PRIVACY POLICY- BEE IN HARMONY FOOT CARE & REFLEXOLOGY
Under the above regulation we are required to inform you of certain information regarding the data we keep along with rights you have.
Dawn & John Powell Bee in Harmony Foot care & Reflexology
33 Wood Lane, Pelsall, Walsall, West Midlands, WS35DY
01922 683328, Dawn 07846 169545, John 07989 409256
The categories of personal Data obtained
CUSTOMER DATA – Name, address, telephone numbers, Date of Birth, GP Name & Address, medical history, treatment notes including appointment dates
The purpose of processing
To safely & effectively undertake foot health/reflexology treatment
The lawful Basis of processing
Article 6(b) Contract – the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. Article 9(a) the data subject has given explicit consent to the processing of those personal data for one or more specified purposes.
The Source of the Personal Data
Data is provided by the data subject
Who is the Data shared with
Data may be shared with Bee in Harmony associates, the clients GP or other medical professional
Details of Transfers of the Personal Data to any Third countries or International Organisations
None
The Retention Periods for the Personal Data
All Personal Data will be retained for 7 years after the clients last appointment, or to age 25 in the case of a minor. After this time all Personal Data will be incinerated.
Data Breaches
We will report any data breach within 72 hours of becoming aware, where feasible. If the breach is likely to result in a high risk of adversely affecting individual’s rights and freedoms, we will also inform the individuals affected without undue delay. We will record all personal data breaches, regardless of whether we are required to notify.
Right of Access
Individuals (Data subjects) have the right to access their personal data and supplementary information. We are required to provide you a copy within one month. To request access to your personal data please do so in writing.
Rights of Rectification
Individuals have the right to request that inaccurate personal data is rectified or completed if it is incomplete. An individual can make a request for rectification verbally or in writing.
Right of Erasure
Individuals have the right of erasure. All personal data will be retained for 7 years after the clients last appointment or to a min age of 25 in the case of a minor. This is for protection in case of the establishment, exercise or defence of a legal claim. However we may be able to erase minimal data such as personal phone numbers. Please do so in writing.
Right to Restrict Processing
Individuals have the right to request the restriction or suppression of their personal data except when needed for protection in case of establishment, exercise or defence of legal claim. Please do so in writing.
Right to Data Portability
Individuals have the right to Data portability. This allows individuals to obtain and reuse their personal data for their own purposes across other services. Should you wish to request this please do so in writing. This will be provided within one month.
Right to Withdraw Consent
Individuals have the right to withdraw consent. However if consent is withdrawn we will be unable to perform any further treatments. Additionally, all personal data will be retained for 7 years after the customer’s last appointment or to a minimum age of 25 in the case of a minor. This is for protection in case of the establishment, exercise or defence of legal claims. However we may be able to erase minimal data such as phone numbers. Please contact us in writing if you wish to request the withdrawal of consent.
The Right to Lodge a Complaint with a supervisory Authority
If you have a concern in the way we are handling your personal information you may contact the Information Commissioner’s Office and report your concerns. This can be done online at https://ico.org.uk/concerns/handling/ or by telephoning the ICO on 030