This privacy notice provides you with details of how we collect and process your personal data through your use of our site www.thecbtpractice.co.uk
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would be grateful if you would contact us first if you do have a complaint so that we can try to resolve it for you.
OWNER AND DATA CONTROLLER
Claudia Herrieven, 48 Beaufort Avenue, Langland, Swansea, SA3 4PB, [email protected], 07985020837.
THE LEGAL BASES, WE RELY ON FOR PROCESSING
The Owner may process Personal Data relating to Users if one of the following applies:
• Users have given their consent for one or more specific purposes;
• provision of Data is necessary for the performance of an agreement with the User and any pre-contractual obligations;
• processing is necessary for compliance with a legal obligation to which the Owner is subject;
• processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party;
• Upon request, the Owner will help to clarify the specific legal basis that applies to the processing if there is any concern.
WHEN DO WE COLLECT YOUR PERSONAL DATA?
Personal Data is collected in the following methods:
1. filling in forms on our website
2. communicating with us by post, phone, email
3. automatically collected Technical Data about your equipment, browsing actions and usage patterns. We collect this data by using cookies, server logs and similar technologies.
WHAT PERSONAL DATA DO WE COLLECT?
We collect the following Personal Data from you:
1. Identity Data may include your first name, last name
2. Contact Data may include your email address and telephone numbers
3. Technical Data may include your, internet protocol addresses, browser type and version, browser plug-in types and versions, time zone setting and location, operating system and platform and other technology on the devices you use to access this site
4. Usage Data may include information about how you use our website
HOW AND WHY DO WE USE YOUR PERSONAL DATA?
The Data is used to respond to your queries or questions about our services or products; as well as for the following purposes: analytics, SPAM protection, managing contacts and contacting the User.
We want to provide the best possible User experience for customers, and we use Data to allow us to offer to you information, products and services that are most likely to interest you.
The Data privacy law allows this as part of our legitimate interest in understanding our customers and delivering the best possible service.
HOW WE PROTECT YOUR PERSONAL DATA
We know how much Data security matters to all our customers. We will treat your Data with the utmost care and have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
Our website interaction with customers is secured using ‘https’ technology.
We will notify you and any applicable regulator of a breach where we are legally required to do so.¬
HOW LONG WILL WE KEEP YOUR PERSONAL DATA?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for six years after they cease being customers for tax purposes.
Once the retention period expires, Personal Data shall be deleted.
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
We may at times share your Personal Data with third parties we work with (e.g. if you are referred through a referral agency or a private health insurance)
WHERE YOUR PERSONAL DATA MAY BE PROCESSED
We will not share your Personal Data with third parties and suppliers outside the European Economic Area (EEA).
WHAT ARE MY RIGHTS?
Users may exercise certain rights regarding the processing of Personal Data by the Owner.
• Right to withdraw their consent at any time. Users have the right to withdraw consent where they have previously given their consent to the processing of their Personal Data.
• Right to object to the processing of their Data. Users have the right to object to the processing of their Data if the processing is carried out on a legal basis other than consent.
• Right to access their Data. Users have the right to learn if Data is being processed by the Owner and obtain a copy of the Data being processed.
• Right to verify and seek rectification. Users have the right to verify the accuracy of their Data and ask for it to be updated or corrected.
• Right to restrict the processing of their Data. Users have the right, under certain circumstances, to restrict the processing of their Data. In this case, the Owner will not process their Data for any purpose other than storing it.
• Right to have their Personal Data deleted. Users have the right, under certain circumstances, to obtain the erasure of their Data from the Owner.
• Right to receive their Data and have it transferred to another controller. Users have the right to receive their Data and, if technically feasible, to have it transmitted to another controller without any hindrance.
• Right to object. Users have the right to bring a claim before their competent data protection authority.
DETAILS ABOUT THE RIGHT TO OBJECT
Where Personal Data is processed for the legitimate interests pursued by the Owner, Users may object to such processing by providing a ground related to their particular situation to justify the objection.
Users must know that, however, should their Personal Data be processed for direct marketing purposes, they can object to that processing at any time without providing any justification.
HOW TO EXERCISE YOUR RIGHTS
Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. These requests can be free of charge and will be addressed by the Owner within one month.
CONTACTING THE INFORMATION COMMISSIONER’S OFFICE (UK)
If you have any issue with how your Data has been handled or are not satisfied with the response you have received to any request, you have the right to lodge a complaint with the Information Commissioner’s Office by calling 0303 123 1113 or go online to www.ico.org.uk/concerns.
INFORMATION NOT CONTAINED IN THIS POLICY
More details concerning the collection or processing of Personal Data may be requested from the Owner at any time. Please see the contact information at the beginning of this document.