Total Pilates Protects your Data

Data Protection Policy

April 2020

 

Introduction

TOTAL PILATES gathers and uses data about individuals. This includes our clients, business suppliers and other professional services.

 

This policy describes how this data is collected, handled and stored in order to comply with the General Data Protection Law (GDPR).

 

Why this policy exists

This data protection policy ensures TOTAL PILATES

  • complies with current data protection law and follows good practice,

  • protects the rights of staff, clients and suppliers

  • ensures TOTAL PILATES is open about how it stores and processes individual’s data

  • protects itself from the risks of a data breach.

 

This policy also provides proof of compliance.

 

Policy Scope

This policy applies to all employees of TOTAL PILATES including occasional or short-term staff members. For example, one off help with bookkeeping or self assessment. Please see our Confidentiality Agreement.

 

This applies to all data held by TOTAL PILATES relating to identifiable individuals, including:

  • personal information (name, postal address, telephone number, email address)

  • Bank Details from customers

  • Health screening Questionnaires

  • Medical Documents

 

Responsibility

The Data Controller TOTAL PILATES is responsible for ensuring data is collected, stored and handled in accordance with GDPR regulations. The Data Processor TOTAL PILATES is responsible for collecting, storing and handling data in accordance with GDPR regulations.

 

Data Collection

Data should only be collected for a specific, explicit and legitimate purpose.

Data should be adequate, relevant and limited.

Data should not be kept longer than is necessary.

Data Storage

 

Paper

  • Where data is stored on paper, it must be kept in a secure place (fire proof and lockable) where unauthorised people cannot see it.

  • Data must not be left on a printer or desk where others could see it.

  • Data printouts should be shredded and disposed of securely when no longer required.

 

Electronic

  • Where data is stored electronically, it must be protected from unauthorised access, accidental deletion and malicious hacking attempts.

  • Data should be updated as inaccuracies are found, such as contact numbers.

  • Data should be protected by strong passwords that are changed regularly and never shared.

  • Data stored on removable media such as disc or stick should be locked away securely when not being used.

  • Data should only be stored on designated drives and servers and only uploaded to an approved cloud computing service.

  • Data should never be saved directly to laptops or other mobile devices.

  • All computers containing data should be protected by approved security software and a firewall.

 

Data Use

  • When working with personal data, employees should ensure the screens of their computers are always locked when left unattended.

  • Personal data should not be shared informally.

 

Data Processing

  • The reason for collecting data outside of a normal working relationship will be documented. e.g to refer onto another agency

  • Consent will be requested for communication outside of normal working relationship. e.g to receive a newsletter.

 

Providing Information

TOTAL PILATES aims to ensure that individuals are aware that their data is being processed and that they understand:

  • How the data is being used

  • How to exercise their rights

 

TOTAL PILATES has a Privacy Statement, setting out how data relating to individuals is used by the company.

 

Subject Access Requests

All individuals who are the subject of personal data held by TOTAL PILATES are entitled to ask what information is held about them and why. They are entitled to make rectifications to it, or for it to be erased. They are entitled to ask for access to it by email, addressed to the Data Controller (angela@totalpilates.co.uk). The Data Controller will aim to provide the relevant data within 14 days at a cost of £10 per request. The Data Controller will verify the identity of anyone making a Subject Access Request before responding with the relevant information.

 

Total Pilates, Neath Oak, Sutton Green Road,  Sutton Green

Guildford GU4 7QD 01483 7440717 / 07976 659 688

Previous
Previous

Total Pilates Privacy Policy

Next
Next

Taking a Look at the Basics