1. Summary
1.1 This data privacy policy of anotherway2b.co.uk explains how we look after your personal data and privacy in accordance with the General Data Protection Regulation (GDPR) and related rules.
1.2 By engaging with anotherway2b.co.uk, you are consenting to this privacy statement.
1.3 Data protection laws require that the personal data we hold about you must be:
• collected only for valid purposes that we have clearly explained to you
• relevant to the purposes we have told you about and limited only to those purposes;
• Used, lawfully, fairly and in a transparent way; accurate and
• kept up to date; kept secure and confidential and kept only as long as necessary for the purposes we have told you about.
2. The type of personal information we will collect:
2.1 When you initially contact us, you will be asked to provide your details such as name, telephone number and email. You will then be asked about the difficulties that you are facing so that we can see if we are a good fit to help. If you choose not to proceed with our service, your details will be deleted. If you use our services, we will collect Financial Data including bank account and payment card details.
2.2 During diagnostic assessments and therapy more sensitive information may be obtained to produce relevant reports. This may include medical details/records, financial details, employment details, family and lifestyle details, education and training details, test forms and results. In addition, we may obtain information which is considered special category information such as physical and mental health details, racial or ethnic origin, religious beliefs or other beliefs of a similar nature, criminal convictions and sexual orientation.
2.3 The rationale for obtaining this information will always be explained to you. The basis of processing your data will be due to the following:
· It is necessary for the performance of our contract with you
· It is necessary for us to comply with a legal obligation
· It is in our legitimate interests to do so
· You have given us your consent (this can be withdrawn at any time by advising our data protection officer)
3. How information is stored:
3.1 Your information will be kept on a password-protected computer with appropriate antivirus, malware & firewall protection. Information is held within a secure drive which is encrypted. Most information is stored electronically. Any information provided by you that is kept on paper is scanned and transferred to an electronic record as soon as possible. Paper records will then be destroyed.
3.2 Upon the conclusion of therapy/assessment, the electronic file is kept on a secure encrypted drive for 7 years from the last appointment unless you and the psychologist agree otherwise (or unless there are exceptional reasons such as those linked to legal processes). This is so that should you choose to return for a further appointment/course of therapy, then this information can be accessed as needed. When our services cease to be provided, records will be securely destroyed (or unless there are exceptional reasons such as those linked to legal processes).
4. Disclosure of your data:
4.1 We are very strict about who we share your data with. Some examples of who we may share your data with are:
• Service providers, acting as processors who provide IT and system administration services.
• Professional advisers, acting as processors or joint controllers, including healthcare professionals for supervision, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
• HM Revenue & Customs, regulators and other authorities, acting as processors or joint controllers, based who require reporting of processing activities in certain circumstances.
• We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
4.2 For some clients, our basis for processing is for a ‘legal obligation’, for example, to comply with a Court order and where experts must comply with strict guidelines affecting their duty to the Court. Unfortunately, this reduces your rights over the data. The individual has no right to erasure, right to data portability, or right to object.
5. Contact
We may need to contact you for various reasons, for example: to set up/change appointment times; to send you venue information and other information related to your appointment/s and to help solve any payment problems that might arise. You will be asked your preferred method of contact (Post, Email, Telephone and/or text message). If there are any changes to your personal data (such as a change of address) please let us know as soon as possible by writing to or emailing us.
6. Your rights in relation to your data
6.1 Under data protection law, you have rights including:
· Your right of access - You have the right to ask us for copies of your personal information.
· Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
· Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
· Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
· Your right to object to processing - You have the right to object to the processing of your personal information in certain circumstances.
· Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
· You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
6.2 You may request that we inform you of the data we hold about you and how we process it (your ‘Subject Access Right’). We will not charge a fee for responding to this request unless your request is clearly unfounded, repetitive or excessive in which case we may charge a reasonable fee or decline to respond.
6.3 We will, in most cases, reply within one month of the date of the request unless your request is complex or you have made a large number of requests, in which case we will notify you of any delay and will in any event reply within 3 months. Please contact us at jess@anotherway2b.co.uk if you wish to make a request.
7. Complaints
7.1 We are committed to protecting your personal data but if for some reason you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues. There details are:’
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
ICO website: https://www.ico.org.uk
We would be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
8. Contact details
If you have any questions about this privacy policy or our privacy practices, please contact our Data Protection Officer (Jessica Harris) at jess@anotherway2b.co.uk.