This document establishes the complete Information Governance (IG) framework for Purple Aura.
It ensures that:
- Personal data is processed lawfully and safely
- Patient confidentiality is always maintained
- Staff follow consistent, auditable procedures
- The clinic meets obligations under:
- UK GDPR Data Protection Act 2018
- NMC Code
- ICO guidance
- Aesthetic sector best practice (JCCP, BAMAN)
2. SCOPE
This policy applies to:
- All patient data
- All staff data
- All clinical and administrative systems
- All data formats:
- Electronic
- Paper
- Verbal
3. CLINIC STRUCTURE & DATA GOVERNANCE MODEL
3.1 Shared Clinical Environment
Purple Aura operates a shared clinical model, where independent practitioners deliver services within the same premises.
Each practitioner:
- Operates their own business
- Maintains independent clinical records
- Uses their own secure digital systems
3.2 Data Controllers
- Holly Price → Data Controller for Purple Aura clients
- Lorna Timms → Data Controller for her clients
The treating practitioner is always the Data Controller
3.3 Systems & Separation
- Each practitioner uses their own Aesthetic Nurse Software (ANS) patient records systems
- Systems are separate and secure
- No routine shared access exists
4. LIMITED DATA ACCESS (DATA PROCESSOR ROLE)
4.1 Purpose
To ensure:
- Patient safety
- Continuity of care
- Risk management
- Business continuity
4.2 Exceptional Circumstances Only
Access to another practitioner’s records may occur ONLY in:
Clinical Situations
- Sickness or absence cover
- Patient-requested review or contingency
- Complications or emergency care
- Out-of-hours treatment
Business Continuity
- Serious illness or incapacity
- Death of a practitioner
- Operational disruption
4.3 Role During Access
- The accessing practitioner becomes a Data Processor
- Access is:
- Necessary/Proportionate
- Documented
Data Controller responsibility remains unchanged
5. GDPR PRINCIPLES
Purple Aura complies with:
5.1 Lawfulness, Fairness, Transparency
Data is processed legally and clearly explained to patients
5.2 Purpose Limitation
Data is collected only for specific clinical purposes
5.3 Data Minimisation
Only relevant information is collected
5.4 Accuracy
Records must be complete and up to date
5.5 Storage Limitation
Data retained only as long as required
5.6 Integrity & Confidentiality
Data is securely stored and protected
6. PRIVACY NOTICE & FAIR PROCESSING NOTICE
6.1 What We Collect
- Name, DOB, contact details
- Medical history
- Treatment records
- Photos (with consent)
- Payment and appointment data
6.2 Why We Collect It
- Safe treatment provision
- Legal and insurance compliance
- Appointment management
- Communication
- Marketing (with consent only)
6.3 Lawful Basis
- Healthcare provision (Article 9)
- Contract
- Legal obligation
- Consent
6.4 YOUR RIGHTS
Right of Access (SAR)
You have the right to request a copy of your personal data.
- Requests may be made in writing or email
- You will receive your data within 30 days
- Your data will be provided:
- Securely (e.g. encrypted email via Microsoft Azure)
- In a clear, readable format
Right to Rectification
You may request correction of inaccurate data.
We may require evidence to maintain clinical accuracy.
Right to Erasure
You may request deletion of your data, however:
- Clinical records required for legal or insurance purposes will be retained
- Marketing data can be removed immediately
Right to Restrict Processing
You may request limits on how your data is used.
Right to Data Portability
You may request your data:
- In a structured electronic format
- Sent securely to you or another provider
Right to Object
You may object to certain types of processing, including marketing.
✅ Automated Decision Making
Purple Aura does not carry out automated decision-making affecting care.
