
Parish Green & Beatty Limited t/a Parish and Green Eyecare is a private independent opticians operating from 44 Talbot Rd, Talbot Green, CF72 8AF and 1 Hilda House, The Square, Pencoed, CF35 6NP.
We are registered with the Information Commissioner’s Office as a Data Controller, registration number ZA134384.
This policy provides detailed information on when and why we collect your personal information, how we use it and the very limited conditions under which we may disclose it to others.
Your privacy matters to us and we are committed to the highest data privacy standards, patient confidentiality and adherence with the Data Protection Act 2018 and UK GDPR. We adopt the six core principles of data protection.
Where you provide personal data to us, we will become responsible for it as the data controller.
We will only collect data that is necessary for us to deliver the best possible service and ensure that you are reminded about appointments or information relevant to your ongoing care.
We collect your personal information directly from you, for example, when you visit our practice, get in touch with us by telephone or email, use our booking system or when you visit our website.
We may also collect it from other sources if it is legal to do so. This includes from the NHS or other healthcare providers, institutions, or people you have authorised to provide information on your behalf, for example, parents or guardians, third-party service providers, government, tax or law-enforcement agencies, and others.
| Processing Activity | Personal Data Required/Held | Retention Time | Reason to Hold Data |
|---|---|---|---|
| Optical Service & Products | Name, date of birth, telephone numbers, address and email.
Current and past health and medication information, family history, your examination results, and lifestyle information. Data received from other healthcare professionals as part of your ongoing care. |
10 years after last contact or until age 25, whichever is later | Contract – in order to provide the service or products you have requested.
Where health data is processed, we do so for the provision of healthcare. |
| Reminders | Name, email address, address, telephone numbers | 10 years after last contact or until age 25, whichever is later, or until asked to stop by you | Contract – in order to provide the ongoing service, appointment reminders are sent |
| Credit/Debit Card Payments | Cardholder name, card number, security number | Duration of the transaction | Contract – you have agreed to provide these details to pay for the service or products ordered |
We treat all personal data as sensitive but acknowledge that we also process special category data including health data and children’s data.
During the delivery of our service to you, we will share your data with other companies who are essential for the provision of our service to you. They are under contract with us and have provided sufficient guarantees that they will process your data only as per the terms of that contract and throughout processing activities will ensure your data is protected using appropriate technical and organisational measures.
Where necessary we may disclose your information to health care professionals including the NHS where we have a duty of care or to fulfil our legal obligations. We are compliant with the national data opt-out. For more details and to opt out see: https://www.nhs.uk/your-nhs-data-matters/manage-your-choice/
It may also be necessary, where the latest technology allows us to do so, to use your information and health data to facilitate digital consultations and diagnoses and we will always do this with your security in mind.
We may also pass information to external agencies and organisations, including the police, for the prevention and detection of fraud and criminal activity. Should any claim be made, we may pass your personal information to our insurers and, if our business is wholly or partially transferred to a third party, your personal information may be one of the transferred assets.
Our operations are based in the UK, and your personal information is generally processed within the UK and countries within the European Economic Area (EEA). In some instances, we may transfer your personal information to third countries, for example, where our suppliers or cloud service providers are situated outside the UK and EEA.
If the recipient is situated in a third country that has not received an adequacy decision from the relevant regulator, we will ensure additional safeguards are in place including the use of applicable standard contractual clauses.
A full list of processors is available from our Data Protection Officer.
To provide and manage our services your electronic data is stored and processed within our own IT systems and on our patient management software, Opticabase, which are secured to prevent access or intrusion by anyone who is not authorised to have access to your data. Our practices are operated to ensure that all records and equipment holding your personal data are physically protected.
In the unlikely event that we lose your data, or a device on which your data resides, or it is accessed by someone unauthorised, we will inform you if the loss or unauthorised access of your data has potential to cause you harm. We will report all reportable data breaches to the Information Commissioner’s Office, who are responsible for regulating data protection legislation in the UK.
Under UK data protection law, you have the following rights which you can exercise by emailing our Data Protection Officer.
| Right | Explanation |
|---|---|
| Right to be Informed | We have to be transparent in how we collect and use your personal data. |
| Right of Access | You have the right to access your personal data. |
| Right to Rectification | If the information we hold about you is inaccurate or incomplete you can request that we correct this. |
| Right to Erasure | You can request that we delete or remove personal data in certain circumstances. |
| Right to Restrict Processing | You have the right to request that we cease processing your data if you consider it inaccurate or incomplete, and/or you object to the reason we’re processing your data. We will review the validity of your request and respond to you with our decision. |
| Right to Data Portability | Where you have consented to our processing your data or where the processing is necessary for us to deliver a contract, you can request a copy of that data be provided to a third party. |
| Right to Object | You have the right to object to our processing in certain circumstances and an absolute right to object to direct marketing. |
| Rights Relating to Automated Decision-Making Including Profiling | We do not use automated decision-making or profiling. Where automated decision-making is applied, organisations must give you information about the processing, introduce simple ways for you to request human intervention or challenge a decision, and carry out regular checks to make sure systems are working as intended. |
For all data protection matters or questions relating to how we manage your data, or if you are concerned about how your data is being handled, you can contact our Data Protection Officer:
Data Protection Officer: Clinical DPO
Phone Number: 0203 411 2848
For complaints, please include the following where possible:
Complaints will be acknowledged within 30 days, and we aim to respond fully and resolve the matter without undue delay. If your issue requires more time or clarification, we will keep you informed throughout.
If you are dissatisfied in how we have handled your data, you have the right to complain to the UK Information Commissioner’s Office (ICO):
Website: https://ico.org.uk/make-a-complaint/
Phone: 0303 123 1113
Address: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Parish and Green Opticians is one of many organisations working in the health and care system to improve care for patients and the public.
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. On this web page you will:
You can also find out more about how patient information is used at:
You can change your mind about your choice at any time.
Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.
Health and care organisations have until July 2022 to put systems and processes in place so they can be compliant with the national data opt-out and apply your choice to any confidential patient information they use or share for purposes beyond your individual care. Parish Green and Beatty Ltd only share your data for your individual care, therefore our organisation is currently compliant with the national data opt-out policy.