1. Serene self Therapy will:
• Comply with both the law and good practice in relation to Data Protection.
• Respect individuals’ rights.
• Be open and honest with individuals whose data is held.
• Provide training and support for staff who handle personal data, so that they can act confidently and consistently.
• Serene self Therapy recognises that it’s first priority under the Data Protection Act is to avoid causing harm to individuals. Information about staff and clients will be used fairly, securely and not disclosed to any person unlawfully.
Secondly, the Act aims to ensure that the legitimate concerns of individuals about the ways in which their data may be used are taken into account. In addition to being open and transparent, Serene self therapy will seek to give individuals as much choice as is possible and reasonable over what data is held and how it is used. Serene self Therapy is its Data Controller and is registered under the Data Protection Act 1998. All processing of personal data will be undertaken in accordance with the data protection principles.
2. Brief introduction to Data Protection Act
The Data Protection Act gives individuals the right to know what information is held about them and their child/children. It provides a framework to ensure that personal information is handled properly.
The Act works in two ways. Firstly, it states that anyone who processes personal information must comply with eight principles, which make sure that personal information is:
• Fairly and lawfully processed
• Processed for limited purposes
• Adequate, relevant and not excessive
• Accurate and up to date
• Not kept for longer than is necessary
• Processed in line with the rights of Data Subjects
• Not transferred to other countries without adequate protection
The second area covered by the Act provides individuals with important rights, including the right to find out what personal information is held on computer and most paper records.
Serene self Therapy will:
• Comply with both the law and good practice
• Respect individuals’ rights
• Be open and honest with individuals whose data is held
• Provide training and support for staff and volunteers who handle personal data, so that they can act confidently and consistently
The Data Subject is the individual whose personal data is being processed. Examples include:
• Employees – current and past
• Job applicants
• Service users
Processing means the use made of personal data including:
• Obtaining and retrieving
• Holding and storing
• Making available within or outside the organisation
• Printing, sorting, matching, comparing, destroying.
The Data Controller is the legal ‘person’ or organisation, that decides why and how personal data is to be processed. The data controller is responsible for complying with the Data Protection Act.
The Data Processor - the data controller may get another organisation to be their data processor, in other words to process the data on their behalf. Data processors are not subject to the Data Protection Act. The responsibility of what is processed and how remains with the data controller. There should be a written contract with the data processor who must have appropriate security.
The Data Protection Officer is the name given to the person in organisations who is the central point of contact for all data compliance issues.
Serene self Therapy recognises that it is overall responsible for ensuring that it complies with its legal obligations.
The Data Protection Officer has the following responsibilities:
• Briefing the board on Data Protection responsibilities
• Reviewing Data Protection and related policies
• Advising other staff on Data Protection issues
• Ensuring that Data Protection induction and training takes place
• Handling subject access requests
• Approving unusual or controversial disclosures of personal data
• Ensuring contracts with Data Processors have appropriate data protection clauses
• Electronic security
• Approving data protection-related statements on publicity materials and letters
Each member of staff at Serene self Therapy who handles personal data will comply with the organisation’s operational procedures for handling personal data (including induction and training) to ensure that good Data Protection practice is established and followed.
All staff are required to read, understand and accept any policies and procedures that relate to the personal data they may handle in the course of their work. Significant breaches of this policy will be handled under Serene self Therapy’s disciplinary procedures.
Serene self Therapy has a privacy statement for clients, setting out how their information will be used. This is available on request, and a version of this statement will also be used on the Organisation web site. (See Annex below)
Staff are required to sign a short statement indicating that they have been made aware of their confidentiality responsibilities.
In order to provide some services, Serene self Therapy will need to share client’s personal data with other agencies (Third Parties). Verbal or written agreement will always be sought from the client before data is shared.
Where anyone within Serene self therapy feels that it would be appropriate to disclose information in a way contrary to the confidentiality policy, or where an official disclosure request is received, this will only be done after discussions with a manager or the Data Protection Officer. All such disclosures will be documented.
This section of the policy only addresses security issues relating to personal data. It does not cover security of the building, business continuity or any other aspect of security.
Any recorded information on clients, volunteers and staff will be:
• Kept in locked cabinets
• Protected by the use of passwords if kept on computer
• Destroyed confidentially if it is no longer needed
Access to information on the main database is controlled by a password and only those needing access are given the password. Staff and volunteers should be careful about information that is displayed on their computer screen and make efforts to ensure that no unauthorised person can view the data when it is on display. Notes regarding personal data of clients should be shredded or destroyed.
Data Recording and storage
Serene self Therapy has a database holding basic information about all clients. The back-up discs of data are kept in a lockable unit.
Serene self Therapy will regularly review it’s procedures for ensuring that it’s records remain accurate and consistent and, in particular:
• The database system is reviewed and re-designed, where necessary, to encourage and facilitate the entry of accurate data.
• Data on any individual will be held in as few places as necessary, and all staff will be discouraged from establishing unnecessary additional data sets.
• Effective procedures are in place so that all relevant systems are updated when information about any individual changes.
• Staff who keep more detailed information about individuals will be given additional guidance on accuracy in record keeping.
• Data will be corrected if shown to be inaccurate
Serene self Therapy stores archived paper records of clients securely in the office.
7. Access to data
All clients and customers have the right to request access to all information stored about them.
Parents will have ready access to the records of their own child/children, but will not have access to information about any other child.
If any information is required, we act within the UK’s Freedom of Information act 2000 guidelines.
Access requests will be handled by the Data Protection Officer within the required time limit of 20 working days.
Access requests must be in writing(The letter can be emailed).
There is an administration charge of £20.00
You will be required to include the following;
• Your name (not needed if requesting environmental information)
• A contact address and telephone number.
• A detailed description of the information you want; for example, you might want all information held on a subject, or just a summary.
• Proof of parental responsibility if information is concerning a child.The request will be notified to any other parent who has parental responsibility.
All staff and volunteers are required to pass on anything which might be a subject access request to the Data Protection Officer without delay. All those making a subject access request will be asked to identify any other individuals who may also hold information about them, so that this data can be retrieved.
Where the individual making a subject access request is not personally known to the Data Protection Officer their identity will be verified before handing over any information. The required information will be provided in permanent form unless the applicant makes a specific request to be given supervised access in person.
Serene self Therapy will provide details of information to service users who request it unless the information may cause harm to another person.
Staff have the right to access their file to ensure that information is being used fairly. If information held is inaccurate, the individual must notify the Director so that this can be recorded on file.
Serene self Therapy is committed to ensuring that, in principle, Data Subjects are aware that their data is being processed and
• For what purpose it is being processed;
• What types of disclosure are likely; and
• How to exercise their rights in relation to the data.
Data Subjects will generally be informed in the following ways:
• Staff: in the staff terms and conditions
• Clients: when they request (on paper, on line or by phone) services
Standard statements will be provided to staff for use on forms where data is collected. Whenever data is collected, the number of mandatory fields will be kept to a minimum and Data Subjects will be informed which fields are mandatory and why.
Consent will normally not be sought for most processing of information about staff. Although staff details will only be disclosed for purposes unrelated to their work for Serene self Therapy (e.g. financial references) with their consent.
Information about volunteers will be made public according to their role, and consent will be sought for (a) the means of contact they prefer to be made public, and (b) any publication of information which is not essential for their role.
Information about clients will only be made public with their consent (this includes photographs). Consent should be given in writing. In all cases it will be documented on the database that consent has been given.
All Data Subjects will be given the opportunity to opt out of their data being used in particular ways, such as the right to opt out of direct marketing (see below). Serene self Therapy acknowledges that, once given, consent can be withdrawn, but not retrospectively. There may be occasions where Serene self Therapy has no choice but to retain data for a certain length of time, even though consent for using it has been withdrawn.
10. Direct marketing
Serene self Therapy will treat the following unsolicited direct communication with individuals as marketing:
• Seeking donations and other financial support;
• Promoting any services;
• Promoting events;
• Promoting membership to supporters;
• Promoting sponsored events and other fundraising exercises;
• Marketing products of the organisation
• Marketing on behalf of any other external company or voluntary organisation.
Whenever data is first collected which might be used for any marketing purpose, this purpose will be made clear, and the Data Subject will be given a clear opt out. If it is not possible to give a range of options, any opt-out, which is exercised,will apply to all Serene self Therapy marketing. Serene self Therapy does not have a policy of sharing lists, obtaining external lists or carrying out joint or reciprocal mailings.
Whenever e-mail addresses are collected, any future use for marketing will be identified, and the provision of the address made optional.
Serene self Therapy is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement.
Serene self Therapy may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes. This policy is effective from 1st July 2019.
What we collect
We may collect the following information:
• name and job title
• contact information including email address
• demographic information such as postcode, preferences and interests
• other information relevant to customer surveys and/or offers
What we do with the information we gather
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
Internal record keeping
We may use the information to improve our products and services. We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using the email address which you have provided.
From time to time, we may also use your information to contact you for market research purposes. We may contact you by email, phone, fax or mail. We may use the information to customise the website according to your interests.
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
Controlling your personal information
You may choose to restrict the collection or use of your personal information in the following ways:
• whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you do not want the information to be used by anybody for direct marketing purposes
• if you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at [email address]
• We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so. We may use your personal information to send you promotional information about third parties which we think you may find interesting if you tell us that you wish this to happen.
You may request details of personal information which we hold about you under the Data Protection Act 1998. If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us as soon as possible, at the above address. We will promptly correct any information found to be incorrect.