Sara Wayne Reflexology Privacy Policy – Updated February 2023

Our contact details:

Name: Sara Wayne

Contact email: SWReflexology@yahoo.com (further contact details available on request).

The type of personal information we collect

In order to give professional reflexology treatments, I will need to ask for and keep information about your health. I will only use this for informing reflexology treatments and any advice I give as a result of your treatment. The information to be held is:

  • Your contact details
  • Medical history and other health-related information
  • Treatment details and related notes

How we get the personal information and why we hold it

  • Most of the personal information we process is provided to us directly by you for the following reason for informing reflexology treatments and any advice I give as a result of your treatment.
  • We use the information that you have given us in order to provide you with the best possible treatment options, support and advice.

We will not share this information with other organisations or individuals without your agreement.

Lawful Basis for holding and using Client Information

Under the UK General Data Protection Regulation (UK GDPR), the lawful basis we rely on for processing this information are:

(a) Your consent. You are able to remove your consent at any time. You can do this by contacting Sara Wayne using the contact details at the start of this document.

(b) We have a contractual obligation

(c) We have a legal obligation:

1.1. ‘Claims occurring’ insurance: (records to be kept for 7 years after last treatment)

1.2. Law regarding children’s records (records to be kept until the child is 25 or if 17 when treated, then 26)

1.3. CNHC requirements to retain information for 8 years

(d) We have a vital interest

(e) We need it to perform a public task

(f) We have a legitimate interest (i.e.my requirement to retain the information in order to provide you with the best possible treatment options and advice).

As I hold special category data (i.e. health related information), the additional condition under which I hold and use this information is: for me to fulfil my role as a health care practitioner bound under the AoR Confidentiality as defined in the AoR Code of Practice and Ethics.

How we store your personal information

Protecting your Personal Data

I am committed to ensuring that your personal data is secure. In order to prevent unauthorised access or disclosure, I have put in place appropriate technical, physical and managerial procedures to safeguard and secure the information we collect from you.

I will contact you using the contact preferences you have given me.

We keep required personal information for no more than 7 years, unless stated elsewhere within this document and permitted or required by law. We will then dispose of your information by either deleting it from our systems (including cloud or similar back up systems), or securely disposing via shredding (in the case of paper documentation).


Your data protection rights

Under data protection law, you have rights including:

Your right of access - You have the right to ask us for copies of your personal information.

Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.

Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.

Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.

Your right to object to processing - You have the right to object to the processing of your personal information in certain circumstances.

Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.

You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you. Please contact us in writing using the address at the top of this document if you wish to make such a request.  

Therapist's rights

Please note:

  • If you don’t agree to your therapist keeping records of information about you and your treatments, or if you don’t allow them to use the information in the way they need to for treatments, the therapist may not be able to treat you
  • Your therapist has to keep your records of treatment for a certain period as described above, which may mean that even if you ask them to erase any details about you, they might have to keep these details until after that period has passed
  • Your therapist can move their records between their computers and IT systems, as long as your details are protected from being seen by others without your permission.

How to complain

If you have any concerns about our use of your personal information, you can make a complaint in writing to us using the contact details at the top of this document. You can also complain to the ICO if you are unhappy with how we have used your data.

The ICO’s address:

Information Commissioner’s Office

Wycliffe House

Water Lane, Wilmslow

Cheshire

SK9 5AF

Helpline number: 0303 123 1113

ICO website: https://www.ico.org.uk