TSOR MedGet the app
← All legal documents

Governance and Compliance

1. Modern Slavery Statement

1. Introduction

TSOR Med is committed to preventing slavery, human trafficking, forced labour, and exploitation within our business operations and supply chains.

We recognise our responsibility to promote ethical practices and protect the rights, dignity, and wellbeing of all individuals who interact with our Platform.

This statement is prepared in accordance with the principles of the Modern Slavery Act 2015.

2. Our Business

TSOR Med operates a healthcare workforce technology platform connecting verified healthcare professionals with healthcare organisations.

Our platform supports:

  • Doctors
  • General Practitioners
  • Pharmacists
  • Nurses
  • Dentists
  • Dental Nurses
  • Allied Health Professionals
  • NHS organisations
  • Private healthcare providers
  • Community healthcare organisations

3. Our Commitment

TSOR Med has zero tolerance for:

  • Slavery;
  • Human trafficking;
  • Forced labour;
  • Exploitation;
  • Unlawful employment practices.

We expect all employees, contractors, suppliers, Clients and healthcare professionals using our Platform to share these standards.

4. Risk Assessment

Potential risks may include:

  • Exploitation of temporary workers;
  • Fraudulent recruitment practices;
  • Identity fraud;
  • Illegal employment;
  • Inappropriate deductions or payments;
  • Vulnerable workers being subjected to pressure or coercion.

5. Controls and Prevention

TSOR Med reduces risk through:

  • Identity verification;
  • Right-to-work checks;
  • Professional registration checks;
  • Employer verification;
  • Monitoring suspicious activity;
  • Secure payment processes;
  • Complaints mechanisms;
  • Reporting channels.

6. Reporting Concerns

Anyone who suspects modern slavery or exploitation connected with the Platform should report concerns:

Email: support@tsormed.co.uk

Reports may be handled confidentially.

Where necessary, concerns may be reported to appropriate authorities.

7. Training and Awareness

TSOR Med will promote awareness among staff and relevant partners regarding:

  • Identifying exploitation;
  • Reporting concerns;
  • Ethical recruitment practices.

8. Review

This statement will be reviewed annually.

Approved by: Fahmida Zannat Chowdhury, Director, AidStar trading as TSOR Med.

Date: 19 August 2026

2. Information Security Policy

1. Purpose

This policy establishes the approach TSOR Med takes to protecting:

  • Personal information;
  • Healthcare-related information;
  • Professional documents;
  • Payment information;
  • Platform systems.

2. Security Objectives

TSOR Med aims to maintain:

Confidentiality

Only authorised persons can access information.

Integrity

Information remains accurate and protected from unauthorised modification.

Availability

Systems remain available and reliable for users.

3. Information Security Principles

TSOR Med follows:

  • UK GDPR requirements;
  • Data Protection Act 2018;
  • Privacy by design principles;
  • Industry security practices;
  • Risk-based security controls.

4. Access Control

TSOR Med uses:

  • Role-based access controls;
  • Least privilege principles;
  • Secure authentication;
  • Multi-factor authentication where appropriate;
  • Access reviews.

Employees and contractors only receive access necessary for their role.

5. Data Protection Measures

Security measures may include:

  • Encryption;
  • Secure databases;
  • Encrypted communications;
  • System monitoring;
  • Vulnerability management;
  • Backup systems;
  • Audit logging.

6. Staff Responsibilities

All personnel must:

  • Protect confidential information;
  • Use secure passwords;
  • Report security concerns;
  • Complete security training;
  • Follow access policies.

7. Incident Management

Security incidents include:

  • Unauthorised access;
  • Lost devices;
  • Data breaches;
  • Malware;
  • Phishing;
  • System compromise.

All incidents must be reported immediately.

8. Third-Party Security

Suppliers providing:

  • Payment processing;
  • Identity verification;
  • Hosting;
  • Software services;

must demonstrate appropriate security controls.

9. Business Continuity

TSOR Med maintains procedures to support service recovery following:

  • Cyber incidents;
  • Infrastructure failure;
  • Operational disruption.

10. Review

This policy is reviewed periodically to reflect:

  • Technology changes;
  • Regulatory developments;
  • Security risks.

3. Data Processing Agreement (DPA)

1. Purpose

This Data Processing Agreement governs how personal data is processed between TSOR Med and organisations using the Platform.

This Agreement forms part of the wider contractual relationship between TSOR Med and Clients.

2. Roles of the Parties

Depending on the processing activity:

  • TSOR Med may act as a Data Processor;
  • TSOR Med may act as a Data Controller;
  • Clients may act as Data Controllers.

The applicable role depends on the purpose and nature of processing.

3. Processing Activities

TSOR Med may process information relating to:

  • Healthcare professionals;
  • Employees;
  • Contractors;
  • Authorised representatives;
  • Compliance records;
  • Booking information.

4. Types of Personal Data

Processing may include:

  • Identity information;
  • Contact details;
  • Professional registration information;
  • DBS information;
  • Right-to-work information;
  • Payment information;
  • Employment history;
  • Verification records.

5. Special Category Data

Where applicable, processing may include:

  • Professional information;
  • Occupational health information;
  • Regulatory information.

Appropriate safeguards will be applied.

6. Processor Obligations

Where acting as Processor, TSOR Med will:

  • Process data only on documented instructions;
  • Maintain confidentiality;
  • Implement security measures;
  • Assist with data subject requests;
  • Support compliance obligations;
  • Notify Clients of relevant breaches.

7. Sub-processors

TSOR Med may use trusted sub-processors for:

  • Hosting;
  • Payments;
  • Verification;
  • Identity checking;
  • Communications;
  • Security services.

TSOR Med remains responsible for appropriate supplier management.

8. Data Breaches

TSOR Med will:

  • Investigate suspected breaches;
  • Take reasonable mitigation measures;
  • Notify affected parties where required by law.

9. International Transfers

Where data leaves the UK, appropriate safeguards will be implemented, including:

  • Adequacy decisions;
  • Approved contractual safeguards;
  • Other lawful mechanisms.

10. Data Retention and Deletion

Personal data will be retained only as long as necessary.

Following termination of services, data will be securely deleted or returned where legally permitted.

11. Audit Rights

Clients may request reasonable information demonstrating TSOR Med's compliance with applicable data protection obligations.

12. Governing Law

This Agreement is governed by the laws of England and Wales.

4. Clinical Governance Policy

1. Purpose

TSOR Med is committed to supporting safe, effective, and high-quality healthcare workforce solutions.

This Clinical Governance Policy establishes the framework through which TSOR Med promotes:

  • Patient safety;
  • Professional accountability;
  • Regulatory compliance;
  • Continuous improvement;
  • Safe workforce engagement.

2. Scope

This policy applies to:

  • TSOR Med employees;
  • Contractors;
  • Healthcare professionals using the Platform;
  • Healthcare organisations engaging professionals through the Platform.

3. Role of TSOR Med

TSOR Med operates as a technology marketplace and does not directly provide clinical services.

TSOR Med does not:

  • Diagnose patients;
  • Supervise clinical decisions;
  • Replace employer clinical governance systems.

Clinical responsibility remains with:

  • The healthcare professional delivering care; and
  • The healthcare organisation responsible for the service.

4. Professional Standards

Healthcare professionals using TSOR Med must comply with applicable professional standards, including:

  • GMC Good Medical Practice;
  • GPhC Standards for Pharmacy Professionals;
  • NMC Code;
  • GDC Standards for the Dental Team;
  • HCPC Standards of Conduct, Performance and Ethics.

Professionals must:

  • Work within competence;
  • Maintain professional registration;
  • Maintain confidentiality;
  • Prioritise patient safety;
  • Report concerns appropriately.

5. Verification and Credentialing

TSOR Med supports safe recruitment through verification of:

  • Professional registration;
  • Identity;
  • Right to work;
  • DBS checks where applicable;
  • References;
  • Relevant documentation.

Verification does not replace the Client's responsibility to complete local recruitment checks.

6. Clinical Incidents

Where concerns arise regarding:

  • Patient safety;
  • Professional misconduct;
  • Unsafe practice;
  • Regulatory concerns;

TSOR Med may:

  • Investigate;
  • Request information;
  • Suspend access;
  • Notify relevant organisations or regulators where appropriate.

7. Continuous Improvement

TSOR Med reviews:

  • User feedback;
  • Complaints;
  • Incidents;
  • Platform performance;
  • Compliance trends.

Lessons learned may be used to improve Platform processes.

5. Safeguarding Policy

1. Purpose

TSOR Med is committed to safeguarding vulnerable individuals who may receive healthcare services through professionals engaged via the Platform.

Safeguarding means protecting individuals from:

  • Abuse;
  • Neglect;
  • Exploitation;
  • Harm;
  • Inappropriate treatment.

2. Scope

This policy applies to:

  • Healthcare professionals;
  • Healthcare organisations;
  • TSOR Med staff;
  • Contractors.

3. Types of Abuse

Safeguarding concerns may include:

  • Physical abuse;
  • Emotional abuse;
  • Sexual abuse;
  • Neglect;
  • Financial abuse;
  • Discriminatory abuse;
  • Organisational abuse;
  • Exploitation.

4. Responsibilities of Healthcare Professionals

Professionals must:

  • Recognise safeguarding concerns;
  • Follow employer safeguarding procedures;
  • Report concerns promptly;
  • Maintain accurate records;
  • Cooperate with investigations.

5. Responsibilities of Employers

Healthcare organisations remain responsible for:

  • Safeguarding systems;
  • Training;
  • Policies;
  • Reporting pathways;
  • Compliance with CQC requirements where applicable.

6. Reporting Safeguarding Concerns

Concerns should be reported immediately through:

  • The relevant healthcare organisation;
  • Appropriate safeguarding authority;
  • Emergency services where there is immediate danger.

TSOR Med may be notified where concerns relate to Platform users or activities.

7. Recruitment Safeguards

TSOR Med supports safeguarding through:

  • Identity verification;
  • DBS checks where required;
  • Professional registration checks;
  • Reference checks;
  • Monitoring concerns.

8. Zero Tolerance

TSOR Med does not tolerate behaviour that places patients or vulnerable people at risk.

Concerns may result in:

  • Suspension;
  • Investigation;
  • Removal from the Platform;
  • Referral to regulators or authorities.

6. Equality, Diversity & Inclusion Policy

1. Purpose

TSOR Med is committed to creating a fair, inclusive and respectful healthcare workforce marketplace.

We believe everyone should be treated with dignity and respect regardless of background or personal characteristics.

2. Scope

This policy applies to:

  • Candidates;
  • Employers;
  • Healthcare organisations;
  • TSOR Med employees;
  • Platform users.

3. Protected Characteristics

TSOR Med supports equality regardless of characteristics protected under the Equality Act 2010, including:

  • Age;
  • Disability;
  • Gender reassignment;
  • Marriage and civil partnership;
  • Pregnancy and maternity;
  • Race;
  • Religion or belief;
  • Sex;
  • Sexual orientation.

4. Our Commitments

TSOR Med will:

  • Promote equal opportunities;
  • Prevent discrimination;
  • Challenge inappropriate behaviour;
  • Support accessibility;
  • Treat users fairly.

5. Prohibited Behaviour

Users must not engage in:

  • Direct discrimination;
  • Indirect discrimination;
  • Harassment;
  • Victimisation;
  • Discriminatory recruitment practices.

6. Accessibility

TSOR Med aims to make the Platform accessible by:

  • Considering accessibility requirements;
  • Improving usability;
  • Supporting reasonable adjustments where possible.

7. Reporting Concerns

Concerns regarding discrimination should be reported:

Email: support@tsormed.co.uk

All reports will be treated seriously.

8. Enforcement

Breaches may result in:

  • Investigation;
  • Warnings;
  • Restrictions;
  • Suspension;
  • Removal from the Platform.

7. Incident Reporting Policy

1. Purpose

This policy explains how TSOR Med identifies, manages and learns from incidents affecting:

  • Patient safety;
  • Users;
  • Personal data;
  • Platform operations;
  • Service quality.

2. Types of Incidents

Incidents may include:

Clinical Incidents

  • Unsafe practice;
  • Professional misconduct;
  • Safeguarding concerns.

Data Incidents

  • Unauthorised access;
  • Loss of information;
  • Data breaches.

Platform Incidents

  • System failures;
  • Security issues;
  • Payment errors.

User Conduct Incidents

  • Harassment;
  • Fraud;
  • Inappropriate behaviour.

3. Reporting an Incident

Reports should include:

  • Date and time;
  • People involved;
  • Description;
  • Evidence available;
  • Immediate risks.

Reports should be submitted to: support@tsormed.co.uk

4. Incident Management Process

TSOR Med may:

  1. Record the incident.
  2. Assess severity.
  3. Contain immediate risks.
  4. Investigate the cause.
  5. Take corrective action.
  6. Record lessons learned.

5. Serious Incidents

Serious incidents may be escalated to:

  • Healthcare organisations;
  • Regulators;
  • Law enforcement;
  • The Information Commissioner's Office (ICO);
  • Other relevant authorities.

6. Learning and Improvement

TSOR Med uses incident reviews to improve:

  • Systems;
  • Policies;
  • Training;
  • Platform controls.

8. Business Continuity & Disaster Recovery Policy

1. Purpose

This policy establishes how TSOR Med maintains service availability during unexpected disruption.

2. Potential Disruptions

Events may include:

  • Cyber attacks;
  • System outages;
  • Supplier failure;
  • Data loss;
  • Infrastructure failure;
  • Natural disasters;
  • Major public events.

3. Business Continuity Objectives

TSOR Med aims to:

  • Protect user information;
  • Maintain essential Platform services;
  • Minimise disruption;
  • Restore services quickly;
  • Communicate clearly with users.

4. Critical Services

Critical Platform functions include:

  • User authentication;
  • Booking management;
  • Compliance verification;
  • Messaging;
  • Payment processing;
  • Customer support.

5. Backup and Recovery

TSOR Med maintains appropriate measures including:

  • Regular backups;
  • Secure data storage;
  • Recovery procedures;
  • System monitoring.

6. Incident Response

During a major disruption, TSOR Med may:

  • Activate response procedures;
  • Assign incident managers;
  • Communicate with affected users;
  • Work with suppliers;
  • Restore services.

7. Third-Party Providers

Where critical services rely on third parties, TSOR Med expects providers to maintain appropriate:

  • Security controls;
  • Resilience measures;
  • Recovery plans.

8. Testing and Review

Business continuity arrangements are reviewed periodically to ensure they remain effective.

9. Communication

During significant disruption, updates may be provided through:

  • Email;
  • Platform notifications;
  • Website announcements.

Questions about this document? Email support@tsormed.co.uk and we will send you a copy.

Aidstar Limited trading as TSOR Med · Company number 16026627