DATA PROTECTION STATEMENT
Data Protection Statement for Everything Ears
Introduction
Everything Ears is committed to ensuring the privacy and protection of personal data. This Data Protection Statement outlines how we collect, use, store, and protect the personal information of our customers. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller
Everything Ears
0161 524 9978
info@everythingears.co.uk
Personal Data Collected
We collect the following personal data about our customers:
– Name
– Date of birth
– Contact details (address, phone number, email)
– Medical history (related to ear health)
– Treatment details (such as ear wax removal sessions)
- Purpose of Data Collection
The personal data collected is used for the following purposes:
– Conducting and documenting ear wax removal treatments
– Ensuring the health and safety of our customers
– Complying with legal and regulatory requirements
- Lawful Basis for Processing
The lawful bases for processing personal data include:
– Consent: Obtained from customers before conducting treatments.
– Legitimate interests: Ensuring the health and safety of our customers and compliance with legal obligations.
- Data Retention
Personal data will be retained for one year after the completion of the treatment. After this period, data will be securely deleted or anonymised unless further retention is required by law.
- Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
– Secure storage systems
– Access controls
– Regular data security audits
- Data Sharing
Personal data may be shared with the following parties:
– Medical professionals involved in the treatment
– Regulatory bodies as required by law
We do not share personal data with third parties for marketing purposes.
- Rights of Data Subjects
Customers have the following rights regarding their personal data:
– Right to access: Request a copy of their personal data.
– Right to rectification: Correct inaccurate or incomplete data.
– Right to erasure: Request the deletion of their data, subject to certain conditions.
– Right to restrict processing: Limit the processing of their data under certain circumstances.
– Right to data portability: Receive their data in a structured, commonly used format.
– Right to object: Object to the processing of their data based on legitimate interests.
- Complaints
Customers have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if they believe their data protection rights have been violated.
- Changes to this Statement
We may update this Data Protection Statement from time to time. Any changes will be posted on our website and, where appropriate, notified to customers.
Contact Us
For further information, please contact us at info@everythingears.co.uk