Elemental Balance is the data controller: elemental.balance.with.hannah@gmail.com. This means we decide how your personal data is processed and for what purposes.
The purpose of this policy is to inform you about what information we collect about you, what we will do with this information, how we will store it, and how long we will keep it. The data we collect is for the purposes of your treatment and for communication directly with you for treatment or booking purposes. We do not share your data with 3rd parties unless legally obliged and do not use your data for marketing purposes.
How do we process your personal data?
We comply with our obligations under the GDPR by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorised access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data. We use your personal data for the purposes set out below.
Information we collect
- We collect contact details (full name, phone number, and email) in order to communicate with you regarding appointments plus a named contact in case of emergency.
- We collect relevant health details and any information disclosed by you as relevant to your treatments with us in order to plan and review treatments.
- We use your GP’s name and phone number in the event that we need to contact your GP in an emergency.
Storage and destruction of sensitive information
- All of your personal information is kept securely in electronic form with appropriate security settings (app permissions and passwords).
- Any paper notes from treatment sessions are added to an electronic record and are shredded immediately after.
- Emails are encrypted but you will be responsible for checking that you are happy with the privacy of your own email provider.
- We are required by our insurance company to store your treatment information for 7 years after which it will be securely deleted/destroyed. You have the right to see your records but we are unable to delete records until the requisite period has passed as instructed by our insurer. .
Confidentiality
- All conversations with you are strictly confidential.
- We will not share your information with anyone else unless it is with your written permission (for example, if you wish us to communicate with your GP or another professional) or there is a legal or ethical duty for us to disclose information. These situations include: if you may cause serious harm to yourself or others, when instructed by a court to disclose information, when any criminal activity, or knowledge of any criminal activity is revealed. These exceptions to confidentiality are in place to ensure your safety and the safety of others and to comply with the law. We would hope never to break confidentiality without speaking to you first, however, this may not be legally possible in every situation.
Your rights and your personal data
You have certain rights with respect to your personal data as set out below.
- The right to request a copy of your personal data which we hold about you.
- The right to request that we correct any personal data if it is found to be inaccurate or out of date.
- The right to request your personal data is erased where it is no longer necessary for us to retain such data. Please be aware that not all information can be erased because it is necessary to keep information to establish, exercise and defend legal claims.
- The right to request that we provide you with your personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability), (where applicable) [This right only applies where the processing is based on consent or is necessary for the performance of a contract with you and in either case we are processing the data by automated means].
- The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing.
- The right to be informed if your data is lost. We shall also inform the Information Commissioner’s Office in accordance with the time limits in the GDPR.
- The right to lodge a complaint with the Information Commissioner’s Office. For further details about these rights please visit the Information Commissioner’s website.
Contact Details – to exercise all relevant rights, queries or complaints please in the first instance contact us at elemental.balance.with.hannah@gmail.com
Policy reviewed March 2024.