Edinburgh Sports Clinic Privacy Statement For information about your privacy for events and courses please refer to the University of Edinburgh Sport & Exercise's Privacy StatementSection 1: Section 1: Where does Edinburgh Sports Clinic get your personal data from?You provide us with your: Name, Address, Date of Birth, Contact telephone number(s) and email, and your GP name and practice address. If you are accessing one of our discount rates for services, you provide your matriculation number (student), staff number or a business contact from the sports / school organisation you are affiliated withWe also document information in your medical record relating to your assessment, treatment and health management plan. The telephone and email information you provide us will be used to manage your bookings, and share information about your health issue with you.hone and email information you provide us will be used to manage your bookings, and share information about your health issue with you.Section 2: Purposes for processingThe University processes your data in order to manage your health record, as we have a contract with you to provide services. This forms the legal basis for why the University stores and processes your data.Section 3: Information about you: how we use it and with whom we share itThe University uses an external practice management company and its servers to store your information on the University’s behalf, currently Blue Zinc Ltd. The information you have provided is still considered to be used by the University for the University’s purposes and will be as secure as though stored within the University. View their privacy notice at https://www.tm3practicemanagement.com/information/policy/The University uses a company called Wibbi to email you a copy of your exercise programme, and to process this on the University’s behalf, they store a copy of your email address on their UK servers (Amazon) https://wibbi.com/privacy-policy/The University utilises a platform Heidi Health to facilitate transcription of clinical conversations to a client record note. No patient details are stored or used in this process as the output is coped into the TM3 client record https://www.heidihealth.com/uk/legal/privacy-policyThe University my utilise the Vald Performance platform to measure strength in a range of devices. To access normative data for comparison and give detailed feedback, the system requires a profile to be created including name, date of birth for age, and sex. https://valdperformance.com/policies/privacy-policySharing information with other health and sport professionalsYour data will be shared with your GP or other Consultant / Health professional, in the form of a referral and / or discharge letter, in order to access services for you and to maintain your central NHS health record. The University uses a software company Egress to send medical correspondence securely by email, including referrals to other clinicians and for copies of letters sent to clients https://www.egress.com/legal/privacy-policyWhere you have funding from sportScotland, your medical record will be maintained by the University using password protected access to their online record keeping system PDMS. The University may share health information with sports, health and coaching staff from sportScotland and other sports governing bodies, with your expressed consent Sharing information with other health and sport professionalsYour data will be shared with your GP or other Consultant / Health professional, in the form of a referral and / or discharge letter, in order to access services for you and to maintain your central NHS health record.Where you have funding from sportScotland, your medical record will be maintained by the University using password protected access to their online record keeping system PDMS. The University may share health information with sports, health and coaching staff from sportScotland and other sports governing bodies, with your expressed consent. Sharing information with insurersWe may be asked to share information about you with your insurer for the following purposes:to provide clinical quality information;to allow them to make a funding decision on behalf of a patient;to invoice them for services the University provides to insured patients;to notify them of any serious incidents, orto assist them when investigating an insured patient’s complaint. We will not share your data with any third party. Section 4: Further InformationAutomated decision-makingWe do not use profiling or automated decision-making processes. Some processes are semi-automated (such as anti-fraud data matching) but a human decision maker will always be involved before any decision is reached in relation to you.Retention of data and your rightsFor information about how long your data is held, please consult full retention schedules at https://digital.nhs.uk/codes-of-practice-handling-information. In most cases, retention of medical records for an adult is 8 years and for a child this is until their 25th birthday.You have the right to request access to, copies of and rectification or erasure of personal data held by the University and can request that we restrict processing or object to processing, as well as the right to data portability (i.e. the right to ask us to put your data into a format that means it can be transferred easily to a different organisation). If you wish to make use of one of these rights, please email your local contact heather.binnington@ed.ac.uk. ConsentThe University have asked for your consent in order to assess and manage your health issue according to best practice and to process your personal data. You can withdraw this consent in whole or part at any time. To withdraw consent, please email your local contact heather.binnington@ed.ac.uk who will explain the consequences of doing so in any particular case and initiate proceedings for withdrawing consent. Data controller and contact detailsFor data collected under this privacy notice, the University of Edinburgh (the “University”) is the Data Controller (as that term is defined in the EU General Data Protection Regulation (Regulation (EU) 2016/679), registered with the Information Commissioner’s Office, Registration Number Z6426984You can contact our Data Protection Officer at dpo@ed.ac.uk. Our data protection policy is on our website at http://www.ed.ac.uk/records-management/data-protection/data-protection-policyTransfers outside of EEAThe University will only transfer data to countries outside the EEA when satisfied that both the party which handles the data and the country it is processing it in provide adequate safeguards for personal privacy. Details of such transfers and safeguards are on our website.Complaints• If you are unhappy with the way we have processed your personal data you have the right to complain to the Information Commissioner’s Office at casework@ico.org.uk but we ask that you raise the issue with our Data Protection Officer first. If you have any questions, please contact Heather Binnington, Sport & Exercise Medicine Manager, heather.binnington@ed.ac.uk or 0131 650 2578 This article was published on 2024-05-13