Privacy Notice (May 2018)

New laws relating to General Data Protection Regulation (GDPR) come into effect from 25 May 2018.  The purpose of GDPR is to provide a set of standardised data protection laws across all EU member countries.   This document sets out how Angela Gilchrist Psychology complies with these laws.

 

Data Control

Ms Angela Gilchrist is the data controller for Angela Gilchrist Psychology.

 

What personal data we process

Angela Gilchrist Psychology processes the following personal data from clients:

  • Personal data: basic contact information: name, address, email, contact number, video conference ID (if online therapy), name and contact information for next of kin, and GP contact details.
  • Sensitive personal data: Therapy records (therapist notes, letters, reports and/or outcome measures).
  • If you complete a web-based enquiry form, we will also collect any information you provide to us as well as your internet protocol (IP) address.  This is automatically supplied by the website software used to offer the form.  All web services used by Angela Gilchrist Psychology are verified by themselves as GDPR compliant.

If you are referred by your health insurance provider, we will also collect and process personal data provided by that organisation. This includes basic contact information, referral information, and health insurance policy number and authorisation for psychological treatment.

 

The lawful basis for processing personal data

Angela Gilchrist Psychology has a legitimate interest in using the personal data and sensitive personal data we collect to provide health care and treatment. The data collected is necessary for us to provide psychological therapy to clients.  

We may also ask for information on how you found our service for the purpose of our own marketing research.  No information you provide is passed on without your consent.  We will never sell your information to others.

 

What we do with your personal information

At Angela Gilchrist Psychology we take your privacy seriously. We will only use your personal information to provide the services you have requested from us.

If you do not provide the personal information requested, then we may be unable to provide a service to you.

 

How long we store personal information

We will only store your personal information for as long as it is required.  Basic contact information held on a mobile phone is deleted at the end of therapy.

The sensitive personal data defined above is stored for a period of 7 years after the end of therapy. After this time, this data is deleted at the end of each calendar year.

 

How your personal information is used

We use the information we collect to:

  • Provide our services to you.
  • Process payment for such services.
  • Send you information about our services that might be of interest to you.  You have the right to opt-out at any time, and request that your personal contact information is deleted to prevent future proactive contact from ourselves.

How we might share personal information

We hold information about each of our clients and the therapy they receive in confidence. This means that we will not normally share your personal information with anyone else. However, there are exceptions to this when there may be need for liaison with other parties:

  • If you are referred by your health insurance provider, or otherwise claiming through a health insurance policy to fund therapy, then we will share appointment schedules with that organisation for the purposes of billing. We may also share information with that organisation to provide treatment updates.
  • In cases where treatment has been instructed by a solicitor, relevant clinical information from therapy records will be shared with legal services as required and with your written consent.

In exceptional circumstances, we might need to share personal information with relevant authorities:

  • When there is need-to-know information for another health provider, such as your GP or Psychiatrist.
  • When disclosure is in the public interest, to prevent a miscarriage of justice or where there is a legal duty, for example a Court Order.
  • When the information concerns risk of harm to the client, or risk of harm to another adult or a child. We will discuss such a proposed disclosure with you unless we believe that to do so could increase the level of risk to you or to someone else.

What we will NOT do with your personal information

We will not share your personal information with third-parties for marketing purposes.

 

How we ensure the security of personal information

Personal information is minimised in phone and email communication. Sensitive personal data will be sent to clients in an email attachment that is password protected. Angela Gilchrist Psychology will never use open or insecure Wi-Fi networks to send any personal data.

We use Transport Layer Security (TLS) to encrypt and protect email traffic. If your email service does not support TLS, you should be aware that any emails we send or receive may not be protected in transit.

We will also monitor any emails sent to us, including file attachments, for viruses or malicious software. Please be aware that you have a responsibility to ensure that any email you send is within the bounds of the law.

Should you choose to contact us using an email link, or our contact form none of the data that you supply will be stored by this website or passed to / be processed by any of the third party data processors.

Instead the data will be collated into an email and sent to us over the Transport Layer Security (TLS).

Should you choose not to consent to us using your contact details in any form submitted, please contact us by phone or direct email.

This website is hosted by 3rd party servers located in the EU which are compliant with EU legislation.

 

Personal information is also stored on office computers. These are password protected. Malware and antivirus protection is installed on all computing devices. Mobile devices are protected with a passcode/thumbprint scanner and mobile security.

 

Your right to access the personal information we hold about you

  • You have a right to access the information we hold about you.
  • We will usually share this with you within 30 days of receiving a request.
  • There may be an admin fee for supplying the information to you.
  • We may request further evidence from you to check your identity.
  • A copy of your personal information will usually be sent to you in a permanent form (that is, a printed copy).
  • You have a right to get your personal information corrected if it is inaccurate.
  • You can complain to a regulator. If you think that we haven't complied with data protection laws, you have a right to lodge a complaint with the Information Commissioner’s Office.

Angela Gilchrist Psychology reserves the right to refuse a request to delete a client’s personal information where this constitutes therapy records. Therapy records are retained for a period of 7 years in accordance with the guidelines and requirements for record keeping by The British Psychological Society (BPS; 2000)[1]and The Health and Care Professions Council (HCPC; 2017)[2].

 

Ms Angela Gilchrist

Consultant Clinical Psychologist & Director

May 2018

 

[1]The British Psychological Society (2000). Clinical Psychology and Case Notes: Guidance on Good Practice. Leicester: Division of Clinical Psychology, BPS.

[2]Health and Care Professions Council (2017). Confidentiality – guidance for registrants. London: HCPC.

Website Legal Disclaimer

The information contained in this website is for general information purposes only. Whilst we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk.

In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this website.


Through this website you are able to link to other websites which are not under our control. We have no control over the nature, content and availability of those sites. The inclusion of any links does not necessarily imply a recommendation or endorse the views expressed within them.

We encourage you to read the privacy statements on the other websites you visit.

Every effort is made to keep the website up and running smoothly. However, we take no responsibility for, and will not be liable for, the website being temporarily unavailable due to technical issues beyond our control.