The policy sets out the different areas where user privacy is concerned and outlines the obligations & requirements of the users, the website and website owners. Furthermore the way this website processes, stores and protects user data and information will also be detailed within this policy.
Data Processing & Storage
Your information will be used by us to enable us to provide our services to you. We act as a Data Controller (unless only processing data under a separate agreement) and undertake to protect personal and sensitive data in a manner that is consistent with the requirements of the UK data legislation and the GDPR. We will take reasonable measures to ensure the secure storage of your data.
Data is only held on the grounds that we have a contractual obligation to fulfil.
We undertake to protect all personal and sensitive data that is provided to us and in a manner that is consistent with the requirements of the General Data Protection Regulation (GDPR). We will take reasonable measures to ensure the secure storage of all data, see below.
All data given by clients is recorded by us in accordance with the client’s preferences and as permitted under the GDPR. Data will be held on one of the following grounds; with a client’s specific consent; where data retention is necessitated by a contractual relationship; and on the grounds of being a legitimate business interest.
We don’t share, sell, or distribute your data to third parties.
If it is necessary to share data with a subcontractor working on our behalf, the Data Controller will be informed without delay. Any third party must adhere to all data protection laws and regulations.
We do not give them access to any of your personal data.
We may disclose personal information if we are required to do so by law, in connection with any legal proceedings, and in order to establish, exercise or defend our legal rights.
We cannot guarantee or verify the contents of any externally linked website and users click on external links at their own risk. Atherton Physiotherapy and its owners cannot be held liable for any damages or implications caused by visiting any external links mentioned.
We keep all personal information in accordance with our Data Retention Policy which reflects our needs to provide our services to you as contracted and also to meet legal, statutory and regulatory obligations. We will only retain data that is necessary and this will include data relating to the physiotherapy that we have provided to clients. The need to hold information is regularly reviewed and information/data will be disposed of when no longer required.
All disposal is carried out securely and records will be destroyed so that they are not retrievable.
We use a local network to store all client notes and data, and a local filing cabinet for hard paper notes (under dual lock). All data is password protected and encrypted. Payments are taken by using Paypal - please see their website for payment processing terms and conditions.
In addition, we regularly review our procedures for secure data storage to ensure that all appropriate measures are adopted. In accordance with data protection legislation, data records are stored in a locked cabinet and electronic storage is protected by a user’s password that is individual to the user.
Any information that you supply to us may be stored and processed by servers hosting our website. Data will only be transferred outside EEA countries in accordance with the relevant data protection laws.
Data Subject Rights
As a data processor we understand that we have an obligation under the GDPR to comply with our obligations to the following:
Subject Access Requests
The General Data Protection Regulation (GDPR) gives individuals (‘data subjects’), the right to access personal data that is held by organisations by a subject access request (SAR). We will endeavour to respond quickly to any such requests, which legally require us to respond within one month of receiving the request and necessary information.
Right to Rectification
Data subjects have the right to request that we amend or change personal information that we, that is inaccurate or incorrect. We will act on any request without delay as instructed by you as Data Controller.
Right to Erasure
Data subjects have the right to ask us to delete personal information from our systems without giving any reason and at any time. We will act on any request without delay as instructed by you as Data Controller.
Right to Restrict Processing
Data subjects have the right to rectification or erasure of personal data certain circumstances. We will act on any request without delay as instructed by you as Data Controller
Right to Data Portability
Data subjects have the right to obtain and transfer their data to different service providers. We will act on any request without delay as instructed by you as Data Controller.
Right to Object
Data subjects have the right to object to the processing of data at any time based on their particular situation. This includes objecting to profiling unless it is in the ‘public interest’ or exercised lawfully by an official authority. We will only process data where we can demonstrate lawful grounds for doing so. We will act on any request without delay as instructed by you as Data Controller.
Right to not be subject to decisions based on Automated Processing
We do not use any automated processing that results in any automated decision based on a data subject’s personal information.
We will report any unlawful breach of data as required by the GDPR within 72 hours of the breach occurring, if it is considered that there is an actual, or possibility, that data within our control including the control of our data processors, has been compromised. If the breach is classified as ‘high risk’ we will notify all data subjects concerned using an appropriate means of communication. We will report any relevant breaches of date to the Information Commissioner’s Office (ICO).
This website and its owners take a proactive approach to user privacy and ensure the necessary steps are taken to protect the privacy of its users throughout their visiting experience. This website complies with all UK national laws and requirements for user privacy.
Cookies are small files saved to the user's computer’s hard drive that track, save and store information about the user's interactions and usage of the website. This allows the website, through its server to provide the users with a tailored experience within this website. Users are advised that if they wish to deny the use and saving of cookies from this website on to their computers hard drive they should take necessary steps within their web browsers security settings to block all cookies from this website and its external serving vendors.
This website uses tracking software to monitor its visitors to better understand how they use it. The software will save a cookie to your computer’s hard drive in order to track and monitor your engagement and usage of the website, but will not store, save or collect personal information.
Other cookies may be stored to your computer’s hard drive by external vendors when this website uses referral programs, sponsored links or adverts. Such cookies are used for conversion and referral tracking and typically expire after 30 days, though some may take longer. No personal information is stored, saved or collected.
Contact & Communication
Users contacting this website and/or its owners do so at their own discretion and provide any such personal details requested at their own risk. Your personal information is kept private and stored securely until a time it is no longer required or has no use, as detailed in the Data Protection Act 1998. Every effort has been made to ensure a safe and secure form to email submission process but advise users using such form to email processes that they do so at their own risk.
This website and its owners use any information submitted to provide you with further information about the products / services they offer or to assist you in answering any questions or queries you may have submitted. This includes using your details to subscribe you to any email newsletter program the website operates but only if this was made clear to you and your express permission was granted when submitting any form to email process. Or whereby you the consumer have previously purchased from or enquired about purchasing from the company a product or service that the email newsletter relates to. This is by no means an entire list of your user rights in regard to receiving email marketing material. Your details are not passed on to any third parties.
Adverts and Sponsored Links
This website may contain sponsored links and adverts. These will typically be served through our advertising partners, to whom may have detailed privacy policies relating directly to the adverts they serve.
Social Media Platforms
Communication, engagement and actions taken through external social media platforms that this website and its owners participate on are custom to the terms and conditions as well as the privacy policies held with each social media platform respectively.
Users are advised to use social media platforms wisely and communicate / engage upon them with due care and caution in regard to their own privacy and personal details. This website nor its owners will ever ask for personal or sensitive information through social media platforms and encourage users wishing to discuss sensitive details to contact them through primary communication channels such as by telephone or email.
This website may use social sharing buttons which help share web content directly from web pages to the social media platform in question. Users are advised before using such social sharing buttons that they do so at their own discretion and note that the social media platform may track and save your request to share a web page respectively through your social media platform account.
v.2.0 May 2018 Edited & customised by: Fit Your Bike