PRIVACY POLICY
CHARLOTTE FULLAM THERAPY PRIVACY POLICY
​
GENERAL DATA PROTECTION REGULATION (GDPR)
This privacy policy relates to – Charlotte Fullam Therapy – www.fullamtherapy.co.uk.
Under current data protection legislation the law has now defined how we collect, use, disclose, retain and dispose of your personal data as well as your personal data rights.
I am committed to ensuring that your privacy is protected at all times and therefore have defined within this privacy notice the key principles of how I handle both your Personal Data and Sensitive Personal Data.
​
​
What personal data do I collect and what do I use it for?
​
I may collect and process Personal Data and Sensitive Personal Data (special category data) in forms such as:
Website: When making an online enquiry you may be asked to enter your name and treatment enquiry.
Registration form: Upon registration you will be required to provide personal information such as name, date of birth, GP contact details, any relevant medical history, allergies and medications being taken.
Medical notes and medical history: During your consultation I may collect medical information, past treatment, medical history, and consent. This information will only be processed by myself, who is appointed the processor and controller under the respective lawful basis for processing special category data.
Charlotte Fullam Therapy may process both Personal Data and Special Category Data. The type of data that is needed to take an accurate medical record before performing hypnosis or therapy/coaching, may fall under both Personal Data and Special Category Data (sensitive personal data).
Online payments: I use a booking/payment system within my website. We only use secure reputable payment facilities and follow UK guidelines.
​
​
Personal Data
​
This is any information relating to an identifiable person who can be directly or indirectly identified. For example: Name, ID, online identification.
​
​
Sensitive Personal Data (Special Category Data)
​
Special Category Data is personal data that the GDPR says is more sensitive and, therefore, needs more protection.
In order to lawfully process ‘Special Category Data’, and ‘Sensitive Personal Data’ we have identified both a lawful basis under Article 6 Consent and Vital Interest and a separate condition for processing special category data under Article 9 (2) (h) of the GDPR.
(h) ‘processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;’
​
​
Lawful basis for processing your data
​
I have reviewed my Lawful Basis and have identified Consent and Vital Interests as being the most appropriate Lawful Basis for processing your data. (Article 6)
Lawful Basis requires that the processing of patient data must be ‘necessary’.
Under the guide for transparency, ‘right to be informed’, Charlotte Fullam Therapy will ensure that all persons will be informed of the Lawful Basis for processing and the intended purpose for processing your data.
​
​
To whom and when will I disclose or share your personal data?
​
I will not share, sell, distribute or lease your personal information to any third party unless we have your prior permission or are required to do so by law.
In the case of third party, where you have given your permission for us to share your information, such as with specific health care professionals, if I do, I will require that these third parties acting on our behalf protect the confidentiality and security of your data that you have agreed to share with them.
​
​
How long do I keep your data for?
​
The personal data I hold on will be stored for a period of 7 years. You may request that I delete your personal information by writing to me and asking that the deletion be done. I will contact you to confirm the deletion has been made.
​
​
What are your rights
​
You have the right to be informed, have access to, rectify, erase, object or restrict processing of any data that I hold on you.
To exercise these rights please contact me either by phone or in writing.
​
​
Security
I am committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure I have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect.
​
​
Contact and Communication with me
​
Where I have clearly stated and made you aware of the fact, and where you have given your express permission, I may use your details to send you products/services information through a mailing list system. This is done in accordance with the regulations named in ‘The policy’ above.
The website, www.fullamtherapy.co.uk contains information that enables an electronic contact to my business, as well as direct communication with me, which also includes a general address of electronic mail. If a data subject contacts the controller by email or via a contact form, the personal data transmitted by the data subject are automatically stored. Such personal data, transmitted on a voluntary basis by a data subject to the data controller, are stored for the purpose of processing or contacting or responding to the data subject. There is no transfer of this personal data to third parties.
​
​
Email Mailing List and Marketing Messages
​
I operate an email mailing list program, used to inform subscribers about products, services and/news/courses I supply/publish. Users can subscribe through an online automated process where they have given their explicit permission.
Subscriber personal details are collected, processed, managed and stored in accordance with the regulations named in ‘The policy’ above. Subscribers can unsubscribe at any time through an automated online service, or if not available, other means as detailed in the footer of sent marketing messages. The type and content of marketing messages subscribers receive, and if it may contain third party content, is clearly outlined at the point of subscription.
Email marketing messages may contain tracking beacons / tracked clickable links or similar server technologies in order to track subscriber activity within email marketing messages. Where used, such marketing messages may record a range of subscriber data relating to engagement, geographic, demographics and already stored subscriber data.
​
​
Downloads and Media Files
​
Any downloadable documents, files or media that are made available on this website are provided to users at their own risk. While all precautions have been taken to ensure the downloads and files are virus free, users are advised to verify their authenticity using third party anti-virus software or similar applications.
​
​
Cookies
​
Cookies are small files saved to the user’s computer hard drive that track, save and store information about the user’s interactions and usage of the website. This allows the website, through its server, to provide users with a tailored experience within the website.
Users are advised that, if they wish to deny the use and saving of cookies from this website on to their computer’s hard drive, they should take necessary steps within their web browser’s security settings to block all cookies from this website and its external serving vendors or use the cookie control system, if available upon their first visit.
However, if you select this setting you may be unable to access certain parts of our site. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to my site.
​
​
Website Visitor Tracking
​
When someone visits www.fullamtherpy.co.uk I use a third-party service, Google Analytics, to collect standard internet log information and details of visitor behaviour patterns. I do this to find out things such as the number of visitors to the various parts of the site. This information is only processed in a way that does not identify anyone. We do not make, and do not allow Google to make, any attempt to find out the identities of anyone visiting our website.
​
​
Revising the Privacy Notice
​
From time to time I may need to make changes to my privacy notice to reflect changes in legal obligations or the ways in which we process your data. I will notify you of any changes that may become effective that will affect you.
Policy last updated – November 1st 2021.