Paula Lee Massage Therapy is committed to safe guarding the privacy of clients while providing the highest possible quality of service. Under the terms of the new General Data Protection Regulations (GDPR), I am required to explain to you how I will treat any personal and/or private data which I collect from you. I have a responsibility for ensuring data is collected, stored and handled appropriately and processed in line with this policy and data protection principles.
I/we refers to Paula Lee Massage Therapy and any contractors who may work under the ‘Paula Lee Massage Therapy’ umbrella in the future. Website refers to www.paulaleemassagetherapy.com. Facebook refers to https://www.facebook.com/paulaleemassagetherapy/
Paula Lee – Massage Therapy
I collect and handle two types of data. Basic personal date which includes name, address, contact details. I need this information to make appointments and to communicate my clients regarding any treatments or appointments and for any classes or workshops I may run. I also collect special categories data – which is health related data. This is to ensure it is safe for my clients to receive treatment and to give the appropriate treatment. For me to process health-related data, I am required by EU law to have signed, informed consent which we obtain at the time of consultation. Industry guidelines set by the General Council for Massage Therapists (GCMT) state clients/patients/users records need to be kept for 7 years. In case of children, for 5 years after 21st birthday, for terminally or seriously ill clients/patients/users records should be kept indefinitely. After which time the records will be securely destroyed.
My consultation and treatment forms are kept secured where unauthorised personnel can not view it. I will not collect any personal data that I do not need.
I may also send information regarding any new services, workshops I provide and/or new or additional locations. Permission is given to me at the time of consultation. Clients have the right to opt out of this at any time.
Data is stored for the purposes of recording treatment and evaluating progress. I will not share data with any third party unless required or entitled to do so by law under lawful data processing.
I may, on occasion, look to put testimonials on my facebook page or website. These will be written by, and done with full permission of, the individual.
Under the GDPR, individuals will have the right to obtain confirmation that their data is being processed, access to their personal data and other supplementary information. While I will not charge a fee for accessing this information, photocopying and postage costs require to be covered.