We understand that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy of all of our clients and will only collect and use personal data in ways that are described here, and in a way that is consistent with our obligations and your rights under the law.
This statement is updated from time to time. The latest version is published on our website (www.leathespsychology.co.uk).
If you have any questions about this policy, please email firstname.lastname@example.org or write to: Data Protection Lead, Leathes Psychology, 23 Prospect Street, Caversham, Reading, RG4 8JB.
Leathes Psychology needs to gather and use certain information about clients and prospective clients in line with the information contained within our Terms of Engagement document. This Privacy Statement explains how we use your personal data: how it is collected, how it is held, and how it is processed. It also explains your rights under the law relating to your personal data.
What data we gather
We may collect the following information to enable us to work with you safely and effectively, and to enable the efficient dissemination of appointment reminders and invoicing:
During the course of initial contact and then subsequent therapy, we will inevitably also collect a significant amount of other personal data relevant to assessing and treating your presenting psychological difficulties i.e., to enable us to offer you the service you have sought from us.
Certain types of information are known as “special categories” under data protection law, and receive additional protection due to their sensitivity, for example information that reveals your race or ethnicity, your political views or your religious beliefs. We only use these types of data with your explicit consent, or to protect your vital interests or when it is necessary to meet a lawful purpose under the current legislation.
How we collect your data
When we start work with you as a client, we will ask you to complete a Contact Details form (which is an online Google Form) so that we can collect the initial data necessary to be able to work with you, for example your name, address, GP details etc. Once you have submitted the form, the data is transferred into our Practice Management Software (Cliniko). Should you wish to send us further details of a personal nature (for example copies of reports), we can accept them from your normal email account, but we must advise you to use a secure, encrypted platform instead.
How we use this data
Collecting this data helps us:
The lawful ways we collect your data
We use your information for the following lawful reasons:
"Special category data" is more sensitive personal information that requires higher levels of protection. We need to have further justification for collecting, storing and using this type of personal information. We may process special categories of personal information in the following circumstances:
What are your rights?
Under the Data Protection Legislation, you have the following rights, which we will always work to uphold:
For more information about our use of your personal data or exercising your rights as outlined above, please contact us using the details provided at the start of this notice.
How Can I Access my Personal Information?
If you want to know what personal data, we have about you, you can ask us for details of that personal data and for a copy of it (where any such personal data is held). This is known as a "subject access request".
All subject access requests can be made either in writing and sent to the email or postal addresses shown above, or verbally in person or over the phone.
There is not normally any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover our administrative costs in responding.
We will respond to your subject access request within one month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.
Should, during the course of your contact with us, any personal data be subject to change e.g., if you move, change GPs, change your name etc., we would be grateful if you could notify us at the earliest opportunity so we can ensure our records are up to date.
Controlling information about you
Any personal information we hold about you is stored and processed under our data protection policy, in line with the Data Protection Act 2018 and the UK GDPR (collectively, “the Data Protection Legislation”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.
Your data will be kept for the lifetime of your status as a client with us. When you cease to be a client with us, your data will kept for a minimum period of five years, and a maximum period of ten years in accordance with General Medical Council guidelines. You have the right to ask for your data to be destroyed after the minimum period of five years, but not before then. Leathes Psychology has the right to retain your data for the five-year period so that it can respond effectively to any questions or complaints that may later be raised by you and/or your representatives.
Do You Share My Personal Data?
We will not share any of your personal data with any third parties for any purposes, subject to the following exception(s).
Under these circumstances, Leathes Psychology will disclose relevant data. However, we will take all reasonable steps to notify the individual whose data is being disclosed about the disclosure. We will also ensure that any such data request is legitimate, reasonable and necessary.
How and Where Do You Store or Transfer My Personal Data?
We do store some of your personal data in countries outside of the UK, such as the initial contact form is stored on servers within Europe. These are known as "third countries". We will take additional steps in order to ensure that your personal data is treated just as safely and securely as it would be within the UK and under the Data Protection Legislation as follows:
Please contact us using the details above for further information about the particular data protection safeguards used by us when transferring your personal data to a third country.
How do we keep your data secure?
The security of your personal data is essential to us, and to protect your data, we take a number of important measures, including the following:
To prevent unauthorised disclosure or access to your information, we have implemented strong physical and electronic security safeguards. In the unlikely event of a data protection breach we will notify the Information Commissioner’s Office (ICO) so that their procedures can be followed. We will also notify all individuals whose data may have been accessed to alert them to the breach and any potential risks.
Changes to this Privacy Notice
We may change this Privacy Notice from time to time. This may be necessary, for example, if the law changes, or if we change our business in a way that affects personal data protection. This Privacy Notice was last updated on 16th February 2021.