Patient Privacy Notice
Lanserhof at The Arts Club medical services is committed to protecting your privacy and meeting the requirements of data protection legislation. This privacy notice explains:
- what personal data we collect about you;
- why we collect that personal data;
- who we share your personal data with;
- why we might contact you and how you can change that;
- how long we retain your personal data;
- how we keep your personal data secure; and
- what rights you have in relation to your personal data.
When we talk about “personal data” in this notice, we mean any information which could be used to identify you, either directly or indirectly when combined with any other information we may hold about you.
In this privacy notice, when we refer to “we”, “us” or “our”, we mean Mayfair Medicum Ltd, operating under the trading name of ‘Lanserhof at the Arts Club –Medical Services’, registered office at Acre House, 11/15 William Road, London, United Kingdom, NW1 3ER. We are the data controller under the Information Commissioner’s Office registration number ZA491290.
If you need to contact us about this privacy notice or further details on how we use your personal information please contact the Group Data Protection Officer Edwina Heath by post at 17-18 Dover Street, Mayfair, London W1S 4LT or by emailing firstname.lastname@example.org.
Personal data collected by Lanserhof at The Arts Club Medical Services
The doctors, nurses and team of healthcare professionals caring for you keep records about your health and any treatment and care you receive from us. These records help to ensure that you receive the best possible care.
They may be written down in paper records or held on computer. These records may include:
- Basic details about you such as name, address, date of birth, next of kin, etc.
- Contact we have had with you such as appointments or clinic visits
- Notes and reports about your health, treatment and care
- Results of x-rays, scans and laboratory tests
- Relevant information from people who care for you and know you well such as health professionals and relatives
It is essential that your details which we hold are accurate and up to date. Always check that your personal details are correct when you visit us and please inform us of any changes as soon as possible.
Purposes for collecting and using that personal data
Your personal data is used for a variety of different purposes, but only in circumstances where we have a legal basis to do so. Those purposes and the bases we rely upon are set out below.
(1) Delivery of care and treatment
Your data is most commonly used to direct, manage and deliver the care you receive to ensure that:
- The doctors, nurses and other healthcare professionals involved in your care have accurate and up to date information to assess your health and decide on the most appropriate care for you
- Healthcare professionals have the information they need to be able to assess and improve the quality and type of care you receive
- Your concerns can be properly investigated if a complaint or any concerns are raised
- Appropriate information is available if you see another doctor, or are referred to a specialist or another part of the healthcare system to ensure you receive continuity of care
We generally do so on the basis that it is necessary for us to use your data in this way in order to fulfil our contract with you to provide you with healthcare services. In exceptional circumstances, we may be required to use your information in order to protect your vital interests or those of another person for example. Such incidents are very rare, such as a situation where you are incapacitated and using your health data is necessary to provide emergency treatment.
(2) Improving the quality of our services / other uses of your data
Your information will also be used to help us manage and protect the health of the public by being used to:
- Review the care we provide to ensure it is of the highest standard and quality
- Ensure our services can meet patient needs in the future
- Investigate patient queries, complaints and legal claims
- Ensure clinic receives payment for the care you receive
- Prepare statistics on our performance
- Audit our accounts and services
- Undertaking health research and development (with your explicit consent - you may choose whether or not to be involved)
- Helping to train and educate healthcare professionals where we do not have a contractual or legal obligation to handle your data in a particular way or your explicit consent to use your information for a specific purpose, we have a legitimate interest to conduct general business processes and improve the quality and safety of the health care and treatment we provide. When relying on our legitimate interests we conduct an assessment to ensure that this use of your data is fair, proportionate and in no way detrimental. We will also only use your data where it is necessary for us to do so in connection with the provision of health care or treatment, or the mamagement of such services.
We may also need to use your information for the purposes of establishing, exercising or defending our legal rights, for example in the event of a complaint.
In some circumstances we may want to use your personal data for the purposes of undertaking health research development. However, we will only do so where you have provided your explicit consent, which can be subsequently withdrawn at any time.
We may also contact you about goods and services which we think may be of interest to you but only where you have specifically consented to us using your information in this way. If you do consent to receive marketing materials then this can be withdrawn at any time.
Who we share your personal data with
Everyone working within healthcare is subject to a legal duty to keep information about you confidential. Similarly, anyone who receives information from is under the same a legal duty.
We may need to share information with the following organisations so we can all work together for your benefit, if they have a genuine need for it, or we have your consent.
Therefore, we may also share your information, subject to the restrictions set out in this privacy notice about how it will be used, with:
- Private insurers that are involved in your care
- Your General Practitioner (GP)
- Ambulance Services
- PHIN (Private Healthcare Information Network) who are the government’s recognised body for processing private patient’s data
- Social Care Services
- Local Authorities
- Voluntary and private sector providers working with us
We will not disclose your information to any other third parties without your consent unless there are exceptional circumstances, such as if your health and safety or that of others is at risk or if the law requires us to pass on information.
You have the right to restrict how and with whom we share the personal information in your records that identifies you if that information is inaccurate, held by us unlawfully, or is no longer needed by us . This must be noted explicitly within your records in order that all healthcare professionals and staff treating and involved with you are aware of your decision. By choosing this option, you should be mindful that it may make the provision of treatment or care more difficult or unavailable and that it may be necessary to override that restriction if deemed necessary to do so for your safety and or that of others. You can also change your mind at any time about a disclosure decision.
Receiving communications from Lanserhof at The Arts Club
When attending our facilities for an outpatient appointment or a procedure you may be asked to confirm that we have an accurate email address, contact number and/or mobile telephone number for you. This can be used to provide appointment details via email, SMS text messages and automated calls to advise you of appointment times, with your consent.
We may also contact you about goods and services which we think may be of interest to you but, as set out above, only where you have consented to us using your information in this way.
Updating your preferences
You can update your communications preferences at any time by informing a member of staff or by contacting the Data Protection Officer.
Retention of personal data
We retain personal data for no longer than required and in line with Lanserhof at the Arts Club’s retention schedule. This is based on statutory requirements and legal obligations, as well as our business requirements.
Security of personal data
We take our duty to protect your personal information and confidentiality very seriously and we are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper. Where we have a need to transfer data outside of the European Economic Area (EEA) we do so with appropriate safeguards in place.
Personal data and your rights
Data protection legislation gives you the right to:
- Correct any data we hold about you that is not correct (Rectification)
- Request, in certain circumstances, that we delete your personal data (Erasure). We are not obliged to give effect to all such requests, for example if we are under a legal obligation to retain your data or we need to keep it in order to establish, defend or exercise legal claims.
- Block or suppress the further processing of your personal data in certain circumstances (Restriction)
- Request access to personal data that we hold about you (Subject Access)
- In some circumstances, receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have this transmitted to another data controller (Data Portability)
- Withdraw consent where this is the legal basis for us processing your information
- Object to processing where Lanserhof at the Arts Club is relying on its legitimate interests as the legal ground for processing
- Not be subject to automatic decisions (i.e. decisions that are made about you by computer alone) that have a legal or other significant effect on you.
Please contact the Data Protection Officer using the details above if you wish to exercise your rights in relation to personal data. Our policy is to verify the authenticity of all requests made, and requests may be refused if we are unable to verify the identity of the requester.
If you have concerns about the way we have handled your personal data please contact the Data Protection Officer in the first instance: email@example.com. If you remain unsatisfied you can contact the Information Commissioner’s Office (ICO) on 0303 123 1113, by emailing firstname.lastname@example.org.