GDPR Policy 2018
We take your privacy very seriously. Please read this privacy policy carefully as it contains important information on who we are and how and why we collect, store, use and share your personal information. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities in the event you have a complaint.
We collect,
use and are responsible for certain personal information about you. When we do
so we are subject to the General Data Protection Regulation (http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN).
Which applies across the European Union (including in the United Kingdom) and
we are responsible as ‘controller’ of that personal information for the
purposes of those laws.
Under data protection law, we can only use your personal information if we have a proper reason for doing so, eg:
- To comply with our legal and regulatory obligations;
- For the performance of our contract with you or to take steps at your request before entering into a contract;
- For our legitimate interests or those of a third party: or where you have given consent.
A legitimate interest is when we have a business or commercial reason to use information, so long as this is not overridden by your own rights and interests.
The table below explains what we use/process your personal information for and our reasons for doing so:
The above table does not apply to
special category personal information, which we will only process with your
explicit consent.
We routinely share personal information with:
Third parties we use to help deliver our services to you, eg payment service providers other third parties we use to help us run our business, eg marketing agencies or website hosts; third parties approved by you, eg social media sites you choose to link your account to or third-party payment providers:
Our bank;
We only allow our service providers to handle your personal information if we are satisfied they take appropriate measures to protect your personal information. We also impose contractual obligations on service providers relating to ensure they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, eg in relation to ICO accreditation and the audit of our accounts.
Where your personal information is heldInformation may be held at our offices, third party agencies, service providers, representatives and agents as described above (see above: ‘Who we share your personal information with’). How long your personal information will be kept.
We will keep your personal information while you have an account with us or we are providing services to you. Thereafter, we will keep your personal information for as long as is necessary:
To respond to any questions, complaints or claims made by you or on your behalf;
To show that we treated you fairly:
To keep records required by law.
We will not retain your personal
information for longer than necessary for the purposes set out in this
policy. Different retention periods
apply for different types of personal information. When it is no longer necessary to
retain your personal information, we will delete or anonymise it. If you would like further information,
please contact us (see ‘How to contact [email protected] below).
For further information on each of those rights, including the circumstances in which they apply, please contact us or see the Guidance from the UK information Commissioner’s Office (ICO) on individuals’ rights under the General Data Protection Regulation (http://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/). If you would like to exercise any of those right, please:
Email, call or write to us [us OR our Data Protection Officer] – see below: ‘How to contact us’: and Let us have enough information to identify you [(eg your full name, DOB and/or address)];Let us have proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill); and let us know what right you want to exercise and the information to which your request relates.
Keeping your personal information secure
We have appropriate security measure to prevent personal information from being accidentally lost, or used or accessed unlawfully. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you
and any applicable regulator of a suspected data security breach where we are legally required to do so.
GDPR consent to process personal data
Consent to terms and conditions-not data processing consent
Please state that you have read and agreed to the terms and conditions [[email protected]] before you continue.
Data protection
We use your personal data primarily to provide our services to you, but also for related purposes as described in the Clinic’s Privacy Policy. Our use of your personal data is subject to your instructions, the EU General Data Protection Regulation (GDPR), other relevant UK and EU legislation and our professional duty of confidentiality. Greenwood's Therapeutic Horticulture C.I.C is a data controller for the GDPR and other relevant data protection legislation. We have nominated Amanda Eaglestone as the company’s representative for the GDPR. We take your privacy very seriously. Please read the firm’s Privacy Policy carefully at Greenwood's Therapeutic Horticulture C.I.C as it contains important information on:
What personal data we collect about you and how that data is collected
How, why and on what grounds we use your personal data
Who we share your personal data with
Where your personal data is held and how long it will be kept
Whether your personal data may be transferred out of the European Economic area and, if so, the measures taken to protect that data
Your rights in relation to the personal data we hold or use
The steps we take to secure your personal data
How to make a compliant in relation to our use of your personal data
Promotional communicationsHow to contact us with any queries or concerns in relation to your personal data
We may use your personal data to send you updates (by email, text, telephone or post) about legal developments that might be of interest to you and /or information about our services, including exclusive offers, promotions or new services. You have the right to opt out of receiving promotional communications at any time, by contacting us by email or post.