Security and trust
Joy is used across the NHS to connect people with social prescribing and preventative care. We take information governance and data security seriously, and we maintain comprehensive assurance documentation to support procurement and information-governance review.
Our trust centre
Our DPIA, sub-processor list, security policies, and other assurance documents are held in our dedicated trust centre, maintained by Assuric. This is the authoritative source for procurement and IG review.
Visit the Joy trust centreData protection
Pungo Ltd (trading as Joy) acts as a data processor on behalf of NHS and local authority customers, and as a data controller for our own business operations. We are registered with the Information Commissioner's Office (ICO).
We apply appropriate technical and organisational measures to protect personal data from unauthorised access, disclosure, or loss. Access to personal data is restricted to authorised personnel with a legitimate business need, and all processing is governed by our data processing agreements with customer organisations.
Contact our data protection team
For questions about data protection, to submit a data subject rights request, or to raise an information-governance concern, please contact our data protection team:
dataprotection@explorejoy.co.uk
Privacy Notice
For full details of how Joy collects, uses, and stores personal data, please read our Privacy Notice.
