SHC and Healthcare Management Solutions are joint data controllers and will uphold and actively promote these rights in line with guidance issued by the Information Commissioner’s Office: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/
The GDPR provides the following rights for individuals:
Any request made by you in respect of the rights listed above can be made to: [email protected]
If you wish to withdraw your consent for us to use your data or have any concerns in regards of how we are collecting, processing or using your personal data you should raise your concern first directly with us at: [email protected]
GDPR Query
Tylden House,
Dorking Road,
Warnham,
Near Horsham,
West Sussex, RH12 3RZ
Or direct to the Information Commissioner’s Office at https://ico.org.uk/concerns/
This Privacy Policy may be changed and updated by us at any time in compliance with Data Protection Laws and GDPR enforcement
Data controller: SHC Clemsfold Group Limited
Registration number: ZA121725
Date registered: 17 June 2015
Registration expires: 16 June 2022
Payment tier: Tier 1
Address:
Tylden House,
Dorking Road,
Warnham,
Horsham,
West Sussex, RH12 3RZ
Data controller: SHC Rapkyns Group Limited
Registration number: ZA121728
Date registered: 17 June 2015
Registration expires: 16 June 2022
Payment tier: Tier 1
Address:
Tylden House,
Dorking Road,
Warnham,
Horsham,
West Sussex, RH12 3RZ
Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (the “GDPR”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.
Personal data is, in simpler terms, any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.
The personal data that we use is set out below.
Under the GDPR, you have the following rights, which we will always work to uphold:
For more information about our use of your personal data or exercising your rights as outlined above, please contact us using the details provided in this Privacy Policy.
In some instances, if you refuse to provide us with certain information when requested, we may not be able to:
If you have any cause for complaint about our use of your personal data, please contact us as soon as possible and we will work with you to alleviate any concerns and, if necessary, rectify the problem. If you feel that that the outcome is unsatisfactory, you have the right to lodge a complaint with the Information Commissioner’s Office.
Further information about your rights can also be obtained from the Information Commissioner’s Office (https://ico.org.uk/) or your local Citizens Advice Bureau (https://www.citizensadvice.org.uk/).
1) Obtain and process personal data fairly and lawfully – use the forms and procedures set out in the SHC policies and administration systems.
2) Hold the data only for the purposes specified in your Register entry:
3) Use the data only for the purposes, and disclose only to the people, listed in your Register entry:
4) Only hold data which are adequate, relevant and not excessive in relation to the purpose for which the data are held.
5) Ensure personal data are accurate and, where necessary, kept up to date.
6) Hold the data for no longer than is necessary.
7) Allow individuals access to information held about them and, where appropriate, correct it or erase it.
8) Take security measures to prevent unauthorised or accidental access to, alteration, disclosure, or loss and destruction of information.
The Data Protection Act entitles individuals to find out what personal data is held about them on computers and to have that data corrected or erased if it is inaccurate, and to claim compensation if they can prove that they have suffered damage from an inaccuracy or breach of security.
These rights are known as ‘subject access rights’. An individual who makes a subject access request is entitled to be:
The individual must apply in writing to find out what information is held about him/her.
A response must be made within 40 days of the request provided that:
If the information is not particularly sensitive and the reply is to be sent to the address you know to be that of the individual concerned, the individual’s usual signature should be enough proof of identity.
However, if you judge the information to be more sensitive and requiring further proof of identity, the individual may be asked to provide the following:
Any subject access request must be made to the Registered Manager. A copy must also be sent to the Director of Operations at SHC’s headquarters. SHC will make a charge of £10.00 for each request.
The underlying principle is that the subject of the record is the only person who should be allowed access to information held regarding him/herself. Access should be granted as extensively as possible, considering the individual’s age, maturity and level of understanding.
It is acknowledged that it is also the right of all adults to refuse access to information to their nearest relative including adults with a learning disability or a psychiatric illness. If it is considered that a Person we Support is unable to make a reasoned decision, then it will be the responsibility of the Registered Manager.
Within the records there may be information that it is considered detrimental to the People we Support’s wellbeing, if it were available to them. Such information should be contained in a confidential report module within the records. Decisions regarding information that may be confidential should be made by the Registered Manager in consultation with the key worker and other professionals involved in the People we Support’ case.
Under the GDPR, we must always have a lawful basis for using personal data. This may be because the data is necessary for our performance of a contract with you, because you have consented to our use of your personal data, or because it is in our legitimate business interests to use it. Your personal data may be used for any of the following purposes:
With your permission and/or where permitted by law, we may also use your personal data for marketing purposes, which may include contacting you by email/telephone/text message and post with information, news, and offers on our products and services. These activities are within our Legitimate Interests as a business with whom you have communicated or shown an interest in the services. You will not be sent any unlawful marketing or spam. We will always work to fully protect your rights and comply with our obligations under the GDPR and the Privacy and Electronic Communications (EC Directive) Regulations 2003, and you always can opt out.
We welcome visitors to SHC Ltd’s website without disclosing their information. We will collect visitors’ personal information when they have provided it to us via enquiry forms, contact forms, telephone calls or email, and we would use this information in the following ways:
What are cookies?
Cookies are small data files that are placed on your computer or mobile device when you visit a website. Cookies are widely used by website owners in order to make their websites work, or to work more efficiently, as well as to provide reporting information.
Cookies set by the website owner (in this case, SHC’s website) are called “first party cookies”. Cookies set by parties other than the website owner are called “third party cookies”. Third party cookies enable third party features or functionality to be provided on or through the website (e.g. like advertising, interactive content and analytics). The parties that set these third party cookies can recognise your computer both when it visits the website in question and also when it visits certain other websites.
Why do we use cookies?
Some cookies are required for technical reasons for our Website to operate, and we refer to these as “essential” or “strictly necessary” cookies. Other cookies also enable us to track and target the interests of our users to enhance the experience on our Website.
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org. To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.
Internet-based transfers
Given that the Internet is a global environment, using the Internet to collect and process personal information necessarily involves the transmission of information on an international basis. Therefore, by visiting and browsing the www.sussexhealthcare.co.uk website you are communicating electronically with us, you acknowledge and agree to our processing of personal information in this way.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your information transmitted to any website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.