Cotswold Chiropractic wants to make sure you're completely confident in the skills and services of our team. Please take a look at our policies below and don't hesitate to contact our Cheltenham clinic if you have any questions.
GENERAL POLICY
Coronavirus is thought to be primarily spread between people who are in close contact with one another (within about 2 metres), through respiratory droplets produced when an infected person coughs or sneezes. The virus is also thought to be passed on through surface transmission, when touching a surface or object that has some respiratory droplets on it and then touching your own face, mouth, nose, eyes, or someone else. Our risk assessment for transmission of coronavirus within Cotswold Chiropractic therefore addressed both close contact between individuals and touch of surfaces that may occur. Our policy for risk reduction is to implement measures to remove, minimise or mitigate each of the identified areas of risk.
POLICY FOR PATIENTS AND OTHER VISITORS
CLINICIANS AND OTHER STAFF
Last amended 2nd May 2018
We are committed to protecting and respecting your privacy. This Privacy Policy sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
1.1 We take your privacy seriously and this privacy policy (Privacy Policy) sets out how we will handle your personal data securely and in accordance with your rights.
1.2 Cotswold Chiropractic Limited (we, us, our) is a registered data controller under the terms of the Data Protection Act 1998. Details of our notification to the data protection regulator may be found in the Information Commissioner’s Office Public Register of Data Controllers at ico.org.uk. Our registered office address is at Stoke Road, Bishops Cleeve, Cheltenham, Gloucestershire, GL52 8RP.
1.3 Our Data Protection Officer is: Nicola Matthews.
2.1 This Privacy Policy explains what information we collect about you when you:
How we handle your information in respect of our agreement with you to provide information or advice that you request, to manage patient registrations and bookings that you request, to provide chiropractic clinical care that you request and related clinical management functions (together, our Services) to ensure that we protect your rights.
2.2 Please read this Privacy Policy carefully to understand how we will treat your personal data. In this Privacy Policy, references to you or you shall mean you as a user of our Services.
2.3 By using the Website and/or our Services you will be regarded as having accepted the terms of this Privacy Policy. Please do not use the Websites or our Services if you do not agree to the terms of this Privacy Policy.
3.1 All website users
When you use our website, information collected may include:
IP addresses
We may collect information about your computer, including where available your IP address, operating system and browser type, for system administration and to report aggregate information to our advertisers. This is statistical data about our users’ browsing actions and patterns, and does not identify any individual.
Cookies
Our Site uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our Site. For detailed information on the cookies we use and the purposes for which we use them see our Cookie Policy.
3.2 Prospective patients or general enquiries about services
When you use the website and / or our Services we may ask you to provide certain information such as, your name, date of birth and contact details (including your address, email address, and contact telephone number), along with information that you give us about the nature of your enquiry. Unfortunately, the transmission of information via the internet is not completely secure. Although we employ security measures designed to protect your personal data, we cannot guarantee the security of your data transmitted to our Site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
3.3 All Patients
When you first register as a patient with us, either online or by providing information to our reception staff or clinicians, your name, date of birth, contact details and details of any appointments made will be entered into the patient database and diary provided by our secure, hosted practice management system*. Information relating to further appointments will be collected on an ongoing basis within the system.
*Some non-chiropractor clinicians who practise on-site may not utilise our patient registration and bookings service. In this instance, your registration and booking-related data will not be collected and processed by Cotswold Chiropractic and the relevant clinician will be the Data Controller for any registration or booking information that they may collect from you themselves. Our receptionists will advise you of this, should you contact us to enquire, register or make a booking
3.3.1 Chiropractic patients
When you consult one of our chiropractors, clinical information will be collected, including that relating to your symptom(s), our assessment of the condition(s) for which you are seeking care, general health and medical history, any treatment given, clinical advice or information given or discussed. Accounts, billing and payment information will also be collected
3.3.2 Patients receiving non-chiropractic treatments
Cotswold Chiropractic does not collect, process or store any clinical information or accounts, billing or payment information for consultations with practitioners who work on-site, other than its chiropractors. Any non-chiropractor clinician that you see on-site may collect further personal, clinical or accounts, billing and payment data about you. They are the ‘Data Controller’ for any such information and as such are responsible for meeting requirements for the protection of that data.
3.3.3 Sensitive personal information**
Chiropractic patients: In order to provide you with chiropractic clinical services, information collected may include data relating to your physical or mental health, which the Data Protection Act 1998 (DPA 1998) and the General Data Protection Regulation (GDPR) regards as sensitive or special categories of personal data. We do not collect information for other sensitive or special categories of personal data. By providing data relating to your physical or mental health to us for the purposes of providing our Services, you will signify your explicit consent to such Sensitive Data being processed by us.
** Such as information relating to your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or sexual orientation (Background Information) and/or information relating to any criminal convictions you have or offences you may have committed (Criminal Records Information), Background Information and Criminal Records Information, together, being Sensitive Data
4.1 You have the right to be told the legal basis and purposes for the processing of your personal data. We are relying on your explicit consent to the processing of your personal data (including any Sensitive Data, as defined above). This means that if you exercise your right to withdraw your consent (please see paragraph 8 below) we will no longer be able to process your data. Please note we may retain a copy of your data in accordance with our Data Protection Policy, if necessary to fulfil legal obligations (including those for financial reporting or health records retention***)
*** HMRC requirements (see https://www.gov.uk/running-a-limited-company/company-and-accounting-records) or The Data Protection Act (see https://ico.org.uk/for-the-public/health/)
4.2 We may use your information for the following purposes:
Fulfilment of a contract (or agreement) with you:
Legitimate interests:
4.3 We do not process your personal data for the purpose of marketing or promotional activities, unless you specifically request that we do so or join any social media forum that we control.
4.4 We shall periodically check that the personal data we store for you is accurate. If you would like to update the personal data we hold about you, please contact us with your request using the contact details at paragraph 12, below or by logging-in to your patient registration account online and updating your personal details.
5.1 As part of using our Services, you consent to us sharing your personal information with the following parties:
5.2 We may also share your personal information with third parties:
5.3 We do not share your personal data with third parties for the purpose of any marketing or promotional activities.
6.1We will only transfer your personal data outside of the United Kingdom or EEA if necessary to enable us to communicate with you in relation to our Services, or should we contract any data processing services from companies that are registered outside of these areas. By providing us with your personal information, you agree that we may transfer, store and process your information in this manner.
6.2 We shall ensure that any such transfers outside of the United Kingdom and the EEA are lawful and with an adequate level of protection and that your personal is kept secure in accordance with the DPA 1998 (up to and including 24 May 2018) and the GDPR (from and including 25 May 2018).
We only store your personal information for as long as necessary for the purposes listed in paragraph 4.
8.1 You may exercise your rights below by contacting us using the contact details in paragraph 11 of this Privacy Policy.
8.2 Access to your personal data: You may request access to a copy of your personal data by contacting us using the contact details in paragraph 11.
8.3 Right to withdraw: You may withdraw your consent to us processing your personal data at any time. Please contact us using the details located at paragraph 11 if you would like to withdraw your consent and we will delete your data in line with your right to erasure at paragraph 8.5 below. Please note that in the event that you wish to exercise your rights under this paragraph 8.3, we may be unable to process your data any further or continue to provide our Services to you.
8.4 Rectification: You may ask us to rectify inaccurate information held about you. If you would like to update the data we hold about you, please contact us using the details in paragraph 11 or by logging-in to your online booking account and updating your registration information accordingly.
8.5 Erasure: You may ask us to delete your personal data. If you would like us to delete the personal data we hold about you, please contact us using the contact details in paragraph 11 and specify why you would like us to delete your personal data. Please note that in some instances we may have a legal obligation not to delete some parts of your personal data (See paragraph 4.1, above). Please note also that in the event that you wish to exercise your rights under this paragraph 8.5, we may be unable to process your data any further or continue to provide our Services to you.
8.6 Portability: You may ask us to provide you with the personal information that we hold about you in a structured, commonly used form or ask for us to send such personal data to another data controller by contacting us using the contact details in paragraph 11.
8.7 Right to object: You may object to our processing of your personal data pursuant to this Privacy Policy. Please contact us using the details in paragraph 11, providing details of your objection. Please note that in the event that you wish to exercise your rights under this paragraph 8.7, we may be unable to process your data any further or continue to provide our Services to you.
8.8 Make a complaint: You may make a complaint about our data processing activities to a supervisory authority, for the UK this is the Information Commissioner’s Office, at ico.org.uk.
9.1 We will treat all of your information in strict confidence and we will endeavour to take all reasonable steps to keep your personal data secure once it has been transferred to our systems. We adopt and ensure any third party suppliers providing services on our behalf adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorised access, alteration, disclosure or destruction of your personal information, and data stored on the Websites and associated databases.
9.2 Please note that the internet is not a secure medium and we cannot guarantee the security of any data you disclose online. You accept the inherent security risks of providing information and dealing online over the internet and will not hold us liable for any breaches of your data protection rights attributable to the transmission of your personal data over the internet.
10.1 We may modify this Privacy Policy from time to time, so please review it regularly.
10.2 If we change this Privacy Policy we shall notify you by means of a notice on our Website Privacy Policy page and/or by notices in our clinic reception.
10.3 This Privacy Policy was last amended on 2nd May 2018.
If you have any queries relating to this Privacy Policy or our use of your personal data or you wish to exercise any of your rights under this Privacy Policy please contact our privacy team at reception@cotswoldchiro.co.uk, stating ‘FAO Data Protection Officer’ in the subject field, or our Data Protection Officer by post at Cotswold Chiropractic, Stoke Road, Bishops Cleeve, Cheltenham, Glos, GL52 8RP.
Got any questions about our policies?