Healing Process policy suite
Cookie and Tracking Technologies Policy
1. Purpose
To provide transparent, user-controlled handling of cookies, local storage, pixels, software development kits and similar technologies on the Healing Process public website and apps.
2. Scope and status
This policy covers browser storage, cookie preferences, analytics, embedded media, advertising, app analytics and third-party scripts. Clinical authentication and security technologies are separately documented in the relevant app privacy information.
Core supplier and product policy
3. Policy principles
- Technologies strictly necessary for a requested service may operate without optional consent, but their purpose and duration remain transparent.
- Optional analytics, personalisation or marketing is disabled until a valid affirmative choice and can be rejected as easily as accepted.
- Health information, wound-page viewing or clinical account activity will not be used for behavioural advertising.
- A consent banner is not a substitute for technical blocking, accurate inventory and supplier control.
4. Mandatory requirements
- Maintain an inventory stating name, provider, purpose, category, data, lifetime, domain and international-transfer status.
- Run periodic scans and code review to detect undeclared technologies and third-party changes.
- Use a consent platform or equivalent control that blocks optional tags before choice and records the version, selection and time.
- Provide granular controls where categories differ and preserve essential access when optional technologies are rejected.
- Avoid manipulative design, pre-ticked choices, bundled consent or making the reject route harder to use.
- Provide a persistent route to change preferences and withdraw optional consent.
- Assess embedded video, maps, chat, social and font services before use and use privacy-enhancing modes where available.
- Align app SDK consent and disclosure with mobile-platform and data-protection requirements.
5. Procedure and escalation
- Before a new tag or SDK is enabled, the owner submits purpose, data and supplier details for privacy and security approval.
- A release test verifies no optional request occurs before choice and that withdrawal stops future use.
- An undeclared technology is disabled pending assessment and affected notice/consent records are reviewed.
- Consent logs are retained only as long as necessary to demonstrate the choice and are protected from use for unrelated profiling.
6. Roles and responsibilities
Website owner
maintains implementation and inventory.
DPO
approves category, consent and notice wording.
Engineering
implements blocking, preference and withdrawal correctly.
Marketing
does not add tags outside change control.
Suppliers
do not repurpose data beyond contract.
7. Records, confidentiality and retention
Keep inventories, scan reports, approvals, consent configuration and versions, choice logs, supplier terms, tests, incidents and remediation.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review at least every six months and after each website/app release involving third parties. Monitor undeclared tags, consent failures, preference changes and complaints.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
