Privacy Notice for Patients – Children & Adults
What is a Privacy Notice?
Under data protection law you, as a patient of Corstorphine Chiropractic, have specific rights. To communicate these rights to you in a clear and concise manner, we are providing you with this privacy notice.
Who we are
We are Corstorphine Chiropractic, 1b Drum Brae Avenue, Edinburgh, EH12 8TE, telephone number 0131 339 9451, email address firstname.lastname@example.org. For the purposes of processing your personal data we are the Controller.
The Personal Data We Process
We record and use the following categories of personal data which include:
- Details about you, such as your address, contact details, date of birth, previous medical history and any previous investigations
- Any contact with the clinic has had with you, such as appointments, clinic visits, advice given over the phone or email, emergency appointments etc.
- Notes about your and/or your child’s health
- Details about your and/or your child’s treatment and care
- Relevant information from other health care professionals and health data relevant for treating you at our clinic.
Our lawful basis for storing and using this data is contract and we are allowed to store and use your health data as we are a recognised health care provider.
In addition, we only examine or treat you with your explicit consent.
How we store your personal information
The health care professionals, who provide your care, maintain records about your health and any treatment or care you have received here or previously. These records help provide you with the best possible health care. Our records are on paper, and all files are locked in filing cabinets, and the clinic is always locked out of working hours. We also use electronic diary, payment and mailing services. The providers have given written assurances that they are fully compliant with General Data Protection Regulations. All electronic data is password protected and either securely stored in “the cloud” or on a locked, encrypted hard drive.
How do we maintain the confidentiality of your records
We are committed to protecting your privacy and will only use information collected lawfully in accordance with:
- General Data Protection Rules 2018
- Human Rights Act 1998
- Common Law Duty of Confidentiality
- General Chiropractic Council Code of Conduct
Every member of staff who works at Corstorphine Chiropractic has a legal obligation to keep information about you confidential.
Retaining Your Personal Data
We will retain your data for a period of 8 years after your last treatment as this is a General Chiropractic Council (GCC) requirement of a registered Chiropractor in the UK
Who do we share your information with?
We only ever pass on information about you to others, if there is a genuine need for it and you have given your consent. This may be your GP, dentist or other health care professionals, a solicitor or for court proceedings.
We will not disclose any information about you to any third party without your written permission or in case of a child’s information the parental consent, unless there are exceptional circumstances (i.e. life or death situations), where the law requires information to be passed on.
Access to your personal information
As we process your personal data, you have certain rights. These are a right of access, a right of rectification, a right of erasure and a right to restrict processing.
- You may request a copy of your data at any time. Please make such a request in writing or by email to the clinic, whose details are shown above. Please provide the following information: your name, address, telephone number, email address and details of the information you require.
- If you believe any of the personal data we hold on you is inaccurate or incomplete, please contact us directly and any necessary corrections to your data will be made without undue delay.
- If you believe we should erase your data, please contact the clinic, whose details are shown above. If you wish us to stop storing or using your data, please contact the clinic, whose details are shown above.
- Where you have provided explicit consent for us to use your data you have a right to withdraw this consent at any time.
Should your personal data that we control be lost, stolen or otherwise breached, where this constitutes a high risk to your rights and freedoms, we will contact you without delay. We will give you the contact details of the person who is dealing with the breach, explain to you the nature of the breach and the steps we are taking to deal with it.
Should you have any concerns about how your information is managed at the clinic, please contact the clinic owner (Georgina Beckett) in the first instance. If your complaint is not resolved you have further recourse to the Scottish Chiropractic Association email@example.com. If the complaint remains unresolved, you then have the right to complain to the Information Commissioner’s Office via their website (www.ico.gov.uk)
Automated Decision Making and Profiling
We do not use any system which uses automated decision making or profiling in respect of your personal data.
How We Obtained Your Data
Your personal data has been collected directly from you, via our new patient registration form and health information given to the chiropractor.
22/05/2018 Version 1.1
1b Drum Brae Avenue Edinburgh EH12 8TE
Tel: 0131 399 9451
Company reg: SC567997