1. The identity of the data controller
You are hereby informed that the data that you provide is collected, used, protected, processed and shared by Alan Payne.
2. Collection of date
Data is collected under the Lawful Basis of Legitimate Interest in order to allow and benefit patient-therapist interaction.
I may collect data about my clients, prospects and visitors.
Your data are collected when you browse our website, contact us via email, phone or in person or through our website.
Data we collect fall into the following categories:
- Identification information
- Contact information
- Medical information
- Browsing information
These data are gathered directly from you via online booking and from direct communication with us, i.e. client intake form. Browsing history is collected via automated methods.
2.1. Information you provide to me
I process data you provide directly to me, in particular when you complete a client intake form or book online.
For example, I collect data when you create a booking, use my services, participate in a promotion, register for an event or an online course, apply for a job, request customer support or otherwise communicate with us.
The data may include the following data as well as any other type of information that I specifically request you to provide to me through our client intake forms, such as:
- Date of birth
- Phone no.
- Doctor’s details
- Next of kin
- Medical history
- Medical red flag(s)
- Treatment notes
- Relationship data
- Browsing data.
2.2. Data I collect automatically when you use our online services
When you access or use our online services, I automatically collect the following information about you:
Log information: I log information about your use of the services, including the type of browser you use, access times, pages viewed, your IP address and the page you visited before navigating to our services.
Device information: I collect information about the computer or mobile device you use to access our services, including the hardware model, operating system and version, unique device identifiers and mobile network information.
2.3. Information I collect automatically through cookies and other tracking technology
A “cookie” is a small text file that is placed onto an Internet user’s web browser or device and which is used to record information related to the navigation or the use of a device or a website.
A “web beacon” is a small object or image that is embedded into a web page, application, or email and is used to track activity. They are also sometimes referred to as pixels and tags (also known as “tracking pixels”). It may be used in our services or emails and help deliver cookies, count visits, understand usage and campaign effectiveness and determine whether an email has been opened and acted upon. For more information about cookies, and how to disable them, please see ‘Your Choices’ below.
Some of the cookies are used for the exclusive purpose of enabling or facilitating communication or are strictly necessary for the provision of my online services.
These are essentially of session cookies for authenticating and connecting to our online services, as well as memorizing navigation items during a session.
You have the ability to decline cookies by changing the settings on your browser but this might prevent you from benefiting from some elements of my online services. You can also consult or destroy cookies if you wish, since they are stored on your hard disk.
I may also use these technologies for other purposes than my online service operation, such as:
- To improve our online services
- To remember you, for your convenience, when you use our online services.
2.4. Third-party cookies
When you access or use my online services, one or more third-party cookies are likely to be placed on your equipment.
I inform you that we have no access to, and cannot exercise any control over, third-party cookies. However, I shall ensure that the partner companies agree to process the information collected on my online services in compliance with the GDPR and undertake to implement appropriate measures to secure and protect data confidentiality.
3. How I use the data
I may use information about you for the following purposes:
- Provide, maintain and improve my services
- Provide and deliver the service you request, process transactions and send you related information, including confirmations and invoices
- Send you technical notices, updates, security alerts and support and administrative messages
- Respond to your comments, questions and requests, and provide customer service
- Monitor and analyze trends, usage and activities in connection with our services
- Personalise and improve the services we provide.
According to the GDPR, the legal basis I use for processing your data is Consent
4. How I share your data
I will seek your express consent before sharing your information with your GP or other healthcare providers. However, if we believe that your life is in danger then I may pass your information onto an appropriate authority (such as the police, social services in the case of a child or vulnerable adult, or GP in case of self-harm) using the legal basis of vital interests
I may share your case history in an anonymised form with our peers for the purpose of professional development. This may be at clinical supervision meetings, conferences, online forums, and through publishing in medical journals, trade magazines or online professional sites. We will seek your explicit consent before processing your data in this way
In response to a request for information if I am required by – or believe that disclosure is required by – any applicable law, regulation or legal process, including in connection with lawful requests by law enforcement, national security, or other public authorities.
5. The period of data retention
Following completion of your healthcare, I retain your personal data for the period defined by my professional association, the Association of Master Herbalists (AMH). In this case, the legal basis of our holding your personal data is for contract administration.
6. Data access
Upon receiving a written request from you seeking access to your data, I will provide either a hard or electronic copy of the data that I hold on you, to be sent by registered post or email, respectively. This will include exports of the information held about you on my website. I will provide your data to you within a period of 28 days from the date that I receive your request.
7. Data amendments
Upon receiving a request from you to update, correct or amend your personal data held by me, I will make the amendments within a period of 7 days from the date that I receive your request.
I am committed to taking appropriate measures designed to keep your data secure. My technical, administrative and physical procedures are designed to protect data from loss, theft, misuse and accidental, unlawful or unauthorized access, disclosure, alteration, use and destruction. I follow generally accepted standards to protect the personal information submitted to me, both during transmission and once it is received.
9. Your rights
Under the General Data Protection Regulations 2018 (GDPR), individuals have significantly strengthened rights to:
- Obtain details about how their data are processed by an organisation or business
- Obtain copies of personal data that an organisation holds on them
- Have incorrect or incomplete data corrected
- Have their data erased by an organisation where, for example, the organisation has no legitimate reason for retaining the data
- Obtain their data from an organisation and to have that data transmitted to another organisation (data portability)
- Object to the processing of their data by an organisation in certain circumstances
- Not to be subject to (with some exceptions) automated decision making, including profiling.
10. In the event of a data breach
Every precaution will be taken to avoid a breach of your data. However, if such a breach should occur, it will be documented, assessed as to its severity and appropriate action taken. The Information Commissioner’s Office (ICO) will be informed and you will be contacted to assist you in taking steps to mitigate the risks to yourself if the breach is deemed sufficiently severe to put you or your identity at risk.