Information I Collect
To aid your treatment or as part of purchasing something from my business you will normally provide me with certain information, such as your name, email address, postal address, medical information and payment information. I will store your information on an electronic patient record and diary system which is fully password protected.
Why I Need Your Information and How I Use It
I rely on a number of legal bases to collect, use, and share your information, including:
From time to time I may wish to send you direct marketing material which may include product offers and newsletters. This is unusual, and will only be done with your explicit consent.
Information Sharing and Disclosure
Information about my patients/customers is important to my business. I share your personal information for very limited reasons and in limited circumstances, as follows:
I retain your personal information only for as long as necessary to provide you with my services. However, I may also be required to retain this information to comply with my legal and regulatory obligations, to resolve disputes, and to enforce my agreements. The retention of podiatry records is normally a minimum of 8 years, after the last appointment. For customers who are not patients but may have bought products from my business I will keep any data you may have provided for a minimum of 6 years in line with tax legislation.
Transfers of Personal Information Outside the EU
I may store and process your information through third-party hosting services in the US, Australia and other sites. As a result, I may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction. If I am deemed to transfer information about you outside of the EU, I rely on the highest levels of security and encryption provided by my computer software supplier.
Details of the software supplier (Cliniko) and their security arrangements are stated below.
Cliniko is hosted in state of the art datacenter facilities. Physical access is controlled both at the perimeter and at building ingress points by professional security staff utilising video surveillance, intrusion detection systems, and other electronic means.
Cliniko uses datacenter facilities that are built in clusters in various global regions. In case of failure, automated processes move customer data traffic away from the affected area and into other sites.
Cliniko’s hosting partner has achieved the following accreditations and certifications; PCI DSS Level 1 (Payment Card Industry Data Security Standard), ISO 27001 (Information Security Management System), FIPS 140-2 (United States Federal Information Processing Standard).
Cliniko runs completely under HTTPS. This means your data is encrypted during transfer using a 2048-bit SSL certificate.
The medical database and file attachments are encrypted at rest, using the industry standard AES-256 encryption algorithm.
You have a number of rights in relation to your personal information. While some of these rights apply generally, certain rights apply only in certain limited cases. I describe these rights below:
How to Contact Me
For purposes of the GDPR, I, Kim Coates, am the data controller of your personal information. If you have any questions or concerns, you may contact me at firstname.lastname@example.org. Alternatively, you may mail me at:
Lido Chiropody Clinic | Suite 2.7 | Lido Medical Centre | St Saviour’s Road | St Saviour | Jersey | JE2 7LA