Effective Date: [Date]
Last Updated: [Date]
Data Controller: Osteo Herts
Osteo Herts Osteopathic Clinic is committed to protecting your privacy and personal data in accordance with UK data protection legislation. This Privacy Policy explains how we collect, use, store, and protect your personal information under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and professional standards set by the General Osteopathic Council (GOsC).
As a registered osteopathic practice, we are required to maintain patient confidentiality in accordance with the GOsC's Code of Practice and the common law duty of confidentiality.
Data Controller:Osteo Herts
Registered Address: 142 High Street, Codicote, Hitchin, SG48UB
GOsC Registration: 9215
Data Protection Officer: Lucy Edwards
Contact: info@osteoherts.co.uk 07368490061
We process your personal data under the following lawful bases:
Lawful Basis: Vital interests and healthcare purposes
Special Category Basis: Healthcare treatment and medical diagnosis
Purpose: Providing osteopathic treatment and ongoing care
Purpose: Fulfilling our treatment contract with you
Activities: Appointment scheduling, treatment delivery, payment processing
Purpose: Compliance with professional and legal requirements
Activities: GOsC reporting, safeguarding obligations, clinical governance
Purpose: Practice management and quality improvement
Activities: Clinical audit, training, business operations
Identity Data: Full name, date of birth, address, contact details, NHS number (if provided)
Medical History: Previous treatments, current symptoms, medical conditions, medications, allergies
Clinical Records: Examination findings, treatment notes, progress records, referral letters
Lifestyle Information: Occupation, exercise habits, relevant lifestyle factors
Emergency Contacts: Next of kin details and emergency contact information
Health and medical information
Details of physical or mental health conditions
Treatment and care records
Information about disabilities or health-related adjustments
Payment details and billing information
Insurance information (if applicable)
Direct debit or standing order details
Website usage data and cookies
Patient portal login information
Email communications and appointment confirmations
Providing osteopathic assessment, diagnosis, and treatment
Monitoring your progress and treatment outcomes
Coordinating care with other healthcare professionals
Providing follow-up care and health advice
Appointment scheduling and management
Processing payments and managing accounts
Maintaining accurate clinical records
Practice management and quality assurance
Compliance with GOsC professional standards
Clinical governance and risk management
Safeguarding reporting where required
Responding to legal requests and investigations
Staff training and professional development
Clinical audit and service improvement
Business continuity and disaster recovery
Insurance and legal compliance
We may share your information with:
GPs and Consultants: For coordinated care and referrals
Other Osteopaths: For continuity of care or second opinions
Allied Health Professionals: Physiotherapists, chiropractors, etc.
NHS Services: Where treatment coordination is required
General Osteopathic Council (GOsC): For regulatory compliance
Local Authorities: For safeguarding obligations
Courts and Legal Bodies: When legally required
Professional Insurers: For indemnity and claims purposes
IT Support Companies: For secure data processing and storage
Billing Services: For payment processing (if outsourced)
Professional Advisors: Legal, accounting, and business consultants
Cleaning and Maintenance: Under strict confidentiality agreements
In medical emergencies, we may share information without consent to:
Emergency services and hospitals
Next of kin or emergency contacts
Relevant healthcare professionals involved in emergency care
Request copies of your personal data
Understand how your data is being processed
Receive information about data sharing
Correct inaccurate or incomplete data
Update your personal information
Amend clinical records where appropriate
Request deletion of your data in specific circumstances
Note: Clinical records must be retained for legal and professional requirements
Limit how we use your data in certain circumstances
Object to processing based on legitimate interests
Receive your data in a structured, machine-readable format
Transfer your data to another healthcare provider
Object to processing based on legitimate interests
Opt out of direct marketing communications
Protection against purely automated decision-making
Right to human intervention in automated processes
Adult Patients: Minimum 8 years from last treatment
Children: Until 25th birthday or 8 years from last treatment, whichever is longer
Mental Health Records: 20 years from last treatment
Deceased Patients: 8 years from date of death
Appointment Records: 3 years from last appointment
Financial Records: 6 years from end of accounting period
Correspondence: 3 years from date of communication
Consent Forms: Duration of clinical record retention
Website Analytics: 26 months maximum
CCTV Footage: 30 days (if applicable)
Email Communications: As per clinical record retention
Secure storage of paper records in locked cabinets
Restricted access to clinical areas
Visitor access controls and sign-in procedures
Secure disposal of confidential waste
Encrypted data storage and transmission
Secure network infrastructure and firewalls
Regular security updates and patches
Multi-factor authentication for system access
Regular data backups with encryption
Staff training on data protection and confidentiality
Confidentiality agreements for all staff and contractors
Regular security risk assessments
Incident response procedures
Clear data access controls and permissions
We do not routinely transfer personal data outside the UK. If international transfers are necessary:
We will ensure adequate protection mechanisms are in place
We will obtain your explicit consent where required
We will use approved transfer mechanisms under UK GDPR
Session management and security
Patient portal functionality
Appointment booking system operation
Website usage statistics (anonymised)
Performance monitoring and improvement
User experience enhancement
You can control cookies through your browser settings. Disabling cookies may affect website functionality, particularly for the patient portal and appointment booking system.
Parents/guardians provide consent for children under 16
Young people aged 16-17 can consent to their own treatment
Special consideration for Gillick competence in under-16s
We have a duty to protect children and vulnerable adults. We may share information without consent where there are safeguarding concerns, in accordance with local safeguarding procedures.
In the event of a personal data breach:
We will assess and contain the breach within 72 hours
The ICO will be notified within 72 hours if required
Affected individuals will be informed without undue delay
We will document the breach and our response
We will review and improve our security measures
Practice Manager: Lucy Edwards
Address:142 High Street, Codicote, Hitchin, SG4 8UB
Phone:07368490061
Email:info@osteoherts.co.uk
If you're not satisfied with our response: ICO Helpline: 0303 123 1113
Website: www.ico.org.uk
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
For professional conduct concerns: GOsC: 020 7357 6655
Website: www.osteopathy.org.uk
Address: 176 Tower Bridge Road, London SE1 3LU
We will update this Privacy Policy as necessary to reflect:
Changes in data protection legislation
Updates to our data processing activities
New services or technologies
Regulatory guidance or requirements
Significant changes will be communicated through:
Website notification
Direct communication to active patients
Notice in the clinic reception area
Data Protection Enquiries:
Lucy Edwards
Osteo Herts
142 High Street, Codicote, Hitchin, SG4 8UB
Phone: 07368490061
Email: [info@osteoherts.co.uk
Practice Information
GOsC Registration:9215
Professional Indemnity: Institute of Osteopathy
ICO Registration: [Number] (if applicable)
This Privacy Policy complies with UK GDPR, the Data Protection Act 2018, and General Osteopathic Council professional standards. For specific legal advice regarding your data protection rights, please consult with a qualified UK data protection solicitor.