Grass Roots Remedies Co-operative Privacy Notice
The General Data Protection Regulation which came into force on the 25th May 2018 introduced changes to the information that an organisation must provide to individuals relating to how it uses and stores personal data. This Privacy Notice incorporates these new requirements.
Grass Roots Remedies Co-operative Ltd. is a company registered in Scotland with the Company Number SC525407 and a Data Controller registered with the Information Commissioner’s Office. This Privacy Notice sets out how Grass Roots Remedies Co-op will obtain, use and protect your personal data.
This Privacy Notice may change from time to time; it will be available to you upon request.
How does Grass Roots Remedies Co-operative collect information about you?
Grass Roots Remedies Co-operative receives personal information about you:
- from the NHS (for example, a referral from your GP)
- third sector organisations (for example, a referral from another organisation you are involved with)
- and directly from you (for example, when you book an appointment with us, complete our client details form, a data capture form, self-refer by phone, email us to book onto our courses, or contact us online etc.)
What personal information may Grass Roots Remedies Co-operative collect about you?
We may collect and process the following categories of personal information. We do not collect all of this information from all of our clients and customers.
- Your contact information including your name, address, telephone number;
- Your date of birth;
- Your signature;
- Special category data (for example, race, religion, health information, sexual orientation etc)
- In the case of third party representatives (including legal guardians), details including their name, date of birth, signature and that person’s relationship with you.
If Grass Roots Remedies Co-operative does not receive from third parties, or you do not provide your personal information to us we may not be able to offer you our services.
How may Grass Roots Remedies Co-operative use your personal information?
Grass Roots Remedies Co-operative may use your personal information for the purposes of:
- Opening a client record for you, communicating with you through the record opening process and in the case of third party referrals, to confirm you wish to access our services;
- Communicating with you about your appointments & follow up treatment;
- Communicating with you about our courses and workshops;
- Recording our communications with you including telephone calls and written correspondence;
- Sending you marketing communications about new services within Grass Roots Remedies Co-op that we think would be of interest to you. Grass Roots Remedies Co-op will only contact you in ways that you have given us permission to do so, and you can withdraw your consent at any time.
- To evidence diversity, service attendance and other relevant areas to our funders for reporting purposes and funding application purposes. We may use special category data (for example health complaints, race, sexuality, religion etc) for these purposes anonymously (information that can identify you is not attached to this information).
On what basis does Grass Roots Remedies Co-operative use your personal information?
Grass Roots Remedies Co-op uses your personal information:
- To meet its legitimate interests including:
- offering you the services you requested, or were requested for you by a third party referrer, communicating and co-operating with third parties (for example processing a referral from a GP);
- performing administrative functions such as reporting on special category data (health complaints, race, religion, gender etc),
- In your vital interest for example in the case of an emergency where you have given details of an emergency contact, or if emergency services need to be contacted
- In the vital interest of others where you have shared information that we are legally obliged to share with the police and/or social work
How does Grass Roots Remedies Co-operative keep your information safe?
Grass Roots Remedies Co-op takes a number of steps to protect the privacy and security of your personal information, we maintain physical, electronic, technical and procedural safeguards in accordance with GDPR.
Personal and medical information that is shared with Grass Roots Remedies Co-operative via text message and email can’t be guaranteed to be secure.
How long will Grass Roots Remedies Co-operative keep your personal information?
Grass Roots Remedies Co-operative will keep your personal information for as long as it is necessary to comply with applicable laws. In order to offer our support services in our herbal medicine clinics we are required to collect sensitive personal information, and are obliged to hold onto medical information for a minimum of seven years, and at least up to the age of 25 if you are under the age of 16 when accessing our service. In our clinics we will annually review our patient lists and delete the phone numbers held on mobile phone, text messages and emails of any patient who has not attended for 6 months or more. We will transfer any relevant data contained in emails and text messages to paper patient records which we will keep for the periods stated above.
For course participants we will retain personal information supplied to us at registration only for the duration of the course. Contact information will be held with consent in order to inform participants of future events and courses.
Who may Grass Roots Remedies Co-operative share your information with?
Grass Roots Remedies Co-operative may share your information:
- within our organisation respecting the boundaries of confidentiality;
- with third parties where you have given us permission;
- when legally obligated (for example if you are an immediate danger to yourself or others, or
if you are endangering a population that cannot protect itself, such as the case of child or elder abuse)
What are your rights in respect to your personal information?
Under applicable laws, you have the right to:
- Request a copy of your personal information;
- Request the correction and/or deletion of your personal information. In the case of medical information we are legally obliged to retain it for a minimum of seven years, and at least up to the age of 25 if you are under the age of 16 when accessing our service. In this case you can request to view it and/or correct it, but not to delete it
- Request the restriction of the processing of your personal information or object to that processing. Please note that if we cannot collect or process your personal information we may not be able to offer you our clinical services
- Request receipt or transmission to another organisation, in a, machine-readable form, of the personal information that you have provided to Grass Roots Remedies Co-operative
- Complain to the Information Commissioner’s Office if your privacy rights are violated, or if you have suffered as a result of unlawful processing of your personal information; and
- Object to direct marketing. Where Grass Roots Remedies Co-operative collects your consent to send you marketing communications you have the right to withdraw your consent at any time.
We will respond to queries and requests within 30 days of receiving them.
If you would like to exercise any of these rights you have in regard to your personal information that Grass Roots Remedies Co-operative holds please write to:
Grass Roots Remedies Co-operative Ltd.
Care Of: The Health Agency (Green Reception)
The Wester Hailes Healthy Living Centre
30 Harvesters Way
Or email us on email@example.com Updated January 2019