top of page

Data Protection Policy

At Katy Sizeland, we are committed to protecting the personal information entrusted to us and ensuring that it is handled securely, respectfully and in accordance with applicable data protection requirements.

​

This Data Protection Policy sets out how we manage and protect personal information within our practice.

​

Scope of the Policy

This policy applies to the work of Katy Sizeland and covers the personal information we collect and manage in connection with our services.

​

It sets out how personal information is gathered, stored, protected and managed in line with data protection requirements.

​

This policy is reviewed on an ongoing basis to help ensure that our practice continues to meet applicable data protection requirements.

​

This policy should be read alongside our Privacy Policy.

​

Why This Policy Exists

This Data Protection Policy helps ensure that we:

  • comply with data protection requirements and follow good practice

  • protect the rights of our clients

  • are open and transparent about how we collect, store and process personal information

  • reduce the risks associated with the loss, misuse or unauthorised access to personal information

​

Data Protection Principles

We follow the following data protection principles when handling personal information:

​

1. Lawful, Fair and Transparent
Personal data shall be processed lawfully, fairly and in a transparent manner.

​

2. Specified, Explicit and Legitimate Purposes
Personal data shall only be collected for specified, explicit and legitimate purposes and not processed in a way that is incompatible with those purposes.

​

3. Adequate, Relevant and Limited
Personal data collected shall be adequate, relevant and limited to what is necessary for the purposes for which it is collected.

​

4. Accurate and Up to Date
Personal data held should be accurate and, where necessary, kept up to date. Every reasonable step will be taken to correct or delete inaccurate information without unnecessary delay.

​

5. Kept No Longer Than Necessary
Personal data shall not be kept for longer than is necessary.

​

6. Individual Rights
Personal data shall be processed in accordance with individuals’ data protection rights.

​

7. Secure
Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

​

8. International Transfers
Personal data shall not be transferred outside the European Union unless the applicable requirements for protecting individuals’ rights and freedoms are met.

​

Lawful, Fair and Transparent Data Processing

We collect personal information from clients and potential clients for the purpose of providing our services and managing consultations and appointments.

​

The forms we use to request personal information will contain a privacy statement explaining why the information is being requested and how it will be used.

​

Where consent is required, clients will be asked to provide consent for their information to be collected and held, and a record of that consent will be securely retained.

​

Clients will be informed that they can withdraw their consent where processing is based on consent, and will be informed how to do so.

​

Specified, Explicit and Legitimate Purposes

We only collect and use personal information for specified, explicit and legitimate purposes connected with providing our services and managing our practice.

​

This may include using personal information to:

  • communicate with clients about consultations and appointments

  • understand the information provided during consultations

  • provide our services appropriately

  • maintain accurate client records

  • respond to enquiries and requests

  • meet our professional, legal and insurance responsibilities

 

Personal information will not be used for purposes that are incompatible with those for which it was originally collected.

​

Adequate, Relevant and Limited

We only collect personal information that is adequate, relevant and limited to what is necessary for the purposes for which it is collected.

​

The information we may collect can include:

  • name and date of birth

  • contact details, including address, email address and telephone number

  • relevant health and wellbeing information

  • information provided during consultations

  • appointment and treatment records

  • payment and billing information where applicable

 

Additional information will only be collected where it is relevant to the services being provided and there is an appropriate reason for doing so.

​

We will not routinely collect information that is unnecessary for providing our services or managing our practice.

​

Accurate and Up to Date

We take reasonable steps to ensure that the personal information we hold is accurate and, where necessary, kept up to date.

​

Clients are encouraged to let us know if any of their personal information changes so that our records can be updated.

​

Where we become aware that personal information is inaccurate or out of date, we will take reasonable steps to correct or update it without unnecessary delay.

​

Kept No Longer Than Necessary

We will not keep personal information for longer than is necessary for the purposes for which it was collected.

​

Client records will normally be retained for a minimum of 7 years following the last consultation or treatment, unless there is a specific reason for retaining them for longer.

​

Where records relate to a client who was under 18 at the time of treatment, records will normally be retained for a minimum of 7 years after their 18th birthday.

​

These retention periods reflect our professional and insurance requirements. When information is no longer required, it will be securely deleted, destroyed or disposed of as appropriate.

​

Individual Rights

We respect the rights of individuals in relation to their personal information.

​

Depending on the circumstances, individuals have the right to:

  • be informed about how their personal information is collected and used

  • request access to the personal information we hold about them

  • request correction of inaccurate or incomplete information

  • request erasure of their personal information where appropriate

  • request restriction of processing in certain circumstances

  • object to certain types of processing, including direct marketing

  • request transfer of their personal information where the right to data portability applies

  • raise a concern or complaint about how their personal information is handled

 

These rights are subject to certain legal conditions and exemptions. For example, the right to erasure is not absolute and may not apply where we have a legal or professional reason to retain information.

​

Requests relating to personal information can be made by contacting us using the contact details provided in our Privacy Policy.

​

Secure

We take appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction or damage.

​

This includes:

  • restricting access to personal information to those who need it

  • using appropriate passwords and access controls

  • keeping electronic devices and systems appropriately protected

  • taking care when storing, sending and sharing personal information

  • keeping paper records securely stored

  • taking reasonable steps to protect information held by third-party service providers we use

 

We regularly review our arrangements to help ensure that personal information remains secure.

​

International Transfers

We will not transfer personal information outside the European Union unless the applicable data protection requirements for protecting individuals' rights and freedoms are met.

​

Where we use third-party service providers that may process personal information outside the European Union, we will take reasonable steps to ensure that appropriate safeguards are in place.

​

Accountability

We are responsible for ensuring that personal information is handled in accordance with applicable data protection requirements.

​

We take reasonable steps to demonstrate compliance with these requirements, including maintaining appropriate policies, procedures and records relating to the handling of personal information.

​

Where consent is required, appropriate records of consent will be securely maintained.

​

We regularly review our data protection arrangements and make changes where necessary to help ensure that personal information is handled appropriately and securely.

​

Data Collection and Use

We collect personal information directly from clients and potential clients through our website, forms, email, telephone conversations, consultations, appointments and other communications with us.

​

Personal information is collected and used only where there is an appropriate purpose for doing so, including:

  • arranging and managing consultations and appointments

  • understanding information provided during consultations

  • providing our services

  • maintaining accurate client records

  • communicating with clients

  • processing payments where applicable

  • responding to enquiries

  • meeting our professional, legal and insurance responsibilities

 

Where we collect health or wellbeing information, we will only collect information that is relevant to the services being provided and handle it confidentially and securely.

​

Data Storage

We store personal information in both paper and electronic formats, depending on the nature of the information and how it is collected.

​

Paper records are stored securely and access is restricted to those who need the information for appropriate practice purposes.

​

Electronic information is stored using appropriate password protection and security measures. Where we use third-party systems or service providers to store or process personal information, we take reasonable steps to ensure that appropriate security measures are in place.

​

Information provided through online forms or questionnaires may be printed and added to a client record where appropriate.

​

We take reasonable steps to ensure that personal information remains secure throughout its storage and use.

​

Access to Personal Information

Individuals have the right to request access to the personal information we hold about them, subject to applicable legal requirements and exemptions.

​

Requests should be made in writing and sent using the contact details provided in our Privacy Policy.

​

We will respond to requests within the applicable legal timeframe and may ask for information to confirm the identity of the person making the request.

​

Where appropriate, we will provide access to the information held and explain any information that cannot be provided due to legal or professional requirements.

​

Data Retention and Disposal

We retain personal information only for as long as is necessary for the purposes for which it was collected and in accordance with our professional, legal and insurance requirements.

​

Our normal retention periods are set out in our Privacy Policy.

​

When personal information is no longer required, we will take reasonable steps to ensure that it is securely deleted, destroyed or disposed of, as appropriate.

​

Paper records will be securely destroyed, and electronic information will be securely deleted where appropriate.

​

Data Breaches

We take data security seriously and will respond promptly to any suspected or actual personal data breach.

​

Where a breach occurs, we will:

  • assess the nature and extent of the breach

  • take reasonable steps to contain and minimise any potential harm

  • investigate what happened and take steps to prevent it happening again

  • notify the Information Commissioner's Office (ICO) where required

  • inform affected individuals where appropriate and where required

 

Any data breach will be recorded and managed in accordance with applicable data protection requirements.

​

Sharing Personal Information

We treat personal information as confidential and will not sell or share personal information for purposes unrelated to providing our services.

​

We may share personal information with third parties where this is necessary and appropriate, for example:

  • where we use service providers to support our practice, such as website, booking, payment or email services

  • where we are required to do so by law

  • where sharing is necessary to protect an individual's vital interests or to prevent serious harm

  • where there is another lawful basis for sharing the information

 

Where personal information is shared, we will take reasonable steps to ensure that it is handled securely and only used for the appropriate purpose.

​

Third-Party Service Providers

We may use trusted third-party service providers to support the operation and administration of our practice.

​

These may include providers of website hosting, online forms, appointment booking, payment processing, email and other digital services.

​

Where third-party providers process personal information on our behalf, we take reasonable steps to ensure that they have appropriate security measures in place and handle information in accordance with applicable data protection requirements.

​

We will only provide third parties with the information that is necessary for the relevant service or purpose.

​

Consent

Where we rely on consent to collect or process personal information, we will ensure that consent is given clearly and voluntarily.

​

Where health or wellbeing information is collected, we will obtain explicit consent for its collection and use for the relevant purposes.

​

We will keep an appropriate record of consent and ensure that clients are informed that they can withdraw their consent where consent is the basis for processing.

​

Withdrawal of consent will not affect the lawfulness of processing carried out before consent was withdrawn.

​

Data Protection Responsibilities

Katy Sizeland is responsible for ensuring that personal information within the practice is handled appropriately and in accordance with applicable data protection requirements.

​

We are responsible for:

  • following this Data Protection Policy and our Privacy Policy

  • taking reasonable steps to keep personal information accurate and secure

  • maintaining appropriate records relating to the handling of personal information

  • responding appropriately to requests, concerns and data breaches

  • reviewing our data protection arrangements and updating them where necessary

 

We will take reasonable steps to ensure that anyone who has access to personal information understands their responsibilities in relation to data protection and confidentiality.

​

Review of the Policy

We review this Data Protection Policy on an ongoing basis to ensure that it remains appropriate for our practice and reflects applicable data protection requirements.

​

The policy will be updated where necessary following changes to our services, systems, procedures or relevant data protection requirements.

​

The current version of this policy will be made available alongside our Privacy Policy.

​

Contact Details

If you have any questions about this Data Protection Policy, how we handle personal information, or wish to exercise any of your data protection rights, please contact us:

​

Katy Sizeland
Email: hello@katysizeland.co.uk
Telephone: 07841  590930

​

Further information about how we collect, use and protect personal information can be found in our Privacy Policy.

​

Policy Review

Policy review date: 1 July 2028

​

This policy will be reviewed on or before this date, or sooner if there are significant changes to our practice, systems or applicable data protection requirements.

​

bottom of page