Security Statement
Last Updated: September 2026
Our approach to protecting personal, compliance and operational information.
1. Security Principles
- Access to personal information is limited according to operational need and role.
- Users should only be able to access information necessary for the service being provided to them.
- Authentication and account controls are used to protect platform access.
- Data transmitted through the website and platform is protected using appropriate encrypted connections.
- Security-relevant activity is monitored and investigated where appropriate.
- Back-ups and recovery arrangements are maintained according to the requirements of the services used.
- Technology suppliers are assessed as part of Evergreen's data-protection and security governance.
2. Role-Based Access
- A locum should have access to their own profile and documents.
- A practice should receive only the information necessary for a booking and compliance verification.
- Evergreen personnel receive operational or compliance access appropriate to their role.
- One locum is not given access to another locum's private compliance documents.
3. Information Requiring Particular Care
This includes identity and right-to-work information, DBS records, immunisation and occupational health information, GDC and professional registration information, indemnity records, addresses, payment information, location information, booking history, messages, assignment-specific safety information and practice information.