Your Personal Data
What we need
Dorsi Spinal Institute will be what is known as the controller and the processer of the personal data you provide to us. We collect personal data about you which may also include any special types of information, particularly related to health and life style or location-based information. This is stored in a secure computer system called ‘Practice Hub’; accessed by all members of staff with limited permissions depending on the role of that team member.
We also gather
Name, address, email, Contact information, medical history, life style, diagnostic assessment information including X-Rays information relating to your personal circumstances.
Why we need it
We need to know as much information as possible relating to your health history and personal data as possible in order to provide you with an accurate recommendation for your personal circumstances. We will not collect any personal data from you that we do not need in order to provide and oversee this service to you.
For processing of data to be lawful under GDPR Dorsi Spinal Institute will limit use;
Consent: the individual has given clear consent for you to process their personal data for a specific purpose.
Contract: the processing is necessary for an in depth and accurate diagnosis and effective treatment programme.
What we do with it
All the personal data we use is controlled and processed by the Dorsi Spinal Institute Privacy Policy in the UK, however, for the purposes of IT hosting and maintenance, this information is located on servers within the European Union. Data is controlled / Processed via our Practice Hub Platform which no one outside our organisation and the controllers of practice hub have access to. We have a Data Protection regime in place to oversee the effective and secure processing of your personal data. We destroy all paper records after they are scanned onto the Practice Hub computer system.
Your data is stored electronically on our cloud encrypted server. Our server is based in the UK.
In order to carry out the process, we will be required to contact you using one or more of the following means; post, email, phone, text or automated call.
If you would like to opt out of any of the above do not hesitate to contact us directly on 0115 959 8491.
How long we keep it
We are required under regulation to keep your personal data, such as name, address, contact details and treatment and medical records for a period of 8 years. If we have not had contact with you in that time frame it will be deleted and destroyed. The reason we keep these records for 8 years is due to the potential for the information being required in court legal proceedings; a legal case can be made for up to 7 years after an event such as a road traffic collision.