Definitions and interpretation
collectively all information that you submit to Higher Healing via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws;
a small text file placed on your computer by this Website when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out in the clause below (Cookies);
Data Protection Laws
any applicable law relating to the processing of personal Data, including but not limited to the Directive 96/46/EC (Data Protection Directive) or the GDPR, and any national implementing laws, regulations and secondary legislation, for as long as the GDPR is effective in the UK;
the General Data Protection Regulation (EU) 2016/679;
Higher Healing, or us
Higher Healing, a company incorporated in England and Wales with registered number 08637734 whose registered office is at 51 Clarkegrove Road Sheffield, S10 2NH;
UK and EU Cookie Law
the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011;
User or you
any third party that accesses the Website and is not either (i) employed by Higher Healing and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to Higher Healing and accessing the Website in connection with the provision of such services; and
the website that you are currently using, http://lh9.7b7.myftpupload.com, and any sub-domains of this site unless expressly excluded by their own terms and conditions.
- the singular includes the plural and vice versa;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- “including” is understood to mean “including without limitation”;
- reference to any statutory provision includes any modification or amendment of it;
- For purposes of the applicable Data Protection Laws, Higher Healing is the “data controller”. This means that Higher Healing determines the purposes for which, and the manner in which, your Data is processed.
What We Do
- Higher Healing provides naturopathy, nutritional, herbal and functional medicine services to clients to improve their health through diet and lifestyle interventions. We focus on preventative healthcare, the optimisation of physical and mental health and chronic health conditions. Through consultation, dietary, lifestyle analysis and functional testing, we aim to understand the underlying causes of your health issues which we will seek to address through personalised dietary therapy, nutraceutical prescription (supplements), herbal medicine and lifestyle advice. We also provide consulting services, workshops and seminars.
- We may collect the following Data, which includes personal Data, from you:
- contact Information such as email addresses and telephone numbers;
- information provided on contact form;
- information provided to make purchases;
- details of contact we have had with you such as referrals and appointment requests
- health information, including previous medical history, dietary, lifestyle, supplement and medicine details, functional testing results, clinic notes and health improvement plans
- GP and other medical healthcare provider contact details
Following completion of your healthcare we retain your personal data for the period defined by our professional associations BANT, AMH and registrant body, CNHC. This enables us to process any formal complaint you may make. In this case the legal basis of our holding your personal data is for contract administration.
How we collect Data
- We collect Data in the following ways:
- data is given to us by you;
- data is received from other sources; and
- data is collected automatically.
Data that is given to us by you
- Higher Healing will collect your Data in a number of ways, for example:
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you register with us and set up an account to receive our products/services;
- through completing an intake form or during a consultation
- through signing and agreeing to Terms and Conditions
- when you complete surveys that we use for research purposes (although you are not obliged to respond to them);
- when you enter a competition or promotion through a social media channel;
- when you make payments to us, through this Website or otherwise;
- when you elect to receive marketing communications from us;
- when you use our services;
- google analytics;
- other third party services specified via website;
Data that is received from third parties
- Higher Healing will receive Data about you from the following third parties:
- Test results from functional testing companies. We use this information in order to provide you with direct healthcare. This means that the legal basis of our holding your personal data is for legitimate interest.
- We may obtain sensitive information from other healthcare providers. The provision of this information is subject to you giving us your express consent. If we do not receive this consent from you, we will not be able to coordinate your healthcare with that provided by other providers which means the healthcare provided by us may be less effective.
Data that is received from publicly available third parties sources
- We will receive Data about you from the following publicly available third party sources:
Data that is collected automatically
- To the extent that you access the Website, we will collect your Data automatically, for example:
- we automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation, and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed “Cookies”.
Our use of Data
- Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- internal record keeping;
- improvement of our products / services;
- transmission by email of marketing materials that may be of interest to you;
- contact for market research purposes which may be done using email, telephone, fax or mail. Such information may be used to customise or update the Website;
- We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed “Your rights” below).
- For the delivery of direct marketing to you via e-mail, we’ll need your consent, whether via an opt-in or soft-opt-in:
- soft opt-in consent is a specific type of consent which applies when you have previously engaged with us (for example, you contact us to ask us for more details about a particular product/service, and we are marketing similar products/services). Under “soft opt-in” consent, we will take your consent as given unless you opt-out.
- for other types of e-marketing, we are required to obtain your explicit consent; that is, you need to take positive and affirmative action when consenting by, for example, checking a tick box that we’ll provide.
- if you are not satisfied about our approach to marketing, you have the right to withdraw consent at any time. To find out how to withdraw your consent, see the section headed “Your rights” below.
- When you register with us and set up an account to receive our services, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
Who we share Data with
- We may share your Data with the following groups of people for the following reasons:
- our employees, agents and/or professional advisors – to obtain advice from professional advisers;
- third party service providers who provide services to us which require the processing of personal data – to help third party service providers in receipt of any shared data to perform functions on our behalf to help ensure the website runs smoothly;
- third party payment providers who process payments made over the Website – to enable third party payment providers to process user payments and refunds;
- relevant authorities – to facilitate the detection of crime or the collection of taxes or duties to fulfil duty of care;
- We will keep information about you confidential. We will only disclose your information with other third parties with your express consent with the exception of the following categories of third parties:
- Our registrant body, CNHC and our professional association, BANT or AMH, for the processing of a complaint made by you
- Any contractors and advisors that provide a service to us or act as our agents on the understanding that they keep the information confidential
- Anyone to whom we may transfer our rights and duties under any agreement we have with you
- Any legal or crime prevention agencies and/or to satisfy any regulatory request (eg, CNHC) if we have a duty to do so or if the law allows us to do so
- Information may be shared with supplement companies and functional testing companies as part of providing you with direct healthcare. We do not share sensitive information with supplement companies. Testing companies provide us with results.
- We will seek your express consent before sharing your information with your GP or other healthcare providers. However if we believe that your life is in danger then we may pass your information onto an appropriate authority (such as the police, social services in the case of a child or vulnerable adult, or GP in case of self-harm) using the legal basis of vital interests.
- We may share your case history in an anonymised form with our peers for the purpose of professional development. This may be at clinical supervision meetings, conferences, online forums, and through publishing in medical journals, trade magazines or online professional sites. We will always seek your explicit consent before we would discuss your case anonymously or process your data this way.
Keeping Data secure
- We will use technical and organisational measures to safeguard your Data, for example:
- We only use information that may identify you in accordance with GDPR. This requires us to process personal data only if there is a legitimate basis for doing so and that any processing must be fair and lawful.
- Within the health sector, we also have to follow the common law duty of confidence, which means that where identifiable information about you has been given in confidence, it should be treated as confidential and only shared for the purpose of providing direct healthcare. We will protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared.
- We also ensure the information we hold is kept in secure locations, restrict access to information to authorised personnel only, protect personal and confidential information held on equipment such as laptops with encryption (which masks data so that unauthorised users cannot see or make sense of it). We ensure external data processors that support us are legally and contractually bound to operate and prove security arrangements are in place where data that could or does identify a person are processed.
- Higher Healing is registered with the Information Commissioner’s Office (ICO) as a data controller and collects data for a variety of purposes. A copy of the registration is available through the ICO website (search by business name). We have been registered with the ICO since the business became active.
- Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: hello(at) higherhealing.com.
- If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
- All records held by the Higher Healing will be kept for the duration specified by guidance from our professional associations BANT and AMH or until you request that the Data be deleted.
- Even if we delete your Data, it may persist on backup or archival media for legal, tax or regulatory purposes.
- You have the following rights in relation to your Data:
- Right to access – the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is “manifestly unfounded or excessive.” Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- Right to correct – the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase – the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data – the right to “block” us from using your Data or limit the way in which we can use it.
- Right to data portability – the right to request that we move, copy or transfer your Data.
- Right to object – the right to object to our use of your Data including where we use it for our legitimate interests.
- To make enquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: hello(at) higherhealing.com.
- If you are not satisfied with the way a complaint you make in relation to your Data is handled by us, you may be able to refer your complaint to the relevant data protection authority. For the UK, this is the Information Commissioner’s Office (ICO). The ICO’s contact details can be found on their website at https://ico.org.uk.
- It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
If you want to access your data you must make a subject access request in writing to hello(at) higherhealing.com. Under special circumstances, some information may be withheld. We shall respond within 20 working days from the point of receiving the request and all necessary information from you. Our response will include the details of the personal data we hold on you including:
- Sources from which we acquired the information
- The purposes of processing the information
- Entities with whom we are sharing the information
You have the right, subject to exemptions, to ask to:
- Have your information deleted
- Have your information corrected or updated where it is no longer accurate
- Ask us to stop processing information about you where we are not required to do so by law or in accordance with the BANT and CNHC guidelines.
- Receive a copy of your personal data, which you have provided to us, in a structured, commonly used and machine readable format and have the right to transmit that data to another controller, without hindrance from us.
- Object at any time to the processing of personal data concerning you.
- We do not carry out any automated processing, which may lead to automated decision based on your personal data.
- If you would like to invoke any of the above rights then please write to the Data Controller, Roma Bansil at Higher Healing, 82 Hay Lane, Monkspath, Solihull, B90 4TA, UK or email hello(at) higherhealing.com.
Transfers outside the European Economic Area
- Data which we collect from you may be stored and processed in and transferred to countries outside of the European Economic Area (EEA). For example, this could occur if our servers are located in a country outside the EEA or one of our service providers is situated in a country outside the EEA.
- We will only transfer Data outside the EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data, eg by way of data transfer agreement, incorporating the current standard contractual clauses adopted by the European Commission, or by signing up to the EU-US Privacy Shield Framework, in the event that the organisation in receipt of the Data is based in the United States of America.
- To ensure that your Data receives an adequate level of protection, we have put in place appropriate safeguards and procedures with the third parties we share your Data with. This ensures your Data is treated by those third parties in a way that is consistent with the Data Protection Laws.
Links to other websites
Changes of business ownership and control
- We may also disclose Data to a prospective purchaser of our business or any part of it.
- In the above instances, we will take steps with the aim of ensuring your privacy is protected.
- All Cookies used by this Website are used in accordance with current UK and EU Cookie Law.
- Before the Website places Cookies on your computer, you will be presented with a message bar requesting your consent to set those Cookies. By giving your consent to the placing of Cookies, you are enabling Higher Healing to provide a better experience and service to you. You may, if you wish, deny consent to the placing of Cookies; however certain features of the Website may not function fully or as intended.
- This Website may place the following Cookies:
Type of Cookie
Analytical/ performance cookies
They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
- You can find a list of Cookies that we use in the Cookies Schedule.
- You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies but this can be changed. For further details, please consult the help menu in your internet browser.
- You can choose to delete Cookies at any time; however you may lose any information that enables you to access the Website more quickly and efficiently including, but not limited to, personalisation settings.
- It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
- For more information generally on cookies, including how to disable them, please refer to aboutcookies.org. You will also find details on how to delete cookies from your computer.
- We do use electronic forms on our website making use of an available ‘forms module’ which has a number of built-in features to help ensure privacy. We also aim to use secure forms where appropriate.
- Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
- This Agreement will be governed by and interpreted according to the law of England and Wales. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the English and Welsh courts.
You may contact Higher Healing by email at hello(at)higherhealing.co.uk
24 May 2018
Below is a list of the cookies that we use. We have tried to ensure this is complete and up to date, but if you think that we have missed a cookie or there is any discrepancy, please let us know.
We use the following analytical/performance cookies:
Description of Cookie
We use this cookie to help us analyse how users use the website
To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout