top of page

PRIVACY POLICY

SCOPE OF THIS POLICY —

According to the General Data Protection Regulation 2016 and the Data Protection Act 2018, the processing of personal data includes, but is not limited to holding, obtaining, recording, using and disclosing information, which also applies to confidential client information. These regulations govern how information must be handled and used by the therapist, as well as how a client may have access to their records. This ensures that the data isn’t being used unethically and it also provides legal rights to a client whose information is stored on the therapist's records, giving them the right to request a copy of the data held on record.

 

In compliance with these regulations, this Data Protection and Privacy Policy document details the lawful basis for HOLISTICA to hold certain information about its clients, why this information is held, who the information is shared with, how the information is used and protected, and the rights of its clients in terms of access to the information being held or their right to request to amend or delete the information.

 

For purposes of the applicable Data Protection Laws, HOLISTICA is the "data controller". This means that HOLISTICA determines the purposes for which, and the manner in which the client’s Data is processed.

LAWFUL BASIS FOR REQUESTING INFORMATION —

HOLISTICA requires the client’s contact information like name, email, telephone to arrange appointment times with them, send appointment reminders, reschedule appointments and cancellation confirmations.

 

HOLISTICA also requires information about the client’s current health, diet and lifesyle habits, and medical history like allergies, surgeries, injuries, medications and other health conditions in order to provide an effective and safe aromatherapy and/or massage therapy treatment. The information is only used to ensure that HOLISTICA provides its client’s with a treatment that’s best suited to their needs and requirements.

 

The lawful basis by which HOLISTICA requests, processes and holds such information is held under Special Category Data - Health.

 

As a registered aromatherapist and massage therapist with the Federation of Holistic Therapists (FHT), the therapist Ms. Juliana Rego t/a/ HOLÍSTICA abides by the codes of conduct and confidentiality requirements set out by the FHT.

2

HOW WE COLLECT DATA —

HOLISTICA collects the following information about the client:

  • When the client contacts us to book a treatment or to request information on our available therapy treatments either via phone, email, through our website enquiry form, or by post;

  • During the client’s first treatment appointment via a Client Intake Form  and Consultation form;

  • At subsequent appointments via a Client Consultation Form;

  • When the client completes a Covid-19 Screening Form for safety and risk assessment;

  • When the client provides us information for the purpose of subscribing to our website services, email or text notifications and/or newsletters;

  • When the client takes part in surveys, completes questionnaires and/or feedback forms to help us improve our services.

3

DATA COLLECTED —

HOLISTICA may collect the following Data, which includes personal Data, from the client:

  • The client’s Name, Date of Birth, Occupation, Email, Phone and Address.

  • The client’s Emergency Contact Name, Email Phone and their Relationship to this emergency contact.

  • The client’s GP Name, Email, Phone and Address.

  • The client’s health information such as: allergies, medications, history of illnesses, surgical procedures, injuries, contagious skin or respiratory conditions.

  • The client’s information on their current physical state such as: aches, pains, strains and sprains.

  • The client’s lifestyle information such as: exercise habits, hobbies, diet, stress levels, sleep quality.

  • Information of other bodywork treatments and therapies currently or previously received by the client such as: spa massage, sports massage, physiotherapy, osteopathy, orthopaedic, reiki, aromatherapy massage and more.

  • The client’s treatment information such as: assessment notes, contra-indications, adaptations to the treatment, as well as contra-actions encountered during and/or after treatment, which will be recorded during the consultation and after the massage therapy or aromatherapy treatment session.

  • Diariased records of the client’s treatment appointment times, duration and type of treatment received i.e. aromatherapy massage, massage therapy, and/or aromatherapy product blended for a specific purpose.

  • When booking appointments in person or online, clients will be asked to provide their name, date of birth, address, telephone number, email address, and payment details so that the booking system can create a client record, an appointment and treatments can be paid for upfront, as required by the Booking Terms and Conditions.

4

OUR USE OF DATA —

The information collected is used to assess the client’s suitability for an aromatherapy massage treatment or a massage therapy treatment, and to make the necessary adaptations to ensure we provide the client with a safe and effective therapy treatment.

 

HOLISTICA also uses the information as reference during subsequent therapy treatments, to assess any levels of improvement and if any changes need to be made to the client’s treatment plan.

 

HOLISTICA shall use the contact information that the client provides to contact them about their appointment times, rescheduled appointments, appointment cancellations, and/or for correspondence related to their treatment plan.

5

SHARING DATA —

HOLISTICA may need to share a client’s information with another massage therapist or health practitioner should they be referred to one of these by HOLISTICA. However, we shall only share the information with the client’s consent.

 

HOLISTICA shall not share a client’s personal information with anyone else other than is required for legal processes, without explaining the reason why this is necessary and by obtaining the client’s explicit consent.

 

HOLISTICA shall not share medical information on to a third party without the client’s express permission, unless in the event of an emergency, when medical information may be passed to a third party such as the ambulance service or other medical professional.

6

DATA RETENTION —

HOLISTICA is required to retain the client's data and information for a period of 10 years after the client’s last treatment for insurance purposes. And if the client is a child, then their records must be kept for at least 10 years after they reach adulthood.

 

HOLISTICA shall not transfer the client’s data without their consent.

 

HOLISTICA shall review its records once every two years and shall securely erase/destroy any data, information or records that are no longer bound by the regulated timescale or retention period for such records to be held.

7

DATA BREACH —

In the event of a data breach that leads to loss, destruction, alteration, unauthorised disclosure of or access to an individual(s) data, HOLISTICA shall inform the ICO in the first instance, where the data breach is likely to result in a risk to the rights and freedom of the affected individual(s).

 

In the event of such a breach HOLISTICA shall immediately inform those clients who are directly affected. And, records of any personal data breaches shall be maintained.

8

YOUR INDIVIDUAL RIGHTS —

Under the Data Protection Act 2018, every individual is provided with legal rights that govern the use of their personal data, such as:

  • Right to access – the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is "manifestly unfounded or excessive". Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.

  • Right to correct – the right to have your Data rectified if it is inaccurate or incomplete.

  • Right to erase – the right to request that we delete or remove your Data from our systems.

  • Right to restrict use of your Data – the right to "block" us from using your Data or limit the way in which we can use it.

  • Right to data portability – the right to request that we move, copy or transfer your Data.

  • Right to object – the right to object to our use of your Data including where we use it for our legitimate interests.

9

ADDITIONAL INFORMATION —

If a client objects to HOLISTICA keeping personal information and treatment records, then HOLISTICA will be unable to provide the client therapy.

 

Additionally, aromatherapists and massage therapists are required to keep client treatment records for a specific period of time as detailed in this document. This means that even if you, the client, were to make a request for your information to be erased/deleted, HOLISTICA might be bound to keep these records until the specific and legal data retention period has elapsed.

NOTE:

  • The client intake form and consultation form is used to assess the client’s massage requirements and to provide the client with a safe and effective massage during the first and subsequent treatment sessions respectively.

  • The treatment record is used to record information about the treatment and as a reference for any subsequent treatments.

  • The Covid-19 screening form is used to assess whether it is safe for the client to attend their appointment and that they pose no risk in transmitting the virus or are not at a high risk of Covid-19.

  • Only the therapist will have access to the client intake form, sub-consultation form, Covid-19 screening form and treatment records.

  • Clients can always refuse to supply personal identification information, except that it may prevent them from receiving therapy.

10

COMPLAINTS —

If you are not satisfied with the way HOLISTICA processes your personal data, please contact us at the email address provided.If you feel the information held is incorrect or not being used for the purposes the permission was granted or if information is being held unnecessarily, you can complain to the ICO . For further information click here.

11

CHANGES TO THIS DATA PROTECTION & PRIVACY POLICY —

This Data Protection and Privacy Policy was created on 01 October 2022 and is effective from this date. HOLISTICA reserves the right to make changes to and amend the terms in this policy to reflect current changes in regulations, and/or internal policies in order to keep its client’s information and data secure at all times, within the scope of its legal rights and obligations.

12

YOUR ACCEPTANCE OF THESE TERMS —

By using the therapy services and treatments provided by HOLISTICA, you, the client, acknowledge your acceptance of the terms of this Data Protection and Privacy Policy. If you do not agree to any or all of the terms set out in this policy, please do not use our therapy services and treatments. Your continued use of our therapy services and treatments following the posting of any changes and updates made to this policy will be deemed your acceptance of those changes.

 

Thank you,

— HOLISTICA —

Get in Touch

- HOLISTICA -

- INFORMATION and CONTACT DETAILS —

Data Controller: HOLISTICA
Data Protection Officer: Ms. Juliana Rego, MFHT
Email: holistica.wellness.london@gmail.com
Website: https://holisticaaromatherapy.co.uk

Address:  Lind Street, London, SE8 4JE UK

bottom of page