Personal Information:
GDPR (General Data Protection Regulation 2018) introduced new legal protection for personal information. This explains your rights, and what personal information I hold and why.
Data Controller Contact Details: Tara Ledger, 07917 818235, ICO registration reference: ZB719442
Client Data:
I will be collecting and retaining confidential and personal information as part of your treatment. This information will be stored confidentially and retained securely as per conditions of GDPR. If you wish to read more regarding GDPR please click on the link: UK GDPR guidance and resources | ICO
Lawful Basis for holding and using Client Information
As a member of the Nursing and Midwifery Council (NMC) I abide by the professional code and standards. As a member of the Association of Reflexologists, I abide by the AoR Code of Practice and Ethics. The lawful basis under which I hold and use your information is my legitimate interests for example to provide you with the best treatment and advice. By managing confidential health information (Special Category Data) I am governed and practice under the AoR Code of Practice and Ethics and the NMC code 2018.
Retaining Information:
As part of the clinical reflexology treatments, I will keep information about your:
This information will be retained abiding by the GDPR standards detailed below:
1) Lawfulness, fairness and transparency - I will ensure that the processing of your data is complaint with GDPR. I will not share your information with anyone else (other than within my own practice, or as required for legal process) without explaining why it is necessary, and getting your explicit consent.
2) Purpose Limitation - Your personal data will only be used for your reflexology treatments.
3) Data Minimisation - I will not collect any information that is not necessary or relevant to your treatments.
4) Accuracy - With the information provided by you, I will keep your data updated.
5) Storage Limitation - I will retain your personal information for 8 years if you are an adult, and 25 years if you are a child (records to be kept until the child is 25 or if 17 when treated then 26, as per the Children's Act 1989.) Your data will not be transferred outside the EU without your consent.
Protecting Your Personal Data
I am committed to ensuring that your personal data is secure. In order to prevent unauthorised access or disclosure, I have put procedures in place to safeguard and secure the information I collect from you.
I will contact you using the contact preferences you provide for:
Your Rights
GDPR gives you the following rights:
Full details of your rights can be found at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.
If you wish to exercise any of these rights, please use the contact details given above.
If you are dissatisfied with the response you can complain to the Information Commissioner's Office; their contact details are at: www.ico.org.uk
TLC HEALTH LTD RIGHTS