Delivering high quality care services in the community!
10 Dowanhill Road
Catford, London SE6 1HJ
+44 208 697 6969
admin@waterfieldsh.co.uk
Sunday - Saturday
24 x 7 (365)

Privacy Policy

PRIVACY POLICY

Overview

WATERFIELD SUPPORTED HOMES LTD is committed to data protection and data privacy. With the General Data Protection Regulation (GDPR) becoming enforceable from 25 May 2018, we have undertaken a GDPR readiness programme to review our entire business, the way we handle data and the way in which we use it to provide our services and manage business operations.

We hold personal data on all our residents to meet legal obligations and to perform vital internal functions. This notice details the personal data we may retain process and share with third parties relating to vital business operations. We are committed to ensuring that your information is secure, accurate and relevant. To prevent unauthorised access or disclosure, we have implemented suitable physical, electronic, and managerial procedures to safeguard and secure personal data we hold.

Introduction

We have issued this notice to describe how we handle personal information that we hold about our residents (collectively referred to as “you”). For the purposes of this notice, the term “residents” includes those who are placed in our home by Lewisham Council, other boroughs or by direct placement.

We respect the privacy rights of individuals and are committed to handling personal information responsibly and in accordance with applicable law. This notice sets out the personal data that we collect and process about you, the purposes of the processing and the rights that you have in connection with it. If you are in any doubt regarding this notice, please contact Christiana Ezeilo at coezeilo@waterfieldsh.co.uk, info@waterfieldsh.co.uk.

Types of personal data we collect

During your placement with us, or when assessing your needs, we may process personal and social, employment history data about you and your dependents, beneficiaries and other individuals whose personal data have been provided to us.

The types of personal information we may process include, but are not limited to the following:

  • Identification data – such as your name, gender, photograph, date of birth, IDs.
  • Psychiatric and medical diagnosis – from Psychiatrist’s, forensic, Social care and medical reports
  • Contact details – such as home and telephone/email addresses, emergency contact details.
  • Employment information – such as job title/position,
  • Background information – such as academic/professional qualifications, education, criminal records data
  • Spouse & dependents information, marital status.
  • Financial information – such as benefits, expenses, allowances.

Sensitive personal data (‘special categories of personal data’ under the General Data Protection Regulation) includes any information that reveals your racial or ethnic origin, religious, political or philosophical beliefs, genetic data, or information about your health/sex life.

Generally, we try not to collect or process any sensitive personal information about you, unless authorised by law or where necessary to comply with applicable laws. In some circumstances, we may need to collect some sensitive personal information for legitimate health related purposes: for example:

  • data relating to your racial/ethnic origin, gender and disabilities for the purposes of:
  • equal opportunities monitoring;
  • to comply with anti-discrimination laws; and
  • data relating to your physical or mental health to:
  • provide appropriate psychiatric diagnosis, medical and medication history,
  • health benefits to you

 Purposes for processing personal data

We will observe the Caldicott Principles when processing health and/or social care data, which are set out below.

  1. Justify the purpose(s)

Every proposed use or transfer of personal confidential data within or from an organisation should be clearly defined, scrutinised and documented, with continuing uses regularly reviewed, by an appropriate guardian.

  1. Don’t use personal confidential data unless it is necessary

Personal confidential data items should not be included unless it is essential for the specified purpose(s) of that flow. The need for patients to be identified should be considered at each stage of satisfying the purpose(s).

  1. Use the minimum necessary personal confidential data

Where use of personal confidential data is essential, the inclusion of each discrete item of data should be considered and justified so that the minimum amount of personal confidential data is transferred or accessible as is necessary for a given function.

  1. Access to personal confidential data should be on a strict need-to-know basis

Only those individuals who need access to personal confidential data should have access to it, and they should only have access to the data items that they need to see. This may mean introducing access controls or splitting data flows where one data flow is used for several purposes.

  1. Everyone with access to personal confidential data should be aware of their responsibilities

Action should be taken to ensure that those handling personal confidential data — both clinical and non-clinical employees — are made fully aware of their responsibilities and obligations to respect patient confidentiality.

  1. Comply with the law

Every use of personal confidential data must be lawful. Someone in each organization handling personal confidential data should be responsible for ensuring that the organization complies with legal requirements.

  1. The duty to share information can be as important as the duty to protect patient confidentiality.

Health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by these principles. They should be supported by the policies of their employers, regulators and professional bodies.

 Legitimate business purposes

We may also collect and use personal information when it is necessary for other legitimate purposes, such as to help us conduct our business more effectively and efficiently – for example, for general IT security management, accounting purposes or financial planning. We may also process your personal information to investigate violations of law or breaches of our own internal policies.

The IT Department will record and monitor usage of all our IT equipment, user activity, email and Internet usage as deemed necessary. The IT Department will observe the strictest confidentiality when undertaking these activities. They will make their report directly to the unit deputy managers and Manager and the IT specialist, Uchemus, who will determine the actions that may need to be taken in any particular case.

Our sites are protected by circuit television (CCTV) systems throughout its premises as deemed necessary, and all personnel should expect all areas (other than those where use would contravene common decency) to be visible on a television monitoring system. Any information obtained from systems will be used with strict adherence to the GDPR. Information will be used for the prevention and detection of crime and safeguarding concerns and to ensure compliance with our policies and procedures and our legal obligations. This may include using recorded images as evidence in safeguarding and disciplinary proceedings.

Legal purposes

We may also use your personal data where we consider it necessary for complying with laws and regulations, including collecting and disclosing risk assessments as required by law (e.g. for health and safety), under judicial authorisation, or to exercise or defend our legal rights (e.g. Liability Insurance claims)

Legal basis for processing personal data

Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the way we collect it. We will normally collect personal data from you only where we need it to perform a contract with you (i.e. to assess your needs and manage your care), where we have your freely given consent to do so, or where the processing is in our legitimate interests and only where this interest is not overridden by your own interests or fundamental rights and freedoms.  In some cases, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another person.

Any processing based on consent will be made clear to you at the time of collection or use – consent can be withdrawn at any time by contacting Christiana Ezeilo at coezeilo@waterfieldsh.co.uk, info@waterfieldsh.co.uk.

Who we share your personal data with

We take care to allow access to personal data only to those who require such access to perform their tasks and duties, and to third parties who have a legitimate purpose for accessing it. Whenever we permit a third party to access personal information, we will implement appropriate measures to ensure the data is used in a manner consistent with this notice and that the security and confidentiality of the data is maintained.

Transfers to third-party service providers

In addition, we make certain personal data available to third parties who provide services to us. We do so on a “need to know basis” and in accordance with applicable data protection and data privacy laws. We ensure that their terms and conditions of engagement meet the Local Authority requirements on privacy and Data Protection law

For example, some personal data will be available to our third-party companies who provide us with digital Care Management Systems (Everylife Systems), Employment law for our staff (Citation), and Payroll support services, for expenses, and tax (Sage UK), NEST Pensions, HMRC and JUSTHOST for our e-mails.

The Contractors shall comply with GDPR requirements for maintaining accurate, current and comprehensive Records of Processing Activities. Please see links to the terms and conditions and privacy policy for the organisations.

Everylife Systems: https://www.everylifetechnologies.com/terms-and-conditions/

Everylife Systems: https://www.everylifetechnologies.com/privacy-policy/

Citation:                 http://www.citation.co.uk/privacy-policy

Citation:                 https://auth.citation-atlas.co.uk/identity/terms/termsofuse

Sage:                   https://www.sage.com/en-gb/legal/privacy-and-cookies/

Justhost:              https://www.justhost.com/privacy-policy

Nest Pension: https://www.nestpensions.org.uk/schemeweb/nest/nestcorporation/privacy-policy.html

HMRC:             https://www.gov.uk/help/privacy-policy

Transfer of personal data abroad

We do not currently need to transfer personal data to countries outside of the United Kingdom. However, if we export your personal data to a different country, we will take steps to ensure that such data exports comply with applicable laws. For example, if we transfer personal data outside the European Economic Area (EEA), such as to the United States, we will implement an appropriate data export solution such as entering into contracts with the data importer that contain EU model clauses or taking other measures to provide an adequate level of data protection.

(https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en

 Data retention

Personal data will be stored in accordance with applicable laws and kept for as long as needed to carry out the purposes described in this notice or as otherwise required by law. Generally, this means your personal information will be retained up to 8years.

For more information, please see our Data Retention Policy, which outlines our current document retention schedule.

 For examples of retention periods please see:

http://www.nationalarchives.gov.uk/information-management/browse-guidance-standards/?letter=r&keyword=retention

Your rights

You may exercise the rights available to you under data protection law as follows:

  • The right to be informed.
  • The right of access.
  • The right to rectification.
  • The right to erasure.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object.
  • Rights in relation to automated decision making and profiling.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. You can read more about these rights at:

https://ico.org.uk/for-the-public/is-my-information-being-handled-correctly/

To exercise any of these rights, please contact Christiana Ezeilo

 Issues and complaints

We try to meet the highest standards when collecting and using personal information. For this reason, we take any complaints we receive about this very seriously. We encourage people to bring it to our attention if they think that our collection or use of information is unfair, misleading or inappropriate. We would also welcome any suggestions for improving our procedures.

This notice was drafted with clarity in mind. It does not provide exhaustive detail of all aspects of our collection and use of personal information. However, we are happy to provide any additional information or explanation needed.

If you want to make a complaint about the way we have processed your personal information, you can contact the Information Commissioner’s Office in their capacity as the statutory body which oversees data protection law – www.ico.org.uk/concerns.

 Updates to this notice

This notice may be updated periodically to reflect any necessary changes in our privacy practices. In such cases, we will inform you by Christiana Ezeilo “on the intranet and, for significant changes, by company-wide email.” We encourage you to check this notice periodically to be aware of the most recent version.

Contact details

Please address any questions or requests relating to this notice to Christiana Ezeilo at;

Waterfield Supported Homes Limited. 10 Dowanhill road, Catford, London SE6 1HJ

and at coezeilo@waterfieldsh.co.uk, info@waterfieldsh.co.uk.

Third-party processors

Key third-party processors

The following are our key third-party processors who will, during your placement, process your personal data. Everylife Technologies’s systems use a secure cloud solution. Information on security is available by contacting Christiana Ezeilo.

Local Care

Well trained professional care focusing on the needs of clients.

Reliability

Providing reliable care teams available 24 x 7 days for clients

Experience

Delivering high quality care services to the community

Flexibility

Carefully planned care towards our client's daily need