CMC Wellbeing

Privacy Policy

CMC Wellbeing Privacy Notice

Privacy at a Glance

CMC Wellbeing is committed to protecting your personal information, particularly sensitive health data. Below is a summary of how we handle your information. Please read our full Privacy Notice for detailed information.

Who we are

CMC Wellbeing is the data controller responsible for your personal data when you use our services.

What information we collect

We collect:

• Identity and contact details (e.g. name, date of birth, address)

• Clinical and mental health information

• Appointment and billing information

• Information provided by referring professionals

Why we collect it

We process your information to:

• Provide safe and effective healthcare

• Maintain accurate clinical records

• Communicate with you about your care

• Meet legal and regulatory obligations

Certain information is required for us to deliver healthcare services.

Our legal basis

We process health data under the healthcare provision conditions permitted by data protection law. We do not rely on consent as the primary basis for delivering clinical care.

Who we share it with

We may share relevant information with:

• Your GP or other clinicians involved in your care

• Laboratories and diagnostic providers

• Secure IT and clinical software providers

• Regulators where legally required

We never sell personal data.

How long we keep it

Clinical records are retained in line with recognised healthcare retention standards (typically a minimum of 8 years for adult records).

Your rights

You have the right to access, correct, restrict or object to certain uses of your personal data. You may also lodge a complaint with the Office of the Data Protection Authority (Guernsey).

Questions or concerns

If you have any questions about how your data is handled, please contact:

privacy@cmc.gg

 

CMC Wellbeing Privacy Notice

Version 1.1

Effective Date: 23/02/26

Review Date: 23/02/27

1. Data Controller

CMC Wellbeing (Chiropractic + Massage Clinic Ltd.) (“CMC”, “we”, “us”, “our”) is a healthcare provider operating in the Bailiwick of Guernsey.

For the purposes of the Data Protection (Bailiwick of Guernsey) Law, 2017 and, where applicable, UK GDPR, CMC Wellbeing is the Data Controller in respect of personal data processed in connection with our services.

Registered Address:

Bosq Lane, St Peter Port, Guernsey, GY1 2LP

Data Protection Lead:

Amelia Wells

Email:

privacy@cmc.gg

Telephone:

01481 723724

We are responsible for determining the purposes and means of processing your personal data.

2. Scope

This Privacy Notice applies to:

• Patients and service users

• Prospective patients

• Individuals making enquiries

• Website users

• Individuals referred to us

Separate privacy information applies to employees and contractors.

3. Categories of Personal Data We Collect

3.1 Identity Data

• Full name

• Date of birth

• Gender

• Photographic ID (where required)

3.2 Contact Data

• Home address

• Email address

• Telephone numbers

• Emergency contact details

3.3 Clinical Data (Special Category Data)

• Medical history

• Mental health history

• Psychological assessments

• Diagnostic information

• Treatment plans

• Clinical notes and consultation records

• Medication records

• Risk assessments

• Safeguarding information

• Correspondence with other healthcare professionalsThis constitutes special category health data under data protection law.

3.4 Financial and Transaction Data

• Billing information

• Payment records

• Insurance details (where applicable)

Payment card details are processed via secure third-party payment providers and are not stored by CMC.

3.5 Referral and Third-Party Data

• Information provided by GPs

• Information from other clinicians

• Insurer or occupational health referrals

3.6 Technical and Usage Data

• IP address

• Device/browser information

• Website analytics data (where applicable)

4. How We Collect Data

We collect data:

• Directly from you during enquiries, onboarding, and consultations

• Through secure clinical management systems

• From referring clinicians (with appropriate authority)

• From insurers (where relevant)

• Through our website

Where we receive data from third parties, we ensure there is a lawful basis for that disclosure.

5. Lawful Bases for Processing

We process personal data under the following lawful bases:

5.1 Article 6 Lawful Bases (General Personal Data)

We rely on:

• Contractual necessity – to provide healthcare services to you

• Legal obligation – to comply with regulatory, safeguarding, tax, and professional duties

• Legitimate interests – for governance, audit, service improvement, and IT security (balanced against your rights and interests)

5.2 Article 9 Conditions (Special Category Health Data)

We process health data under the healthcare provision condition permitted by law, specifically:

• Processing necessary for medical diagnosis and the provision of health or social care

• Processing necessary for the management of healthcare systems and services

Where relevant, we may also rely on:

• Establishment, exercise or defence of legal claims

We do not rely on consent as the primary legal basis for core clinical processing. Healthcare provision requires certain data to be processed as part of service delivery.

5.3 Consent (Limited Circumstances)

We rely on consent only where legally required, such as:

• Optional marketing communications

• Specific disclosures outside standard clinical pathways

Where consent is relied upon, it may be withdrawn at any time.

6. Purposes of Processing

We use personal data to:

• Assess, diagnose, and provide treatment

• Maintain accurate clinical records

• Communicate regarding appointments and care

• Coordinate care with other professionals

• Process payments

• Comply with regulatory obligations

• Manage risk and safeguarding

• Defend legal claims

• Improve service quality and safety

We do not sell personal data.

7. Sharing of Personal Data

We may share your data with:

• Your GP (where clinically appropriate)

• Other clinicians involved in your care

• Laboratories and diagnostic providers

• Secure clinical software providers (e.g., practice management systems)

• IT hosting and cloud storage providers

• Payment processors

• Professional advisers (legal, insurance, regulatory)

• Regulatory authorities where legally required

All processors act under written agreements and are required to implement appropriate security measures.

8. International Transfers

Where personal data is processed or stored outside the Bailiwick of Guernsey, we ensure appropriate safeguards are in place, including:

• Transfers to jurisdictions with recognised adequacy

• Standard contractual clauses

• Equivalent data protection mechanisms

We assess all international transfers for compliance and proportionality.

9. Data Retention

Clinical records are retained in accordance with recognised healthcare retention standards and professional guidance.

As a general framework:

• Adult clinical records are retained for a minimum of 8 years after the conclusion of treatment.

• Records relating to children are retained until the individual reaches age 25 (or longer where legally required).

• Financial records are retained for at least 6 years in accordance with tax law.

Retention periods may be extended where:

• There is an ongoing complaint or legal claim

• Safeguarding considerations apply

• Regulatory investigation is ongoing

When records reach the end of their retention period, they are securely destroyed or anonymised.

10. Data Security

We implement appropriate technical and organisational measures, including:

• Encrypted clinical record systems

• Secure hosting environments

• Access controls and role-based permissions

• Multi-factor authentication where appropriate

• Staff confidentiality obligations

• Data protection training

• Incident response procedures

• Regular system review and updates

We limit access to personal data strictly to those who require it for legitimate purposes.

11. Your Rights

Under applicable data protection law, you have the right to:

• Access your personal data

• Request correction of inaccurate data

• Request erasure (where legally applicable)

• Restrict processing

• Object to certain processing

• Request data portability (where applicable)

• Withdraw consent (where consent is relied upon)

Some rights may be limited in the context of healthcare provision where disclosure would cause serious harm or conflict with legal obligations.

Requests should be made to:

privacy@cmc.gg

We may require proof of identity before responding. We aim to respond within one month.

12. Complaints

If you have concerns about how your data is handled, contact us first.

You have the right to lodge a complaint with:

Office of the Data Protection Authority (ODPA)

Bailiwick of Guernsey

Website: https://www.odpa.gg

13. Failure to Provide Data

Certain personal data is required for us to provide safe and lawful healthcare services. If you do not provide necessary information, we may be unable to offer treatment.

14. Automated Decision-Making

CMC Wellbeing does not carry out solely automated decision- making that produces legal or similarly significant effects.

15. Updates to This Notice

This Privacy Notice may be updated periodically to reflect legal, regulatory, or operational changes. The latest version will be available on our website and upon request.