Privacy Policy
Collingwood Ear Care - Data protection policy
Collingwood Ear Care is committed to ensuring the privacy and security of client data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy outlines our approach to handling, storing, and processing personal data collected during home visits for ear irrigation services.
This policy applies to all employees, contractors, and service providers of Collingwood Ear Care who have access to client data. It covers data collected, processed, and stored through Cliniko, and any other relevant systems.
Data Collection and Processing
We collect and process the following types of personal data:
- Client Personal Information: Name, address, date of birth, contact details.
- Medical Information: Relevant health history, ear care treatment records, and assessment details.
- Payment Information: Invoices and transaction records processed.
- Appointment Records: Scheduling and clinical notes stored in Cliniko.
Lawful Basis for Processing
We process personal data under the following legal bases:
- Consent: Clients provide explicit consent for data collection and processing.
- Contractual Obligation: Data is necessary for providing healthcare services.
- Legal Obligation: Compliance with healthcare and financial regulations.
- Legitimate Interest: Ensuring quality of care and business operations.
Data Security Measures
To protect personal data, we implement the following safeguards:
- Secure Systems: Cliniko is used for secure record-keeping and financial transactions.
- Device Security: Laptops, tablets, and mobile devices used for accessing client records are password-protected and encrypted.
- Access Control: Only authorised personnel have access to sensitive client data.
- Data Minimisation: Only essential data is collected and stored.
- Regular Backups: Data is backed up securely to prevent loss.
Data Retention
- Client records are retained for a minimum of 8 years in accordance with healthcare guidelines.
- Financial records are retained for 6 years as per HMRC requirements.
- Data no longer required will be securely deleted or anonymized.
Data Sharing
- Client data is not shared with third parties unless required for medical referrals, legal compliance, or client request.
- Any data sharing will be conducted securely and with appropriate safeguards.
Client Rights
Clients have the right to:
- Access their personal data.
- Request corrections to inaccurate data.
- Request data deletion where applicable.
- Restrict or object to processing under certain conditions.
- Data portability upon request.
- File a complaint with the Information Commissioner’s Office (ICO) if they believe their data is mishandled.
Data Breach Policy
In case of a data breach:
- The incident will be assessed and documented.
- Affected individuals and the ICO will be notified within 72 hours if the breach poses a risk to client rights.
- Corrective actions will be implemented to prevent future breaches.
Policy Review
This policy will be reviewed annually or upon changes to relevant data protection laws.
Contact Information
For data protection inquiries, clients can contact Collingwood Ear Care at 07716451597.