At John Fell Opticians, we are committed to the highest privacy standards. However you choose to interact with us, we will only collect data that is necessary for us to deliver the best possible service and ensure you are reminded about appointments or anything else relevant to your ongoing care. This policy provides detailed information on when and why we collect your personal information, how we use it and the very limited conditions under which we may disclose it to others.
Collection of your Personal Information
In addition to your basic contact information (name, date of birth, telephone numbers and your addresses), we will collect other relevant details including current and past health and medication information, your examination results, payment details and lifestyle information. We may also store associated information received from other health care professionals as part of your ongoing care.
How we use this information
The information we collect about you is used to ensure we provide you with the best and most appropriate products and services. In addition to your ongoing eye care, we will remind you when appointments are due and suggest relevant products or services that we believe would be of interest. We use your contact information to respond to queries from you, and where appropriate your bank details to collect Direct Debit and standing order payments as agreed. We may occasionally contact you to ask for your feedback on services we have provided and to offer the opportunity to trial new products.
Our policy on storage, processing and retention of your information
To provision and manage our services, your data is stored and processed by Optisoft Ltd within their UK facilities that are certified to ISO27001. If we collect Direct Debits from you these payments will be processed by FastPay Ltd. Any third-party company is only permitted to process your data for the specified purposes and in accordance with our instructions.
We retain your information for as long as reasonably necessary to provide our products and services and to maintain records to satisfy tax and other legal requirements.
How and when we may share your Personal Information
Where necessary we may disclose your information to health care professionals including the NHS. We may also pass information to external agencies and organisations, including the police, for the prevention and detection of fraud and criminal activity. Should any claim be made, we may pass your personal information to our insurers and if our business is wholly or partially transferred to a third party, your personal information may be one of the transferred assets.
Your rights with respect to the Personal Information we hold
You are entitled to access the personal information that we hold on you; any such request should be made using our contact details below. If any data we hold is inaccurate, this will be corrected promptly on request. In certain circumstances you can request that we erase your data which we will do where this would not prevent us meeting our legal and regulatory obligations.
Updating your communication preferences
You may ask that we do not send you communications using any of the contact details we hold on our records, this may include your email, SMS, telephone and postal information. You may also request we restrict our communications to clinically necessary messages. Your personal preferences can be changed at any time by using the link at the end of every email and SMS message we send or by using our contact details below.
A cookie is a small text file containing information that a web site transfers to your computer’s hard disk for record-keeping purposes. A cookie cannot give us access to your computer or to your personal information. Most web browsers automatically accept cookies; consult your browser’s manual or online help if you want information on restricting or disabling the browser’s handling of cookies. If you disable cookies, you can still view the information on our web site, but the functionality of certain areas may be reduced.
Why we collect and process your data
We collect and process patients’ personal data for the purposes of healthcare and marketing.
Our legal bases for processing personal data for healthcare purposes, including appointment reminders, include public task or legitimate interests.
- When we provide services under the NHS General Optical Services contract (such as a sight test funded by the NHS,) our legal basis for processing personal data in respect of that service is public task
- Otherwise our legal basis is legitimate interests
Our condition for processing special care.
We process out patients’ personal data for marketing purposes with their consent or to meet a legitimate interest. This means we can tell you about eye care products and services that may be relevant to you. If you do not want us to process your personal data for marketing purposes, please let us know and we will stop.
The data we may collect and process
The personal data of patients that we may collect and process includes:
- Your name, contact details and personal identifiers (such as date of birth and NHS number)
- Your general and ocular health history, your family medical and ocular history, and any relevant signs or symptoms you tell us about
- Details of medicines, spectacles and contact lenses prescribed for you
- Details of examinations and other healthcare checks and treatments we provide
- Information relevant to your continued care from other people who care for you or know you well, such as other health professionals and relatives
How we hold and share your personal data
We process your personal data in strict confidence. We keep your personal data securely in our filing and electronic systems. Patient records are only accessible to the healthcare professionals working at the practice and those under their supervision.
We will usually keep any personal data we hold about you for ten years after our last contact with you before we delete it. This is the period recommended as good practice by the College of Optometrists. If we collected the data when you were aged under 18 we will keep it until your 25th birthday, in line with NHS requirement. In exceptional cases we may need to retain personal data for a longer period, and will explain our reasons for doing so on request.
In the course of processing your personal data we may share it with:
- The healthcare professionals working at this practice and those under their supervision
- Healthcare professionals and those under their supervision at other optical practices, but only if you have specifically asked us to pass your personal data (such as your prescription) to them
- Your GP, ophthalmologists and other healthcare providers and commissioners, and supplier of optical appliances or similar products, in connection with your ongoing healthcare treatment
- Software providers for our patient record and invoicing systems, and financial institutions, so that we can keep patient records up to date and arrange payment for services provided to you
You have legal rights in respect in respect of the personal data we hold about you. The Information Commissioner’s Office (ICO) has published guidance on the full range of rights. The rights that are most relevant to the way in which we use your Personal Data include:
- The right to be informed about how we use personal data – this privacy notice gives that information
- The right to object – if you object to us processing your data for marketing purposes, or for healthcare purposes where our legal basis is legitimate interests (see ‘why we collect and process your personal data’ above), we will then stop doing so, unless we are processing the data in respect of a legal claim or can otherwise show that our legitimist interest in processing the data overrides your rights and interests
- The right of access – if you ask us for the personal data we hold about you we will provide it within a month, free of charge (unless we have already provided it to you, in which case we may have to charge you the administrative cost of providing it again).
- The right to rectification – if you ask us to correct personal data about you that is inaccurate or incomplete, we will do so within a month (unless we need longer, in which case we will discuss this with you)
- The right to erasure – also known as the ‘right to be forgotten’. If you ask us to delete your personal data, we will do so if there is no compelling reason to continue processing the data. We will not usually delete healthcare data before our usual time limit (see ‘how we hold and share your personal data’ above) where we have a duty to keep accurate records – for example, to comply with a legal obligation, or in connection with a legal claim. If you ask us to delete such data we will discuss with you
Contacting us and the ICO about your personal data
Please speak to us first if you have any questions or concerns about the way in which we process personal data. You can contact (our Data Protection Officer (NB only use this wording if you have a registered DPO) (Name) via (Contact Details).
You have the right to complain to the ICO if you have a concern about our handling of your personal data which you do not think we can resolve. You can contact the ICO here ico.org.uk
You can reach John Fell Opticians by email: [email protected], telephone: 01332 517388, or by post at John Fell Opticians, 8 The Parade, Uttoxeter Road, Mickleover, Derby, DE3 0GB.
Last updated: January 2019