Social Media Privacy Policy

Target Data Subject: Social Media Enquiries – Instagram and Facebook

Who We Are

We are Camberley Chiropractic Clinic, Portland House, Park Street, Bagshot, GU19 5AQ, telephone number 01276 21637, email address gdpr@camberleychiropractic.co.uk. For the purposes of processing your personal data we are the controller.

Data Protection Officer
As we record and use sensitive health data we take the protection of this data very seriously. We have therefore appointed a Data Protection Officer, Camberley Chiropractic Clinic which is your first point of contact for any matters regarding your personal data we process. They can be contacted on 01276 21637. The email address is gdpr@camberleychiropractic.co.uk, the address is Portland House, Park Street, Bagshot, GU19 5AQ.

The Personal Data We Process and What We Do With It
We record and use the following categories of personal data: name, contact number and email address once given by yourselves on Facebook or Instagram. Our lawful basis of processing this data is one of contract and, for the health information, the provision of health-related services as a chiropractic clinic. In addition, we will only examine or treat you with your explicit consent.

No personal data is passed onto third parties without the consent from the patient.

The enquiry is passed on through the provider you have submitted your information to – Facebook or Instagram Messenger. Their policy has been checked and no data will be passed on to third parties other than to us through the messenger service at the clinic.

Retaining Your Personal Data
We aim to make contact with you within 48 hours of receiving a message request on social media. If we are unable to make contact with you within one month of receiving the data we will safely remove the data provided to us.
If you go on to become a patient at the clinic, whilst you are receiving treatment clinic we will continue to store your personal data. Once you have been discharged, we will be required to retain your personal data for a minimum of 8 years. After 8 years of no appointments at the clinic, we will safely destroy your personal data.

Your Rights
As we process your personal data, you have certain rights. These are a right of access, a right of rectification, a right of erasure and a right to restrict processing.

You may request a copy of your data at any time. Please make such a request in writing or by email to the Data Protection Officer, whose details are shown above. Please provide the following information: your name, address, telephone number, email address and details of the information you require.
We will need to verify your identity so we may ask for a copy of your passport, driving license and/or recent utility bill.

If you believe any of the personal data we hold on you is inaccurate or incomplete, please contact the clinic directly and any necessary corrections to your data will be made promptly.

If you believe we should erase your data, please contact the Data Protection Officer, whose details are shown above.

If you wish us to stop storing or using your data, please contact the Data Protection Officer, whose details are shown above.

Data Breaches
Should your personal data that we control be lost, stolen or otherwise breached, where this constitutes a high risk to your rights and freedoms, we will contact you without delay. We will give you the contact details of the Data Protection Officer who is dealing with the breach, explain to you the nature of the breach and the steps we are taking to deal with it.

Should You Wish To Complain
You can contact the ICO via their website: www.ico.org.uk should you wish to make a complaint about the way we are processing your personal data.

Automated Decision Making and Profiling
We do not use any system which uses automated decision making or profiling in respect of your personal data.