Privacy Policy
CMC Wellbeing Privacy Notice
Privacy at a Glance
CMC Wellbeing is committed to protecting your personal information, particularly sensitive health data. Below is a summary of how we handle your information. Please read our full Privacy Notice for detailed information.
Who we are
CMC Wellbeing is the data controller responsible for your personal data when you use our services.
What information we collect
We collect:
• Identity and contact details (e.g. name, date of birth, address)
• Clinical and mental health information
• Appointment and billing information
• Information provided by referring professionals
Why we collect it
We process your information to:
• Provide safe and effective healthcare
• Maintain accurate clinical records
• Communicate with you about your care
• Meet legal and regulatory obligations
Certain information is required for us to deliver healthcare services.
Our legal basis
We process health data under the healthcare provision conditions permitted by data protection law. We do not rely on consent as the primary basis for delivering clinical care.
Who we share it with
We may share relevant information with:
• Your GP or other clinicians involved in your care
• Laboratories and diagnostic providers
• Secure IT and clinical software providers
• Regulators where legally required
We never sell personal data.
How long we keep it
Clinical records are retained in line with recognised healthcare retention standards (typically a minimum of 8 years for adult records).
Your rights
You have the right to access, correct, restrict or object to certain uses of your personal data. You may also lodge a complaint with the Office of the Data Protection Authority (Guernsey).
Questions or concerns
If you have any questions about how your data is handled, please contact:
privacy@cmc.gg
CMC Wellbeing Privacy Notice
Version 1.1
Effective Date: 23/02/26
Review Date: 23/02/27
1. Data Controller
CMC Wellbeing (Chiropractic + Massage Clinic Ltd.) (“CMC”, “we”, “us”, “our”) is a healthcare provider operating in the Bailiwick of Guernsey.
For the purposes of the Data Protection (Bailiwick of Guernsey) Law, 2017 and, where applicable, UK GDPR, CMC Wellbeing is the Data Controller in respect of personal data processed in connection with our services.
Registered Address:
Bosq Lane, St Peter Port, Guernsey, GY1 2LP
Data Protection Lead:
Amelia Wells
Email:
privacy@cmc.gg
Telephone:
01481 723724
We are responsible for determining the purposes and means of processing your personal data.
2. Scope
This Privacy Notice applies to:
• Patients and service users
• Prospective patients
• Individuals making enquiries
• Website users
• Individuals referred to us
Separate privacy information applies to employees and contractors.
3. Categories of Personal Data We Collect
3.1 Identity Data
• Full name
• Date of birth
• Gender
• Photographic ID (where required)
3.2 Contact Data
• Home address
• Email address
• Telephone numbers
• Emergency contact details
3.3 Clinical Data (Special Category Data)
• Medical history
• Mental health history
• Psychological assessments
• Diagnostic information
• Treatment plans
• Clinical notes and consultation records
• Medication records
• Risk assessments
• Safeguarding information
• Correspondence with other healthcare professionalsThis constitutes special category health data under data protection law.
3.4 Financial and Transaction Data
• Billing information
• Payment records
• Insurance details (where applicable)
Payment card details are processed via secure third-party payment providers and are not stored by CMC.
3.5 Referral and Third-Party Data
• Information provided by GPs
• Information from other clinicians
• Insurer or occupational health referrals
3.6 Technical and Usage Data
• IP address
• Device/browser information
• Website analytics data (where applicable)
4. How We Collect Data
We collect data:
• Directly from you during enquiries, onboarding, and consultations
• Through secure clinical management systems
• From referring clinicians (with appropriate authority)
• From insurers (where relevant)
• Through our website
Where we receive data from third parties, we ensure there is a lawful basis for that disclosure.
5. Lawful Bases for Processing
We process personal data under the following lawful bases:
5.1 Article 6 Lawful Bases (General Personal Data)
We rely on:
• Contractual necessity – to provide healthcare services to you
• Legal obligation – to comply with regulatory, safeguarding, tax, and professional duties
• Legitimate interests – for governance, audit, service improvement, and IT security (balanced against your rights and interests)
5.2 Article 9 Conditions (Special Category Health Data)
We process health data under the healthcare provision condition permitted by law, specifically:
• Processing necessary for medical diagnosis and the provision of health or social care
• Processing necessary for the management of healthcare systems and services
Where relevant, we may also rely on:
• Establishment, exercise or defence of legal claims
We do not rely on consent as the primary legal basis for core clinical processing. Healthcare provision requires certain data to be processed as part of service delivery.
5.3 Consent (Limited Circumstances)
We rely on consent only where legally required, such as:
• Optional marketing communications
• Specific disclosures outside standard clinical pathways
Where consent is relied upon, it may be withdrawn at any time.
6. Purposes of Processing
We use personal data to:
• Assess, diagnose, and provide treatment
• Maintain accurate clinical records
• Communicate regarding appointments and care
• Coordinate care with other professionals
• Process payments
• Comply with regulatory obligations
• Manage risk and safeguarding
• Defend legal claims
• Improve service quality and safety
We do not sell personal data.
7. Sharing of Personal Data
We may share your data with:
• Your GP (where clinically appropriate)
• Other clinicians involved in your care
• Laboratories and diagnostic providers
• Secure clinical software providers (e.g., practice management systems)
• IT hosting and cloud storage providers
• Payment processors
• Professional advisers (legal, insurance, regulatory)
• Regulatory authorities where legally required
All processors act under written agreements and are required to implement appropriate security measures.
8. International Transfers
Where personal data is processed or stored outside the Bailiwick of Guernsey, we ensure appropriate safeguards are in place, including:
• Transfers to jurisdictions with recognised adequacy
• Standard contractual clauses
• Equivalent data protection mechanisms
We assess all international transfers for compliance and proportionality.
9. Data Retention
Clinical records are retained in accordance with recognised healthcare retention standards and professional guidance.
As a general framework:
• Adult clinical records are retained for a minimum of 8 years after the conclusion of treatment.
• Records relating to children are retained until the individual reaches age 25 (or longer where legally required).
• Financial records are retained for at least 6 years in accordance with tax law.
Retention periods may be extended where:
• There is an ongoing complaint or legal claim
• Safeguarding considerations apply
• Regulatory investigation is ongoing
When records reach the end of their retention period, they are securely destroyed or anonymised.
10. Data Security
We implement appropriate technical and organisational measures, including:
• Encrypted clinical record systems
• Secure hosting environments
• Access controls and role-based permissions
• Multi-factor authentication where appropriate
• Staff confidentiality obligations
• Data protection training
• Incident response procedures
• Regular system review and updates
We limit access to personal data strictly to those who require it for legitimate purposes.
11. Your Rights
Under applicable data protection law, you have the right to:
• Access your personal data
• Request correction of inaccurate data
• Request erasure (where legally applicable)
• Restrict processing
• Object to certain processing
• Request data portability (where applicable)
• Withdraw consent (where consent is relied upon)
Some rights may be limited in the context of healthcare provision where disclosure would cause serious harm or conflict with legal obligations.
Requests should be made to:
privacy@cmc.gg
We may require proof of identity before responding. We aim to respond within one month.
12. Complaints
If you have concerns about how your data is handled, contact us first.
You have the right to lodge a complaint with:
Office of the Data Protection Authority (ODPA)
Bailiwick of Guernsey
Website: https://www.odpa.gg
13. Failure to Provide Data
Certain personal data is required for us to provide safe and lawful healthcare services. If you do not provide necessary information, we may be unable to offer treatment.
14. Automated Decision-Making
CMC Wellbeing does not carry out solely automated decision- making that produces legal or similarly significant effects.
15. Updates to This Notice
This Privacy Notice may be updated periodically to reflect legal, regulatory, or operational changes. The latest version will be available on our website and upon request.