Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

Website and General Enquiries Privacy Notice

StatusWorking draft
Version1.0-draft
OwnerData Protection Officer
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To explain how the public Healing Process website and general enquiry routes use personal information. This draft must be completed with the production contact details, hosting, form processor, analytics configuration and retention periods before publication.

2. Scope and status

This notice covers ordinary website visits, cookie choices, demonstration or provider enquiries, accessibility feedback, event registrations and non-clinical support. It does not cover patient care accounts or provider-linked clinical processing, which require separate deployment-specific privacy information.

Core supplier and product policy

3. Policy principles

  • The public website must not invite or accept wound photographs, NHS numbers, medical records or confidential patient information through a general form.
  • Only essential storage is used by default in this prototype. Optional analytics or marketing technology must remain off until the person has made a valid choice and the notice accurately describes it.
  • The operator will process enquiry data only for the stated contact, relationship and security purposes and will not sell it or use it for behavioural health advertising.
  • Where a person accidentally submits health information, access will be restricted and the information handled under the incident and deletion/retention process rather than routinely added to a marketing system.

4. Mandatory requirements

  • State the full controller identity, registered address, privacy contact and supervisory authority route in production.
  • List actual categories such as name, work email, organisation, message, technical logs, IP address, browser and cookie preference.
  • Identify the lawful basis for each purpose, including responding to requests, legitimate security/administration, legal obligation or consent for optional communications.
  • Name or describe recipients such as approved hosting, form, CRM, security and communications providers and document international transfers.
  • State retention periods or criteria for unsuccessful enquiries, active commercial relationships, security logs, consent records and complaints.
  • Explain access, correction, erasure, restriction, objection, portability where applicable, consent withdrawal and complaint rights.
  • Provide an unsubscribe route for promotional communication and retain only the minimum suppression record needed to respect it.
  • Keep clinical account privacy notices separate and link to the correct controller/provider information at enrolment.

5. Procedure and escalation

  • The privacy owner verifies the live data flow before launch and after each website, cookie, CRM or form change.
  • Rights requests are routed to the correct controller, identity is verified proportionately and responses are recorded.
  • Accidental clinical submissions are isolated from ordinary enquiry systems, assessed for risk and handled under approved instructions.
  • Material notice changes are dated and, where appropriate, brought to the attention of affected people rather than silently replacing prior wording.

6. Roles and responsibilities

Data Protection Officer

approves the live notice and rights process.

Website/Product owner

keeps forms and tags consistent with the stated purposes.

Marketing/Support

use enquiry data only for authorised contact and avoid collecting health information.

Security

protects website logs and investigates abuse.

Suppliers

process only under written terms.

7. Records, confidentiality and retention

Retain notice versions, data-flow review, consent and preference records, enquiries, suppression records, rights requests, incidents, supplier terms and deletion evidence.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review at least annually and before changes to forms, analytics, cookies, CRM, hosting, communications or international transfers. Test that optional tags remain blocked until valid choice.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre