Privacy Policy

The Perrin Clinic
83 Whittaker Lane, Prestwich , Manchester M25 1ET 

0161 773 0123

www.theperrinclinic.com

For data protection queries, please contact us at: info@theperrinclinic.com

We are registered with the Information Commissioner’s Office (ICO).
ICO Registration Number: Z9113572


  1. THE DATA WE COLLECT ABOUT YOU

    We collect and process the following categories of personal data:

    Contact and identity data
    – Full name, date of birth, address, telephone number, email address
    – Emergency contact details

    Health and clinical data (special category data)
    – Medical history, current and past conditions, medications, and allergies
    – Clinical assessment findings, treatment notes, and progress records
    – Referral letters and correspondence from other healthcare providers
    – Details of symptoms, diagnoses, and treatment outcomes

    Administrative and financial data
    – Appointment records and attendance history
    – Payment information and invoices
    – Insurance details (where applicable)

    Communications data
    – Correspondence by email, telephone, or letter

  2. HOW WE COLLECT YOUR DATA

    We collect your personal data:
    – Directly from you when you register as a patient, complete intake forms, or attend appointments
    – From third parties including referring practitioners, GPs, specialists, or insurers (with your knowledge)
    – During the course of your clinical care and treatment

  3. THE LEGAL BASIS FOR PROCESSING YOUR DATA

    Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we process your personal data on the following lawful bases:

    For general personal data (Article 6 UK GDPR):
    Contract: Processing is necessary to provide you with osteopathic care and fulfil our obligations to you as a patient.
    Legal obligation: We are required to retain certain records by law and professional regulatory requirements.
    Legitimate interests: For administrative purposes such as appointment management, billing, and clinic communications, where these interests are not overridden by your rights.

    For special category health data (Article 9 UK GDPR):
    Healthcare provision (Article 9(2)(h)): Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care or treatment, and the management of health or social care systems. This is the primary basis on which we process your clinical health data.
    Explicit consent (Article 9(2)(a)): Where required, we will seek your explicit consent, for example for uses of data beyond direct clinical care.

  4. HOW WE USE YOUR DATA

    We use your personal data to:
    – Provide, manage, and administer your osteopathic care and treatment
    – Maintain accurate and up-to-date clinical records
    – Communicate with you about appointments, treatment, and follow-up care
    – Process payments and manage billing
    – Correspond with other healthcare professionals involved in your care (where clinically appropriate)
    – Meet our legal, regulatory, and professional obligations as registered osteopaths under the General Osteopathic Council (GOsC)
    – Ensure the safety and continuity of your care

  5. OUR TECHNOLOGY SYSTEMS AND THIRD-PARTY DATA PROCESSORS

    To deliver our services effectively and securely, we use the following third-party systems. Each acts as a data processor under a data processing agreement with us and is contractually required to handle your data in accordance with UK GDPR:

    Cliniko (Practice Management Software)
    We use Cliniko to manage patient records, appointments, clinical notes, and invoicing. Cliniko stores data on secure servers. For further information, see Cliniko’s Privacy Policy at www.cliniko.com/privacy.

    Heidi Health (AI-Assisted Clinical Documentation)
    We use Heidi Health to assist with the creation of clinical consultation notes. Heidi listens to consultations to generate transcripts and clinical documentation, which are then reviewed and approved by your treating osteopath. Heidi processes data in accordance with HIPAA and GDPR standards. For further information, see Heidi’s Privacy Policy at www.heidihealth.com/privacy.

    ScanSnap (Document Digitisation)
    We use Fujitsu ScanSnap scanning equipment to digitise paper documents such as referral letters and intake forms. Digitised documents are stored securely within Cliniko. No personal data is transmitted externally by this device beyond our secure internal network.

    We do not sell your personal data to any third party. We do not use your data for marketing without your explicit consent.

  6. DATA SHARING

    We may share your personal data in the following circumstances:

    – With other healthcare professionals involved in your care (e.g. your GP, specialist, or physiotherapist), where clinically necessary and appropriate
    – With your insurer or third-party payer, with your consent or where required to process a claim
    – With regulatory bodies or professional organisations where we are required to do so by law (e.g. GOsC, ICO)
    – With law enforcement or courts where required by a legal obligation
    – With our professional indemnity insurers in the event of a complaint or legal claim

    We will always aim to inform you when sharing your data unless we are legally prohibited from doing so.

  7. HOW LONG WE KEEP YOUR DATA

    We retain clinical and personal records in line with the following guidelines:

    Adult patient records: A minimum of 8 years following the last date of treatment, in line with NHS and professional guidance
    Children’s records: Until the patient’s 25th birthday, or 8 years after the last treatment if later
    Financial records: 6 years in line with HMRC requirements
    Deceased patients: A minimum of 8 years from the date of death

    After the applicable retention period, data is securely destroyed in accordance with our data retention policy.
  8. USE OF ANONYMISED DATA FOR RESEARCH AND EDUCATION

    9.1 Our Commitment to Research and Education

    The Perrin Clinic is committed to advancing the understanding and treatment of osteopathic conditions. We may use patient data, in strictly anonymised form, to support clinical research, audit, service improvement, and the education and training of healthcare professionals.

    9.2 What We Mean by Anonymisation

    Anonymised data is data from which all information that could reasonably identify you — including your name, date of birth, address, NHS number, and any other identifying details — has been permanently removed. Once data is truly anonymised, it no longer constitutes personal data and falls outside the scope of UK GDPR.

    Where data is pseudonymised (e.g. replaced with a code, but re-identification remains theoretically possible), it continues to be treated as personal data and all protections in this Privacy Policy continue to apply in full.

    We apply the Information Commissioner’s Office (ICO) anonymisation standard when preparing any data for research or educational use, and we take all reasonable technical and organisational steps to prevent re-identification.

    9.3 Lawful Basis for Research Using Personal Data

    In cases where truly anonymised data cannot be used and identifiable or pseudonymised personal data is required for research purposes, we rely on the following lawful bases under UK GDPR and the Data Protection Act 2018:

    Article 6(1)(e) UK GDPR: Processing necessary for the performance of a task in the public interest.
    Article 9(2)(j) UK GDPR: Processing of special category health data necessary for scientific or historical research purposes, in accordance with Article 89(1) UK GDPR.
    Data Protection Act 2018, Schedule 1, Part 1, Section 4: Processing for research purposes that is in the public interest and carried out with appropriate safeguards.

    We will only rely on these bases where the research meets a genuine public interest test, where the use of fully anonymised data is not reasonably practicable, and where appropriate safeguards are in place.

    Where required by law or ethics, we will seek your explicit consent before using your identifiable data for any research purpose.

    9.4 How Anonymised Data May Be Used

    Anonymised data derived from clinical records at the Perrin Clinic may be used for:

    – Clinical audit and service evaluation to improve patient outcomes and clinic performance
    – Academic and peer-reviewed research into osteopathic conditions, treatment efficacy, and related musculoskeletal or systemic conditions
    – Case studies and educational materials for the training and development of osteopaths and other healthcare professionals
    – Presentations at professional conferences, seminars, or educational events
    – Publication in professional or academic journals or textbooks

    In all such uses, no information that could identify you will be disclosed. Where case presentations are used for educational purposes, these will be sufficiently generalised or modified to prevent identification, unless your explicit written consent has been obtained.

    9.5 Sharing Anonymised Data with Third Parties

    Anonymised data may be shared with:

    – Academic institutions and research collaborators for approved research projects
    – Professional bodies such as the General Osteopathic Council (GOsC) or the Institute of Osteopathy for audit and regulatory purposes
    – Publishers or conference organisers, solely in anonymised form

    We do not sell anonymised data. Any sharing with third parties for research purposes is governed by a data sharing agreement or equivalent safeguard.

9.6 Your Right to Object

You have the right to object at any time to your data being used for research or educational purposes beyond your direct clinical care. You may exercise this right by contacting us at [Insert data protection contact email].

Where your objection relates to the processing of truly anonymised data, please note that we may be unable to identify your data within anonymised datasets in order to exclude it. We will always inform you of this limitation when you exercise this right.


  1. YOUR DATA PROTECTION RIGHTS

    Under UK GDPR, you have the following rights regarding your personal data:

    Right of access: You may request a copy of the personal data we hold about you (a Subject Access Request).
    Right to rectification: You may ask us to correct inaccurate or incomplete data.
    Right to erasure: In certain circumstances, you may request that we delete your data. Note that this right may be limited where we are required to retain records for legal or professional regulatory purposes.
    Right to restrict processing: You may ask us to limit how we use your data in certain circumstances.
    Right to data portability: Where processing is based on consent or contract, you may request your data in a portable format.
    Right to object: You may object to processing based on legitimate interests.
    Rights related to automated decision-making: We do not make automated decisions about you that have significant legal or similarly significant effects.
    Right to withdraw consent: Where we rely on your consent to process data, you may withdraw it at any time without affecting the lawfulness of prior processing.

    To exercise any of these rights, please contact us at [Insert data protection contact email]. We will respond within one calendar month of receiving your request.

  2. DATA SECURITY

    We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:

    – Secure password-protected access to all clinical systems
    – Encryption of data in transit
    – Regular software updates and security patching
    – Restricted access to clinical data on a need-to-know basis
    – Secure disposal of paper documents using cross-cut shredding

  3. DATA BREACHES

    In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform you without undue delay where required by law.

  4. COOKIES AND WEBSITE DATA

    If you visit our website, we may collect limited data through cookies. Please see our separate Cookie Policy [Insert link] for further information.

  5. CHANGES TO THIS POLICY

    We may update this Privacy Policy from time to time. The current version will always be available at www.theperrinclinic.com and on request from the clinic. Material changes will be communicated to patients directly.

  6. HOW TO COMPLAIN

    If you are unhappy with how we have handled your personal data, please contact us in the first instance at info@theperrinclinic.com. Or write to The Perrin Clinic, 83 Whittaker Lane, Prestwich, Manchester, M25 1ET.

    You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

    Information Commissioner’s Office
    Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
    Telephone: 0303 123 1113
    Website: www.ico.org.uk