GDPR Policy

This document establishes the complete Information Governance (IG) framework for Purple Aura.

It ensures that:

  • Personal data is processed lawfully and safely
  • Patient confidentiality is always maintained
  • Staff follow consistent, auditable procedures
  • The clinic meets obligations under:
    • UK GDPR Data Protection Act 2018
    • NMC Code
    • ICO guidance
    • Aesthetic sector best practice (JCCP, BAMAN)

2. SCOPE

This policy applies to:

  • All patient data
  • All staff data
  • All clinical and administrative systems
  • All data formats:
    • Electronic
    • Paper
    • Verbal

3. CLINIC STRUCTURE & DATA GOVERNANCE MODEL

3.1 Shared Clinical Environment

Purple Aura operates a shared clinical model, where independent practitioners deliver services within the same premises.

Each practitioner:

  • Operates their own business
  • Maintains independent clinical records
  • Uses their own secure digital systems

3.2 Data Controllers

  • Holly Price → Data Controller for Purple Aura clients
  • Lorna Timms → Data Controller for her clients

The treating practitioner is always the Data Controller

3.3 Systems & Separation

  • Each practitioner uses their own Aesthetic Nurse Software (ANS) patient records systems
  • Systems are separate and secure
  • No routine shared access exists

4. LIMITED DATA ACCESS (DATA PROCESSOR ROLE)

4.1 Purpose

To ensure:

  • Patient safety
  • Continuity of care
  • Risk management
  • Business continuity

4.2 Exceptional Circumstances Only

Access to another practitioner’s records may occur ONLY in:

Clinical Situations

  • Sickness or absence cover
  • Patient-requested review or contingency
  • Complications or emergency care
  • Out-of-hours treatment

Business Continuity

  • Serious illness or incapacity
  • Death of a practitioner
  • Operational disruption

4.3 Role During Access

  • The accessing practitioner becomes a Data Processor
  • Access is:
    • Necessary/Proportionate
    • Documented

 Data Controller responsibility remains unchanged

5. GDPR PRINCIPLES

Purple Aura complies with:

5.1 Lawfulness, Fairness, Transparency

Data is processed legally and clearly explained to patients

5.2 Purpose Limitation

Data is collected only for specific clinical purposes

5.3 Data Minimisation

Only relevant information is collected

5.4 Accuracy

Records must be complete and up to date

5.5 Storage Limitation

Data retained only as long as required

5.6 Integrity & Confidentiality

Data is securely stored and protected

6. PRIVACY NOTICE & FAIR PROCESSING NOTICE

6.1 What We Collect

  • Name, DOB, contact details
  • Medical history
  • Treatment records
  • Photos (with consent)
  • Payment and appointment data

6.2 Why We Collect It

  • Safe treatment provision
  • Legal and insurance compliance
  • Appointment management
  • Communication
  • Marketing (with consent only)

6.3 Lawful Basis

  • Healthcare provision (Article 9)
  • Contract
  • Legal obligation
  • Consent

6.4 YOUR RIGHTS

Right of Access (SAR)

You have the right to request a copy of your personal data.

  • Requests may be made in writing or email
  • You will receive your data within 30 days
  • Your data will be provided:
    • Securely (e.g. encrypted email via Microsoft Azure)
    • In a clear, readable format

 Right to Rectification

You may request correction of inaccurate data.

We may require evidence to maintain clinical accuracy.

Right to Erasure

You may request deletion of your data, however:

  • Clinical records required for legal or insurance purposes will be retained
  • Marketing data can be removed immediately

Right to Restrict Processing

You may request limits on how your data is used.

Right to Data Portability

You may request your data:

  • In a structured electronic format
  • Sent securely to you or another provider

Right to Object

You may object to certain types of processing, including marketing.

✅ Automated Decision Making

Purple Aura does not carry out automated decision-making affecting care.