Health Your Way C.I.C. understands that your privacy is important to you and that you care about how your personal data is used. We respect and value the privacy ofeveryone who visits our website www.healthyourway.co.uk (“the Website”) or provides data to us through other means. This may include information given by health and social care professionals, or by you in meetings with our employees or through the completion of forms or other documentation. We will only collect and use personal data in ways that are described here, and in a way that is consistent with ourobligations and your rights under the law.
- Information About Us
We are Health Your Way C.I.C., a not-for-profit community interest company registered in England under company number 08518953.
The address of our registered office is: Queens Gardens Business Centre, 31 Ironmarket, Newcastle-under-Lyme, Staffordshire ST5 1RP.
We are registered with the Information Commissioner’s Office under reference ZA006181.
- What Does This Policy Cover?
- What is Personal Data?
Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.
Personal data is, in simpler terms, any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers. It does not include anonymised data.
- What Are My Rights?
Under the GDPR, you have the following rights:
- The right to access the personal data we hold about you. Section 10 will tell you how to do this.
- The right to have your personal data rectified if any of your personal data held by us is inaccurate or incomplete. Please contact us using the details in section 11 to find out more.
- The right of erasure. You may ask us to delete or otherwise dispose of any of your personal data that we have. Please contact us using the details in section 11 to find out more.
- The right to restrict the processing of your personal data.
- The right to object to us using your personal data for a particular purpose or purposes.
- The right to data portability. This means that, if you have provided personal data to us directly, weare using it with your consent or for the performance of a contract, and that data is processed using automated means, you can ask us for a copy of that personal data to re-use with another service or business in many cases.
- Rights relating to automated decision-making and profiling. We do not use your personal data in this way.
For more information about our use of your personal data or exercising your rights as outlined above, please contact us using the details provided in section 11.
Further information about your rights can also be obtained from the Information Commissioner’s Office the UK supervisory authority for data protection issuesor your local Citizens Advice Bureau.
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office. We should be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
- What Data Do You Collect?
Depending upon how you use the Website and whether you are a client of ours, the types of personal and non-personal data that we collect are listed in the Schedule.
- How Do You Use My Personal Data?
Under the GDPR,we must always have a lawful basis for using personal data. This may be because the data is necessary for our performance of a contract with you, because you have consented to our use of your personal data, or because it is in ourlegitimate business interests to use it. Your personal data may be used for one or more of the following purposes:
- Supplying services to you. Your personal details are required in order for usto enter into a contract with you.
- Personalising and tailoring ourservices for you. This may involve sharing your data with the relevant Clinical Commissioning Group, Local Authority, care agency and Innovue Limited where you have given us permission to do so.
- Communicating with you. This may include responding to emails or calls from you.
- Supplying you with informationby email that you have opted-in to (you may unsubscribe or opt-out at any time by clicking on the ‘Unsubscribe’ link at the foot of the email).
With your permission and/or where permitted by law, we may also use your personal data for marketing purposes, which may include contacting you by email, telephone, text messageandpost with information and news about ourservices. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with ourobligations under the GDPR and the Privacy and Electronic Communications (EC Directive) Regulations 2003, and you will always have the opportunity to opt-out.
- How Long Will You Keep My Personal Data?
We will only retain your personal data for as long as is necessary to fulfil the purposes we collected it for. These purposes may include satisfying any legal, accounting, or reporting requirements.
When deciding what is the correct time to retain your personal data, we consider its amount, nature and sensitivity, potential risk of harm from unauthorised use or disclosure, the processing purposes, and whether these can be achieved by other means and legal requirements. Some personal data may be retained for up to 8 years to enable us to comply with various regulatory requirements.
In some circumstances we may anonymise your personal data for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
- How and Where Do You Store or Transfer My Personal Data?
We will only store or transfer your personal data within the European Economic Area (the “EEA”). The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein. This means that your personal data will be fully protected under the GDPR or to equivalent standards by law.
- Can I Withhold Information?
You may access the Website without providing any personal data. However, to use all features and functions available on the Website (e.g. the contact form) you may be required to submit or allow for the collection of certain data.
If you are a client, then you are free not to provide personal data. However, this may mean that we are unable to provide some or any services to you.
- How Can I Access My Personal Data?
If you want to know what personal data wehold about you, you can ask usfor details of that personal data and for a copy of it (where any such personal data is held). This is known as a “subject access request”.
All subject access requests should be made in writing and sent to the email or postal addresses shown in section 11.
There is not normally any charge for a subject access request. If your request is ‘manifestly unfounded or excessive’ (for example, if you make repetitive requests) a fee may be charged to cover ouradministrative costs in responding.
Wewill respond to your subject access request within one month of receiving it. Normally, we aim to provide a complete response, including a copy of your personal data within that time. In some cases, however, particularly if your request is more complex, more time may be required up to a maximum of three months from the date we receive your request. You will be kept fully informed of our progress.
- How Do I Contact You?
To contact usabout anything to do with your personal data and data protection, including to make a subject access request, please contact Anne-Marie Mason (Director) on 0800 6446414 or at firstname.lastname@example.org
Data that may be collected through using the Website
Date of birth
Information that you provide on the contact form not listed above
Web browser type and version
Data that may be collected through using our services as a client
- Home phone number
- Mobile phone number
- Email address
- Home address
- Date of birth
- Indicative Budget
- Actual Budget
- Carer / guardian name
- Carer / guardian home phone number
- Carer / guardian mobile phone number
- Carer / guardian email address
- Carer / guardian home address
- Carer / guardian relation to client
- Referrer name
- Referrer home phone number
- Referrer mobile phone number
- Referrer email address
- Referrer home address
- Referrer relation to client
- Client health needs
- Client health and social care provision
- Client care and support preferences
- Client direct payment / managed account details
- Individual Employer Name
- Employer Phone Number
- Employer Mobile
- Employer Email Address
- Employer Home Address
- Employer Gender
- Employer National Insurance Number
- Employers and Public Liability Insurance Provider
- Payroll Provider
- Payroll Preferences
- Employer HMRC Consent
- Employee Name
- Employee Phone Number
- Employee Mobile
- Employee Email Address
- Employee Home Address
- Employee Date of Birth
- Employee Nationality
- Employee Gender
- Employee National Insurance Number
- Employee Employment Details and Status
- Employee Student Loan Status
- Employee Bank Details
- Employee Time Sheet
- Employee Statutory Entitlement Record
- Employee Expense Records
- Employee Mileage Records
- Employer Pension ID
- Employer’s employees references/ reference requests
- Completed DBS check notifications