I am committed to safeguarding the privacy of website visitors and service users; this privacy notice provides you with details of how I collect and process your personal data through your use of my site: www.emilyjnewman.co.uk
I adhere to all laws and procedures relating to the General Data Protection Regulation (GDPR) and will only use your data to provide you with the specific service or services you explicitly agree to.
OWNER AND DATA CONTROLLER
I am registered with the Information Commissioner’s Office (ICO) as the Data Controller of the organisation named Emily J Newman; reference ZA578546.
For further details relating to clinical notes, please refer to my GDPR privacy notice given to clients after the first session.
THE LEGAL BASES I RELY ON FOR PROCESSING
The Owner may process Personal Data relating to Users if one of the following applies:
• Users have given their consent for one or more specific purposes;
• Provision of Data is necessary for the performance of an agreement with the User and any pre-contractual obligations;
• Processing is necessary for compliance with a legal obligation to which the Owner is subject;
• Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party;
• Upon request, the Owner will help to clarify the specific legal basis that applies to the processing if there is any concern.
WHEN DO I COLLECT YOUR PERSONAL DATA?
Personal Data is collected in the following methods:
1. communicating with me by post, phone, email
2. automatically collected Technical Data about your equipment, browsing actions and usage patterns. I collect this data by using cookies, server logs and similar technologies.
WHAT PERSONAL DATA DO I COLLECT?
I collect the following Personal Data from you:
1. Identity Data may include your first name, last name
2. Contact Data may include your billing address, email address and telephone numbers
3. Technical Data may include your, internet protocol addresses, browser type and version, browser plug-in types and versions, time zone setting and location, operating system and platform and other technology on the devices you use to access this site
4. Usage Data may include information about how you use our website
HOW AND WHY DO I USE YOUR PERSONAL DATA?
The Data is used to respond to your queries or questions about my professional services, as well as for the following purposes: analytics, SPAM protection and managing contacts, and contacting the User.
The Data privacy law allows this as part of my legitimate interest in understanding those who consult with me and delivering the best possible service.
HOW I PROTECT YOUR PERSONAL DATA
I will treat your Data with the utmost care and have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
My website interaction with customers is secured using ‘https’ technology.
I will notify you and any applicable regulator of a breach where I am legally required to do so.
HOW LONG WILL I KEEP YOUR PERSONAL DATA?
I will only retain your personal data for as long as necessary to fulfil the purposes I collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
By law I have to keep basic information about my clients (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
Once the retention period expires, Personal Data shall be deleted.
WHO DO I SHARE YOUR PERSONAL DATA WITH?
Your data is not shared with third parties unless you give permission for me to do so, as agreed in the contract between us. No data is used for marketing purposes.
WHAT ARE MY RIGHTS?
Users may exercise certain rights regarding the processing of Personal Data by the Owner.
• Right to withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
• Right to object to the processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
• Right to access their Data. Users have the right to learn if Data is being processed by the Owner and obtain a copy of the Data being processed.
• Right to verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
• Right to restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
• Right to have their Personal Data deleted. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
• Right to receive their Data and have it transferred to another controller. Users have the right to receive their Data and, if technically feasible, to have it transmitted to another controller without any hindrance.
• Right to object. Users have the right to bring a claim before their competent data protection authority.
DETAILS ABOUT THE RIGHT TO OBJECT
Where Personal Data is processed for the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
HOW TO EXERCISE YOUR RIGHTS
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be free of charge and will be addressed by the Owner within one month.
CONTACTING THE INFORMATION COMMISSIONER’S OFFICE (UK)
If you have any issue with how your Data has been handled or are not satisfied with the response you have received to any request, you have the right to lodge a complaint with the Information Commissioner’s Office by calling 0303 123 1113 or go online to www.ico.org.uk/concerns.
DEFINITIONS AND LEGAL REFERENCES
Personal Data (Data)
Any information that directly, indirectly, or in connection with other information — allows for the identification of a natural person.
Information collected automatically through this website which can include: the IP addresses or domain names of the computers utilised by the Users who use this website, the time of the request, the method utilised to submit the request to the server, the country of origin, the browser and the operating system, the time details per visit and the path followed within the website and other parameters about the device operating system and/or the User's computer environment.
The individual using this website who, unless otherwise specified, coincides with the Data Subject.
The natural person to whom the Personal Data refers.
Data Controller (or Owner)
The Data Controller, unless otherwise specified, is the Owner of this Website.
The means by which the Personal Data of the User is collected and processed.
The service provided by this website as described on this site.
European Union (or EU)
Unless otherwise specified, all references made within this document to the European Union include all current member states to the European Union and the European Economic Area.
A small piece of Data stored in the User's device.