Legal

GDPR and Privacy Policy

Colleen Balston Physiotherapy is committed to protecting your privacy and will process your personal information in accordance with GDPR, UK data protection, and other current legislation. We want to be clear and transparent about what data we collect, how we collect it, how it is processed and protected. We are registered with the Information Commission to process personal data. Our registration number is ZC243077.

What data do we collect?

1.

If you visit our website and make an enquiry, we will collect your name and email address along with any other information you provide, such as telephone number and reason for contacting us. Under GDPR we have a legitimate interest to process this information, as with data subjects who have become clients, under the provision of healthcare. The information you provide on the contact form is only used to contact you and is stored in your file along with any information provided by email or over the phone if you become a client. If you don’t become a client, the information from the contact email and any phone calls is deleted. Data provided by you on the contact form is encrypted until it reaches our server.

2.

If you visit our website then anonymous statistical information about your visit will be collected to assist us in understanding how our site is used, this is captured and managed using cookies. We also use Google analytics to monitor visitor numbers, they may gather your IP address, location and device information. Google analytics information is only used to monitor the use of our website and not for any other purpose, it is stored on Google servers. You can opt not to have your data captured for analytical purposes via your browser settings or add-on.

3.

Your personal information is processed (i.e. collected, recorded, stored, retrieved, etc) for the purposes of ensuring accurate identity and safe medical & therapeutic intervention and is limited to what is necessary. We are permitted to process your personal information, including sensitive information for healthcare provision and to meet our legal and healthcare regulations.

4.

It may be necessary for your treatment, health and safety to share information with valid colleagues, such as GPs and other health professionals, unless this is specifically and expressly denied by you, the client.

5.

Data, including medical and treatment notes, may be retained indefinitely for the purposes of ensuring the client’s safe and adequate medical intervention and for legal purposes in any future medical claims.

6.

When video consultations are offered these will be done using third party software, such as Zoom which is hosted in the USA but is part of the Privacy Shield Scheme. No recording of the session will take place without expressed consent of the other party. You can read the GDPR policy, or privacy and security policy on the third parties’ website.

7.

The collection and processing by Colleen Balston Physiotherapy of personal information, your condition for which you seek treatment, lifestyle and medical history is legitimate and fully necessary under the GDPR and UK Law for the purposes outlined in part 1.

8.

We ask that you, the client, notifies Colleen Balston, the Data Controller, as soon as is reasonably possible of any change in personal data, e.g. email, home address, phone numbers, so your personal data and medical history remain secure and is not at risk of being sent to a third party.

9.

Financial data is not stored on any of our systems, payments are made online through a third-party payment service (Stripe), the only financial data we record is the name and amount paid.

How is your data processed?

1.

Treatment and medical notes may be written electronically or on paper and kept in a secure location within the physiotherapy clinic to protect against unauthorised, unlawful access and/or accidental loss, destruction or damage.

2.

Medical & personal information (name, address, email, referral source, occupation and hobbies, payment and payment methods) is stored electronically on the clinic’s computer, is password/digital ID protected and has antivirus protection with Norton Security.

3.

Data is regularly backed securely up to Microsoft’s secure OneDrive.

4.

Telephone numbers may also be kept electronically on a mobile phone, accessed by passcode or facial recognition.

5.

Emails containing personal data & medical information may also be transferred to a secure hard drive.

6.

Personal & medical data passed by email will be password protected.

Why we need your data

1.

We have a legal obligation to process and store your data as it is essential for the provision of our healthcare service.

2.

We have a legal obligation to keep your data as medical records of our care. This all helps us provide the most effective service for you. We will process your information in line with what is set out in this privacy policy and in accordance with GDPR guidelines for providing health or social care or treatment, under our statutory legal obligations, in the event of any legal claims, and where appropriate with your consent.

How we use your information

1.

To provide you with our healthcare service.

2.

We will use your information to provide treatment and to contact you, this includes to remind you of your appointment and emailing practices/exercises.

3.

Your information is not passed to third parties except in relation to your care, and as specified above unless any overriding lawful reason exists for sharing this and is usually only done with your consent wherever possible.

4.

It is important data is accurate and up to date, we will do our utmost to ensure it is, however, you must also advise of any changes to your circumstances whilst you are a client at Colleen Balston Physiotherapy.

How is your data stored and security?

1.

Your data is stored on a locked computer, backed up onto a password protected external drive and cloud storage which is also password protected and meets GDPR requirements. Emails are downloaded and stored with your client file and then the email is deleted. Text messages are stored on a locked phone.

2.

Whilst we always aim to keep your data within the UK, or EU, this may not always be possible. For example, we utilise some exercise management platforms to assist you with doing your exercises and these may be hosted outside the EEA. Your name, email and list of recommended exercises is the only data held on these sites. We will only use sites that can demonstrate adequate security to protect your information.

Cookies

1.

Use of HTTP cookies: HTTP cookies are small blocks of information created by your web server while browsing our website. More than one cookie may be placed on your device during your visit. We may use these cookies to gather information about your device to assist us in improving our website and your online experience while on our website.

2.

Cookies are used for statistical purposes and do not identify personal details.

3.

You have the right and ability to adjust your device settings to decline the use of cookies.

Accessibility

1.

We are committed to ensuring our website is accessible to all users, regardless of ability or technology.

2.

We aim to provide a positive online experience for everyone, including people with visual, hearing, motor, or cognitive impairments.

3.

If you encounter any accessibility barriers while using our site or have suggestions for improvement, please contact us at [email protected]

Direct marketing and publicity

1.

We would like to stay in touch with you to provide general information that can help you look after your health and wellbeing, keep you up to date with any changes in our service, and generally send you information which the GDPR labels as direct marketing. We will only do this with your permission.

2.

To keep clients and subscribers up to date with information we will use a third-party email broadcast company which may be outside of the EEA, we will ensure that they have adequate technical and organisation measures in place to protect the information. Subscribers can change their preferences at any time by clicking on the unsubscribe link in any email broadcast or simply email us at [email protected] and you will be removed from our broadcast list.

3.

If you give a testimonial, we will attribute this to you in a way you choose although we don’t usually state your full name. At any time, you can withdraw your consent, but any testimonial or case study used in hardcopy marketing materials or already indexed by search engines may be difficult to stop.

Links to other websites

1.

Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.

2.

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

3.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.

Your rights

You, the client, has certain rights to access, rectify, erase, restrict, transfer and/or object to your personal data. Such requests should be made in writing and may have a one calendar month response time limit. We strive to respond to all legitimate requests within one month. In some cases, particularly if your request is complex or if you have made multiple requests, it may take us longer than a month to respond. In such cases, we will notify you and keep you informed.

Questions

If you have any concerns or questions, please contact the Data Controller at:
Colleen Balston