Air + Earth Reflexology customer privacy notice:
This privacy notice tells you what to expect us to do with your personal information.
Contact details: jenni@airandearthreflexology.com
What information I collect, use, and why:
We collect or use the following information to provide patient care, services, pharmaceutical products and other goods:
Name, address and contact details
Date of birth
Next of Kin details including any support networks
Emergency contact details
Information about care needs (including disabilities, home conditions, medication and dietary requirements and general care provisions)
Payment details (including card or bank information for transfers and direct debits)
Records of meetings and decisions
We also collect the following special category information to provide patient care, services, pharmaceutical products and other goods.
This information is subject to additional protection due to its sensitive nature:
Health information (including medical conditions, allergies, medical requirements and medical history)
Lawful bases and data protection rights:
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights, which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.
Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.
Your right to erasure - You have the right to ask us to delete your personal information. Read more about the right to erasure.
Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.
Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.
Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.
Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.
If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
My lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide patient care, services, pharmaceutical products and other goods are:
Consent - we have permission from you after we gave you all the relevant information.
All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
Where I get personal information from:
Directly from you
Family members or carers
How I keep information and for how long :
I am committed to ensuring that your personal data is secure. In order to prevent unauthorised access or disclosure, I have put in place appropriate technical, physical and managerial procedures to safeguard and secure the information I collect from you. I keep all booking data (name, email, mobile number and debit or credit card) in my secure online booking system, Acuity Scheduling. I then keep all client records (including name, address, GP details, health & lifestyle information, and next of kin) in a secure Google Drive that is password-protected and has 2-factor authentication applied (meaning a constantly changing security number needs to be entered in order to access. My computer and laptop are always kept in a secure, locked location with an alarm.
I will contact you using the contact preferences you have given me.
I keep all personal information for a period of 7 years (or longer in the case of ongoing reflexology treatment). I will then dispose of your information by deleting it from my digital files and also deleting it from any trash/deleted folders.
Who we share information with:
Care providers (if appropriate)
Organisations we need to share information with for safeguarding reasons
Duty of confidentiality:
We are subject to a common law duty of confidentiality. However, there are circumstances where we will share relevant health and care information. These are where:
You’ve provided me with your consent (I have taken it as implied to provide you with care, or you have given it explicitly for other uses);
I have a legal requirement (including court orders) to collect, share or use the data;
On a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example, sharing information with the police to support the detection or prevention of serious crime);
If in England or Wales, the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied.
Therapists Rights: *Please note:
If you don’t agree to your therapist keeping records of information about you and your treatments, or if you don’t allow them to use the information in the way they need to for treatments, the therapist may not be able to treat you
Your therapist has to keep your records of treatment for a certain period as described above, which may mean that even if you ask them to erase any details about you, they might have to keep these details until after that period has passed
Your therapist can move their records between their computers and IT systems, as long as your details are protected from being seen by others without your permission.
How to complain:
If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113