Privacy Policy

 

PRIVACY NOTICE

Data Controller

Isabella Osmond

27 Porchester Road, Newbury, RG14 7QH

Email: hello@isabellaosmond.com

Website: www.isabellaosmond.com 

Introduction 

I am committed to protecting your privacy and handling your personal information in accordance with UK GDPR and the Data Protection Act 2018.

What Information I Collect

I may collect and process the following personal information: 

  • Full name

  • Date of birth

  • Postal address

  • Email address

  • Telephone number

  • GP name, practice address and contact details

  • Therapist, psychiatrist or other healthcare professional contact details

  • Health and lifestyle information relevant to nutritional therapy

  • Consultation notes

  • Treatment plans and recommendations

  • Appointment records and correspondence

How I Collect Information

Information may be collected when:

  • You submit an enquiry through my website contact form

  • You contact me by email or telephone

  • You complete intake forms or questionnaires

  • You attend consultations

  • Another healthcare professional refers you with your consent

Why I Process Your Information

I process your information to:

  • Provide nutritional therapy services

  • Assess your suitability for nutritional therapy

  • Maintain accurate clinical records

  • Communicate regarding appointments and recommendations

  • Liaise with healthcare professionals involved in your care where appropriate

and authorised

  • Facilitate supplement recommendations and ordering through professional

supplement dispensaries where appropriate

  • Meet legal, insurance and professional obligations

Lawful Basis for Processing

Personal information is processed under Article 6(1)(b) UK GDPR where processing is necessary for the performance of a contract for nutritional therapy services, and under Article 6(1)(f) UK GDPR where processing is necessary for my legitimate interests in administering and managing my practice.

Health information is processed as special category data under Article 9(2)(h) UK GDPR where processing is necessary for the provision of health care and treatment.

Who Information May Be Shared With

With your consent, information may be shared with: 

  • Your GP

  • Therapists

  • Psychiatrists

  • Other healthcare professionals involved in your care

  • Professional supplement dispensaries and suppliers where required to facilitate supplement recommendations and ordering

Information may be shared by email, letter or other appropriate means of communication where necessary to support your care.

Information may also be disclosed where required by law, safeguarding obligations, court order or regulatory requirements.

Supplement Dispensaries and Suppliers

Where appropriate as part of providing nutritional therapy services, I may use professional supplement dispensaries or supplier platforms, such as The Natural Dispensary, to facilitate supplement recommendations and ordering.

This may involve sharing limited personal information, such as your name and email address, in order to create an account, provide access to recommendations, or enable ordering of products.

Only the minimum information necessary for these purposes will be shared.

International Transfers

Some service providers used within my practice, including Google Workspace, may process personal information outside the United Kingdom.

Where this occurs, appropriate safeguards are in place to protect personal information in accordance with UK GDPR requirements.

Data Storage and Security

Information is stored securely using password-protected systems and devices.

Google Workspace is used for email and document management.

Consultation notes may be stored in pseudonymised form where possible and are password protected.

I use appropriate technical and organisational measures to protect personal information from unauthorised access, loss, misuse or disclosure, including:

  • Password-protected devices and files

  • Two-factor authentication

  • Restricted access to records

  • Secure storage and backup procedures

How Long Information Is Retained

Client records are retained for 8 years from the date of the last consultation in accordance with professional record-keeping requirements.

After this period, records will be securely deleted or anonymised unless there is a legal, regulatory or insurance-related reason to retain them for longer.

Professional Obligations

As a registered nutritional therapist, I am required to maintain accurate clinical records and comply with professional, insurance and legal obligations. This may require retaining certain information for the retention periods described above.

Providing Information

The provision of certain personal and health information is necessary in order for nutritional therapy services to be provided safely and effectively.

If you choose not to provide information requested during the assessment process, I may be unable to provide nutritional therapy services or may need to limit the services I can provide. 

Your Rights

Under UK GDPR you have the right to:

  • Request access to your personal information

  • Request correction of inaccurate or incomplete information

  • Request erasure of your information in certain circumstances

  • Request restriction of processing in certain circumstances

  • Object to processing in certain circumstances

  • Request transfer of your information where applicable

Withdrawal of Consent

Where processing is based on your consent, including consent to share information with healthcare professionals involved in your care, you may withdraw that consent at any time.

Withdrawal of consent will not affect the lawfulness of processing carried out before consent was withdrawn.

Automated Decision-Making

No automated decision-making or profiling is carried out.

Complaints

If you are concerned about the way your personal information is being handled, please contact me in the first instance via email: hello@isabellaosmond.com

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Contact

If you have any questions regarding this Privacy Notice or the way your information is handled, please contact me using the details above.