PRIVACY Notice for Patients

Website Privacy Policy

Purpose

Surrey Orthodontics Godalming aims to meet the requirements of the Data Protection Act 2018, the United Kingdom General Data Protection Regulation (UK GDP), the guidelines on the Information Commissioner's (ICO) website, and our professional guidelines and requirements.

This privacy notice describes the type of personal information we hold, why we keep it, and what we do with it.

Registered name

The data controller is Trevor Matewu.

Contact details

If you have an enquiry or request, please contact Trevor Matewu

Surrey Orthodontics Godalming
115 High Street, Godalming, GU7 1AQ
Email: [email protected]
Phone: 01483 421511

This privacy notice is also available [on the practice website at insert URL, or a hard copy can be requested from the Practice by emailing or calling directly].

What information we collect, use, and why

The persona data we process includes:

Name, address, contact details, gender, pronoun preferences, date of birth, nationality, NHS number, medical history, dental history, family medical history, family contact details, emergency contact details, marital status, information about care needs, rinancial details, doctor's details, treatment plans, consent, X-rays, clinical photographs, digital scans, study models, appointment dates, details of complaints, call recordings and CCTV recordings].

We may also process more sensitive special category data, including:

Ethnicity, race, religion, health records, sex life information, or sexual orientation.

The reasons we process the data include:

  1. To fulfil our contract with you

  2. To maintain a contemporaneous clinical record

  3. To discuss treatment options

  4. To provide dental prevention and oral health advice

  5. To ensure any medication we prescribe is suitable

  6. To modify treatments based on individual needs

  7. To meet our obligations under the Equalty Act 2010

  8. To carry out financial transactions

  9. To manage appointments, recall arrangements and send reminders

  10. To communicate with your next of kin in an emergency

  11. To communicate with parents or carers about the person being cared for

  12. To refer to other dentists, doctors and health professionals as required

  13. For debt recovery

  14. To continutally improve the care and service you receive from us

  15. To assist with safeguarding or public protection concerns

  16. To assist with dealing with queries, complaints or claims

Lawful basis (Personal data)

Our lawful bases for processing personal data:

  1. A legitimate interest to provide evidence-based dental care to patients safely and effectively

  2. Consent of the data subject

  3. To comply with our legal obligations

Lawful basis (Special category data)

Our Article 9 conditions for processing special category data:

  1. Processing is necessary for ethical and professional health care purposes

  2. Processing is necessary to monitor and assess the quality of opportunity or treatment between different groups

  3. Consent of the data subject

Data protection rights

You have the following personal data rights:

Where we get personal information from

We obtain your details when you enquire about our care and service, when you join the practice, when you subscribe to our newsletter or register online, when you complete a registration or medical history form, from family members or carers, and when another healthcare provider refers you for treatment at our practice.

How long we keep information

We minimise the data that we keep, and do not keep it for longer than necessary.

We keep your records for [11 years after the date of your last visit to the Practice or until you reach the age of 25, whichever is longer]. At your request, we will delete non-essential information (for example, some contact details) before the end of this period.

[Images captured with CCTV will be kept and destroyed securely after [3 months] unless they are needed for longer due to ongoing investigation, legal proceedings, or regulatory compliance.]

How we store information

We store your personal information securely [on our practice computer system and in a manual filing system]. Only those working at the practice have access to your information. They understand their legal responsibility to maintain confidentiality and follow practice procedures to ensure this.

We take precautions to ensure the security of the practice premises, the practice filing systems and computers.

We use high-quality specialist dental software to record and use your personal information safely and effectively. Our computer system has a secure audit trail, and we back up information routinely.

Sharing information

To provide you with appropriate care, we might need to share personal data with the following; however, only the minimum information required will be shared:

Duty of confidentiality

Exceptional circumstances might override the duty to maintain confidentiality. We will inform you of requests to share personal information where possible. The decision to disclose information will only be taken by senior staff. Examples include:

National data opt-out

Whenever you use a health or care service, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment. The information collected about you can also be used and provided to other organisations for purposes beyond your care, for instance, to help with:

This may only occur when there is a clear legal basis for using this information. All these uses help to provide better health and care for you, your family and future generations.

If you are happy with this use of information, you do not need to do anything. To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. If you choose to opt out, your confidential patient information will still be used to support your care.]

How to complain

If you have any comments, suggestions, or complaints about how we use your data, you can contact us using the contact details at the top of this privacy notice. If you remain unhappy with our response or feel unable to discuss it with the Practice, you can contact the Information Commissioner's Office (ICO) on 0303 123 1113 or by visiting https://www.ico.org.uk/make-a-complaint

Review and Revision

This privacy notice is reviewed annually and updated to ensure its effectiveness and compliance with current regulations, guidance, and standards.