Tollgate Clinic Limited – Your Information Your Rights
This Privacy Notice describes what information we collect and hold about you, how we use it, who can access it and your rights with regards to accessing your information.
Who are we? Important News
From 1st April 2021, Provide Wellbeing Limited, trading as ‘Wellbeing’ and Tollgate Clinic Limited will be merging and operating as one legal entity. Both are part of the Provide Group.
As a result of this merger Tollgate Clinic Limited, will become the Data Controller of your personal data as defined under UK General Data Protection Regulation and the Data Protection Act 2018.
Tollgate Clinic Limited is registered with the Information Commissioner’s Office (ICO) to process personal and special categories of information under the Data Protection Act and our registration number is Z2525693
Why we keep personal information about you
We aim to provide you with the highest quality care. To do this, we must keep records about you and the care we provide for you.
Our staff are trained to handle your information correctly and protect your privacy. We aim to maintain high standards, adopt best practice for our record keeping and regularly check and report on how we are doing.
We do not collect your information for direct marketing purposes unless you specifically opt-in, and your data is not sold on to any other third parties. Your information is not processed overseas.
Electronic health records are accessed by use of an NHS Smartcard which are issued to our staff under strict NHS protocols. Any access by our staff to your health records is fully audited.
Information is held for specified periods of time as set out in the Records Management Code of Practice for Health and Social Care.
Non – NHS Patients
Your information will be processed safely and securely within our secure infrastructure. Your data will be stored securely within approved systems hosted by accredited and authorised vendors within the UK. Only authorised individuals will be granted access to your information.
If for any reason your data needs to be processed outside the UK/EEA we will ensure that the processing is legal and that the appropriate safeguard is put in place in accordance with the UK GDPR.
How do we collect Information about you?
We collect Information about you in a number of ways:
Information You Tell Us – Some of our services accept self-referrals which means that you can contact us directly to arrange an appointment and do not need to be referred by your G.P. You will be asked for certain information when you contact us to enable us to book you an appointment and to be able to provide appropriate care. You may also be asked to complete a form when you come in for your appointment so that we have relevant information to be able to help you. We may also seek your opinion on our services through our customer surveys
Information Others Tell Us – Where you are referred to us from another health care professional, for example your GP, they will share relevant information about the care you have received from them to enable us to provide effective and safe care to you. All our NHS patient data is recorded on SystmOne which is used widely across the NHS and care organisations to maintain accurate medical records about you. You can choose which other organisations involved in your care can view your full medical record. Speak to your GP to set your choice or you can set them yourself using SystmOne. For more information please visit https://systmonline.tpp-uk.com/2/help/help.html
The NHS Personal Demographics Service– When we register you to receive care from one of our NHS services, we receive information from the NHS Personal Demographic service. The Personal Demographics Service (PDS) is the national electronic database of NHS patient details such as name, address, date of birth and NHS Number (known as demographic information). This is to ensure that the information we hold about you is accurate and up to date and to ensure that you are entitled to receive NHS Care.
NHS Summary Care Record– To support you and provide high quality and safe health care it may very occasionally be necessary to access your NHS Summary Care Record. The NHS Summary Care Record is an electronic summary of key clinical information (including medicines, allergies and adverse reactions) sourced from your G.P Record. We will discuss this with you should the need arise to access this and will only do so this with your permission, unless another legal reason to access applies (please see below)
What Information do we keep about you?
The information we hold may include:
- Basic details, such as your name, address and next of kin.
- Contact information such as telephone numbers and email addresses
- Contacts we have had with you, such as clinic visits.
- Notes and reports about your health and any treatment or care you needed.
- Details about your treatment and care.
- Results of tests that may have been undertaken on our behalf as part of your care (i.e. Nerve Conduction Studies, Post Vasectomy Semenology Test, Biopsies)
- Unless you authorise us to we don’t access your health records information from other health professionals, relatives or those who care for you.
- If you are paying us for your services then we will take payment through a PCI compliant provider
- Your opinions through our Customer surveys and Complaints & Compliments process if you chose to identify yourself
- Marketing permissions (self-pay only) with your consent
How do we hold your information?
We create and hold your records electronically and sometimes in hard copy where necessary. We may also hold paper records from previous contacts with you.
Any records we hold about you are held securely and are only accessible to those who are involved in your care or have a legitimate need to access.
All of our staff and contractors receive appropriate and on-going training to ensure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. Staff only have access to personal information where it is appropriate to their role and is strictly on a need-to-know basis.
How do we use your information?
Information collected about you to deliver your health care may also be used to assist with:
- Making sure your care is of a high standard.
- Using statistical information to look after the health and wellbeing of the general public and planning services to meet the needs of the population.
- Assessing your condition against a set of risk criteria to ensure you are receiving the best possible care.
- Helping train staff and support research.
- Supporting the funding of your care.
- Reporting and investigation of complaints, claims and untoward incidents.
- Reporting events to the appropriate authorities when we are required to do so by law.
- Improving the quality of services
- Sending updates on our services (with your consent)
- Processing payments/refunds
If your treatment is being funded by the NHS then the legal basis for the processing of data for these purposes is that as a provider of NHS care we have a public duty to care for our patients, as guided by the Department of Health and Data Protection law says it is appropriate to do so for health and social care treatment of patients, and the management of health or social care systems and services.
There may also be situations where we are under a duty to share your information. We are required by law to report certain information to the appropriate authorities. Occasions when we must pass on information include: Notification of new births, infectious diseases that may endanger others, such as meningitis and measles (but not HIV/AIDS), where a formal court order has been issued and sharing with the Care Quality Commission (CQC) to inspect the quality and safety of the care that we provide. We may also have to share your information when it is absolutely necessary for the prevention or detection of crime or prosecution of offenders or where there are serious risks to the public or our staff.
If you are funding your own treatment then the legal basis may primarily be that the processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
If we send you marketing communications then the legal basis is consent. If you no longer wish to receive marketing updates from us, please contact us by email to [email protected], with unsubscribe as the email subject.
Who can see your information?
Your information is only accessible to those involved in your care (clinical staff) or administration. Administrative staff include receptionists who check patients in for clinics and staff who assist with the administration of our clinics/ services (for example typing up letters and reports). These members of staff are bound by the same rules of confidentiality as our clinical staff.
Organisations that we may share information with:
- General Practitioners
- NHS Hospitals & Clinics
- Also, Subject to Strict Protocols : Education Services, Local Authority Services, Private Sector Providers, Children’s Centre’s, Commissioners of our Services, the Department of Health, the Family Health Service Authority (FHSA) and the Health Protection Agency
- Organisations who supply us with services (tests) that may have been undertaken on our behalf as part of your care (i.e. Nerve Conduction Studies, Post Vasectomy Semenology Test, Biopsies)
- Organisations who provide us with services that help support the care we provide, for example providers of information systems and necessary business applications. Information shared in these instances will be limited to the minimum data necessary to fulfil the service provided and strict access controls will be put in place.
- Third parties to whom we may choose to sell, transfer or merge parts of our organisation or assets. If a change of ownership happens to our organisation or to a service contract then we may share or transfer your personal data to the new owners or service provider who are obliged to process your data with the same level of protection set out in this privacy Notice.
We will only share information with those who have a legitimate right to know
How Long Do We Keep Your Data
NHS Patients;- Information is held for specified periods of time as set out in the Records Management Code of Practice for Health and Social Care.
Self Pay Patients:- we only keep your data for as long as we need to use it. This will depend on the service we are providing. There may also be legal requirements to retain your data for a certain length of time.
If we need to use your personal information for any reasons beyond those stated above, we will discuss this with you and ask for your permission to do so where you will have the option to agree or disagree. This is known as explicit consent. Data Protection laws gives individuals rights in respect of the personal information that we hold about you. These are:
- To ask for access to your information
- To ask for your information to be corrected if it is inaccurate or incomplete.
- To ask for your information to be deleted or erased. Please note that this does not apply to your health or care record, or where we process information for public health or scientific research purposes.
- To ask us to restrict the use of your information in some circumstances.
- To request your personal information to be transferred to other providers on certain occasions.
- Object to the use of your personal information: In certain circumstances you may also have the right to ‘object’ to the processing (e.g. sharing) of your information where the sharing would be for a purpose beyond your care and treatment (e.g. as part of a local/regional data sharing initiative). You can also stop your personal information from being used for research and planning via the opt-out initiative. This ‘‘Data Opt-out’ initiative, developed by Dame Caldicott, commenced in May 2018 and all Health and Care organisations must comply by 30th September 2021. Further information can be found on the following website: https://digital.nhs.uk/national-data-opt-out
All requests for any of the above should be made to the Data Protection Lead
- by telephone on 01206 987525
- by email: [email protected]
- or in writing 145 London Road, Stanway, Colchester, Essex, CO3 8NZ
Should you wish to lodge a complaint about the use of your information, please contact our General Manager
- by telephone on 01206 987525
- by email: [email protected]
- or in writing 145 London Road, Stanway, Colchester, Essex, CO3 8NZ
You may also contact our Group Data Protection Officer, John Adegoke
- by email: john.[email protected]
- or in writing: Provide CIC, 900 The Crescent, Colchester Business Park, Colchester, Essex C04 9YQ
If you are still unhappy with the outcome of your enquiry you can write to: The Information Commissioner, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF – Telephone: 0303 123 1113 or 01625 545700
This policy was last reviewed on 1 April 2021