PRIVACY NOTICE
(JANE SINGLETON REFLEXOLOGY)
YOUR PERSONAL INFORMATION – GENERAL DATA PROTECTION REGULATION (GDPR)
The GDPR, effective from 25 May 2018, relates to legal protection for personal information. This document tells you what personal information I hold and why, and what your rights are. This also includes any personal information I gather through my website, outlining why it is gathered and what your rights are. If you are reading this on my website, you consent to its contents. If you have an appointment to receive a service from me, once you have read this Privacy Statement please complete and sign the declaration at the bottom of this document.
Therapist’s Name/Identity: Jane Singleton Reflexology
Therapist’s Contact Details:
Telephone No: 07787 566034
Email address: hello@janesingletonwellbeing.co.uk
Address: 130 Manor Road, Barton Seagrave, Kettering, NN15 6WD
Data Controller Contact Details: Jane Phillips (Founder of Jane Singleton Reflexology)
Data Protection Officer (as above)
The purpose of processing Client Data
If you contact me by email, ‘phone, ‘What’s App’, via my website contact form/newsletter sign-up form, or any other social media platforms, or via my Neal’s Yard shop, you will be providing me with personal information (e.g. name, telephone number, email address, home address) and possibly sensitive information about your current or past health and wellbeing. This information will only be used to allow enquiry to be dealt with/order to be processed, contact you and confirm future appointments. Sensitive information will only be requested in order to fulfil my role as a healthcare practitioner, bound under the Association of Reflexologist’s confidentiality as defined in its Code of Practice and Ethics. Any data relating to enquires that do not proceed to an appointment will be erased where I am able to do so.
In order to give professional treatments, if you confirm an appointment with me, I will need to gather and retain sensitive information about your health. I will only use this information for informing treatments and associated recommendations concerning aspects of health and wellbeing which I will offer to you. You will be required to read and sign a copy of this Privacy Notice before/at your appointment.
Lawful Basis for holding and using Client Information
As a member of the Association of Reflexologists (AoR), I abide by the AoR Code of Practice and Ethics. The lawful basis under which I hold and use your information is my legitimate interests (i.e. my requirement to retain the information in order to provide you with the best possible treatment options and advice).
As I hold special category data (i.e. health related information), the Additional Condition under which I hold and use this information is: for me to fulfil my role as a health care practitioner bound under the AoR Confidentiality as defined in the AoR Code of Practice and Ethics.
What information I hold and what I do with it
In order to handle your initial enquiry and give professional treatments, I will need to ask for and keep information about your health. I will only use this information to inform treatments and any advice I give as a result of your treatment. The information to be held is:
- Your contact details
- Medical history and other health-related information (some of which you may share with me via your initial contact with me, but the majority of which I will take from you at our first consultation)
- Treatment details and related notes (which I will take after each consultation)
I will NOT share your information with anyone else (other than within my own practice, or as required for legal process) without explaining why it is necessary, and getting your explicit consent.
If you visit my website, please be advised that ‘cookies’ are used to enhance visitor experience and gather information about visits/visitors. I also use Google Analytics to collect information about your visit which helps me to analyse website traffic to help me make improvements to my website. Data collected is processed in a way which means that individual visitors cannot be identified (more info below under ‘Third Party Services’).
If you sign-up to be added to my email list, I will only use your email to send you newsletters and details of event etc. You can unsubscribe at any time. Please note that this list will be managed by either the third party website ‘MailerLite’ or ‘MailChimp’ (see below under ‘Third Party Services’).
How long I retain your Information for
I will keep your information for the following periods
- for 7 years after your last treatment (for claims occurring insurance purposes)
- if treatment related to a child, until the child is 25 or if 17 when treated, then 26 (legal requirement)
Third Party Services
I personally will not transfer your data outside the EU without your consent, although you need to be aware that I do use third party services as part of my operations. These are:
Email & Website – My email and website hosting are provided by Heart Internet, arranged via my website designer, Red2design. Both are UK based companies & have their own Privacy Statements on their website which can be found at https://www.heartinternet.uk/terms/heart-internet-privacy-statement & https://www.red2design.co.uk/privacy-statement/ . These organisations do not hold any personal data on my behalf. My website has been created using ‘WordPress’ and it uses cookies. Please refer to the cookie policy at the bottom of my website for more information about what cookies are and how they are used on my website.
OnlineBooking facility – 10to8.com – if you choose to make a booking using this facility (either via me directly at the end of your appointment or independently via my website), you should refer to 10to8.com’s Privacy Policy before doing so to ensure you are comfortable with its approach to handling your data.
Electronic Payment – I offer the use of SumUp for card payments which holds all its Merchant Data in the European Union. Full details of its privacy policy can be found here: https://help.sumup.com/hc/en-gb/articles/360004703114-GDPR-SumUp-and-your-data
Paypal & Internet banking – if you choose to make payments via these methods, please refer to Paypal’s and your own bank’s privacy policies before making these payments.
Facebook, Instagram – If you choose to contact me through Social Media, or interact with me via my Facebook Group/s, you should refer to Facebook and Instagram’s Privacy Policies before doing so.
Neal’s Yard Remedies – As a consultant for Neal’s Yard Remedies, I display a third party link to my consultant shop on my website, and social media pages and any subsequent orders are processed by Neal’s Yard directly. Once an order is placed I then receive information about the order, including customer contact details, items ordered and the order value via email which is then stored securely by me and not used for any other purpose. Please refer to Neal’s Yard Remedies own Privacy policy before placing an order.
MailerLite and/or MailChimp – I use these service to manage my email lists for those who have signed up to receive a newsletter, product or service. Please refer to MailerLite’s & MailChimp’s own Privacy Policies before providing your email address.
Google Analytics – please refer to Google’s Privacy Policy for more information.
Please be aware that the internet is not a secure environment and assurance cannot be guaranteed with regard to the security of any information beyond the precautions set out within this and the above privacy referenced privacy statements for the third party services I access.
Protecting Your Personal Data
I am committed to ensuring that your personal data is secure. In order to prevent unauthorised access or disclosure, I have put in place appropriate technical, physical and managerial procedures to safeguard and secure the information we collect from you.
I will contact you using the contact preferences you give me in relation to:
- Appointment times/reminders
- Information about my therapies and/or information related to your health
- Special offers, promotions and updates via an e-newsletter (you may unsubscribe from this at any time)
Your Rights
GDPR gives you the following rights:
- The right to be informed:
To know how your information will be held and used (this notice). - The right of access:
To see your therapist’s records of your personal information, so you know what is held about you and can verify it. - The right to rectification:
To tell your therapist to make changes to your personal information if it is incorrect or incomplete. - The right to erasure (also called “the right to be forgotten”):
For you to request your therapist to erase any information they hold about you - The right to restrict processing of personal data:.
You have the right to request limits on how your therapist uses your personal information - The right to data portability: under certain circumstances you can request a copy of personal information held electronically so you can reuse it in other systems.
- The right to object:
To be able to tell your therapist you don’t want them to use certain parts of your information, or only to use it for certain purposes. - Rights in relation to automated decision-making and profiling.
- The right to lodge a complaint with the Information Commissioner’s Office:
To be able to complain to the ICO if you feel your details are not correct, if they are not being used in a way that you have given permission for, or if they are being stored when they don’t have to be.
Full details of your rights can be found at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
If you wish to exercise any of these rights, please use the contact details given above.
If you are dissatisfied with the response you can complain to the Information Commissioner’s Office; their contact details are at: www.ico.org.uk
My ICO certificate number is: ZA398305, which is renewed annually on 24th May.
THERAPIST’S RIGHTS
Please note:
- If you don’t agree to your therapist keeping records of information about you and your treatments, or if you don’t allow them to use the information in the way they need to for treatments, the therapist may not be able to treat you
- Your therapist has to keep your records of treatment for a certain period as described above, which may mean that even if you ask them to erase any details about you, they might have to keep these details until after that period has passed
- Your therapist can move their records between their computers and IT systems, as long as your details are protected from being seen by others without your permission.
This notice was created on 24 May 2018 and this is the third version, updated 11 July 2020.
CONSENT & DECLARATION
If you are reading this document on my website, you consent to this Privacy Notice.
If you are receiving a service from me, please read and sign the following declaration:
I have seen this document and understand that you will hold and use my personal information, using it in order to provide me with the best possible treatment options and advice in line with the statements above.
I have received a copy of this document.
Name:
Date:
Signature: ……………………………………………..
Note: for children under 16 a parental or guardian signature is required.