Body ReNewell Health and Wellbeing
2 Forty Green Courtyard, Forty Green, Bledlow, Bucks. HP27 9PN
This notice applies to all clients of Body ReNewell and clients treated by other Practitioners/Therapists at the Body ReNewell premises.
Body ReNewell Health and Wellbeing is aware of its obligations under UK data protection legislation, and is committed to processing your data fairly, lawfully and transparently. This privacy notice sets out, in line with current data protection obligations, the types of data that we hold on you, how we use that information, how long we keep it for and other relevant information.
Data controller details
Claire Newell, as owner of Body ReNewell, is the data controller, meaning that she determines the processes to be used when using your personal data. She can be contacted at firstname.lastname@example.org. She has received training on data protection legislation and regularly refreshes this training.
Where you are treated by another Practitioner/Therapist at the Body ReNewell premises, that Practitioner/Therapist will also be a data controller and you should contact them directly to understand how they collect and process your personal data.
Data protection principles
In relation to your personal data, we will:
- collect your data only for valid reasons and clearly explain what we will use it for
- process it fairly, lawfully and in a clear, transparent way
- only use it in the ways that we have told you about
- ensure it is correct and up to date
- keep your data for only as long as we need it
- process it in a way that ensures it will not be used for anything that you are not aware of or have consented to (as appropriate), or be lost or destroyed
Types of data we process
We may hold many types of data about you, including:
- Personal identification details such as name and date of birth
- Personal contact details such as address, phone numbers and email address
- Completed medical history questionnaires (see below for information about Special Category Data)
- Notes made by the relevant Practitioner/Therapist following an appointment with you
If you use our website, we may also hold data such as
- Browser and hardware data, such as IP address, type of device, operating system, browser type, screen resolution, language, device make and model, as well as the versions of the above mentioned services.
- Cookie and tracking technology data, which would include pages visited, time spent on pages, language preferences, and other anonymous traffic data.
How we collect and store your data
The personal data we collect and process will be collected directly from you or from the relevant Practitioner/Therapist. All this data will be held within our practice management application (Cliniko).
Why we process your data
We process your personal data in order to enable you to book appointments with your Practitioner/Therapist and for your Practitioner/Therapist to keep records of your medical history and your appointments, to support effective treatment and for legal reasons.
If you are currently a client of one of the Practitioners/Therapists working from the Body ReNewell premises then the lawful basis for us retaining and using your personal data will be necessity to perform the contract with you.
If you have had an appointment in the past then the lawful basis for us retaining your personal data will be legitimate interest.
Special categories of data
Special category data is personal data that needs more protection because it is sensitive.
- Special category data relating to your: health
- sex life
- sexual orientation
- race or ethnic origin
- religion or philosophical belief
- political opinions
- trade union membership
- genetic and biometric data
Special categories of data must be processed in accordance with more stringent guidelines.
Body ReNewell will process health information about you within the medical history questionnaires you complete and in notes made by the relevant Practitioner/Therapist following an appointment with you. The purpose of this is the provision of health care or treatment to you and we only collect what data is necessary in the particular circumstances.
Completed medical history questionnaires, and any notes made by your Practitioner/Therapist are stored within the Cliniko system. Your Practitioner/Therapist may also keep notes outside the system - this would be covered by their own Privacy Notice.
Sharing your data
Within Body ReNewell your personal data will be accessed and processed only by Claire Newell. As the owner and director of Body ReNewell, Claire Newell has access to all data stored within the Cliniko application.
Other than Claire Newell, the only people who can access your personal data within the Cliniko application are:
- the Practitioners/Therapists that you have appointments with - each Practitioner/Therapist can only see the medical history questionnaires you complete for them and the notes they make themselves following an appointment with you (not any questionnaires you may complete for other Practitioners/Therapists or notes that other Practitioners/Therapists may make following appointments)
- our Bookkeeper - who can only see the information required to issue invoices to you and reconcile payments
Externally to Body ReNewell, your data will not be shared with any third parties other than through the data being stored within the Cliniko application.
However, we may be required to share your data with third parties to comply with a legal obligation upon us.
Protecting your data
We are aware of the requirement to ensure your personal data is protected against accidental loss or disclosure, destruction and abuse. We have implemented appropriate technical and organisational measures to ensure the security of your personal data.
We have conducted an appropriate assessment of the Cliniko application and believe it to be suitably secure for the purposes for which we use it.
Access to the Cliniko application is controlled through user accounts. Users are only permitted to see the data that is necessary for their role. Strong passwords and two factor authentication are in place to secure access to the applications. Practitioners/Therapists are required to ensure that devices and networks used to access the Cliniko application are secured through strong passwords or PINs. Accessing the Cliniko application via unsecured WiFi connections is not permitted.
How long we keep your data for
In line with data protection principles, we only keep your data for as long as we need it, which will be a period of 7 years following your last appointment at Body ReNewell, for accounting and legal purposes. Once your data is no longer needed, it will be securely deleted from the Cliniko application.
If you do not provide your data to us
As the reason for processing your data is to allow you to have appointments with Practitioners/Therapists at the Body ReNewell premises, if you do not agree to provide us with the data needed to do this, we will be unable to provide you with any appointments.
Your rights in relation to your data
The law on data protection gives you certain rights in relation to the data we hold on you. These are:
- the right to be informed - this means that we must tell you how we use your data, and this is the purpose of this privacy notice
- the right of access - you have the right to access the data that we hold on you - to do so, you should make a subject access request directly to Claire Newell
- the right have any inaccuracies corrected - if any data that we hold about you is incomplete or inaccurate, you are able to require us to complete or correct it - to do so, you should contact Claire Newell
- the right to have information deleted - if you would like us to stop processing your data, you have the right to ask us to delete it from our systems where you believe there is no valid reason for us to continue processing it - however, if we need to keep your data for financial or legal reasons then we will be unable to delete it
- the right to restrict the processing of the data - in certain circumstances, you have the right to ask us to restrict the processing of your data
- the right to portability - in certain circumstances, you have the right to ask that we transfer the data that we hold on you to you or another organisations
- the right to object to the inclusion of any information - you have the right to object to the way we use your data where we are using it for our legitimate interests
Where you have provided consent to our use of your data, you also have the unrestricted right to withdraw that consent at any time. Withdrawing your consent means that we will stop processing the data that you had previously given us consent to use. There will be no consequences for withdrawing your consent. However, in some cases, we may continue to use the data where so permitted by having a legitimate reason for doing so.
However, we would like to clarify that the lawful basis for you providing your personal data to us is not consent. You provide us with your personal data in order that we can provide you with access to appointments with Practitioners/Therapists at the Body ReNewell premises and those Practitioners/Therapists can provide you with appropriate treatment.
If you wish to exercise any of the rights explained above, please contact Claire Newell at email@example.com.
Making a complaint
If you have any questions or concerns about how your personal data is used by Body ReNewell then please contact Claire Newell at firstname.lastname@example.org to discuss this.
The supervisory authority in the UK for data protection matters is the Information Commissioner’s Office (ICO). If you think your data protection rights have been breached in any way by us, you are able to make a complaint to the ICO.