Your Privacy Is Very Important To Us
GENERAL DATA PROTECTION REGULATIONS
Effective date of implementation 28 May 2018.
Purpose: To comply with the requirements of the General Data Protection Regulations 2018.
Scope: This policy covers all aspects of information obtained and held by Clifton Homecare Ltd (CHCL) including (but not limited to):
- Service user & employees details, medical history & NOK detail
- Personal information provided by clients & families in order that we can deliver our care & support duties
- Employee details to enable a contract of employment to be issued.
Caroline Cosh has been appointed as the Senior Information Risk Owner (SIRO) and is responsible for data protection.
GDPR identifies the rights of individuals:-
- Right to be informed
- Right of access
- Right to rectification (in CHCL case immediately any discrepancy is identified)
- Right to erasure portability
- Right to restrict processing
- Right to data portability
- Right to object
- Rights in relation to automated decision making & profiling
Right To Be Informed
We may collect information or data about you in various ways in order to develop a support and care plan to allow the team at CHCL to meet your needs safely. The main circumstances we do so are noted below:
- The information obtained from either the client, relative, lasting power of attorney appointee or advocate is used in the formulation of the care plan. All appropriate parties will be encouraged to read the care plan to ensure the information is accurate & correctly documented. These details are stored in digital format on our software system, cloud based storage facility & in paper format in client files stored at client addresses & administration files stored in our secure offices. Any updates to the support & care plan will be documented after approval of the details by yourselves. At the end of each visit & at the time of medication administration the care team will complete notes summarising the duties completed & medication administered. Clients & family members can have access to all digital care plans & rotas; seeing in live time the time, duration & associated notes of care visits completed. Please speak to one of our team for more details.
- Our website does not collect details of your IP address & which version of the web browser you used to review our website. We use photographs of some of our clients in our marketing video BUT only after consultation with yourselves (& relatives if necessary) after consent has been obtained & records of consent are retained. We maintain a photo headshot of clients within their client file for safeguarding & security purposes.
Rights Of Access
We have to request your approval for Clifton Homecare to maintain these personal records.
You have a right to access your personal data but we can refuse access to data if we feel your request is unreasonable, repetitive or excessive. Clifton Homecare will provide information within one month from receipt of request. We are allowed to charge a reasonable fee to cover admin costs.
Right To Rectification
If Clifton Homecare or you believe any specific information we have obtained is, in your or our opinion incorrect, please inform one of our administration team as soon as this is identified.
If we, as a Company, believe the information is accurate and correct, we will not change the information. You have a right to make a complaint and you can seek to enforce your rights through a judicial remedy. Please refer to our separate Complaints Policy & Procedure for details.
Right To Restrict Processing
We do not process any information electronically.
We use our software system to produce and store the care plan. Any information gleaned from a client in relation to production and subsequent implementation of the care package is appropriate, relevant to the care we provide and used to maintain a client’s wellbeing and safety.
Our payroll processing is undertaken by Forbes Watson Accountancy and our DBS checking process is managed by Forbes Watson Accountancy. Forbes Watson Accountancy have their own GDPR policies and procedures.
Right To Data Portability
As stated previously we do not process any information electronically.
Right To Object
The GDPR right to object allows clients and staff to object to certain types of data processing and stop Clifton Homecare from continuing to process their personal data.
There are only certain situations when a legitimate right to object can be sent to a company. These are:
- Direct marketing
- The processing of personal data for statistical purposes related to historical or scientific research
- The processing of data for tasks in the public interest
- The exercising of official authority invested in you
- Objections to data processing in yours or a third party’s legitimate interest
- Objections to data processing based on their own beliefs & situations
Clifton Homecare have one month to assess, review and provide feedback to an objection, in accordance with the legitimate right to object.
Rights In Relation To Automated Decision Making & Profiling
We do not use any automated decision making or profiling software.
Obtaining Consent
We may use personal information:
- To provide you with information relevant to your care package and details of any medical practitioner requirements specific to your care
- To notify you of any change to our services we provide for you
- To assist with any contractual obligations
- To allow training courses to be undertaken and any additional training required to be identified
- Supervisory reports completed after regular monitoring of employee performance
Personal and special category of data obtained from client, our team and any other source relevant to our domiciliary care activities may include:
- Racial or ethnic origin of a client or employee
- Their religious beliefs if these will impinge on any care packages we implement
- Their physical &/or mental health condition
- Their sexual life but only so far as this will affect the care package we provide
- Name & contact details
How We Secure Your Data
We use Cloud based software for maintaining electronic storage information – a secure system, password protected with password changed regularly.
Service user and employee files are locked away when the office is closed. No records are left on desks when the office is unmanned and no paper records are stored in company cars.
Messaging to staff uses a secure password protected WhatsApp messaging service which is encrypted.
All passwords are changed regularly and all clients are encouraged to change key-safe codes regularly. Clifton Homecare will assist with this process, if required.
Retention Periods Of Records Obtained
We collect employee information such as their address, contact details, next of kin and any details of any physical concerns that may affect their health and/or wellbeing whilst at work.
Details of the retention periods for data is set out in our Retention Policy.
How We Use Cookies
A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site.
Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
If you leave a comment on this site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
We use traffic log cookies to identify which pages are being used. This helps us to analyse data about web page traffic and improve this website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not.
A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.
You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Further guidance on how to control cookies in your browser can be found on the Information Commissioner’s Office website.
This Site Uses The Following Cookies:
- Google Analytics Cookies: These are set for monitoring & tracking visitors behaviour on the site. Google Analytics cookie usage on websites can be found here: https://policies.google.com/technologies/cookies
- Limit Login Attempts Cookies: This is used by the Limit login attempts plugin to provide brute force security in logins by monitoring user cookies.
- WordFence Security Cookies: Uses cookies for analyzing trends, site administration, tracking user movement, & to gather demographic information to monitor & maintain website security. To meet GDPR compliance & for a list of cookies, please see here: wordfence.com/help/general-data-protection-regulation
- WordPress Cookies: These are used by WordPress as tiny pieces of information stored on your computer, to verify who you are. There are cookies for logged in users & for commenters to authenticate logged-in visitors, password authentication & user verification.
Comments
When visitors leave comments on this website, we collect the data shown in the comments form and also the visitor’s IP address and browser user agent string to help spam detection.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Contact Forms
We use Contact Form 7 plugin, their Privacy Policy can be found here: contactform7.com/privacy-policy
Information submitted through the contact forms on this website are sent to our email address. The plugin, in itself, does not:
- Track users by stealth
- Write any user personal data to the database
- Send any data to external servers
- Use cookies
While we keep these form submissions for membership and enquiry purposes, they are never shared with third parties.
Embedded Content From Other Websites
Articles on this site may include embedded content (e.g. videos, images, articles etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Links To Other Websites
This website may contain links to other websites of interest. However, once you have used these links to leave this website, you should note that we do not have any control over that other website.
Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement.
You should exercise caution and look at the privacy statement applicable to the website in question.