Privacy Notice
- Home
- /
- Privacy Notice
Privacy Notice
The practice aims to meet the requirements of the Data Protection Act 2018, the General Data Protection Regulation (GDPR], the guidelines on the Information Commissioner’s website as well as our professional guidelines and requirements.
The data controller is Dr Basirat. The Information Governance Lead and Date Protection Officer is Dr Basirat.
This Privacy Notice is available on the practice website. You can also request a copy at reception, by email if you contact info@monalisasmiles.co.uk or by calling 020 8449 3411.
You will be asked to provide personal information when joining the practice. The purpose of processing your personal data is to provide you with optimum dental health care and prevention.
The categories and examples of data we process are:
- Personal data for the provision of dental health care
- Personal data for the purposes of providing treatment plans, recall appointments, reminders or estimates
- Personal data such as details of family members for the provision of health care to children or for emergency contact details
- Personal data for the purposes of employed and self-employed team members employment and engagement respectively
- Personal data for the purposes of direct mail, email and text to inform you of important announcements or about new treatments or services
- Personal data – IP addresses so that we can understand our patients better and inform our marketing approach as well as improve the web site experience
- Special category data including health records for the purposes of the delivery of health care and meeting our legal obligations
- Special category data including health records
- Special category data to meet the requirements of the Equality Act 2010
- Special category data details of criminal record checks for employees and contracted team members
- Personal data is stored in the [EU] whether in digital or hard copy format
- Personal data is stored in the US in digital format when the data storage company is certified with the EU-US Privacy Shield
- Personal data is obtained when a patient joins the practice, when a patient is referred to the practice and [when a patient subscribes to an email list / other
- The legitimate interests of the dental practice
- Processing is necessary for the performance of a contract with the data subject or to take steps to enter into a contract
- Consent of the data subject
- To comply with our legal obligations
- Processing is necessary for health care purposes
- Processing necessary for identifying or keeping under review the existence or absence of equality of opportunity or treatment between groups of people with the view to enabling such equality to be promoted or maintained
- We obtain consent of the data subject to process criminal record checks
- To maintain your contemporaneous clinical records
- To provide you with dental treatment, prevention and oral health advice
- To carry out financial transactions with you
- To manage your NHS or HSC dental care treatment
- To send your personal data to the General Dental Council or other authority as required by law
- To communicate with you as and when required including appointment reminders, treatment plans, estimates and other communications about your treatment or the practice
- To communicate with your next of kin in an emergency
- If a parent or carer to communicate with you about the person you parent or care for
- To refer you to other dentists or doctors and health professionals as required
- To obtain criminal record disclosures for team members
- For debt recovery
- To continually improve the care and service you receive from us
- The right to be informed about the collection and use of your personal data
- The right of access – to have a free copy of your data that we have
- The right to rectification – to correct the data we have if it is inaccurate or incomplete
- The right to deletion of your personal data (clinical records must be retained for a certain time period)
- The right to restrict processing of your personal data
- The right to data portability – to have your data transferred to someone else
- The right to object to the processing of your personal data.
- Rights in relation to automated decision making and profiling
- If you are a patient of the practice you have the right to withdraw consent for important notifications, newsletters, surveys or marketing. You can inform us to correct errors in your personal details or withdraw consent from communication methods such as telephone, email or text. You have the right to obtain a free copy of your patient records within one month.
- If you are not a patient of the practice you have the right to withdraw consent for processing personal data, to have a free copy of it within one month, to correct errors in it or to ask us to delete it. You can also withdraw consent from communication methods such as telephone, email or text.
- Data Protection and Information Security Policy (M 233-DPT), Consent Policy (M 233-CNS)
- Privacy Impact Assessment (M 217Q), Information Governance Procedures (M 217C), Record Retention (M 215)