GDPR & Privacy Policy
GDPR & Privacy Policy
‘GDPR’ the General Data Protection Act 1998, the General Data Protection Regulation (EU 2016/679) and any applicable statutory or regulatory provisions in force from time to time relating to the protection and transfer of personal data.
‘Data Controller’ determines the purpose and means of processing personal data ‘Data Processor’ responsible for processing personal data on behalf of a ‘Controller,’ responsible for maintaining records of personal data and processing activities.
‘Personal Data’ information relating to a person who can be directly or indirectly identified by the data held.
‘Sensitive Personal Data’ special categories of personal data, including genetic and biometric data, uniquely specific to an individual.
Epilepsy Matters Cymru is a training provider and private consultancy service, established to provide training for care staff on epilepsy. Epilepsy Matters Cymru also offers private consultations to people with epilepsy.
Epilepsy Matters Cymru has a responsibility to process data in accordance with the General Data Protection Act 1998, the General Data Protection Regulation (EU 2016/679) and any applicable statutory or regulatory provisions in force from time to time relating to the protection and transfer of personal data.
Epilepsy Matters Cymru must have a legal basis for processing your personal data and in turn providing you with these services. In doing so, the Company acts as a Data Controller.
Obligations: As a training provider and consultancy service, Epilepsy Matters Cymru is responsible for ensuring that all data is:
processed lawfully, fairly and in a transparent manner
collected for specified, explicit and legitimate purposes and not be further processed in a manner which is incompatible with those purposes
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
accurate and current
kept in a form which permits identification of data subjects for no longer than is necessary, for the purposes for which the data is processed
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage
Legal Basis for Processing Data: In all instances, personal data via direct or indirect means, either supplied by yourself or obtained via a public forum is received, data will only be used on the basis for legitimate purposes for training and consultations.
Legitimate Interest; processing is necessary for the purposes of our legitimate interest to provide training and private consultations.
How Your Data is Collected: You may provide your personal details via email, telephone enquiry or through the website. Your data may be sent through via a third-party referral.
What Data is Stored and Processed? Epilepsy Matters Cymru will collect personal data in respect of attending a training course or via a private consultation. This data includes contact name; name of the employees’ organisation; dates and times training has been provided. Data in respect of private consultations will include name, date of birth, address, assessment of diagnosis, areas of need and management plan. Copies of letters produced will be sent to the individual and their respective GP and Consultant, ensuring verbal consent is provided at the time of the consultation.
How is Data Stored and Processed? At Epilepsy Matters Cymru, data is stored on a secure, password protected computer, with relevant security software and appropriate cloud-based mechanisms to protect the restoration of this data when required. Information from consultations will only be shared with the relevant health professionals involved in the individual’s care. Information regarding training may be shared with the relevant services involved in the provision of care. The information will be stored for only for as long as is necessary.
Your Rights as a Data Subject? As an individual, you have several rights in respect to the processing of your personal data. This includes the right to withdraw consent and the right to erasure at any time. If you wish this to enact this right, please contact Epilepsy Matters Cymru via email at