SENSORY FOOTSTEPS LIMITED – PRIVACY POLICY
Sensory Footsteps Limited, a company registered in England and Wales, with company number 13966133 (we, us or our), understands that protecting your personal data is important. This Privacy Policy sets out our commitment to protecting the privacy of personal data provided to us, or otherwise collected by us when providing our website and occupational therapy services (Services) or when otherwise interacting with you.
It is important that you read this Privacy Policy together with any other detailed privacy notices we may provide when we are collecting or processing personal data about you so that you understand our privacy practices in relation to your data.
The information we collect
Personal data: is information that relates to an identified or identifiable individual.
Where you are a parent or guardian of a client of ours:
We may collect, use, store and disclose different kinds of personal data about you which we have listed below:
· Identity Data including first name, last name and relationship to our client.
· Contact Data including billing address, delivery address, email address and telephone numbers.
· Financial Data including bank account and payment card details (through our third party payment processor, Square).
· Transaction Data including details about payments to you from us and from you to us and other details of products and services you have purchased from us or we have purchased from you.
· Marketing and Communications Data including your preferences in receiving marketing from us and our third parties and your communication preferences.
We may also collect, use, store and disclose different kinds of personal data about your child which we have listed below:
· Identity Data including first name, last name, gender, date of birth, family make up (including number of family members), and languages spoken.
· Contact Data including residential address, school name and school address.
· Special Categories of Personal Data is a special category of personal data that includes details about an individual’s race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about their health and genetic biometric data. In providing our Services, we may collect and process special categories of personal data about your child’s health, including information about their symptoms, medical history and diagnosis, any medications or allergies, developmental history, feeding habits, behavioural and social skills, sleeping habits, and hobbies and interests.
Where you are a client of ours over the age of 18:
· Identity Data including first name, last name, gender, date of birth, family make up (including number of family members), and languages spoken.
· Contact Data including billing address, delivery address, email address and telephone numbers.
· Financial Data including bank account and payment card details (through our third party payment processor, Square).
· Transaction Data including details about payments to you from us and from you to us and other details of products and services you have purchased from us or we have purchased from you.
· Marketing and Communications Data including your preferences in receiving marketing from us and our third parties and your communication preferences.
· Special Categories of Personal Data is a special category of personal data that includes details about an individual’s race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about their health and genetic biometric data. In providing our Services, we may collect and process special categories of personal data about your health, including information about their symptoms, medical history and diagnosis, any medications or allergies, developmental history, feeding habits, behavioural and social skills, sleeping habits, and hobbies and interests.
Where you are a user of our website:
· Technical and Usage Data including internet protocol (IP) address, your browser session and geo-location data, device and network information, statistics on page views and sessions, acquisition sources, search queries and/or browsing behaviour, information about your access and use of our website, including through the use of Internet cookies, your communications with our website, the type of browser you are using, the type of operating system you are using and the domain name of your Internet service provider.
· Marketing and Communications Data including your preferences in receiving marketing from us and our third parties and your communication preferences.
· Professional data including where you are a worker of ours or applying for a role with us, your professional history such as your previous positions and professional experiences.
How we collect personal data
We collect personal data in a variety of ways, including:
· Directly: We collect personal data which you directly provide to us, including when you sign up to our services, through the ‘contact us’ form on our website or when you request our assistance via email, or over the telephone.
· Indirectly: We may collect personal data which you indirectly provide to us while interacting with us, such as when you use our website, in emails, over the telephone and in your online enquiries.
· From third parties: We collect personal data from third parties, such as from your referring third party, your parents or guardians, your healthcare practitioners, your school or other local authority (as applicable) and details of your use of our website from our analytics and cookie providers and marketing providers. See the “Cookies” section below for more detail on the use of cookies.
Purposes and legal bases for processing
We collect and process personal data about you only where we have legal bases for doing so under applicable laws. We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please reach out to us if you need further details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.
Photo and Video Consent
In addition to the personal data outlined above, Sensory Footsteps Limited may collect, use, store, and disclose photographs and videos of our clients for the following purposes:
Clinical Documentation and Assessment: To document progress, assess therapy effectiveness, and tailor future interventions.
Training and Educational Purposes: To educate and train our staff and other professionals in sensory integration therapy and related practices.
Marketing and Promotional Activities: To promote our services and share insights into our therapy practices with a broader audience.
Photo Consent Process
Obtaining Consent: At the start of therapy, parents or guardians will be asked to provide explicit consent for the collection and use of photographs and videos of their child for the purposes stated above.
Voluntary Nature of Consent: Providing this consent is entirely voluntary. Refusal to provide consent will not impact the quality of services provided to the client.
Withdrawal of Consent: Consent may be withdrawn at any time by contacting Sensory Footsteps Limited. Upon withdrawal, we will cease to use the client's photographs and videos for the purposes stated above and will, where feasible, remove them from our materials.
Use and Disclosure
Confidentiality and Security: All photographs and videos will be treated with the utmost confidentiality and stored securely. Access to this media will be limited to authorised personnel only.
Sharing with Third Parties: We will not share photographs or videos with third parties without obtaining additional, specific consent, except as required by law or in accordance with our professional obligations.
This section of the Privacy Policy is subject to the same rights and controls as other personal data outlined in this document, including the right to access, correction, and deletion.
Artificial Intelligence Data Processing
At times we may use AI as a company to enhance our workflows and provide a more thorough service to our clients. Our uses for AI are as follows:
- Enquiry phone calls - Heidi scribe may be used to note take details during point of enquiry by transcribing audio. To book an enquiry you will have been given the option to opt in or out. If the option wasn't available at point of booking this means it is not in place.
- During direct input - We like to capture lots of detail within our assessment reports, we pride ourselves on thoroughness and accuracy whilst also being competitive in terms of costs to clients. Heidi scribe may be used to transcribe audio during assessments or telephone calls to capture details and assist in documentation. Transcriptions are always fact-checked against the audio.
We are dedicated to maintaining the highest standards of data privacy and security. We employ advanced Artificial Intelligence (AI) technologies to assist with documentation and note-taking, enhancing the efficiency and accuracy of our services. The AI tools we use include:
Benefits of Using AI
Potential Risks and Mitigations:
You can read more about Heidi scribe GDPR policy here: GDPR Compliance - Heidi (heidihealth.com)
Client Rights and Opt-Out Options: Clients may opt out of AI-assisted processing and pseudonymisation at any time
For any questions or concerns regarding our use of CCTV, or to exercise your data protection rights, please contact:
We are dedicated to using CCTV responsibly and transparently, ensuring the privacy and dignity of all individuals. This policy will be reviewed and updated periodically to reflect best practices and legal requirements
Purpose of use / disclosure
Type of Data
Legal Basis for processing
To provide our Services to you or your child, including to manage your appointments, and assess your progress.
· Identity Data
· Contact Data
· Transaction Data
· Special Categories of Personal Data
· Performance of a contract with you
· Consent
To contact and communicate with you about our Services including in response to any support requests you lodge with us or other enquiries you make with us.
· Identity Data
· Contact Data
· Performance of a contract with you
To contact and communicate with you about any enquiries you make with us via our website.
· Identity Data
· Contact Data
· Legitimate interests: to ensure we provide the best client experience we can offer by answering all of your questions.
For internal record keeping, administrative, invoicing and billing purposes.
· Identity Data
· Contact Data
· Financial Data
· Transaction Data
· Performance of a contract with you
· To comply with a legal obligation
· Legitimate interests: to recover debts due to us and ensure we can notify you about changes to our terms of business and any other administrative points.
For analytics, market research and business development, including to operate and improve our Services, associated applications and associated social media platforms.
· Technical and usage Data
· Legitimate interests: to keep our website updated and relevant, to develop our business, improve our Services and to inform our marketing strategy
For advertising and marketing, including to send you promotional information about our events and experiences and information that we consider may be of interest to you.
· Identity Data
· Contact Data
· Technical and usage Data
· Marketing and communications Data
· Legitimate interests: to develop our Services and grow our business
If you have applied to work with us; to consider your application.
· Identity Data
· Contact Data
· Professional Data
· Legitimate interests: to consider your employment application
To comply with our legal obligations or if otherwise required or authorised by law.
· All relevant Personal Data
· To comply with a legal obligation
If you have consented to our use of data about you for a specific purpose, you have the right to change your mind at any time, but this will not affect any processing that has already taken place. Where we are using your data because we or a third party have a legitimate interest to do so, you have the right to object to that use though, in some cases, this may mean no longer using our services. Further information about your rights is available below.
Our disclosures of personal data to third parties
We may disclose personal data to:
· third parties who refer you to us, including your healthcare practitioners, school or local authority;
· our employees, contractors and/or related entities;
· IT service providers, data storage, web-hosting and server providers such as WriteUpp, Powerdiary and GoDaddy;
· marketing or advertising providers such as GoDaddy;
· professional advisors, bankers, auditors, our insurers and insurance brokers;
· Changing practice management software. There may be times where we need to migrate data between different electronic health record systems to enhance service efficiency and quality. When such migrations are necessary, we may engage external GDPR-compliant data migration teams to ensure the process is conducted securely and in accordance with data protection laws.
Our commitments during data migration include:
· payment systems operators such as Square or stripe;
· our existing or potential agents or business partners;
· anyone to whom our business or assets (or any part of them) are, or may (in good faith) be, transferred;
· courts, tribunals and regulatory authorities, in the event you fail to pay for goods or services we have provided to you;
· courts, tribunals, regulatory authorities and law enforcement officers, as required or authorised by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights;
· third parties to collect and process data, such as Google Analytics (To find out how Google uses data when you use third party websites or applications, please see www.google.com/policies/privacy/partners/ or any other URL Google may use from time to time), Facebook Pixel or other relevant analytics businesses; and
· any other third parties as required or permitted by law, such as where we receive a summons.
Google Analytics: We have enabled Google Analytics Advertising Features including Remarketing Features, Advertising Reporting Features, Demographics and Interest Reports, Store Visits, and Google Display Network Impression reporting. We and third-party vendors use first-party cookies (such as the Google Analytics cookie) or other first-party identifiers, and third-party cookies (such as Google advertising cookies) or other third-party identifiers together.
You can opt-out of Google Analytics Advertising Features including using a Google Analytics Opt-out Browser add-on found here. To opt-out of personalised ad delivery on the Google content network, please visit Google’s Ads Preferences Manager here or if you wish to opt-out permanently even when all cookies are deleted from your browser you can install their plugin here. To opt out of interest-based ads on mobile devices, please follow these instructions for your mobile device: On android open the Google Settings app on your device and select “ads” to control the settings. On iOS devices with iOS 6 and above use Apple’s advertising identifier. To learn more about limiting ad tracking using this identifier, visit the settings menu on your device.
Overseas transfers
Where we disclose personal data to the third parties listed above, these third parties may store, transfer or access personal data outside of the United Kingdom. The level of data protection in countries outside of the United Kingdom may be less comprehensive than what is offered in the United Kingdom. Where we transfer your personal data outside of the United Kingdom, we will perform those transfers using appropriate safeguards in accordance with the requirements of applicable data protection laws and we will protect the transferred personal data in accordance with this Privacy Policy. This includes:
· only transferring your personal data to countries that have been deemed by applicable data protection laws to provide an adequate level of protection for personal data; or
· including standard contractual clauses in our agreements with third parties that are overseas.
Data retention
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Your rights and controlling your personal data
Your choice: Please read this Privacy Policy carefully. If you provide personal data to us, you understand we will collect, hold, use and disclose your personal data in accordance with this Privacy Policy. You do not have to provide personal data to us, however, if you do not, it may affect our ability to provide our Services to you and your use of our Services.
Information from third parties: If we receive personal data about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal data about somebody else, you represent and warrant that you have such person’s consent to provide the personal data to us.
Access, correction, processing and portability:You may request details of the personal data that we hold about you and how we process it (commonly known as a “data subject request”). You may also have a right in accordance with applicable data protection law to have your personal data rectified or deleted, to restrict our processing of that information, to object to decisions being made based on automated processing where the decision will produce a legal effect or a similarly significant effect on you, to stop unauthorised transfers of your personal data to a third party and, in some circumstances, to have personal data relating to you transferred to you or another organisation.
Unsubscribe: To unsubscribe from our e-mail database or opt-out of communications (including marketing communications), please contact us using the details below or opt-out using the opt-out facilities provided in the communication.
Withdraw consent: Where we are relying on consent to process your personal data, you have the right to withdraw your consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Complaints: If you wish to make a complaint, please contact us using the details below and provide us with full details of the complaint. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
Storage and security
We are committed to ensuring that the personal data we collect is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures, to safeguard and secure personal data and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.
While we are committed to security, we cannot guarantee the security of any information that is transmitted to or by us over the Internet. The transmission and exchange of information is carried out at your own risk.
Cookies
We may use cookies on our website from time to time. Cookies are text files placed in your computer's browser to store your preferences. For more information about the cookies we use, please visit our Cookies policy on the footer of our website.
Links to other websites
Our website may contain links to other party’s websites. We do not have any control over those websites and we are not responsible for the protection and privacy of any personal data which you provide whilst visiting those websites. Those websites are not governed by this Privacy Policy.
Amendments
We may change this Privacy Policy from time to time. We will notify you if we make a significant change to this Privacy Policy, by contacting you through the contact details you have provided to us and by publishing an updated version on our website.
For any questions or notices, please contact us at:
Sensory Footsteps Limited, a company registered in England and Wales, with company number, 13966133.
Email: sensoryfootstepsenquiries@gmail.com
Last update: 16 February 2024
Sensory foOTsteps Limited
We have been making some changes to our IT systems, processes and phone lines to streamline our service. Our online booking will resume on the 3/6/2024
We are also pleased to announce a permanent clinic location for Cornwall/Devon area in Launceston and local therapy support. Our Doncaster clinic continues to run as usual with our full time staff team.