Cwtch Dental Care takes managing personal data very seriously and acts in accordance with the Data Protection Act 2018 as well as the General Data Protection Regulations.
This Privacy Notice is available on the practice website footer at www.cwtchdental.co.uk.
A copy can be requested from our reception team in person, via the telephone on TBC, via the contact form on the website at www.cwtchdental.co.uk, by emailing hello@cwtchdental.co.uk, or by writing to Cwtch Dental Care, Unit 6 Greenmeadow Springs Business Park, Village Way, Cardiff CF15 7NE.
Sarah Gatley of Cwtch Dental Care, Unit 6 Greenmeadow Springs Business Park, Village Way, Cardiff CF15 7NE is the “Data Controller”.
The Data Controller processes personal data for the purposes of:
• The provision of dental care to patients
• The provision of managing practice personnel (nurses, receptionists, practice managers, associates, hygienists, third party contractors)
• The provision of dental care to patients on referral from other healthcare providers
• The provision of managing patient referrals to and from other healthcare providers
• The management of patient appointments
• Communicating via newsletters to existing referring healthcare providers and existing patients of the practice
• Marketing to existing referring healthcare providers and existing patients of the practice
• Other marketing
The data controller processes special category personal data for the purposes of:
• The provision of dental care to patients
• The provision of managing practice personnel
• The provision of dental care to patients on referral from other healthcare providers
• The provision of managing patient referrals to and from other healthcare providers
The lawful basis for the processing of personal information relating to the provision of dental care to patients, provision of managing practice personnel, provision of dental care to patients on referral from other healthcare providers and the provision of managing referrals to and from other healthcare providers is:
• Performance of contract
• Legal obligation
The lawful basis for the management of patient appointments; communicating via newsletters to existing referring healthcare providers and existing patients of the practice; and marketing to existing referring healthcare providers and existing patients of the practice is:
• Legitimate interest
The lawful basis for marketing otherwise is:
• Consent
The lawful basis for the processing of special category data relating to provision of dental care to patients, provision of managing practice personnel, provision of dental care to patients on referral from other healthcare providers and provision of managing patient referrals to and from other healthcare providers is:
• Performance of contract
• Legal obligations
With the conditions under Article 9(2) under GDPR of:
“processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;”
and
“processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity”.
The practice holds personal data in the following categories:
• Patient: information relating to contact details, clinical records, health records, appointment history, payment records, limited financial records, complaints record and correspondence etc. (including special category personal data)
• Information relating to the contact details of healthcare providers/dentists we accept referrals from, or refer to
• Practice personnel: information relating to contact details, recruitment details, eligibility to work in the UK details, GDC registrations, indemnity registrations, disclosure and barring service information, contracts, attendance records, holiday records, sick day records, occupational health/medical records, appraisals, disciplinary records, capability records, grievance records, correspondence with the data subject and third parties in relation to the data subjects work at the practice, pay records, bank details, national insurance number etc. (including special category personal data)
• Cookies used on the practice website.
In most instances, personal data and special category personal data is received directly from the data subject themselves (e.g. patients, practice personnel, referring healthcare providers).
In some instances, personal data and special category personal data may be received from third parties (e.g. referring healthcare providers, disclosure and barring service, regulatory bodies, indemnity providers, dental insurance providers, NHS, legal representatives, website cookies etc.)
Relevant practice personnel of Cwtch Dental Care.
Patients of the practice and patients on referral from other healthcare providers
Data is stored on our internal server and is backed up within the practice and via an external cloud service which is based within the EU.
It may be necessary for third parties to access this data such as dental software providers, IT support companies, cloud back up providers, email providers, website developers and website hosts.
It may be necessary to share this information with organisations such as other healthcare providers when a referral is made or received, dental laboratories when dental prostheses are needed, indemnity providers if needed, regulatory bodies if needed, dental insurance providers, NHS, appointment reminder texting companies, debt collection companies, legal representatives if needed, prospective practice owners etc.
Other than this data is kept confidential.
Data is stored on our internal server and is backed up within the practice and via an external cloud service which is based within the EU.
It may be necessary for third parties to access this data e.g. IT support companies, cloud back up providers, email providers etc.
It may be necessary to share this information with organisations such as pension providers, HMRC, human resources support, payroll support, insurers, accountants, legal representatives if needed, indemnity providers if needed, regulatory bodies if needed, prospective practice owners, in connection with providing a reference to a future employer etc.
Other than this data is kept confidential.
Data is stored on our internal server and is backed up within the practice and via an external cloud service which is based within the EU.
It may be necessary for third parties to access this data such as dental software providers, IT support companies, cloud back up providers, email providers, website developers and website hosts.
It may be necessary to share this information with organisations such as other healthcare providers when a referral is made or received, indemnity providers if needed, regulatory bodies if needed, dental insurance providers, NHS, legal representatives if needed, prospective practice owners etc.
Special category patient personal data: Minimum of 10 years after the last contact or until the patient reaches 25 years old (whichever is longer); and we may store it for longer if there is justification to do so
Practice personnel data: 6 years after the data subject has left the practice
Cookies: Different cookies types are stored for different lengths of time. Full details can be found on the website cookie policy located on the footer of our website www.cwtchdental.co.uk.
Further details on individual data retention periods are available on the practice data retention policy.
Under the GDPR data subjects have:
• The right to be informed about the personal data we hold
• The right of access to the information we hold about them
• The right to rectification of the personal data we hold if incorrect
• The right to erasure of personal data we hold- (This may not apply if there is an overriding obligation to retain data for example clinical records)
• The right to restrict processing of personal data we hold
• The right to have the data we hold transferred to someone else at their request
• The right to object to processing the data we hold about them
For data subjects who have given their consent to us marketing to them, they have the right to withdraw that consent at any time. This can be done in person, via the telephone on TBC, via the contact form on the website at www.cwtchdental.co.uk, by emailing hello@cwtchdental.co.uk, or by writing to Cwtch Dental Care, Unit 6 Greenmeadow Springs Business Park, Village Way, Cardiff CF15 7NE.
Should you have a query or a complaint about the processing of your data by the practice, then please contact Sarah Gatley, the practice owner, who will endeavour to help.
Lucy Sharples can be contacted via telephoning the practice on TBC, by emailing hello@cwtchdental.co.uk, or by writing to Cwtch Dental Care, Unit 6 Greenmeadow Springs Business Park, Village Way, Cardiff CF15 7NE.
In the event that you have a complaint and are unhappy with our response, you can contact the Information Commissioner on 0303 123 1113 or by visiting their website at https://ico.org.uk/concerns.