Privacy Policy
At My Health Platform Limited we’re committed to protecting and respecting your privacy.
My Health Platform Ltd is a company registered in England and Wales with number: 14837730 and registered address: 27 St George’s Road, Cheltenham, Gloucestershire GL50 3DT. My Health Platform is registered with the Information Commissioner’s Office, wtih registration reference ZB671801. All My Health Platform practitioners are independent third parties, but also required to comply with this policy.
My Health Platform also operates a website, with the domain name www.myhealthplatform.co.uk.
My Health Platform holds some information about you. This policy outlines how that information is used, who we may share that information with and how we keep it secure. This Policy explains when and why we collect personal information about people who visit our website, how we use it, the conditions under which we may disclose it to others and how we keep it secure. By using our website, you’re agreeing to be bound by this Policy.
This Privacy Policy explains our policies and practices regarding our processing of your personal data and explains your privacy rights under applicable privacy and security laws.
This privacy policy complements other policies and agreements, which may be used in more specific terms, for example when collecting data on an online form, or contractual arrangements.
This policy explains when and why we collect personal information about people who visit our website, how we use it, the conditions under which we may disclose it to others and how we keep it secure.
This notice does not provide exhaustive detail. However, we are happy to provide any additional information or explanation needed. Any requests for this should be sent to info@myhealthplatform.co.uk.
How do we collect information from you?
My Heath Platform provides online health education and nutritional therapy services to clients to improve their health through diet and lifestyle interventions. We focus on preventative healthcare, the optimisation of physical and mental health and chronic health conditions. Through nutritional therapy consultations, dietary and lifestyle analysis and biochemical testing, we aim to understand the underlying causes of your health issues which we will seek to address through personalised dietary therapy, nutraceutical prescription (supplements) and lifestyle advice.
How We Obtain Your Personal Data Information provided by you
We obtain information about you when you use our website, for example, when you complete the contact form, purchase a product from our store, create an account on our website, subscribe to our service or publications, request marketing to be sent to you or engage with other forms within our site.
What type of information is collected from you?
Information provided by you
You provide us with personal data in the following ways:
– By completing a nutritional therapy questionnaire
– By signing a terms of engagement form
– During a nutritional therapy consultation
– Through email, over the telephone or by post
– By taking credit card and online payment
– By completing an online form on our website to purchase courses or functional tests
– By completing online health forms in the Health Portal on our website
– By filling out an online contact form
– By creating an account on our website
– By subscribing to our services or publications
– By requesting marketing to be sent to you.
– By engaging with other forms on our site and commenting on Q&A Forums
This may include the following information:
– Basic details such as name, title, gender, address, email address, contact details and next of kin
– IP address and information regarding what pages are accessed and when
– Details of contact we have had with you such as referrals and appointment requests
– Health information including your previous medical history, dietary, lifestyle, supplement and medicine details, biochemical test results, clinic notes and health improvement plans
– Other personal data you provide to us in your contact with us through our website, such as description of yourself, health, genetic or otherwise special category data that you give to us
– GP contact information
– Bank details
– If you purchase a product from us, your card information is not held by us, it is collected by our third-party payment processors, who specialise in the secure online capture and processing of credit/debit card transactions, as explained below.
We use this information in order to provide you with direct healthcare. This means that the legal basis of our holding your personal data is for legitimate interest.
Following completion of your healthcare we retain your personal data for the period defined by our professional association BANT and registrant body, CNHC. This enables us to process any complaint you may make. In this case the legal basis of our holding your personal data is for contract administration.
Information we get from other sources
We may obtain sensitive medical information in the form of test results from biochemical testing companies. We use this information in order to provide you with direct healthcare. This means that the legal basis of our holding your personal data is for legitimate interest.
We may obtain sensitive information from other healthcare providers. The provision of this information is subject to you giving us your express consent. If we do not receive this consent from you, we will not be able to coordinate your healthcare with that provided by other providers which means the healthcare provided by us may be less effective.
How we use your personal data
We act as a data controller for use of your personal data to provide direct healthcare. We also act as a controller and processor in regard to the processing of your data from third parties such as testing companies and other healthcare providers. We act as a data controller and processor in regard to the processing of credit card and online payments.
We undertake at all times to protect your personal data, including any health and contact details, in a manner which is consistent with our duty of professional confidence and the requirements of the UK General Data Protection Regulation (UK GDPR) concerning data protection. We will also take reasonable security measures to protect your personal data storage.
We may use your personal data where there is an overriding public interest in using the information e.g. in order to safeguard an individual, or to prevent a serious crime. Also where there is a legal requirement such as a formal court order. We may use your data for marketing purposes such as newsletters but this would be subject to you giving us your express consent.
Do you share my information with other organisations?
We will keep information about you confidential. We will only disclose your information with other third parties with your express consent with the exception of the following categories of third parties:
– Our registrant body, CNHC and our professional association, BANT, for the processing of a complaint made by you
– Firstbeat Technologies Oy, a company registered in Finland, as a data processor for the purposes of providing our services (when you purchase the course including the Firstbeat wearable monitor). We only supply your email address in order for them to set up the service and for you to provide them with your data via their App – Firstbeat Life. Please read Firstbeat’s Privacy Policy (link available via My Health Platform website)
– Any contractors and advisors that provide a service to us or act as our agents on the understanding that they keep the information confidential
– Anyone to whom we may transfer our rights and duties under any agreement we have with you
– Any legal or crime prevention agencies and/or to satisfy any regulatory request (eg, CNHC) if we have a duty to do so or if the law allows us to do so
We may share your information with supplement companies and biochemical testing companies as part of providing you with direct healthcare. We will not include any sensitive information
We will seek your express consent before sharing your information with your GP or other healthcare providers. However if we believe that your life is in danger then we may pass your information onto an appropriate authority (such as the police, social services in the case of a child or vulnerable adult, or GP in case of self-harm) using the legal basis of vital interests.
We may share your case history in an anonymised form with our peers for the purpose of professional development. This may be at clinical supervision meetings, conferences, online forums, and through publishing in medical journals, trade magazines or online professional sites.
We will seek your explicit consent before processing your data in this way.
Who has access to your information?
We will not sell or rent your information to third parties.
We will not share your information with third parties for marketing purposes.
Third Party Service Providers working on our behalf: We may pass your information to our third-party service providers, agents subcontractors and other associated organisations for the purposes of completing tasks and providing services to you on our behalf (for example to process donations and send you mailings).
However, when we use third party service providers, we disclose only the personal information that is necessary to deliver the service and we have a contract in place that requires them to keep your information secure and not to use it for their own direct marketing purposes. Please be reassured that we will not release your information to third parties beyond the company for them to use for their own direct marketing purposes, unless you have requested us to do so, or we are required to do so by law, for example, by a court order or for the purposes of prevention of fraud or other crime.
When you are using our secure store pages, your payments are processed by a third-party payment processor, who specialises in the secure online capture and processing of credit/debit card transactions. If you have any questions regarding secure transactions, please contact us.
We may transfer your personal information to a third party as part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganisation, or if we’re under a duty to disclose or share your personal data in order to comply with any legal obligation or to enforce or apply our terms of use or to protect the rights, property or safety of our supporters and customers. However, we will take steps with the aim of ensuring that your privacy rights continue to be protected.
What are your rights?
Every individual has the right to see, amend, delete or have a copy, of data held that can identify you, with some exceptions. You do not need to give a reason to see your data.
If you want to access your data you must make a subject access request in writing to info@myhealthplatform.co.uk. Under special circumstances, some information may be withheld. We shall respond within 20 working days from the point of receiving the request and all necessary information from you. Our response will include the details of the personal data we hold on you including:
– Sources from which we acquired the information
– The purposes of processing the information
– Persons or entities with whom we are sharing the information
You have the right, subject to exemptions, to ask to:
– Have your information deleted
– Have your information corrected or updated where it is no longer accurate
– Ask us to stop processing information about you where we are not required to do so by law or in accordance with the BANT and CNHC guidelines.
– Receive a copy of your personal data, which you have provided to us, in a structured, commonly used and machine readable format and have the right to transmit that data to another controller, without hindrance from us.
– Object at any time to the processing of personal data concerning you
We do not carry out any automated processing, which may lead to automated decision based on your personal data.
If you would like to invoke any of the above rights then please write to the Data Controller at My Health Platform, 27 St Georges Road, Cheltenham, GL50 3DT or email info@myhealthplatform.co.uk.
What safeguards are in place to ensure data that identifies me is secure?
We only use information that may identify you in accordance with UK GDPR. This requires us to process personal data only if there is a legitimate basis for doing so and that any processing must be fair and lawful.
Within the health sector, we also have to follow the common law duty of confidence, which means that where identifiable information about you has been given in confidence, it should be treated as confidential and only shared for the purpose of providing direct healthcare. We will protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared.
We also ensure the information we hold is kept in secure locations, restrict access to information to authorised personnel only, protect personal and confidential information held on equipment such as laptops with encryption (which masks data so that unauthorised users cannot see or make sense of it). We ensure external data processors that support us are legally and contractually bound to operate and prove security arrangements are in place where data that could or does identify a person are processed.
My Health Platform is registered with the Information Commissioner’s Office (ICO) as a data controller and collects data for a variety of purposes. A copy of the registration is available through the ICO website (search by business name).
How long do you hold confidential information for?
All records held by My Health Platform will be kept for the duration specified by guidance from our professional association BANT.
Website technical details
Forms
We do use electronic forms on our website making use of an available ‘forms module’ which has a number of built-in features to help ensure privacy. We also aim to use secure forms where appropriate.
Use of ‘cookies’
Like many other websites, the My Health Platform website uses cookies. ‘Cookies’ are small pieces of information sent by an organisation to your computer and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. For example, we use cookies to store your country preference. This helps us to improve our website and deliver a better more personalised service.
Advanced areas of this site may use cookies to store your presentation preferences in a purely technical fashion with no individually identifiable information. Note also our statement on analytics software below – as analytics software also uses cookies to function.
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org
To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout
Turning cookies off may result in a loss of functionality when using our website.
Main Cookies used on our site
Google Analytics
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site.
The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited
For more information on Google Analytics’ privacy policy visit here – http://www.google.com/analytics/learn/privacy.html
Google Maps
These are Google Maps third party cookies, which are unique identifiers to allow traffic analysis to Google Maps.
Cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited.
You have a choice about whether or not you wish to receive information from us. If you do not want to receive direct marketing communications from us about our exciting products and services, then you can select your choices by ticking the relevant boxes situated on the form on which we collect your information.
We will not contact you for marketing purposes by email, phone or text message unless you have given your prior consent. We will not contact you for marketing purposes by post if you have indicated that you do not wish to be contacted.
How you can access and update your information
The accuracy of your information is important to us. You have the right to request a copy of the information we hold about you so that you can ensure its accuracy.
Right to erasure
Visitors / users of the site should have the ability to have all records of their personal data held by a business where there is no legitimate reason for that business to maintain that reason. This includes where GDPR is super-ceded by other laws governing the details obtained.
This section should clarify how users request erasure.
Security precautions in place to protect the loss, misuse or alteration of your information
When you give us personal information, we take steps to ensure that it’s treated securely. Any sensitive information (such as credit or debit card details) is encrypted and protected with the following software 128 Bit encryption on SSL. When you are on a secure page, a lock icon will appear in the search bar next to your URL in browsers such as Google Chrome.
Non-sensitive details (your email address etc.) are transmitted normally over the Internet, and this can never be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems. Where we have given (or where you have chosen) a password which enables you to access certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Profiling
We may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you. We may make use of additional information about you when it is available from external sources to help us do this effectively. We may also use your personal information to detect and reduce fraud and credit risk.
Links to other websites
Our website may contain links to other websites run by other organisations. This privacy policy applies only to our website‚ so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.
In addition, if you linked to our website from a third-party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and recommend that you check the policy of that third party site.
16 or Under
We are concerned to protect the privacy of children aged 16 or under. If you are aged 16 or under‚ please get your parent/guardian’s permission beforehand whenever you provide us with personal information.
Transferring your information outside of Europe
As part of the services offered to you through this website, the information which you provide to us may be transferred to countries outside the European Union (“EU”). By way of example, this may happen if any of our servers are from time to time located in a country outside of the EU. These countries may not have similar data protection laws to the UK. By submitting your personal data, you’re agreeing to this transfer, storing or processing. If we transfer your information outside of the EU in this way, we will take steps to ensure that appropriate security measures are taken with the aim of ensuring that your privacy rights continue to be protected as outlined in this Policy.
If you use our services while you are outside the EU, your information may be transferred outside the EU in order to provide you with those services.
Analytics
Like most websites, we make use of analytics software in order to help us understand the trends in popularity of our website and of different sections. We make no use of personally identifiable information in any of the statistical reports we use from this package. We use an analytics package called Google Analytics who provide details of their privacy policy on the Google website.
Complaints
If you have a complaint regarding the use of your personal data then please contact us by writing to the Data Controller at My Health Platform Ltd, 27 St George’s Road, Cheltenham, Gloucestershire GL50 3DT. or email info@myhealthplatform.co.uk and we will do our best to help you.
If your complaint is not resolved to your satisfaction and you wish to make a formal complaint to the Information Commissioner’s Office (ICO), you can contact them on 01625 545745 or 0303 1231113.
Review of this Policy
We keep our Privacy Notice under regular review. This Privacy Notice was last reviewed in April 2024.