Privacy Policy

banner logo

Ilminster Eyecare Ltd.

Customer Privacy Notice.

Introduction

Ilminster Eyecare Ltd T/A Richard Stent Optometrist (hereafter “Richard Stent”) are committed to protecting and respecting your privacy.

This notice explains when and why we may collect personal information about you, how we use it, how it is kept secure and the conditions under which we may disclose it to others.

Richard Stent is a registered data controller and our Data Protection (ICO) Registration number is Z1349448. Richard Stent will collect and use information about all customers: current and former and persons within the community for whom a service is provided (hereafter referred to as "customers”) in accordance with data protection principals within the Data Protection Act (2018) and General Data Protection Regulation (GDPR).

What information we collect about you?

In order to carry out its duties, aims and services Richard Stent must collect and process personal data (including sensitive personal data) relating to its customers.

This information will be collected either directly from you or information will have been sent to us via a third party, NHS, Dr surgery’s or another referring agency.

A record relating to your use of the support and services of the business will be held by the managers and employees of Richard Stent Optometrists.

Data held about you may include, but is not restricted to, the following:

  • Personal identifiers such as name, national insurance number and date of birth

  • Personal medical information

  • Financial details such as benefits received or personal income

  • Personal details relating to special support needs

  • Diary notes/meeting notes

  • Optical consultation notes

  • Next of kin information for emergency purposes

How we use cookies

A cookie is a small file which asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences. We use traffic log cookies to identify which pages are being used. This helps us analyse data about web page traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system. Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

The following first party Cookies may be placed on your computer or device:

Name of Cookie

Purpose

Strictly Necessary?

XSRF_TOKEN

This cookie is provided by the Laravel framework in order to prevent cross-scripting attacks

Yes

richardstent_session

This cookie is provided by the Laravel framework in order to handle sessions

Yes

The analytics service(s) used by Our Site use(s) the following Cookies

Name of Cookie

Name of Provider

Purpose

_ga KM07E1ELM4

Google

Used for Google Analytics

How we use this information

We process personal data relating to you to provide support and services. The legal basis for this processing is for the legitimate interest of the company to perform the running of the business and to perform its obligations to its customers.

In addition, some data may be held and processed for the compliance with the legal obligations of the organisation.

In the case of special category data, we ask for this data to be provided to best safeguard the individual and to provide appropriate optical advice. The legal basis for holding and processing this information is under Article 9(2) paragraph (h) of the Data Protection Act (2018).

We might also hold your contact information for the purposes of updating you with news, services or special offers. We will always ask for your consent to contact you via email.

Who has access to your information?

The data is held in paper format within the main office. Personal information is also held on a computer database accessible only by Richard Stent staff.

Special Category Data

Richard Stent recognises the significance of the processing of special category data and has considered is further obligations under data protection legislation. Special category data is generally defined as:

  • Race or ethnic origin

  • Political opinion

  • Religious or philosophical beliefs

  • Trade union membership

  • Genetic or Biometric data

  • Health data

  • Sexual orientation

Richard Stent will endeavour to limit the collection of this data to where it is absolutely necessary for the provision of services to you.

These records will be kept in the strictest confidence and will not be released to third parties except where it is required to safeguard your vital interests, to provide ongoing health services, where it is necessary to meet statutory obligations, where the disclosure is made for the purpose of prevention or detection of crime or is pursuant to a court order requiring disclosure.

Sharing and Disclosing your Personal Information

Richard Stent may disclose certain personal data to external bodies. At all times, the amount of information disclosed and the manner in which it is disclosed will be in accordance with the provisions of the Data Protection Act and the GDPR.

If your personal data is shared with an external body it will be done so in a manner that is secure and we will only share what is necessary.

Such external bodies may include, but is not limited to:

  • NHS or other Healthcare providers

  • Local authorities

  • Third party service providers specific to the individual needs of the customer, for example Lens or Frame suppliers

  • Third-party IT provision or software providers - any such transfer will be subject to the formal agreement of the third-party provider to ensure protection of your personal data

Data is not shared with or transferred to any country outside the EU

How long do we keep your information?

Richard Stent will keep your personal data only as long as it remains relevant, accurate and is absolutely necessary to conclude the purpose(s) for which it was collected in accordance with Richard Stent's Data Protection and Retention of Records policy.

Notwithstanding the above, we will retain documents (including electronic documents) containing personal data:

  • To the extent that we are required to do so by law

  • If we believe that the documents may be relevant to any ongoing or prospective legal proceedings; and

  • In order to establish, exercise or defend our legal rights

Data will be destroyed via secure means when no longer required.

Access to your information and correction

Richard Stent observes individual's rights to access, rectification or erasure of their data within Data Protection and GDPR legislation.

If you wish to request a copy of the personal data we hold about you, you can do so by contacting the Data Protection Officer, details as below. Subject to the complexity of the data held, Richard Stent will endeavour to provide copy data within a period of one calendar month from the date the request is received.

Similarly, if you wish to rectify any of the data held about yourself or request full or partial erasure you should make such a request to the Data Protection Officer. Any such request will be considered within the legitimate interest of the business and the individual, taking into account business need, safeguarding and best interest considerations as well as in consideration of the guidance provided by the NHS National Data Opt Out. Where you have provided us with your consent to hold your data, for any specific purpose, you have the right to withdraw that consent at any time.

How to contact us

In the first instance, you can contact the business who will undertake to assist your queries.

You can also contact Richard Stent Data Protection Officer as follows:

Mr Richard Stent
12-14 East Street
Ilminster
TA19 0AJ
info@richardstent.co.uk

Or if you wish to make a complaint to the supervising authority or find out more about Data Protection obligations, please contact

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire
SK9 5AF
Tel: 0303 123 1113