Get Mind Fit

Privacy Notice For Individual Clients , Company Clients, Students and Supervisees.

 Hilary Norris-Evans

119 Victoria Road, Cirencester GL7 1 HA

 07887714892,

info@getmindfit.co.uk

 www.getmindfit.co.uk

Get Mind Fit is the trading name of Hilary Norris-Evans. Another trading name is UK Academy of Therapeutic Arts and Sciences for the provision of training.

Get Mind Fit is a limited company, registered in England/Wales/Scotland/Northern Ireland. Company Number 03931406

I, Hilary Norris-Evans, am the Data Controller and Processor of Get Mind Fit.

The lawful basis for processing data

The basis on which I keep client data is that of “Legitimate Interests”. This means that the data is necessary for me to fulfil the contract that we have together (i.e. to provide therapy for individual clients, to provide supervision for supervisees, to provide assessment for students of CEC and to provide training, tutorials and supervision for students of hypnotherapy ( UK Academy) and that it is data that you would reasonably expect me to hold and use.  

Data

For those who enquire about therapy, assessment or training, the data I hold includes any information you have sent me by email/text/message

For those clients who book and attend at least one session, the data I hold includes:

·         Basic information such as name, email address, phone number

·         Information that you give me as part of the work we do together

·         Records of what interventions that I use (or potentially do not use) in our sessions

·         Emails, texts and/or messages that are sent between us

·         Information sent from any third party, e.g. GP, insurance company, EAP

Some of the information that you give me may fall under the definition of special category of data as defined by the General Data Protection Regulation. The condition for processing this special data is (précised from the Act) “processing is necessary for medical diagnosis, the provision of health care or treatment pursuant to contract with a health professional”.

Data is not shared with anyone, except possibly your GP, and for any reasons covered by the Requirements for Disclosure which are detailed and discussed when we first meet.

The data is primarily used to enable me to provide therapy for you. It may also be used for scientific research purposes and statistical purposes.

For fellow therapists or students who require supervision, assessment or training in therapy, the data I hold: is:

·         information you provide on the forms required for supervision, training or assessment

·         financial information

·         emails and texts sent between us

·         details of any complaints or concerns

·         work submitted

Data Sharing

Data is shared in the following situations:

·         If I am required to provide data to a court of law or to your GP ( for clients)

·         With our regulators ( CNHC) who may enquire if students or supervisee hypnotherapists are in good standing

·         With NCH (to register students for membership and for completing the portfolio and external certification process)

·         With my accountant who may see data that you submit when making payment (clients, supervisees, students and fellow therapists)

·         With any venues that may require attendee lists for their own regulations ( students and supervisees)

·         With CEC ( Central England College for students being assessed)

 

Details of where data is held:

·         Any emails sent between us are held on my computer, my tablet and smart phone, in cloudand also on hard drive.

·         Any texts sent between us are held on my smart phone.

·         Your notes are held in a locked filing cabinet.

 

 

  For clients, data is kept for 8 years. The length of time is based on advice from my insurance company. After this time any paper records are shredded and computer records permanently deleted. For students and supervisees, data is kept for 840 years. This is based on the likely length of your career, during which time you may need to confirm your training and/or supervision.

Security

Get Mind Fit takes the security of data seriously and as such:

·         All data is held securely (including payment systems)

However, we are not in control of any data, including emails which you may send us.

If there is any breach of data security Get Mind Fit will give full details to the Information Commissioners Office and any person affected within 72 hours of the breach and do all possible to minimise any potential impact.

Your Rights

You have rights with regards to the data held:

·         The right of access. I will provide you with all data I hold on you as soon as I can following a request (and definitely within 30 days, unless this is impossible due to holidays or illness).

·         The right to rectification. If any data I hold is incorrect, just let me know and I will correct it as soon as I can following a request (and definitely within 30 days, unless this is impossible due to holidays or illness).

·         The right to erasure. If you wish me to erase your data just let me know and I will delete any computer records and shred any paper records as soon as I can following a request (and definitely within 30 days, unless this is impossible due to holidays or illness). NB: data may be retained for scientific research, historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing but this would never include case notes or data such as address/email/phone. If you are a student/graduate/supervisee, erasure of your data would mean we will not in any circumstances be able to confirm details of training or qualifications. Please consider carefully the implications of erasure of data.

·         The right to restrict processing. This would usually be a stop-gap measure before correction of any errors or before erasure

·         The right to data portability. This might apply if you want your notes sent to another therapist for example, but it is likely that the easiest solution would come under the right to access, i.e., I would send the data to you.

·         The right to object to:

o    processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling). Get Mind Fit  does not engage in these things

o    direct marketing.  I may send emails, texts about courses or offers of interest to you, particularly, but not exclusively if you are a student ( through UK Academy, fellow therapist) or supervisee of mine . If you do not wish to receive these , please inform me. You may opt out at any time.

o    processing for purposes of scientific/historical research and statistics. For this, you must provide grounds for your objection.

o    automated decision making and profiling. Get Mind Fit does not engage in automated decision making or profiling

In exceptional circumstances, I may be required to provide legal or regulatory authorities with your personal data in order to comply with legal requirements or regulations.  Whilst I will be required to comply with any such request, I will use reasonable endeavours (if allowed by law) to ensure that you are first informed about this.

Personal data that I hold about you will not be distributed or processed outside of England and Wales.

If you have any doubts or concerns over the way that I hold or process your personal data you have the right to complain to the ICO, I would however hope that you would contact me first with any complaint, and I will use my best endeavours to address this promptly.