Appendix
GDPR Policy document for WellNow
Date drafted: 1st Feb 2018
Last date reviewed: 3rd May 2022
Next review date: 1st November 2022
Introduction
This document outlines the policies and procedures in places to ensure that WellNow is GDPR compliant and has the data security interests of all clients in mind through every steps of conducting business with them.
Background to business
Suzanne Leyden is a qualified Nutrition, Health & Wellness Coach and business owner of WellNow, offering individual and group coaching sessions to clients to help them set their wellness goals, co-create a wellness plan and continue to live out their goals, leading to a more healthy and fulfilled life.
Due to the nature of the business there are a number of personal information details, including those relating to health, that are required in order to effectively work with clients and offer the full coaching services.
In this document I will outline what information is requested, the upfront consent notification shared with clients, storage and security policies and filing systems, which will enable swift response to clients who wish to access or withdraw any information that may be held in relation to them. I will also outline the procedures in place should a data breach occur.
Information requested
Following an initial conversation with a new client where the coaching process is explained, they will be emailed the above ‘Client Agreement Form’ and a ‘Welcome Pack’, which they complete and email back to me or printed versions can be brought to the first session.
The ‘Client Agreement Form’ explains what coaching is, how the process works along with general ‘rules of business’.
The information requested in the ‘Welcome Pack’ falls under the following categories;
· Basic personal information
Name, Address, Main phone number, Email, Date of Birth, Marital status, No. of children and whether they live at home, whether pregnant or trying to conceive.
· The Coaching Relationship
This includes information regarding their expectations of the coaching process and ways for us to best work together.
· Personal information
These questions help to establish a person’s values and goals, which is a useful process for the client to go through but also to give me a better understanding of their perspective on their life, currently and where the direction they wish to take it.
· Basic Health & Wellness information
This section asks questions about a person’s current level of health, what they do to stay healthy, whether they are under the supervision of any other healthcare professionals and whether they are on any medications. How they manage stress, what their typical diet consists of and what they do to bring joy and happiness to their lives. This all helps to give a broad but clear picture of a client’s health so that appropriate advice and guidance can be prepared prior to a coaching session.
The full Welcome Pack can be requested for review at any time, where one has been completed.
The information from the Welcome Pack helps me (Suzanne Leyden) as a coach to establish what my client’s current health situation is, what their goals are and what limiting factors (real or perceived) may be at play with regard to them achieving their goals. It is essential as a coach to have this picture of a client prior to starting our coaching sessions in order to offer them the highest standard of coaching that they deserve.
Throughout the coaching process, further coaching tools may be used to help establish goals and co-create a wellness plan. Again, all of these tools can be made accessible at any time for review for GDPR purposes.
Consent & Processing of your Personal Data
At WellNow, we take the privacy and protection of your personal data very seriously. Here is some information about the way we process your personal data.
Your data will be processed by:
Suzanne Leyden, WellNow, 13 Boyd Avenue, Honeypark, Dun Laoghaire, Co. Dublin, Ireland.
Further information about data protection can be requested.
Your personal data will be processed by us for the following purposes: in order to deliver coaching services to the highest standard, for occasional marketing communications and administrative communications. In order to be part of our mailing list, we require your email address and other optional details including name, date of birth, address and phone number. This information is shared with Mailchimp in order to facilitate email communications. We never share your data with anyone else.
We never share personal health data with any third party, this data is only used for the purpose of carrying out coaching services.
The data that you provide us, is processed internally by us for the aforementioned purposes. The legal basis for the processing of your data results from your Client Agreement and for marketing communications, from this consent.
Your information will only be stored by us for as long as it is necessary to provide the service to you. Subsequently, this data will be deleted if we do not have your consent to continue to process it and there is no other legal reason for retaining the data.
You have the right to access the personal data we hold relating to you at any time. Also, on request, we will correct your data according to your preference should errors be identified. At your request, we will also delete all of your personal data, provided that we do not have to keep it to comply with statutory retention requirements. In any such case, we will restrict your data for further processing so that it can no longer be used. You also have a right to object to the further processing of your data and the right to receive your data in electronic form. If you wish to exercise any of these rights, please email hello@thewellnowco.com.
You have the right to revoke your consent at any time.
Your data will not be used by us for automated decision-making or profiling.
If you believe that your data is not being processed by us in accordance with applicable data protection laws, you have the right of appeal to the Data Protection Commissioner.
The provision of your data is required for establishing and maintaining contact with you as a client under your Client Agreement and is voluntary on your part.
The following note is included in the welcome pack to all clients. This outlines the reasons why the information requested is required and shows how consent is collected.
Hello and congratulations on taking the first step to a healthier, happier and more fulfilling life!
This Welcome Pack will help you to start thinking about your life in a different way, become more aware of what you want to get out of this coaching process and identify what issues need to be addressed. It will also give me an insight into you and your unique situation and act as a starting point for the initial exploratory stage of the coaching process.
As your coach, it’s important for me to understand how you view the world, yourself, and your job or career. Each person is unique and understanding you will help me support and assist you.
Answering these questions clearly and thoughtfully, will serve both you and me. You may find that they help you clarify perceptions about yourself and the direction of your life. These are “pondering” type questions, designed to stimulate your thinking in a way that will make our work together more productive. Take your time answering them. If they are not complete by our first (foundation) session, just bring what you have completed and finish the rest later.
The information in this document and any further information relating to you that we discuss or document throughout our coaching partnership will be securely stored and treated with complete professional confidentiality. Your personal files will be securely stored for 12 months from the date of our last session unless otherwise agreed in writing between us. Should you wish to review any of your personal files at any stage, this can be requested in writing and will be shared with you within 5 working days.
Please sign and date below to confirm you understand the reasons why the information in this form is required and that you agree to sharing it under the terms outlined above.
Signature:
Date:
Storage, filing and Security Policies
Client files will take both digital and paper form. Please note that not all files will be duplicated in both formats but some documents relating to a client will be processed digitally and others will be printed.
Digital Files
A new digital folder will be created for each client following an initial telephone conversation or email exchange with a client. This folder will not be listed by the client name but will be coded using their initials and the date of the file being opened. For example a file for John Smith, opened on 1st Feb 2018 would be called WN01022018.
These folders will be password protected and I will have sole access to these files.
All digital folders will be deleted 12 months after the last session with a client unless otherwise agreed in writing with the client.
Paper Files
Any paper files relating to a client will be held in a personalized folder and housed in grouped folder, which is locked using a combination padlock. I will have sole access to these files.
As with the digital files, all paper files will be destroyed 12 months after the last session with a client, unless otherwise agreed in writing with that client. Paper files will be shredded and disposed of in general waste.
Based on the filing and storage system outlined above, files can be retrieved quickly should they be requested by the client at any stage. I have indicated a 5 working day turn around for supplying client files in the Welcome Pack note. This is due to me being to sole manager of these files and is to allow ample time for me to access and share the files in the event that I am away or otherwise unable to respond immediately.
Data Breach
In the unlikely event of a data breach or a risk of a data breach (i.e. computer theft), I will notify the Data Commissioner Office and the effected client(s) as soon as I have been made aware of the situation and I will work with the authorities to retrieve or disable the data to safeguard my client’s security.
Privacy Policy & Third Parties
The full Privacy Policy for The WellNow Co can be read here. It outlines third parties used for the functionality of the products and services.