1. Our Commitment To Personal Data.
The protection of personal data should be your right.
It is our responsibility to do everything we can to protect your data.
Data should ONLY be collected when it is required to provide a certain product or service.
We will NEVER sell, share or disclose your personal data without your permission unless it is requested by warrant by law enforcement agencies.
2. Legislation We Abide By.
Scartho Dental Care follows the guidelines and legislation of the following bodies
We follow the guidelines of the Information Commissioners Office the UK's official data protection body.
All the regulators above impose strict practices when it comes to the processing and storing of your personal data. If you are not from the UK the chances are we will meet the data regulations in your country too. If you wish to check on any aspect of your data protection rights you think may not be covered you can contact our data protection officer whose contact details can be found in section 9.
3. Data Retention.
Scartho Dental Care does not store ANY personally identifiable information of any kind on its website. In this section, we tell you what information we do collect, why we collect it, how long we store it for and where we store it.
3.1 Browser Tracking Information
What: What site you came from to get to our site, what link you clicked, what browser you use, what operating system you use, your geographical location, your IP address.
Why: Like a lot of websites we may use Google Analytics and other tracking software to track user interaction with our website. This helps us find out things like how many people visit our site, how they navigate around our site, the pages that are most visited. This data is stored on our website to provide us with traffic analysis. It helps us improve our site and our services. This information does not directly identify you as a person it is just behavioural data. Google may also record your IP address which could be used to identify you, however, they do not give Scartho Dental Care access to that information.
How Long: This data is normally purged every 2 years or so. It is not personally identifying data so there is no way we can remove data about your visits as we do not know what part of the data is attributed to you.
Where: Basic tracking information we store on our web hosting account with 3001web. See third-party providers. All our web hosts servers encrypt data during transfer and employ the latest in server security. This data, however, does not personally identify you and is not classed as sensitive personal data.
Any Google based tracking is stored by Google on their servers. While this data may be used to track you Google does not give us access to that kind of information. See third-party providers.
What: Our site is backed up daily by our hosts 3001 web and those backups are stored on the Google Drive account of our host. See third-party providers.
Why: For recovery purposes if a site gets damaged, hacked or in the case of hardware failure resulting in data loss.
How Long: These backups are kept for three days then automatically deleted.
Where: They are stored securely in our hosts Google Drive account.
4. Where We Store Your Data
4.1 Non-identifiable information about your visit
These are saved on our hosting account at 3001web.com. See third-party providers.
4.2 Our Website Backups
These are stored securely on our web hosts Google drive account.
4.3 Sensitive Data About Our Clients
This is stored in our surgery on the practice computers using an industry respected cloud-based software provided by dentally (See third party providers)
5. Third Party Providers And Data Processors
Some of the services we use may process, store or have access to your browsing data to help us run our service to you. We have no control over their processing or data storage however they are all reputable and data protection focussed companies that have been vetted by us. The companies we use are as follows;
6. How We Protect Your Data
6.1 Non-Identifying data collected on our site.
Data is encrypted when sent between your devices and our website using 256bit encryption provided by SSL certificates issued for our own site.
Our web hosts servers have regular security checks and hardening performed on them by their server administration team.
Our web hosts servers contain (among others) the following security protocols;
cPHulk brute force protection to protect against brute force attacks
PHP open_basedir Protection
CageFS is enabled This provides filesystem-level protections for our site.
Apache Symlink Protection: CloudLinux protections are in effect ensuring each hosting account is caged and totally separate from other accounts on our cloud.
CSF firewall is installed, and LFD is running.
System kernels are updated instantly as released.
The MySQL port is blocked by the firewall, effectively allowing only local connections.
Password strength requirements are strong at both server level and admin areas for our site.
Outbound SMTP connections are restricted.
Php versions upgraded regularly as soon as they are stable.
Our site is monitored by 3001web for out of date or no longer supported plugins, themes and core code. Any outdated plugins or theme are updated immediately.
6.2 Sensitive Personal Data Within Our Surgery.
This is stored securely in our surgery on the practice computers using an industry respected cloud-based software provided by dentally (See third party providers)
7. Data Breaches
We will report any unlawful data breach where we believe there is a threat to the personal data of our clients. This will be reported to the ICO in the UK. The report will be submitted within 72 hours if we can establish that personal data was accessed or stolen. In the event that personal data was accessed and in accordance with the GDPR rules we may also inform the data subject (you).
8. Name And Address Of The Controller
The controller for the purposes of the General Data Protection Regulation (GDPR) And The UK Data Protection Act (DPA) is:
Mrs Katie Milner
Scartho Dental Care
1 Waltham Road
9. Name and Address of the Data Protection Officer
The Data Protection Officer of the controller is:
Mrs Katie Milner
Scartho Dental Care
1 Waltham Road
Phone: 01472 870105
Any data subject may, at any time, contact our Data Protection Officer directly with all questions and suggestions concerning data protection.
You, of course, may, at any time, prevent the setting of cookies through our website by means of corresponding settings of your Internet browser, and deny the setting of cookies. Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programmes. This is possible in all popular Internet browsers. If you deactivate the setting of cookies in your browser, not all functions of our website may be entirely usable.
11. Your Rights As A Data Subject
GDPR and DPA give you the following rights to do with the data we store on you.
The right to be informed.
Put simply you can ask our data controller why we store your information and what we use it for. However, that is openly discussed above.
The right of access
You have a right of access to that data to look at it.
The right to rectification
If any of the information we hold about you is incorrect you have the right to have it amended. In most cases this is possible by logging into our client area you can correct it yourself. Anything you cannot edit yourself you can ask our data controller to edit for you. Obviously, we will need to verify your identity before we edit any of your information.
The right to erasure (Right to be forgotten)
You have the right to have all data we have on you erased. This, in the case of Scartho dental care, would mean you contacting our reception team if you are one of our clients. We do not store personal data of any kind on our website or within our web hosting account.
The right to restrict processing
If you want to restrict us from processing information that is incorrect until it is corrected, but would like us to still let you have access to the data for your accounting, in this case, it would be stored but not processed. When processing is unlawful and you oppose erasure and request restriction instead. If we no longer need your personal data but you require the data to establish, exercise or defend a legal claim.
The right to data portability
The right to data portability allows you to obtain and reuse your personal data for your own purposes across different services.
It allows you to move, copy or transfer personal data easily from Scartho dental care to another company in a safe and secure way, without hindrance to usability.
The right to object
You have the right to object to the processing of your data for the following purposes;
Processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
Direct marketing (including profiling); and
Processing for purposes of scientific/historical research and statistics.
Rights in relation to automated decision making and profiling.
Scartho dental care does NOT employ automated profiling in any way.
12. Lawful Basis For The Processing Of Your Data
We do not process personal data on our website. If you are one of our clients and would like to find out how we process your personal data in the surgery please contact one of our reception team.
13. Changes to this policy