Privacy Notice

 PRIVACY NOTICE

The “Winchester Health Clinic” is committed to safeguarding the privacy of its clients, including visitors to its website. This privacy notice will set out what personal information The Winchester Health Clinic will collect from you, the lawful basis it is relying upon to process this information, how this information will be managed, and your own rights in this processing.

By accessing and using this website, you hereby agree to the terms of this notice. If you do not agree with this Privacy Notice, please leave this website.

WHAT INFORMATION WILL THE CLINIC COLLECT?

The Clinic may collect, store and use the following kinds of personal data:

a) Information relating to any transactions carried out between you and the Clinic, including on or in relation to this website. This will include information relating to any requests you make of the Clinic’s services

b) Information that you provide to us to subscribe to our website services, email notifications and/or newsletters. By sending an electronic message (email), you may be sending us personal information such as your name, address, email address and information on your medical problem/history. The “University of Winchester Physiotherapy Clinic” will use the personal data supplied to process your request.

c) Relevant health and wellbeing information to enable the Clinic to carry out safe and effective treatments.

d) Any assessment and treatment records will be kept for a minimum of 8 years after the conclusion of treatment in accordance with existing policies and current legislation. However, they may be kept indefinitely in the case of any legal proceedings.

e) If you choose to complete the mailing list subscription form we will collect your name and email address. This information will only be used to send you specific marketing and communication information via the mailchimp platform. You will have the option to opt out of email at the bottom of all communication or by contacting us winchesterhealthclinic@winchester.ac.uk. Mailchimp privacy policy can be found here (https://mailchimp.com/legal)

f) Any other information that you choose to send to us.

g) patient names and appointment times will be shared with everyone active reception team and will be deleted at the end of the day

HOW DO WE USE YOUR PERSONAL DATA?

The personal data and special category data you submit on this website and to The Clinic will be processed for the purposes specified in this privacy notice. The personal data will be processed under the lawful bases as set out under Article 6 of the UK GDPR. These processes will include:

a) ‘consent’, (Article 6(1)(a)

b) ‘contract’ (Article 6. (1.) (b.)

c) ‘public task’ (Article 6. (1) (e.)

d) ‘legitimate interests’ (Article 6. (1.) (f.)

The special category data will be processed under the lawful basis of Article 9(2)(a), with subjects giving explicit consent to the processing.

The Clinic may use your personal information to:

a) Send to you details of services requested via the contact form on the website (‘Consent’)

b) Send statements and invoices to you, and to collect payments from you. (‘Contract’)

c) Send you email/text notifications which you have specifically requested. (‘Consent’)

d) To make onward referrals to other healthcare professionals e.g. GP/consultant/podiatrist/orthotist etc. where appropriate (‘Contract’)

e) Send you general (non-marketing) commercial communications. (‘Legitimate Interests’)

f) “The Winchester Health Clinic” may use this information to contact you in the future to tell you about products or services we believe will be of interest to you. If it does so, each communication sent will contain an ‘opt-out’ clause which, if used, will prevent you receiving such communications in the future. (‘Legitimate Interests’)

Please refer to the appendix of this Notice which lists the types of personal data which will be processed.

OTHER DISCLOSURES

In addition to the disclosures reasonably necessary for the purposes identified in this privacy notice, we may disclose information about you:

a) To the extent that we are required to do so by law;

b) In connection with any legal proceedings or prospective legal proceedings

c) To establish, exercise or defend our legal rights

This processing would be made under the lawful basis of ‘legal obligation’ as defined in Article 6 (1.) (c.) of the UK GDPR.

Except as provided in this privacy notice, the personal information submitted will not be supplied to third parties.

THIRD PARTY WEBSITES

This website may contain links to other websites, blogs or products. The Clinic is are not responsible for the privacy policies or practices of third-party websites.

SECURITY OF YOUR PERSONAL DATA

The University will take all reasonable technical and organisational precautions to prevent the loss, misuse or alteration of your personal information. Only authorised staff will have access to your information.

POLICY AMENDMENTS

The University may review and update this privacy notice from time-to-time by posting a new version on our website. You should check this page occasionally to ensure you are happy with any changes.

YOUR RIGHTS

As an individual you have rights available to you regarding how your data is used. More information on these rights can be found here.

Should you have concerns about how your information is used you can raise them with the University’s Data Protection Officer, whose details are below. Alternatively, you have a right to contact the ICO to raise any concerns you may have. Details on how to contact the ICO can be found here.

UPDATING INFORMATION

If the personal information the Clinic holds on you needs to be corrected or updated, please contact: <WinchesterHealthClinic@winchester.ac.uk>

CONTACTS

The Data Protection Officer for the University of Winchester is:

Stephen Dowell,

University of Winchester

Winchester

Hampshire

SO22 4NR

email: stephen.dowell@winchester.ac.uk

tel.no: +44 (0)1962 841515 ext:7217

The name and contact details of our organisation are:

University of Winchester

Winchester

Hampshire

SO22 4NR

United Kingdom

Tel.no: +44 (0)1962 841515

APPENDIX

The Types of Personal Data Processed:

Patient Name

Patient Date of birth

Sex

NHS number

Ethnic Origin

Patient contact phone number

Patient email address

Patient home address

Patient Health History

Patient Social History