Provide Wellbeing Limited – Your Information Your RightsÂ
Privacy NoticeÂ
This Privacy Notice describes what information we collect and hold about you, how we use it, who can access it and your rights with regards to accessing your information.Â
Who are we?
Provide Wellbeing Ltd (part of the Provide Community Group) is registered with the Information Commissioner’s Office (ICO) to process personal and special categories of information under the Data Protection Act, our registration number is Z2525693.
Why we keep personal information about youÂ
We aim to provide you with the highest quality care. To do this, we must keep records about you and the care we provide for you.Â
Our staff are trained to handle your information correctly and protect your privacy. We aim to maintain high standards, adopt best practice for our record keeping and regularly check and report on how we are doing.Â
NHS patients and Non-NHS Patients
We do not collect your information for direct marketing purposes unless you specifically opt-in, and your data is not sold on to any other third parties. Your information is not processed overseas.Â
For NHS patients, electronic health records are accessed by use of an NHS Smartcard which are issued to our staff under strict NHS protocols. Any access by our staff to your health records is fully audited.
Information is held for specified periods of time as set out in the Records Management Code of Practice for Health and Social Care.Â
Your information will be processed safely and securely within our secure infrastructure. Your data will be stored securely within approved systems hosted by accredited and authorised vendors within the UK. Only authorised individuals will be granted access to your information. If for any reason your data needs to be processed outside the UK/EEA we will ensure that the processing is legal and that the appropriate safeguard is put in place in accordance with the UK GDPR.Â
How do we collect Information about you?Â
We collect Information about you in a number of ways:
Information You Tell Us – Some of our services accept self-referrals which means that you can contact us directly to arrange an appointment and do not need to be referred by your G.P. You will be asked for certain information when you contact us to enable us to book you an appointment and to be able to provide appropriate care. You may also be asked to complete a form when you come in for your appointment so that we have relevant information to be able to help you. We may also seek your opinion on our services through our customer surveys.
Information Others Tell Us –Where you are referred to us from another health care professional, for example your GP, they will share relevant information about the care you have received from them to enable us to provide effective and safe care to you. All our NHS patient data is recorded on SystmOne which is used widely across the NHS and care organisations to maintain accurate medical records about you. You can choose which other organisations involved in your care can view your full medical record. Speak to your GP to set your choice or you can contact the Provide Wellbeing admin team for neurodevelopmental assessments on provide.wellbeing@nhs.net and for surgical procedures on, hello@providewellbeing.co.uk. For more information, please visit https://systmonline.tpp-uk.com/2/help/help.html.
The NHS Personal Demographics Service– When we register you to receive care from one of our NHS services, we receive information from the NHS Personal Demographic service. The Personal Demographics Service (PDS) is the national electronic database of NHS patient details such as name, address, date of birth and NHS Number (known as demographic information). This is to ensure that the information we hold about you is accurate and up to date and to ensure that you are entitled to receive NHS Care.Â
NHS Summary Care Record– To support you and provide high quality and safe health care it may very occasionally be necessary to access your NHS Summary Care Record. The NHS Summary Care Record is an electronic summary of key clinical information (including medicines, allergies and adverse reactions) sourced from your G.P Record. We will discuss this with you should the need arise to access this and will only do so this with your permission, unless another legal reason to access applies (please see below)Â
Cookies – Cookies are small text files placed on your computer when you use a website. They help us collect standard internet log information and visitor behaviour information during your visit to the website. Where we use non-essential cookies that may collect some of your personal information, we will ask for your consent before we use the cookies. You have a right to withdraw your consent for us to use non-essential cookies.
What information do we keep about you?Â
The information we hold may include:Â
- Basic details, such as your name, address and next of kin.Â
- Contact information such as telephone numbers and email addresses.Â
- Contacts we have had with you, such as clinic visits.Â
- Notes and reports about your health and any treatment or care you needed.Â
- Details about your treatment and care.Â
- Results of tests that may have been undertaken on our behalf as part of your care (i.e. Nerve Conduction Studies, Post Vasectomy Semenology Test, Biopsies)Â
- Unless you authorise us to, we do not access your health records information from other health professionals, relatives or those who care for you.Â
- If you are paying us for your services, then we will take payment through a PCI compliant provider.
- Your experience and outcomes through our Customer surveys and Complaints & Compliments processÂ
- Marketing permissions (self-pay only) with your consentÂ
We create and hold your records electronically and sometimes in hard copy where necessary. We may also hold paper records from previous contacts with you.Â
Any records we hold about you are held securely and are only accessible to those who are involved in your care or have a legitimate need to access.Â
All our staff and contractors receive appropriate and on-going training to ensure they are aware of their personal responsibilities and have contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. Staff only have access to personal information where it is appropriate to their role and is strictly on a need-to-know basis.Â
How do we use your information?Â
Information collected about you to deliver your health care may also be used to assist with:Â
- Making sure your care is of a high standard.Â
- Using statistical information to look after the health and wellbeing of the general public and planning services to meet the needs of the population.Â
- Assessing your condition against a set of risk criteria and identifying post-operative complications to ensure you are receiving the best possible care.Â
- Helping train staff and support research.Â
- Supporting the funding of your care.Â
- Reporting and investigation of complaints, claims and untoward incidents.Â
- Reporting events to the appropriate authorities when we are required to do so by law.Â
- Improving the quality of servicesÂ
- Sending updates on our services (with your consent)Â
- Processing payments/refundsÂ
If your treatment is being funded by the NHS then the legal basis for the processing of data for these purposes is that as a provider of NHS care we have a public duty to care for our patients, as guided by the Department of Health and Data Protection law says it is appropriate to do so for health and social care treatment of patients, and the management of health or social care systems and services.Â
There may also be situations where we are under a duty to share your information. We are required by law to report certain information to the appropriate authorities. Occasions when we must pass on information include Notification of new births, infectious diseases that may endanger others, such as meningitis and measles (but not HIV/AIDS), where a formal court order has been issued and sharing with the Care Quality Commission (CQC) to inspect the quality and safety of the care that we provide. We may also have to share your information when it is necessary for the prevention or detection of crime or prosecution of offenders or where there are serious risks to the public or our staff.Â
If you are funding your own treatment, then the legal basis may primarily be that the processing is necessary for the performance of a contract to which you are a party or to take steps at your request prior to entering a contract.Â
If we send you marketing communications, then the legal basis is consent. If you no longer wish to receive marketing updates from us, please contact us by email to provide.wellbeing@nhs.net, with unsubscribe as the email subject.Â
Who can see your information?
Your information is only accessible to those involved in your care (clinical staff) or administration. Administrative staff include receptionists who check patients in for clinics and staff who assist with the administration of our clinics/ services (for example typing up letters and reports). These members of staff are bound by the same rules of confidentiality as our clinical staff.Â
Organisations that we may share information with:Â
- General PractitionersÂ
- NHS Hospitals & ClinicsÂ
- Mind Professionals (a joint subsidiary with Provide Wellbeing and part of the Provide Community) to deliver Neurodevelopmental assessment services in conjunction with us.
- Also, Subject to Strict Protocols: Education Services, Local Authority Services, Private Sector Providers, Children’s Centre’s, Commissioners of our Services, the Department of Health, the Family Health Service Authority (FHSA) and the Health Protection AgencyÂ
- Organisations who supply us with services (tests) that may have been undertaken on our behalf as part of your care (i.e. Nerve Conduction Studies, Post Vasectomy Semenology Test, Biopsies)Â
- Organisations who provide us with services that help support the care we provide, for example providers of information systems and necessary business applications. Information shared in these instances will be limited to the minimum data necessary to fulfil the service provided and strict access controls will be put in place.Â
- Third parties to whom we may choose to sell, transfer or merge parts of our organisation or assets. If a change of ownership happens to our organisation or to a service contract, then we may share or transfer your personal data to the new owners or service provider who are obliged to process your data with the same level of protection set out in this privacy notice.Â
We will only share information with those who have a legitimate right to know.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information is not needed. You have a choice about whether you want your confidential patient information to be used in this way through the NHS National Data Opt Out Policy. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care. To find out more or to register your choice to opt out, please visit https://www.nhs.uk/your-nhs-data-matters/
How Long Do We Keep Your DataÂ
NHS Patients: - Information is held for specified periods of time as set out in the Records Management Code of Practice for Health and Social Care.Â
Self-Pay Patients: - We only keep your data for as long as we need to use it. This will depend on the service we are providing. There may also be legal requirements to retain your data for a certain length of time.Â
Your Rights
If we need to use your personal information for any reasons beyond those stated above, we will discuss this with you and ask for your permission to do so where you will have the option to agree or disagree. This is known as explicit consent. Data Protection laws give individuals rights in respect of the personal information that we hold about you. These are:Â
- To ask for access to your information (See our Home Page - Portal (ams-sar.com) page)
- To ask for your information to be corrected if it is inaccurate or incomplete.Â
- To ask for your information to be deleted or erased. Please note that this does not apply to your health or care record, or where we process information for public health or scientific research purposes.Â
- To ask us to restrict the use of your information in some circumstances.Â
- Automated decision making. You can request a manual review of the accuracy of an automated decision making.Â
- To request your personal information to be transferred to other providers on certain occasions.
All requests for any of the above should be made to the Data Protection LeadÂ
- by telephone on 0300 3039966Â
- by email:Â hello@providewellbeing.co.uk
- or in writing Provide Wellbeing, Business Park, 900 The Crescent, Highwoods, Colchester CO4 9YQ.Â
Should you wish to lodge a complaint about the use of your information, please contact our General Manager
- by telephone on 0300 3039966Â
- by email:Â hello@providewellbeing.co.uk
- or in writing Provide Wellbeing, Business Park, 900 The Crescent, Highwoods, Colchester CO4 9YQ.Â
You may also contact our Group Data Protection Officer, John AdegokeÂ
- by email:Â john.adegoke@nhs.netÂ
- or in writing: Provide CIC, 900 The Crescent, Colchester Business Park, Colchester, Essex C04 9YQ.Â
If you are still unhappy with the outcome of your enquiry you can write to: The Information Commissioner, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF – Telephone: 0303 123 1113 or 01625 545700Â
This policy was last reviewed on 10/07/2024.