requests a number of permissions from your phone. These include:
- Camera - Camera access is required for use in Video calls.
- Microphone - We use this for audio to allow you to speak to your contact during video calls
- Bluetooth – We use this to identify whether you are using the service via a Bluetooth connected device such as headphones, or a speaker.
- Phone number – We use this to pre-fill forms with your default contact details, for user verification, and to provide customer support.
- Notifications - Receive notifications about video calls, and changes to your account status.
The iOS version of the MICES mobile app requests a number of permissions from your phone. These include:
- Camera - Camera access is required for use in Video calls.
- Microphone - We use this for audio to allow you to speak to your contact during video calls
- Notifications - Receive notifications about video calls, and changes to your account status.
- Phone number – We use this to pre-fill forms with your default contact details, for user verification, and to provide customer support.
Information rights
Phonehub IO Ltd would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:
The right to access – You have the right to request Phonehub IO Ltd for copies of your personal data.
The right to rectification – You have the right to request that Phonehub IO Ltd correct any information you believe is inaccurate. You also have the right to request Phonehub IO Ltd to complete the information you believe is incomplete.
The right to erasure – You have the right to request that Phonehub IO Ltd erase your personal data, under certain conditions.
The right to restrict processing – You have the right to request that Phonehub IO Ltd restrict the processing of your personal data, under certain conditions.
The right to object to processing – You have the right to object to Phonehub IO Ltd's processing of your personal data, under certain conditions.
The right to data portability – You have the right to request that Phonehub IO Ltd transfer the data that we have collected to another organization, or directly to you, under certain conditions.
The right to decision review - You have a right to request any automated decision be reviewed by a human operator.
We may charge an administration fee for repeated or excessive requests. In addition, it may not be possible to continue offering the service (or it may be temporarily suspended) after personal data is modified.
If you make a request, we will respond within one month.
To exercise any of these rights, please contact:
Call us on 01603 361822
Or email us: privacy@mices.com
Or write to our Information Security Manager/Data Protection Officer at:
Information Security Manager
Phonehub IO Ltd
1-2, The Old Church
St. Matthews Road
Norwich NR1 1SP
United Kingdom
You have the right to lodge a complaint with a supervisory authority if you believe your information is not handled according to regulation.
In the UK you can complain to the Information Commissioner's Office:
Using their live chat service ico.org.uk/livechat or calling their helpline on 0303 123 1113.
By writing to:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Data relating to Service Users and/or Patients
As internal service users are not able to access this website directly, account holders provide certain details relating to service user and/or patient in order to use the service.
We process service user and/or patient data in order to provide the service, to comply with NHS service requirements, and to meet safeguarding and security obligations. This processing is carried out under the lawful bases set out in this policy and does not rely solely on consent.
If an internal service user submits a data protection request, we will assess the request in accordance with applicable law and NHS regulations. Certain rights may be restricted where processing is necessary for safeguarding, security, or the prevention and detection of crime.
Changes to this policy
We regularly review this Privacy Policy and make sure that we process your information in ways that comply with it.
Phonehub IO Ltd may change this policy at a later date. Any changes will be updated on this page. You should check when providing new data to ensure that you are happy with any changes. This policy is effective from 16 February 2026.
How to contact us
If you have additional questions or requests related to your rights, you can contact our data protection officer by emailing: privacy@mices.com
Or write to our Information Security Manager/Data Protection Officer at:
Information Security Manager
Phonehub IO Ltd
1-2, The Old Church
St. Matthews Road
Norwich NR1 1SP
United Kingdom
Version: 1.0
Last
Updated: 04/06/2026