We use personal data (information that relates to and identifies living people) and other information to help us to carry out our role as a provider of tinnitus and other adult audiology rehabilitation services in the UK.
We will always make sure that your information is protected and treated securely. Any information about you that we hold, or details you give us, will be held in accordance with:
- The Data Protection Act 1998
- General Data Protection Regulation (being introduced May 2018)
- The Tinnitus Clinic’s Information Governance Policy
This is the personal information we hold about people who are patients:
- Patient name
- Date of birth
- Patient Identifier number which is IA followed by a six-digit number
- Address and postcode of patient
- Email address if provided
- Phone number/s
- Next of Kin if provided
Medical information is held separately and includes all the above plus treatment information, audiology and assessment test results and medical journal notes of appointments.
This is the personal information we hold about people who have requested information from us:
- Name
- Address and postcode if provided
- Email address if provided
- Phone numbers
Information about our own staff and people applying to work for or with us
- Name
- Address and postcode
- Email address if provided
- Phone number/s
- Next of Kin
- Work record in the form of a CV
Information about people who use our website
- We do not collect personal information unless you have requested information or are a patient.
Sharing information
We do not share your personal information with any other organisation other than those who process personal data on our behalf. Where we do this, those companies are required to follow the same rules and information security requirements as us, and are not permitted to reuse the data for other purposes.
We work with research experts who are seeking information on tinnitus populations and treatments. Where we do this, we supply only anonymised data and do not reveal personal details without approaching you for specific consent.
Retention and disposal of personal data
We are required by Medical Device Regulations to be able to trace individual patients if required. To comply, we retain personal information for twenty years after the last contact date, or until a request is made to delete it, whichever is the sooner.
Personal data is deleted or securely destroyed at the end of its retention period.
Your right to access information about you
If you think we may hold your personal data and you want to see it, find out how to make a subject access request. We will ask you for proof of identity and provide you with the personal details which we hold. We will aim to provide this information with ten working days.
If you want us to correct information that you believe is wrong, or if you want us to delete your personal data or to stop processing it, then you have the right to ask for it to be removed or corrected.
Please make your enquiry in writing by sending an email to: info@thetinnitusclinic.co.uk
or send it by post to:
Josephine Swinhoe
Data Controller
The Tinnitus Clinic Ltd
Bentinck House, 3-8 Bolsover Street, London W1W 6AB
Telephone: Freephone 0800 030 6617