Governance and Compliance
1. Modern Slavery Statement
1. Introduction
TSOR Med is committed to preventing slavery, human trafficking, forced labour, and exploitation within our business operations and supply chains.
We recognise our responsibility to promote ethical practices and protect the rights, dignity, and wellbeing of all individuals who interact with our Platform.
This statement is prepared in accordance with the principles of the Modern Slavery Act 2015.
2. Our Business
TSOR Med operates a healthcare workforce technology platform connecting verified healthcare professionals with healthcare organisations.
Our platform supports:
- Doctors
- General Practitioners
- Pharmacists
- Nurses
- Dentists
- Dental Nurses
- Allied Health Professionals
- NHS organisations
- Private healthcare providers
- Community healthcare organisations
3. Our Commitment
TSOR Med has zero tolerance for:
- Slavery;
- Human trafficking;
- Forced labour;
- Exploitation;
- Unlawful employment practices.
We expect all employees, contractors, suppliers, Clients and healthcare professionals using our Platform to share these standards.
4. Risk Assessment
Potential risks may include:
- Exploitation of temporary workers;
- Fraudulent recruitment practices;
- Identity fraud;
- Illegal employment;
- Inappropriate deductions or payments;
- Vulnerable workers being subjected to pressure or coercion.
5. Controls and Prevention
TSOR Med reduces risk through:
- Identity verification;
- Right-to-work checks;
- Professional registration checks;
- Employer verification;
- Monitoring suspicious activity;
- Secure payment processes;
- Complaints mechanisms;
- Reporting channels.
6. Reporting Concerns
Anyone who suspects modern slavery or exploitation connected with the Platform should report concerns:
Email: support@tsormed.co.uk
Reports may be handled confidentially.
Where necessary, concerns may be reported to appropriate authorities.
7. Training and Awareness
TSOR Med will promote awareness among staff and relevant partners regarding:
- Identifying exploitation;
- Reporting concerns;
- Ethical recruitment practices.
8. Review
This statement will be reviewed annually.
Approved by: Fahmida Zannat Chowdhury, Director, AidStar trading as TSOR Med.
Date: 19 August 2026
2. Information Security Policy
1. Purpose
This policy establishes the approach TSOR Med takes to protecting:
- Personal information;
- Healthcare-related information;
- Professional documents;
- Payment information;
- Platform systems.
2. Security Objectives
TSOR Med aims to maintain:
Confidentiality
Only authorised persons can access information.
Integrity
Information remains accurate and protected from unauthorised modification.
Availability
Systems remain available and reliable for users.
3. Information Security Principles
TSOR Med follows:
- UK GDPR requirements;
- Data Protection Act 2018;
- Privacy by design principles;
- Industry security practices;
- Risk-based security controls.
4. Access Control
TSOR Med uses:
- Role-based access controls;
- Least privilege principles;
- Secure authentication;
- Multi-factor authentication where appropriate;
- Access reviews.
Employees and contractors only receive access necessary for their role.
5. Data Protection Measures
Security measures may include:
- Encryption;
- Secure databases;
- Encrypted communications;
- System monitoring;
- Vulnerability management;
- Backup systems;
- Audit logging.
6. Staff Responsibilities
All personnel must:
- Protect confidential information;
- Use secure passwords;
- Report security concerns;
- Complete security training;
- Follow access policies.
7. Incident Management
Security incidents include:
- Unauthorised access;
- Lost devices;
- Data breaches;
- Malware;
- Phishing;
- System compromise.
All incidents must be reported immediately.
8. Third-Party Security
Suppliers providing:
- Payment processing;
- Identity verification;
- Hosting;
- Software services;
must demonstrate appropriate security controls.
9. Business Continuity
TSOR Med maintains procedures to support service recovery following:
- Cyber incidents;
- Infrastructure failure;
- Operational disruption.
10. Review
This policy is reviewed periodically to reflect:
- Technology changes;
- Regulatory developments;
- Security risks.
3. Data Processing Agreement (DPA)
1. Purpose
This Data Processing Agreement governs how personal data is processed between TSOR Med and organisations using the Platform.
This Agreement forms part of the wider contractual relationship between TSOR Med and Clients.
2. Roles of the Parties
Depending on the processing activity:
- TSOR Med may act as a Data Processor;
- TSOR Med may act as a Data Controller;
- Clients may act as Data Controllers.
The applicable role depends on the purpose and nature of processing.
3. Processing Activities
TSOR Med may process information relating to:
- Healthcare professionals;
- Employees;
- Contractors;
- Authorised representatives;
- Compliance records;
- Booking information.
4. Types of Personal Data
Processing may include:
- Identity information;
- Contact details;
- Professional registration information;
- DBS information;
- Right-to-work information;
- Payment information;
- Employment history;
- Verification records.
5. Special Category Data
Where applicable, processing may include:
- Professional information;
- Occupational health information;
- Regulatory information.
Appropriate safeguards will be applied.
6. Processor Obligations
Where acting as Processor, TSOR Med will:
- Process data only on documented instructions;
- Maintain confidentiality;
- Implement security measures;
- Assist with data subject requests;
- Support compliance obligations;
- Notify Clients of relevant breaches.
7. Sub-processors
TSOR Med may use trusted sub-processors for:
- Hosting;
- Payments;
- Verification;
- Identity checking;
- Communications;
- Security services.
TSOR Med remains responsible for appropriate supplier management.
8. Data Breaches
TSOR Med will:
- Investigate suspected breaches;
- Take reasonable mitigation measures;
- Notify affected parties where required by law.
9. International Transfers
Where data leaves the UK, appropriate safeguards will be implemented, including:
- Adequacy decisions;
- Approved contractual safeguards;
- Other lawful mechanisms.
10. Data Retention and Deletion
Personal data will be retained only as long as necessary.
Following termination of services, data will be securely deleted or returned where legally permitted.
11. Audit Rights
Clients may request reasonable information demonstrating TSOR Med's compliance with applicable data protection obligations.
12. Governing Law
This Agreement is governed by the laws of England and Wales.
4. Clinical Governance Policy
1. Purpose
TSOR Med is committed to supporting safe, effective, and high-quality healthcare workforce solutions.
This Clinical Governance Policy establishes the framework through which TSOR Med promotes:
- Patient safety;
- Professional accountability;
- Regulatory compliance;
- Continuous improvement;
- Safe workforce engagement.
2. Scope
This policy applies to:
- TSOR Med employees;
- Contractors;
- Healthcare professionals using the Platform;
- Healthcare organisations engaging professionals through the Platform.
3. Role of TSOR Med
TSOR Med operates as a technology marketplace and does not directly provide clinical services.
TSOR Med does not:
- Diagnose patients;
- Supervise clinical decisions;
- Replace employer clinical governance systems.
Clinical responsibility remains with:
- The healthcare professional delivering care; and
- The healthcare organisation responsible for the service.
4. Professional Standards
Healthcare professionals using TSOR Med must comply with applicable professional standards, including:
- GMC Good Medical Practice;
- GPhC Standards for Pharmacy Professionals;
- NMC Code;
- GDC Standards for the Dental Team;
- HCPC Standards of Conduct, Performance and Ethics.
Professionals must:
- Work within competence;
- Maintain professional registration;
- Maintain confidentiality;
- Prioritise patient safety;
- Report concerns appropriately.
5. Verification and Credentialing
TSOR Med supports safe recruitment through verification of:
- Professional registration;
- Identity;
- Right to work;
- DBS checks where applicable;
- References;
- Relevant documentation.
Verification does not replace the Client's responsibility to complete local recruitment checks.
6. Clinical Incidents
Where concerns arise regarding:
- Patient safety;
- Professional misconduct;
- Unsafe practice;
- Regulatory concerns;
TSOR Med may:
- Investigate;
- Request information;
- Suspend access;
- Notify relevant organisations or regulators where appropriate.
7. Continuous Improvement
TSOR Med reviews:
- User feedback;
- Complaints;
- Incidents;
- Platform performance;
- Compliance trends.
Lessons learned may be used to improve Platform processes.
5. Safeguarding Policy
1. Purpose
TSOR Med is committed to safeguarding vulnerable individuals who may receive healthcare services through professionals engaged via the Platform.
Safeguarding means protecting individuals from:
- Abuse;
- Neglect;
- Exploitation;
- Harm;
- Inappropriate treatment.
2. Scope
This policy applies to:
- Healthcare professionals;
- Healthcare organisations;
- TSOR Med staff;
- Contractors.
3. Types of Abuse
Safeguarding concerns may include:
- Physical abuse;
- Emotional abuse;
- Sexual abuse;
- Neglect;
- Financial abuse;
- Discriminatory abuse;
- Organisational abuse;
- Exploitation.
4. Responsibilities of Healthcare Professionals
Professionals must:
- Recognise safeguarding concerns;
- Follow employer safeguarding procedures;
- Report concerns promptly;
- Maintain accurate records;
- Cooperate with investigations.
5. Responsibilities of Employers
Healthcare organisations remain responsible for:
- Safeguarding systems;
- Training;
- Policies;
- Reporting pathways;
- Compliance with CQC requirements where applicable.
6. Reporting Safeguarding Concerns
Concerns should be reported immediately through:
- The relevant healthcare organisation;
- Appropriate safeguarding authority;
- Emergency services where there is immediate danger.
TSOR Med may be notified where concerns relate to Platform users or activities.
7. Recruitment Safeguards
TSOR Med supports safeguarding through:
- Identity verification;
- DBS checks where required;
- Professional registration checks;
- Reference checks;
- Monitoring concerns.
8. Zero Tolerance
TSOR Med does not tolerate behaviour that places patients or vulnerable people at risk.
Concerns may result in:
- Suspension;
- Investigation;
- Removal from the Platform;
- Referral to regulators or authorities.
6. Equality, Diversity & Inclusion Policy
1. Purpose
TSOR Med is committed to creating a fair, inclusive and respectful healthcare workforce marketplace.
We believe everyone should be treated with dignity and respect regardless of background or personal characteristics.
2. Scope
This policy applies to:
- Candidates;
- Employers;
- Healthcare organisations;
- TSOR Med employees;
- Platform users.
3. Protected Characteristics
TSOR Med supports equality regardless of characteristics protected under the Equality Act 2010, including:
- Age;
- Disability;
- Gender reassignment;
- Marriage and civil partnership;
- Pregnancy and maternity;
- Race;
- Religion or belief;
- Sex;
- Sexual orientation.
4. Our Commitments
TSOR Med will:
- Promote equal opportunities;
- Prevent discrimination;
- Challenge inappropriate behaviour;
- Support accessibility;
- Treat users fairly.
5. Prohibited Behaviour
Users must not engage in:
- Direct discrimination;
- Indirect discrimination;
- Harassment;
- Victimisation;
- Discriminatory recruitment practices.
6. Accessibility
TSOR Med aims to make the Platform accessible by:
- Considering accessibility requirements;
- Improving usability;
- Supporting reasonable adjustments where possible.
7. Reporting Concerns
Concerns regarding discrimination should be reported:
Email: support@tsormed.co.uk
All reports will be treated seriously.
8. Enforcement
Breaches may result in:
- Investigation;
- Warnings;
- Restrictions;
- Suspension;
- Removal from the Platform.
7. Incident Reporting Policy
1. Purpose
This policy explains how TSOR Med identifies, manages and learns from incidents affecting:
- Patient safety;
- Users;
- Personal data;
- Platform operations;
- Service quality.
2. Types of Incidents
Incidents may include:
Clinical Incidents
- Unsafe practice;
- Professional misconduct;
- Safeguarding concerns.
Data Incidents
- Unauthorised access;
- Loss of information;
- Data breaches.
Platform Incidents
- System failures;
- Security issues;
- Payment errors.
User Conduct Incidents
- Harassment;
- Fraud;
- Inappropriate behaviour.
3. Reporting an Incident
Reports should include:
- Date and time;
- People involved;
- Description;
- Evidence available;
- Immediate risks.
Reports should be submitted to: support@tsormed.co.uk
4. Incident Management Process
TSOR Med may:
- Record the incident.
- Assess severity.
- Contain immediate risks.
- Investigate the cause.
- Take corrective action.
- Record lessons learned.
5. Serious Incidents
Serious incidents may be escalated to:
- Healthcare organisations;
- Regulators;
- Law enforcement;
- The Information Commissioner's Office (ICO);
- Other relevant authorities.
6. Learning and Improvement
TSOR Med uses incident reviews to improve:
- Systems;
- Policies;
- Training;
- Platform controls.
8. Business Continuity & Disaster Recovery Policy
1. Purpose
This policy establishes how TSOR Med maintains service availability during unexpected disruption.
2. Potential Disruptions
Events may include:
- Cyber attacks;
- System outages;
- Supplier failure;
- Data loss;
- Infrastructure failure;
- Natural disasters;
- Major public events.
3. Business Continuity Objectives
TSOR Med aims to:
- Protect user information;
- Maintain essential Platform services;
- Minimise disruption;
- Restore services quickly;
- Communicate clearly with users.
4. Critical Services
Critical Platform functions include:
- User authentication;
- Booking management;
- Compliance verification;
- Messaging;
- Payment processing;
- Customer support.
5. Backup and Recovery
TSOR Med maintains appropriate measures including:
- Regular backups;
- Secure data storage;
- Recovery procedures;
- System monitoring.
6. Incident Response
During a major disruption, TSOR Med may:
- Activate response procedures;
- Assign incident managers;
- Communicate with affected users;
- Work with suppliers;
- Restore services.
7. Third-Party Providers
Where critical services rely on third parties, TSOR Med expects providers to maintain appropriate:
- Security controls;
- Resilience measures;
- Recovery plans.
8. Testing and Review
Business continuity arrangements are reviewed periodically to ensure they remain effective.
9. Communication
During significant disruption, updates may be provided through:
- Email;
- Platform notifications;
- Website announcements.
Questions about this document? Email support@tsormed.co.uk and we will send you a copy.
Aidstar Limited trading as TSOR Med · Company number 16026627