How RDA Autism & ADHD Practice collects, uses and protects your personal data under UK GDPR.
This privacy policy aims to give you information on how RDA Autism & ADHD Practice Ltd. collects and processes your personal data through your use of this site (regardless of where you visit it from), including any data you may provide through this site when you purchase a service. This privacy policy describes how we collect and use information through our site and information from clients, prospective clients, and client representatives. In this privacy policy, “you” or “your” refers to users of our site, clients, prospective clients, or client representatives as the context requires. Please note, our site is not intended for children under 16 years of age, and we only collect data relating to children with the guardian’s consent. Please read this privacy policy together with any other privacy notice we may provide you with when we are collecting or processing personal information about you, so you are fully aware of how and why we are using your information. This privacy policy supplements the other notices and does not override them.
We are RDA AAP, a company incorporated and registered in England and Wales under company number 16148462. Our registered office is 6-7 East Street, Ware, SG12 9HJ. RDA AAP is a CQC regulated healthcare provider. We are registered with the Information Commissioner's Office (ICO). We are committed to protecting your privacy, acting ethically, and complying with the UK GDPR, Data Protection Act 2018. By accessing our website or using our services, you agree to the practices described in this Privacy Policy. If you have any questions, please contact RDA Autism & ADHD Practice at [email protected] or call us on 020 3906 1488 or write to us at 6-7 East Street, Ware, SG12 9HJ. You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
We keep our privacy policy under regular review. Please check this page from time to time to take note of any changes made. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
This site may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We are not liable to you for any issues arising in connection with their use of your information, the website content or the services offered to you by those websites. When you leave our site, we recommend that you check the privacy policy and terms and conditions on each website you visit to see how each third party processes your information.
RDA AUTISM & ADHD PRACTICE LTD is the controller and responsible for your personal data (collectively referred to as ”Company”, “we”, “us” or “our” in this privacy policy). We are the data controller of the personal information that we process, i.e. the organisation which determines, alone or jointly with another party, how your personal information is processed and for what purposes. This means that we are legally responsible for ensuring our systems, processes, suppliers and people comply with data protection laws in relation to the personal information that we handle.
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We collect non-personal information such as statistical data and certain personal information (information about an individual from which that person can be identified) when you use this site, become a client or sign up for client alerts.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
•Identity Data: includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender, patient ID, insurance details, nominated dependants, national insurance and passport number.
•Contact Data: includes address, email address and telephone numbers, next of kin and emergency contacts.
•Financial Data: includes bank account, payment card details and details of any fees and payments.
•Technical Data: includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this site.
•Profile Data: includes your username and password, purchases made by you, your interests, preferences, feedback and survey responses, details of any contact we have had with you, including audio recordings of phone calls, written complaints.
•Usage Data: includes information about how you use our site and our services.
•Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences.
•Client Matter Data: includes data provided by you as a client, generated by us based on our interactions with you or by others (e.g. practitioner) during the course of a matter.
•Health Data: includes information about your physical or mental health, including genetic information, medical history, and the name and address of your GP. Health Data is a Special Category of Personal Data.
We do collect Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data) as this is necessary for us to provide you with the right practitioner(s) for your issues.
We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.
If you do not provide personal data where we need to collect the personal data by law or under the terms of a contract we have with you, and you fail or decline to provide that data when requested, then we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with services requested, or to be able to complete a booking with your chosen practitioner). In this scenario, we may need to cancel the service you have with us, but we will notify you if this is the case at the time.
We collect most information from you as part of the client onboarding process, or when you fill in a form, contact us, book our services or provide feedback.
We generally collect personal information directly from you. In most circumstances where the personal information that we collect about you is held by a third party, we will obtain your permission before we seek out this information from such sources (such permission may be given directly by you, or implied from your actions), an example of this would be contacting a GP to seek medical records. We use different methods to collect data from and about you including through:
•Direct interactions. You may give us your Identity, Contact, Health Data and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
•apply for our services;
•create an account on our site;
•request marketing to be sent to you;
•give us feedback or contact us;
•referrals from your existing insurance provider or GP;
•request quotes;
•notes and reports about your health and any treatment and care you’ve received or need;
•claims and pre-authorisations;
•records of medical services and treatment you’ve received.
•Automated technologies or interactions. As you interact with our site, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our Cookie Policy for further details.
•Third parties or publicly available sources. We will receive personal data about you from various third parties as set out below:
a)Parent or Guardian if you are a child and authorised third parties. You have given us consent to collect information from and share information with a third party on your behalf, such as a family member, solicitor, or a person acting through a Power of Attorney.
Our reasons:
•Deliver our services to you
•Manage our relationship with you
•Set you up as a customer
•Meet our regulatory obligations or comply with legal requests or legal claims
•Manage complaints, claims or individual rights requests b)Health Care Providers. We collect information from and share information with doctors, clinicians and other healthcare professionals; hospitals and clinics; medical laboratories; individuals or organisations who pay for your care; patient record databases such as the NHS’s GP Connect or the Northern Ireland Electronic Care Record.
Our reasons:
•To enable healthcare providers to provide treatment and healthcare services, and to enable you to receive it
•To provide our healthcare professionals with access to the information they need to make informed clinical decisions (e.g. when prescribing medications)
•To process and validate invoices and make or receive payments
•To investigate complaints, claims and possible fraudulent activity c)Medical regulators, bodies and associations to which our consultants belong. We collect information from and share information with professional associations our consultants belong to or are regulated by, including but not limited to:
•Care Quality Commission
•General Medical Council
•The Health and Care Professions Council
•Responsible Officer
Our reasons:
•For safeguarding purposes
•Investigate complaints and clinical incidents
•Monitor quality and performance d)Credit reference and fraud prevention agencies. We collect information from and share information with health insurance counter-fraud groups and financial crime screening services.
Our reasons:
•Detect and prevent fraud
•Meet our regulatory and legal obligations e)Professional consultants. We share information with solicitors, auditors, actuaries and tax advisors, translators and interpreters.
Our reasons:
•Support us to manage our business and meet our regulatory obligations
•Gain advice on business decisions and strategy f)Public sector bodies, government and regulatory organisations. We share information with government and their agencies, law enforcement agencies, like the police, authorities and regulators such as the Financial Conduct Authority (FCA) or Prudential Regulation Authority (PRA), data protection supervisory authorities, HM Courts and Tribunals Service.
Our reasons:
•Comply with our legal and regulatory obligations
•Protect our rights and defend ourselves against claims g)Suppliers who process your personal information on our behalf. We share information with a number of suppliers and service providers we use in connection with the operation of our business who may have access to the personal information that we process, e.g. IT suppliers when providing us with software support or cloud services, or a company which we use for a marketing campaign when processing your contact information on our behalf or a company we use for customer service support: In all cases, your personal information is handled and protected in accordance with applicable data protection law. Where we use cloud services, our data will generally be hosted within the UK or EU, save where certain categories of information must be stored in other jurisdictions due to requirements imposed by our clients, technical necessity or applicable law. Where any personal data is processed by suppliers outside the EEA in countries that applicable data protection laws have not assessed as providing an adequate level of data protection for the personal information we are processing, we ensure that such data is adequately protected by ensuring information security and other appropriate safeguards are in place, and using approved model contract clauses to cover the transfer or by ensuring that the supplier has Binding Corporate Rules in place.
Our reasons
•Help us run our business
•Manage our relationship and communicate with you
•Provide our services to you
•Identify and communicate with people that might be interested in our services
•Grow our business and keep our customers
From time to time, we may use the services of third parties and may also receive personal information collected by those third parties in the course of the performance of their services for us. In that case, we will take reasonable steps to ensure that such third parties have represented to us that they have the right to disclose your personal information to us.
To support accurate and efficient clinical documentation, RDA Autism & ADHD Practice may use AI such as Heidi Health during some online consultations. AI assists Consultants in generating appointment summaries and clinical notes. Before each appointment, your practitioner will confirm whether you consent to the use of AI for that session. If you do not consent, your care will not be affected in any way.
Under data protection laws, we can only process your information if we have a legal reason (known as a ‘lawful ground’) for doing so. The lawful basis for processing your personal data will depend on the purpose for which it was obtained. The table below sets out the purposes for which we may process your personal information and the relevant lawful basis/bases that allow for that processing. In certain circumstances, we rely on the legal ground known as 'legitimate interests' to process your personal information. This is where the processing of your personal information is necessary to pursue our legitimate interests in a way which is reasonably expected as part of running our business, but which is not detrimental to you and would have minimal impact on your privacy. We undertake an assessment of any potential impact on your privacy before we process your personal information for our legitimate interests.
Insofar as we wish to use your personal information for purposes other than those we originally collected it for, we will check whether these additional purposes are compatible with the original or primary purposes, according to applicable law. Depending on the circumstances, we will inform you about the change of purpose and obtain your consent for the further processing of your personal information.
We will only ask you for consent to process your personal information if there’s no other legal reason to process it, or we think it’s appropriate to do so. Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.
We will tell you when we need your consent and ask you for it. If we can’t provide a service without your consent, we’ll make this clear when we ask for it. If you later withdraw your consent, we will be unable to provide you with any service that relies on us having your consent to process your personal information. This will not affect our provision of services to you prior to you withdrawing your consent.
Most commonly, we will use your personal data in the following circumstances:
•Where we need to perform the contract we are about to enter into or have entered into with you.
•Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
•Where we need to comply with a legal obligation.
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
| Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
|---|---|---|
| To register you as a new client | (a) Identity Data (b) Contact Data (c) Client Matter Data (d) Financial Data | – Performance of a contract with you – Necessary to comply with a legal obligation |
| Managing our relationship with you and providing our services including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us | (a) Identity Data (b) Contact Data (c) Financial Data (d) Marketing and Communications (e) Health Data (f) Client Matter Data | – Performance of a contract with you – Necessary for our legitimate interests (e.g. to recover debts due to us) – Necessary to comply with a legal obligation For special category information: – it’s necessary for health or social care purposes such as: medical diagnosis providing healthcare or treatment managing healthcare or social care systems or services – With your consent (if required) – When it's in your vital interests |
| To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Asking you to leave a review or take a survey | (a) Identity Data (b) Contact Data (c) Profile Data (d) Marketing and Communications Data (e) Usage Data | – Performance of a contract with you – Necessary to comply with a legal obligation – Necessary for our legitimate interests (to keep our records updated and to study how customers use our service |
| Administration purposes and the protection of our business and the website (including accounting, billing, troubleshooting, data analysis, testing, system maintenance, support, reporting, hosting of data and to defend our business interests including exercising our legal rights) | (a) Identity Data (b) Contact Data (c) Technical Data (d) Financial Data | – Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) – Necessary to comply with a legal obligation |
| To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you | (a) Identity Data (b) Contact Data (c) Profile Data (d) Usage Data (e) Marketing and Communications Data (f) Technical Data | – Necessary for our legitimate interests (to study how customers use our services, to develop them, to grow our business and to inform our marketing strategy) |
| To use data analytics to improve our website, services, marketing, customer relationships and experiences | (a) Technical Data (b) Usage Data | – Necessary for our legitimate interests (to define types of customers for our services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
| To make suggestions and recommendations to you about services that may be of interest to you | (a) Identity Data (b) Contact Data (c) Technical Data (d) Usage Data (e) Profile Data (f) Marketing and Communications Data | – Necessary for our legitimate interests (to develop our services and grow our business) |
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which services and offers may be relevant for you (we call this marketing). You will receive marketing communications from us if you have requested information from us or purchased services from us and you have not opted out of receiving that marketing. We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.
You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a service purchase, service experience or other transactions.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Sometimes we need to share your information with other people or organisations. We share as little of your information as possible, and only for specific purposes. We do not share or transfer the information we have collected except as set out in this policy. Where we share your personal information with third parties we will ensure they respect your privacy and keep your information secure.
We have processes in place to make sure that your information is protected when we share it with third parties. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. If you are sharing someone else’s personal information with us, please make sure they have seen this privacy notice and are comfortable with you giving us their information.
You can view the types of third parties with which we collect and share information, and our reasons for doing so below. We may also disclose your personal information to other third parties if we are required or permitted to do so by law.
We may share your personal data with the parties set out below for the purposes set out in the table Purposes for which we will use your personal data above.
•Suppliers who process your personal information on our behalf - We put measures in place to ensure that our suppliers process your personal information fairly and in line with our expectations. We share your personal information with our supplier to help us run our business, manage our relationship and communicate with you, provide our services to you, identify and communicate with people that might be interested in our services and grow our business. We use the types of suppliers listed below:
IT service providers: Cloud storage, databases and data repositories, practice management systems, customer relationship management systems (CRM), communication and phone software, back-up solutions, network security and monitoring solutions and other ‘software as a service’ providers.
Marketing, sales and business development: market and customer research consultants, social media platforms and marketing and digital marketing agencies, data set and contact list providers.
Customer service support: outsourced support with customer communication and servicing, including translation.
•Healthcare providers and those providing treatment – we share your personal information with those providing your treatment such as consultants, clinicians, doctors, practitioners and other healthcare professionals, hospitals, clinics and other healthcare providers. We share your personal information to provide you with your treatment, to provide our healthcare professionals with access to the information they need to make informed clinical decisions (e.g. when prescribing medications), to manage our relationship with consultants, to process and validate invoices and make or receive payments and to investigate complaints, claims and possible fraudulent activity.
•Medical regulators, bodies and associations to which our consultants belong - we share your personal information with professional associations our consultants belong to or are regulated by, including but not limited to Care Quality Commission, General Medical Council and the Health and Care Professions Council. We share your personal information for safeguarding purposes, investigate complaints and clinical incidents and monitor quality and performance.
•Public sector bodies, government and regulatory organisations - we share your personal information with HM Revenue & Customs, local authorities, social services, and other public sector bodies. We share your personal information in order to comply with our legal and regulatory obligations and to protect our rights and defend ourselves against claims.
•Professional advisers - we share your personal information with our professional advisers including accountants, solicitors, bankers, auditors, insurers who provide us with professional services based in the UK. We share your personal information in order to support us to manage our business and meet our regulatory obligations and to gain advice on business decisions and strategy.
•Third party that buys or takes over any of our businesses – We may share your personal information with third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. We share your personal information to enable the third party to take over our business activities and to support the third party’s decision making and processes to buy our business. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy policy.
We work with organisations that operate in, or from, various countries worldwide. In providing services to you, we may need to transfer your personal information to the United States and other countries outside of the EU that do not afford the same level of data protection as the UK. Your personal data may also be processed by our suppliers outside of the EU. Where your data is processed outside of the EU, we will ensure your personal information is protected by putting in place appropriate safeguards such as EU Commission Standard Contractual Clauses.
To ensure the safety and security of your personal data, we apply standards of security which are appropriate and expected of us as healthcare providers. We store copies of your registration documents, collateral forms and any letters, both initial assessment letters & any follow-up letters between you and your clinician. This information is necessary to facilitate the provision of our services to you and to ensure proper administration. This information is also needed by our clinicians in the provision of our services to you. These copies are kept on a secure system and are encrypted upon upload. This information will be held securely and confidentially and will never be shared with any third party without your advance permission.
We keep your personal information in line with set periods calculated using the following criteria:
•How long you have been a client with us, the types of services you have with us.
•How long it is reasonable to keep records to show we have met the obligations we have to you and by law.
•Any periods for keeping information which are set by law or recommended by regulators, professional bodies or associations.
•Any relevant proceedings that apply.
If you would like more information about how long we will keep your information for, please contact us at [email protected]
In compliance with UK GDPR, and the Data Protection Act 2018 you have the right to: be notified about the personal data we hold about you, or request access any information we hold about you. You may ask us to correct any incorrect data. You also have the right to object to us using your information, to ask us to transfer of information you have provided, to withdraw permission you have given us to use your information. You have the following rights (certain exceptions apply).
Right to be notified: this right allows for you to be notified about what personal data we hold about you. We explain what data we hold in this Privacy Notice.
Right of access: the right to make a written request for details of your personal information and a copy of that personal information
Right to rectification: the right to have inaccurate information about you corrected or removed
Right to be forgotten: the right to have certain personal information about you deleted.
Right to object: to the use of your personal data for the purposes of direct marketing.
Right to data portability: the right to ask for the personal information you have made available to us to be transferred to you or a third party in machine-readable formats
Right to withdraw consent: the right to withdraw any consent you have previously given us to handle your personal information. If you withdraw your consent, this will not affect the lawfulness of RDA Autism & ADHD Practice use of your personal information prior to the withdrawal of your consent.
Please note: Other than your right to object to the use of your data for direct marketing, your rights are not absolute, and they will not always apply in all cases (for example Legitimate interests) and we will let you know in our correspondence with you how we will be able to comply with your request.
If you make a request, we may ask you to confirm your identity if we need to, and to provide information that will help us to understand your request better. If we do not meet your request, we will explain why.
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Contact us: By accessing our website or using our services, you agree to the practices described in this Privacy Policy. If you have any questions, please contact RDA Autism & ADHD Practice at [email protected] or call us on 020 3906 1488 or write to us at 6-7 East Street, Ware, SG12 9HJ.