GDPR

Overview

This document sets out the obligations of KLINIKK’s data protection and the rights of customers, people with whom it works and any employees in respect of their personal data under the United Kingdom General Data Protection Regulation (“GDPR”). 

This Policy shall set out procedures which are to be followed when dealing with personal data.  The procedures set out herein must be followed by KLINIKK’s employees, contractors, agents, consultants, partners or other parties working on its behalf.

KLINIKK views the correct and lawful handling of personal data as key to its success and dealings with third parties and its employees.  KLINIKK shall ensure that it handles all personal data correctly and lawfully.

Definitions

Data is information which is stored electronically, on a computer, or in certain paper-based filing systems. 

Data subjects for this policy include all living individuals about whom we hold personal data. A data subject need not be a UK national or resident. 

Personal data means data relating to a living individual who can be identified from that data (or from that data and other information in our possession). Personal data can be factual (such as a name, address, IP address or date of birth) or it can be an opinion (such as a performance appraisal). 

Data controllers are the people who or organisations which determine the purposes for which, and the way, any personal data is processed. They have a responsibility to establish practices and policies in line with the Act. We are the data controller of all personal data used in our business. 

Data users include employees whose work involves using personal data. Data users have a duty to protect the information they handle by following our data protection and security policies always. 

Data processors include any person who processes personal data on behalf of a data controller. Employees of data controllers are excluded from this definition, but it could include suppliers which handle personal data on our behalf. 

Data processing is any activity that involves use of the data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.

Special category data means personal data relating to the racial or ethnic origin of the data subject; their political opinions; their religious (or similar) beliefs; trade union membership; their physical or mental health condition; their sexual life; the commission or alleged commission by them of any offence; or any proceedings for any offence committed or alleged to have been committed by them, the disposal of such proceedings or the sentence of any court in such proceedings. 

Policy Statement

KLINIKK is committed to the proper processing of customer data and will endeavour to ensure the company, and its employees act in accordance with the GDPR together with expectations of the Information Commissioners Office (ICO)

It is the policy of KLINIKK to ensure that:

  • Information will only be processed where the conditions for doing so have been met, where this includes consent, consent will be informed and freely given through a positive action by the data subject or nominated third party 
  • Information will be protected against unauthorised access
  • Confidentiality of information will be assured
  • Integrity of information will be maintained
  • Regulatory and legislative requirements will be met
  • Citizens will be provided with timely and clear information about the processing of their data 
  • Data subjects will be provided with all rights applicable to them 
  • All breaches of Information Security, actual or suspected, will be reported and investigated
  • Standards will be produced to support the policy. These include virus controls and passwords
  • Business requirements for the availability of information and information systems will be met
  • All Managers or Directors are directly responsible for implementing the policy within their business areas, and for adherence by their staff.

 

Data

KLINIKK will hold certain information on data subjects to fulfil our legal or contractual duty to our customers, to employ staff or in relation to steps taken to enter into a contract. Customers includes patients receiving treatment. 

Processing of personal information by the company will be fair and lawful and in accordance with the privacy notice the customer consented to as part of the terms and conditions of their agreement or equivalent. In addition, it is company policy that individuals will not be misled as to the purposes to which the company will process the information. 

KLINIKK will ensure that, as far as practicable, all individuals who have information processed by the company are aware of the way in which that information will be obtained, held, used and disclosed. 

Data will therefore be obtained from the following sources only:

  • The customer or their authorised representative
  • Public/consented databases 

 

The obtained data will only be used for servicing the agreement with that individual and/or exercising a contractual right under that agreement, marketing (where consent has been given) and will not be sent to any other third party, except:

  • The customer 
  • The customer’s authorised representative such as somebody with power of attorney 
  • The data controller (where applicable) 
  • Required IT providers 
  • Selected third parties with the knowledge of the data subject
Details of Data Controller

Dr Julie Nowak
Klinikk
Room 3, 2nd Floor
20 Lansdowne Terrace
High Street
Newcastle upon Tyne
NE3 1HP

Purposes for prosessing

Cosmetic treatments

Categories of data subjects

Data subjects interested in purchasing services 

Customers

Categories of personal data

Data subjects interested in purchasing services:

  • Contact details 
  • Interested service  


Customers:

  • Contact details 
  • Service purchased 
  • Payment information 
  • Special category data to enable safe treatment or reasonable adjustment 
  • Interest in future treatments
Retention

See Data Retention Policy

Data Rights

Data Subjects, under GDPR, have the following rights which, where they apply, are reflected under this policy:

  1. Right to be informed 
  2. Right to access
  3. Right to erasure (to be forgotten) 
  4. Right to object
  5. Right to rectification
  6. Right to restrict
  7. Rights in relation to automated decision making and/or profiling
  8. Right to portability 

Data Retention 

Data will be maintained in accordance with the timescales in the Data Map and Data Retention Policy of KLINIKK 

Where data is deleted, this will be by: 

  • Confidential waste bins / shredding 
  • Deletion from internal system 
  • Deletion from external suppliers 

Information Quality and Integrity 

KLINIKK will endeavour to record all information accurately and rectify incorrect data to ensure high data quality, this will usually be conducted through:

  1. High level of staff training & regular communication amongst staff.   (if applicable)
  2. Double checking / quality assuring data imputing.
  3. Allowing data subjects, the right to rectification where it is identified data is incorrect 

Safeguarding Data

Safeguarding means keeping data secure and not divulging it to any unauthorised third party. Employees must safeguard data by completing the following data protection steps:

  • Three pieces of customer information must be confirmed by the customer at the beginning of each telephone call; if the customer does not confirm these correctly then no account details may be given.
  • Before discussing account details with any third party we must hold authority from the customer and ensure the third party passes through the above data protection check.
  • Employees must dispose of all sensitive data using confidential waste bins / shredded appropriately. 
  • Employees are prohibited from discussing customer details with non-employees of the company, accept where this is permissible and required in relation to authorised third parties, regulators and law enforcement agencies. 
  • All electronic copies of personal data should be stored securely using passwords and suitable data encryption, where possible on a drive or server which cannot be accessed via the internet; and
  • All passwords used to protect personal data should be changed quarterly and should not use words or phrases which can be easily guessed or otherwise compromised

Data Breach Guide

You must report any data breaches within 72 hours to the ICO, if the breach is likely to result in a high risk or adversely affecting individuals’ rights and freedoms, you must also inform those individuals as soon as possible.

You must investigate immediately and have internal procedures in place, this will help with decision making as to whether you inform the ICO and the individuals.

You must keep a record of any personal breaches using the Data Mapping spreadsheet.

Preparing for a personal breach

  1. We know how to recognise a personal breach.
  2. We understand that a personal breach isn’t only about loss or theft of personal data.
  3. We have prepared a response plan for addressing any personal data breaches that occur.
  4. We have allocated responsibility for managing breaches to a dedicated person.
  5. We know how to escalate a security incident to the appropriate person.

Responding to a personal breach

  1. A process is in place to assess the likely risk to individuals as a result of a breach.
  2. A process is in place to inform affected individuals about a breach when their rights and freedoms are at risk.
  3. A process is in place to inform the individual without undue delay.
  4. To be aware of the relevant supervisory authority for our processing activities.
  5. A process is in place to notify the ICO within 72 hours of becoming aware of it, even if you do not have the details yet.
  6. Understand what information we must give to the ICO about the breach.
  7. A process is in place to give information to the individuals, and that should help them protect themselves from its effects.
  8. ALL breaches are documented, even if they don’t need to be reported using the Data Mapping spreadsheet.

Disclaimer:

We may update this disclaimer from time to time to reflect changes in our data processing practices or legal obligations. Any updates will be noted on this policy with the date and what has changed.

Contact us:

If you have any questions or concerns about your personal data or wish to exercise your rights, please contact us. 

Call: 07554 587890

Write: Dr Julie Nowak, Klinikk, Room 3, 2nd Floor, 20 Lansdowne, High Street, Newcastle upon Tyne, NE3 1HP

Email: hello@klinikk.co.uk

This policy is subject to change at any time without prior notice. While we strive to provide accurate and up-to-date information, we do not guarantee the completeness or accuracy of this policy. Compliance with this policy does not constitute a legal obligation beyond the applicable laws and regulations.