Massage for Everyone
Massage for Everyone
Treatment & Prices
Treatment & Prices
Privacy Policy
Name: Vicky Barbour trading as Every Body Massage Therapy under Barbour Solutions Ltd
Tel: 01259 809151
Email: info@everybodymassagetherapy.co.uk
ICO reference: ZA492493
Date created/updated: 23/10/2020
The GDPR (General Data Protection Regulation) May 2018 is the legal regulation that has been put in place to safeguard an individual’s personal information. The following privacy policy details the lawful basis for Every Body Massage Therapy to hold information, the type of information that Every Body Massage Therapy holds about it’s clients, why that information is required, who it is shared with, how that information is used and protected and details the rights an individual has in terms of access to that information or, requests for information held to be amended or deleted.
These privacy notices applies to our web site and all products and services offered by Every Body Massage Therapy.
Why the information is required
The lawful basis for Every Body Massage Therapy processing client data is:
-
consent or contract for personal data
and
-
the fact that the processing of the special category of personal data is necessary for the provision of healthcare
-
there is also a legitimate interest in retention of records as detailed in ‘ How long is the information held for’ below.
In order to provide effective and safe massage therapy, information about your current health is required along with your medical history. This information is used only to provide you with the best possible therapy and advises.
We also require your contact details to arrange appointment times with you and for you to book & manage your appointments online.
As a registered massage therapist with the SMTO (Scottish Massage Therapists Organisation) and the CNHC (Complementary & Natural Healthcare Council) I abide by these associations codes of conduct and confidentiality requirements.
Where the information is gathered
Every Body Massage Therapy collects personal identification information by clients filling out a consultation form when attending the therapy room and / or receiving therapy from the therapist.
Post lockdown for COVID-19 (September 2020), clients will be asked to supply this information via an online form which links to a third party application called Jotform. Jotform is fully GDPR compliant and the information for this is found here: https://www.jotform.com/gdpr-compliance/ and their privacy policy found here: https://www.jotform.com/privacy/
Clients will be asked for name, address, email address, phone number, occupation and relevant medical information provided on the consultation form and discussed during the first and subsequent treatments. This is required in order to assess treatment requirements and in order to provide a safe and effective massage.
Clients will also be asked to complete a COVID-19 screening form online via Jotform to ensure that it is safe for them to attend for their treatment. Clients will be asked for name, address, email address, phone number and relevant medical and other information related to COVID-19.
Clients can always refuse to supply personally identification information, except that it may prevent them from receiving therapy.
When booking appointments in person or online, clients will be asked to provide name, address, telephone number and payment details so that the booking system can create a customer record, an appointment and treatments can be paid for upfront if required. Client records are created in the web host provider Wix. Wix is Payment Card Industry Data Security Standards (PCI DSS) compliant and is accredited as a level 1 service provider and merchant. This standard helps create a secure environment by increasing cardholder data, thus reducing credit card fraud. WIX is also fully GDPR compliant and their privacy policy can be read here: https://www.wix.com/about/privacy
Every Body Massage Therapy will also collect information by keeping treatment notes, which will be recorded after each massage session and by keeping diarised records of appointment times. We may also collect information supplied by clients when corresponding by email or text.
What is done with the information gathered
The consultation form is used in order to assess your massage requirements and to provide you with a safe and effective massage. The treatment record is used to record information about the treatment and as a reference for any subsequent treatments. The COVID-19 screening form is used to assess whether it is safe for clients to attend their appointment and that they pose no risk in transmitting the virus or are not at a high risk of COVID-19. Only the therapist will have access to the consultation form, COVID form and treatment record.
The booking system is used to create your appointment, allow you to pay online and to allow you to cancel or reschedule your appointment. It is also used to create your client record where your reward points are stored.
Your information will never be shared with anyone else (other than required for legal process) without explaining the reason why this is necessary and by obtaining your explicit consent. No medical information is passed on to a third party unless with your express written permission unless this is in the event of an emergency when medical information may be passed to a third party such as the ambulance service or other medical professional.
The contact information you provide may be used by Every Body Massage Therapy to contact you in relation to appointment times or regarding your treatment.
How long is the information held for
Every Body Massage Therapy will hold client data for 7 years from the date of the client's last visit or, if the client is a child, until his or her 25th birthday if the client was 17 when the treatment ended.
This means that there is a 'legitimate interest' in retaining records for this period.
Records are also required to be kept for insurance purposes.
Your data will not be transferred without your consent.
Records will be reviewed and data will be disposed of once a year and destroyed if they are no longer bound by the regulated legal timescale for such records to be held.
At any point you may request to see, rectify or request copies of your information.
Security Policy
Every Body Massage Therapy is committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, suitable physical, electronic and managerial procedures have been put in place to safeguard and secure the information that is collected both online and on paper.
The consultation form along with your record of treatment is stored in a locked filing cabinet in the treatment room at Room 3, Alloa Business Centre, Whins Road, Alloa, FK10 3SA. Post re-opening following COVID-19 lockdown (September 2020), all consultation information and COVID screening information is held electronically on a password protected document on the cloud drive of a password protected computer.
A copy of the PDF consultation and COVID screening forms that are created on submission are also held on Jotform however theses are deleted once saved on Every Body Massage Therapy password protected computer.
Changes to these privacy notices
Every Body Massage Therapy has the discretion to update these privacy notices at any time. When we do, we will revise the updated date at the top of this document. We encourage clients to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect. You acknowledge and agree that it is your responsibility to review these privacy notices periodically and become aware of modifications.
Individual's (Clients) Rights
You, the client, have the following rights:
-
The right to be informed how we use your personal data
-
The right to access your personal data
-
The right to limit how the information is used or shared
-
The right to be forgotten and have your data deleted in specific circumstances where this does not contravene our legal or our insurance responsibilities.
-
The right to data portability to transfer copies of your data to another service provider
-
The right to have information corrected if it’s out of date, incomplete or incorrect
-
The right to lodge a complaint with the Information Commissioner's Office.
More information can be found here:
Your acceptance of these terms
By using our services, you signify your acceptance of this policy. If you do not agree to this policy, please do not use our services. Your continued use of our services following the posting of changes to this policy will be deemed your acceptance of those changes.
Contacting us
If you have any questions about these privacy notices, the practices of Every Body Massage Therapy, or your dealings with us, please contact the business owner Vicky Barbour at
info@everybodymassagetherapy.co.uk
Every Body Massage Therapy
Room 3 Alloa Business Centre
Whins Road
Alloa
FK10 3SA
Tel: 01259 809151