When you supply your personal details to this clinic they are stored and processed for 3 reasons:
1. We have a legal obligation to maintain medical notes in order to provide you with treatment.
2. We may contact you in order to confirm or remind you of your appointments with us or to update you on matters related to your medical care or settling your account. Under the GDPR, this is known as Legitimate Interest.
3. Again, provided we have your consent, we may occasionally send you general health information in the form of articles, advice or newsletters. This, too, constitutes “Legitimate Interest” under the GDPR.
We have a legal obligation to retain your records for 8 years after your most recent appointment (or age 25, if this is longer), but after this period you can ask us to delete your records if you wish. Otherwise, we will retain your records indefinitely in order that we can provide you with the best possible care should you need to see us at some future date.
Your records may be stored either:
- Electronically (“in the cloud”), using a specialist client management system – Cliniko Ltd. They have given us their assurances that they are fully compliant with the General Data Protection Regulations. Access to the Client Management System has 2 factor authentication, password protected, and the passwords are changed regularly.
- On my office laptop. These are password-protected, backed up regularly (at least weekly), and kept in the treatment room.
- On paper, in my treatment room at my home practice. I rarely keep paper documentation and if I receive any document from you I endeavour to scan it and file it either ‘in the cloud’ on my client management system and on my computer. The paper copy is either returned to you or shredded using a cross cutter shredder.
- My treatment room is part of my home and not accessible to the general public. The treatment room is locked when I am away from my home overnight or if visitors are staying.
We will never share your data with anyone who does not need access without your written consent. Only the following people/agencies will have routine access to your data:
The client Management Company who electronically store and process our files
My off-site reception staff – Ideal Receptionist Ltd, because they organise my clinic diary, and co-ordinate appointments (they only have access to limited information to allow them to schedule and amend appointments but they do not have access to your medical history, sensitive personal information or treatment notes).
Your practitioner – in order that they can provide you with treatment