To give professional reflexology treatments, I will need to ask for and keep information about your health. I will only use this for informing reflexology treatments and any advice I give because of your treatment. The information to be held is:
As I hold special category data (health-related information), the additional condition under which I process this information is Article 9(2)(h) UK GDPR, namely that processing is necessary for the purposes of preventive or occupational medicine and the provision of health care or treatment. The corresponding condition under Schedule 1, Part 1, Paragraph 2 of the Data Protection Act 2018 applies.
I use carefully selected third-party service providers to support the operation of my business.
Most of the personal information I collect and process is provided to me by you in your client information form via the Jotform platform and during subsequent treatments verbally for the reason of informing your reflexology treatments and any advice I give because of your treatment. I hold and use the information given to me by you in the cloud of Google Drive to provide you with the best possible treatment options, support and advice. I use Samsung Notes to write and update my treatment notes.
For client communication I use Webhealer Webmail, Gmail, WhatsApp and text message.
For processing electronic payments I use Sum Up.
These providers are responsible for protecting any personal information they process on my behalf and have their own privacy policies.
I may share this information with a third party if there is a safeguarding concern or when I'm responding to an emergency which poses a risk to your life or health.
Under the UK General Data Protection Regulation (UK GDPR), the lawful basis I rely on for processing this information are:
(a) Your consent. You can remove your consent at any time by contacting hello@solefulreflexology.com
(b) I have a contractual obligation to fulfil service agreement
(c) I have a legal obligation:
1.1. ‘Claims occurring’ insurance (records to be kept for 7 years after last treatment)
1.2. Law regarding children’s records (records to be kept until the child is 25 or if 17 when treated, then 26)
(d) I have a legitimate interest [i.e. my requirement to retain the information to provide you with the best possible treatment options and advice and to maintain my insurance]
As I hold special category data (i.e. health related information), the additional condition under which I hold and use this information is for me to
fulfil my role as a health care practitioner bound under the Association of Reflexologists Confidentiality as defined in the AoR Code of Practice and Ethics.
I am committed to ensuring that your personal data is secure. To prevent unauthorised access or disclosure, I have put in place appropriate technical, physical and managerial procedures to safeguard and secure the information I collect from you. I will contact you using the contact preferences you have given me.
I keep the information you have provided to me for the period stated above. I will then dispose your information by permanently deleting it from my files.
Under data protection law, you have rights including:
You are not required to pay any charge for exercising your rights. If you make a request, I have one month to respond to you. Please email me at hello@solefulreflexology.com or call me at 07480 174754 if you wish to make a request.
Full details of your rights can be found at https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
If you don’t agree to your therapist keeping records of information about you and your treatments, or if you don’t allow them to use the information in the way they need to for treatments, the therapist may not be able to treat you.
Your therapist must keep your records of treatment for a certain period as described above, which may mean that even if you ask them to erase any details about you, they might have to keep these details until after that period has passed.
Your therapist can move their records between their computers and IT systems without your permission if your details are protected from being seen by others.
If you have any concerns about the way I collect, use, store, share or otherwise process your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, or if you believe I have not respected one or more of these rights, you are entitled to raise a
formal complaint using the procedure set out below.
My contact details
All GDPR-related complaints should be directed to us using the contact details below.
Business name: Soleful Reflexology
Registered address: 1 Pirie Road, Congleton, CW12 2EE
Complaints email: hello@solefulreflexology.com
Complaints address: Ildiko Horvath, 1 Pirie Road, Congleton, CW12 2EE
How to make a complaint
Please submit your complaint in writing (either by email or post) using the contact details above. To help me investigate your concern as efficiently as possible, please include:
My complaints procedure
Once I receive your complaint, I will follow the five steps below. I am committed to handling all complaints promptly, fairly and confidentially.
1. Acknowledgement — within 30 days
I will acknowledge your complaint in writing within 30 days of receiving it, confirming that I have recorded it and will be investigating.
2. Requesting further information
If I need any additional details to fully investigate your complaint, I will contact you as soon as possible and explain what I need and why.
3. Investigation and review
I will carry out a thorough and impartial review of your complaint. I will agree a realistic timescale with you once I have all necessary information, and I will keep you updated if there are any delays.
4. Decision and outcome
I will communicate the outcome of my investigation to you clearly and in writing within one calendar month of receiving all the information needed
(this may be extended by up to two further months for complex complaints — I will notify you if this is the case).
5. Closure or escalation
If you are satisfied with the outcome, I will close your complaint. If you remain dissatisfied, you have the right to refer your complaint to the ICO free of charge (see below).
Escalating your complaint to the ICO
If you remain dissatisfied with my response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) — the UK’s independent supervisory authority for data protection. This service is free of charge.
ICO website: https://ico.org.uk/make-a-complaint/
ICO helpline: 0303 123 1113 (Monday–Friday, 9am–5pm)
ICO postal address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF