Legal notice

Name of Practice

SWA CHILDREN'S PHYSIOTHERAPY & HANDWRITING SERVICES

 

Practice Manager

Sally Wright MCSP HCPC Chartered Physiotherapist

 

Office

8 Burnley Road

LONDON NW10 1EB

 

Contact details 

Tel: 020 82081361

E-mail: swatherapy@sky.com

Fax:

 

 VAT number

702 2813 75

 

SWA DATA PROTECTION POLICY:

Introduction:

SWA has updated our policy concerning the collection, storage and other use of personal data under the Data Protection Act 1998 (DPA) and the General Data Protection Regulations (GDPR). Data Protection Law requires us to meet at least one “legal ground” for processing, currently set out in Article 6 of the GDPR. For the purpose of the DPA and GDPR we are the data controller and enquiries regarding any data held by us should be addressed to SWA, 8 Burnley Road, Dollis Hill, London NW10 1EB. We are registered with the Information Commissioner’s Office for this purpose. This notice (together with any terms of use on our website, any contracts between us and any other documents referred to in this notice) sets out the basis on which any personal data we collect from you, that you provide to us, or that we obtain about you from other sources, will be processed by us.

Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. By visiting our website, or by providing us with any personal data, you are accepting and agreeing to the practices described in this notice.

What data do we collect, process and store and why do we hold it?

  1. Information you give us:  

This is information about you / your child that you give us, for example completed registration forms or handwriting classes booking forms; providing information on our website or by phone / email or otherwise or by providing us with documents. The information you give us may include your name, your child’s name and date of birth, address, e-mail address and phone number, copies of reports relevant to that enquiry and Health and Safety information.  

The personal data (name; dob; address, telephone nos and emails) we collect, process and hold is used primarily to enable us to contact our clients about matters pertaining to appointments, non confidential treatment advice, equipment advice and invoicing.  We have a secure invoicing system with Preori Ltd and generally use emails and text to communicate non-confidential information such as confirmation and changes of appointments. Health and Safety information is used for health and safety purposes.

We may also use your personal contact data for the following purposes:

  1. To contact you about future handwriting groups if you have attended a previous course or made a previous enquiry about the courses.
  2. To provide information on other parties’ products or services that you have requested or the therapist feels may be helpful to your child such as equipment, footwear, other therapies.
  3. Information we collect about you / your child:

This includes information such as medical reports, educational psychology reports, educational /school reports, EHCP documents and /or correspondence sent to us by other professionals about your child.

We require this information in order to more fully assess your child’s needs and to provide a safe, effective, relevant physiotherapy and / or handwriting service to your child. 

 

  1. Other Information we hold about you / your child:

We create and store physiotherapy assessment reports, physiotherapy case notes and contributions to EHCP.

You would usually be sent a copy of any physiotherapy reports we prepare for you about your child and can ask for copies of any other data we hold.

 

Disclosure of your information:

We may copy / share confidential information with other professionals directly involved with your child if this benefits their treatment ,safety and well being – this with your consent and through secure channels such as Egress or post. 

We have a duty to disclose information we hold about your child in Child Safeguarding issues. We can do this without necessarily informing you first.

We would only disclose your information to regulatory bodies to enable us to comply with the law and to assist fraud protection and minimise credit risk.

We do not disclose sensitive personal data, such as race, religion, or political affiliations, without your explicit consent.

We may disclose your personal data outside of our group: (a) in the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets; and (b) if SWA’s business is bought by a third party, in which case personal data held by it about its customers will be one of the assets to transfer to the buyer.  However any such transfer will only be on terms that the confidentiality of your personal data is protected and that the terms of this privacy policy will continue to be complied with by the recipient and would require your consent.

Otherwise, we will process, disclose or share your personal data only if required to do so by law or in the good faith belief that such action is necessary to comply with legal requirements or legal process served on us or the website.

Controlling the use of your data:

Clients will have the opportunity to withhold consent to us using your data when you register with us or by completing consent form. You can revoke or vary any consent given or withhold consent at any time by writing to us at the address detailed above or email us at swa-admin@sky.com at any time.

Storage of data:

All records are destroyed securely once your child is 25 years of age or, 8 years after death.

Paper records are kept under lock and key.

Electronic records are kept securely on passworded hardware.

We use Egress secure email to send confidential information.

Our invoicing system is secure.

Emails re appointments or non-confidential data are usually sent via regular email / text.

Web site:

We will collect personal data on this Website only if it is directly provided to us by you the user, e.g. your e-mail address, name, home or work address and telephone number, and therefore has been provided by you with your consent. Normally you will only provide such details if you wish to find out about our courses/physiotherapy treatments.

Your payment information (e.g. credit card details) provided when you make a purchase from our website is not received or stored by us. That information is processed securely and privately by the third party payment processors that we use. Sally Wright Associates will not have access to that information at any time. We may share your personal data with our payment processors, but only for the purpose of completing the relevant payment transaction. Such payment processors are banned from using your personal data, except to provide these necessary payment services to us, and they are required to maintain the confidentiality of your personal data and payment information

Security of Data:

The transmission of information via the Internet or email or text / Smart phone apps is not completely secure.  We will do our best to protect your personal data but we cannot guarantee the security of data while you are transmitting it to our site / email  or via mobile; any such transmission is at your own risk.  Once we have received your personal data, we will use procedures and security features to try to prevent unauthorised access.

Where we have given you (or where you have chosen) a password so that you can access certain correspondence/parts of our site, you are responsible for keeping this password confidential.  You should choose a password it is not easy for someone to guess.

Information provided through our website may be transferred to and stored in countries outside of the European Economic Area (EEA) as we use remote website server hosts to provide the website and some aspects of our service, which may be based outside of the EEA, or use servers based outside of the EEA - this is generally the nature of data stored in “the Cloud”.  It may also be processed by staff operating outside the EEA who work for one of our suppliers, e.g. our website server host, or work for us when temporarily outside of the EEA.

A transfer of your personal data may happen if any of our servers are located in a country outside of the EEA or one of our service providers is located in a country outside of the EEA. If we transfer or store your personal data outside the EEA in this way, we will take steps with the aim of ensuring that your privacy rights continue to be protected, as outlined in this privacy policy and in accordance with the DPA and GDPR. If you use our service while you are outside the EEA, your personal data may be transferred outside the EEA in order to provide you with these services.

We do not keep medical information on either our invoicing system or our web site – only your personal contact information and dates of treatment.

Use of cookies:

Our Website uses cookies. We use cookies to gather information about your computer for our services and to provide statistical information regarding the use of our Website. Such information will not identify you personally - it is statistical data about our visitors and their use of our Website. Information about your general Internet use may also be gathered using a cookie file. Where used, these cookies are downloaded to your computer automatically. This cookie file is stored on the hard drive of your computer, as cookies contain information that is transferred to your computer's hard drive. They help us to improve our Website and the service that we provide to you via our web site. All computers have the ability to decline cookies. This can be done by activating the setting on your browser which enables you to decline the cookies. Please note that should you choose to decline cookies, you may be unable to access particular parts of our Website.

Your rights:

You have the right to access information held about you / your child by us. You can request confirmation of what personal information we hold relating to you and also can request copies of the information we hold about you. You can do this by writing to us at the address detailed above or by email to swa-admin@sky.com. There is no charge for requesting confirmation about what information we hold, but we may charge you for photocopying and post for sending medical and therapy notes we hold. We will provide this information within one month of your requesting the data.

You have the right to change the permissions that you have given us in relation to how we may use your data. You also have the right to request that we cease using your data or that we delete all personal data records that we hold relating to you. You can exercise these rights at any time by writing to us at the address above, or by email to swa-admin@sky.com

Information we hold about employees and self employed staff:

We hold details of pre-employment checks such as copies of proof of identity, DBS numbers, curriculum vitae and references. We are required to collect and hold this information to protect our clients. Schools that our employees / self employed staff work in hold copies of proof of identity and have their own data protection policies.

Updating data protection policy:

We may update these policies to reflect changes to the website, customer feedback and /or changes to the law. Please regularly review these policies to be informed of how we are protecting your personal data.

We welcome any queries, comments or requests you may have regarding this Privacy Policy. Please do not hesitate to contact us at SWA, 8 Burnley Road, Dollis Hill, London NW10  or swa-admin@sky.com

Complaints:

We hope there will be no reason to complain about our data protection policy and practices, but if you wish to raise a complaint either telephone us on 020 8208 1361 or write to us at SWA, 8 Burnley Road, Dollis Hill, London NW10  or email us on swa-admin@sky.com

 

Sally WRIGHT Lead Physiotherapist and Practice Manager

MCSP HCPC Chartered Physiotherapist

25 May 2018