Privacy Statement, Cookies and GDPR

Beech Tree Therapies Cornwall Reflexology

 
124870150_2478840722418273_5659736415329

 YOUR PERSONAL INFORMATION - GENERAL DATA PROTECTION REGULATION (GDPR)

GDPR (implemented by DPA2018 in the UK) brought in new legal protection for personal information. This document describes:

  • About Me

  • The purpose of processing Client Data - what personal data I collect

  • Lawful basis for holding and using client information

  • What information I hold and what I do with it

  • Other reasons I may hold information and why, and use of third party organisations, including Cookies and Analytics

  • Use of Personal Information and security of information:

  • How long I retain your information for

  • Protecting your personal data

  • Your right's and your right to object

  • Therapists rights

  • Consent

About Me:

My name is Rachel Waller, I am a Clinical Reflexologist. I am the owner and Data Controller for Beech Tree Therapies. 

Contact details: Mobile - 07500337466 or email info@beechtreetherapiescornwall.co.uk.  I manage my own Wix website.

This document is effective from 9th April 2021

The Purpose of processing Client Data - what personal data I collect:

My policy is to keep the personal information I receive from this website completely confidential and used solely for internal processes.  I will not share your personal information with any other parties.  Please review this statement carefully.

In order to provide professional reflexology treatments, I will need to gather and retain potentially sensitive information about your health. I will only use this information for informing reflexology treatments and associated recommendations concerning aspects of health and well-being, which I will offer to you.

Personal data is any information which identifies you personally, for example, your name. This Privacy statement is concerned with the personal data for the following:

  • My Reflexology clients and those who enquire about treatments

  • Users of this website who sign up to the email newsletter

  • Customers who may purchase Gift Vouchers through my website, using Paypal which is an approved secure method.

  • Data collected when an order is placed via the shop page

Lawful Basis for holding and using Client Information

As a full member of the Association of Reflexologists, I abide by the AoR Code of Practice and Ethics. The lawful basis under which I hold and use your information is my legitimate interests i.e.my requirement to retain the information in order to provide you with the best possible treatment options and advice.  As I hold special category data (i.e. health related information), the Additional Condition under which I hold and use this information is: for me to fulfil my role as a health care practitioner bound under the AoR Confidentiality as defined in the AoR Code of Practice and Ethics.

What information I hold and what I do with it

In order to provide professional reflexology treatments, I will need to ask for, and keep information about your health. I will only use this for informing reflexology treatments and any advice I give as a result of your treatment. The information to be held is:

  • Your full contact details for Reflexology treatments

  • Medical history and other health-related information (which I will take from you at first consultation)

  • Treatment details and related notes (which I will take after each consultation)

  • If you provide information prior to your appointment and then decide not to proceed to treatment, I will securely erase this information.

  • When a treatment is booked, all Reflexology clients will be required to sign a Privacy Notice under GDPR guidelines.  This will be provided to you at your first appointment.

Other reasons I may hold information and why, and use of third party organisations: 

  • Neal's Yard:  As a Neal's Yard consultant I display a link to my consultant shop on its website. Neal's Yard processes orders taken via this shop and dispatch them to customers.  As a NY Consultant I receive information about the order placed and items purchased, and the customer contact details. This information is held securely after I receive it and it is not used for marketing purposes.  Please refer to the Neal's Yard Privacy policy.

  • Paypal:  I will collect your contact details when you purchase a Reflexology Gift Voucher through my website.  If you are purchasing the Gift Voucher for someone else I will also collect their contact details, as recipients of the Gift Voucher. I use Paypal to process Gift Voucher payments.  I would advise you to read PayPal's own Privacy policy before using its website.

  • Cookies: Like many websites, I use Cookies to enhance your experience and gather information about visitors and visits to my website.  My website uses Cookies.  I use Wix to create and update my website.  Registered members need a cookie to be able to log in. I do not use these types of cookies for visitors to my website. Visitors who may leave a comment on a blog will have a cookie set up on their computer, however this is a visitor's choice whether or not to leave a comment.

  • Third Party Cookies: These are installed by third parties (including Google Analytics) with the aim of collecting information to carry out research into the behaviour and demographics to my website.  I do not gather personal information which could be used to identify visitors or their personal data. 

  • Third Party Links:  This website does contain links to the following websites: Neals Yard Remedies and Zone Face Lift - Ziggie Bergman and professional bodies.

  • Mailerlite: If you subscribe to my newsletter, this is managed by a 3rd party website Mailerlite.  Your email address is not shared with any other party.  You can unsubscribe at any time by clicking on the unsubscribe link or by contacting me directly. I recommend that you read Mailerlite's own Privacy Policy before entering your email address in the sign up box.

  • Wix:  I use a third-party service, Wix to publish my website.  I use a standard Wix service to collect anonymous information about user's activity on the website. For example, the number of users viewing pages on this website, to monitor the effectiveness of the website and help us to improve it.  Wix requires that visitors to my website that wish to post a comment enter their name and address.

  • Google Analytics:  I use Google Analytics on my website.  From this I may collect certain information about your visit, such as the type of browser you use, the date and time you accessed the website, the pages you access whilst visiting this website and the web address from which you linked to my website.  I only use this for statistical analysis purposes, to help improve and administer the website, it will not be shared with any other parties.  This information is only processed in a way which does not identify visitors.  I do not make, and do not allow Google to make any attempt to find out the identities of those visiting my website.  I recommend that you read Google's own privacy policy.

Use of Personal Information and security of information:

  • To quickly process transactions of items purchased via the shop page and deliver them to the correct address

  • To deliver Gift Vouchers purchased, to the recipient of the Gift Voucher

  • To publish comments on any blogs, submitted by the user as requested.  If at any time you wish to remove a comment from a blog please contact me, stating the comment you would like to remove and this will be done for you within 14 days of your request.

  • To improve and administer the website

  • You may choose to restrict the collection or use of your personal information by contacting me directly.

 

I will NOT share your information with anyone else without explaining why it is necessary, and getting your explicit consent.  

How Long I Retain Your Information for

I will keep your information for the following periods: 

  1.  ‘claims occurring’ insurance: (records to be kept for 7 years after last treatment)

  2. law regarding children’s records (records to be kept until the child is 25 or if 17 when treated, then 26)

  3. CNHC requirements to retain information for 8 years

Protecting Your Personal Data 

I am committed to ensuring that your personal data is secure. In order to prevent unauthorised access or disclosure, I have put in place appropriate technical, physical and managerial procedures to safeguard and secure the information we collect from you.

I will contact you using the contact preferences you give me in relation to: 

  • Appointment times                                                                                       

  • Reflexology information or information related to your health  

  • Special offers and promotions   (you may unsubscribe from this at any time)

Your Rights - GDPR gives you the following rights:

  • The right to be informed:
    To know how your information will be held and used (this notice).

  • The right of access:
    To see your therapist’s records of your personal information, so you know what is held about you and can verify it.

  • The right to rectification:
    To tell your therapist to make changes to your personal information if it is incorrect or incomplete.

  • The right to erasure (also called “the right to be forgotten”):
    For you to request your therapist to erase any information they hold about you

  • The right to restrict processing of personal data:.
    You have the right to request limits on how your therapist uses your personal information

  • The right to object:

  • To be able to tell your therapist you don’t want them to use certain parts of your information, or only to use it for certain purposes.

  • Rights in relation to automated decision-making and profiling.

  • The right to lodge a complaint with the Information Commissioner’s Office:
    To be able to complain to the ICO if you feel your details are not correct, if they are not being used in a way that you have given permission for, or if they are being stored when they don’t have to be.  I am registered with the Information Commissioner's Office.

Full details of your rights can be found at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/.

If you wish to exercise any of these rights, please use the contact details given above. If you are dissatisfied with the response you can complain to the Information Commissioner's Office; their contact details are at:  www.ico.org.uk

Therapist's Rights:

Please note:

  • if you don’t agree to your therapist keeping records of information about you and your treatments, or if you don’t allow them to use the information in the way they need to for treatments, the therapist may not be able to treat you  

  •  Your therapist has to keep your records of treatment for a certain period  as described above, which may mean that even if you ask them to erase any details about you, they might have to keep these details until after that period has passed

  • Your therapist can move their records between their computers and IT systems, as long as your details are protected from being seen by others without your permission.

Consent:

By using this website, you consent to this Privacy Statement.