This document explains how we use your personal data. We are committed to ensuring the privacy of our clients, employees and potential candidates for job vacancies, and other website visitors. In this policy we explain how we hold, process and retain your personal data.
1. How we use your personal data
1.1 This section provides you with information about:
(a) what personal data we hold and process;
(b) in respect of personal data that we did not collect from you directly, where we obtained that data from, and what types of data we have collected;
(c) the purposes for which we may process your personal data; and
(d) the legal grounds on which we process your data.
1.2 Contact data.We may process information that you provide to us ("contact data"). This profile data may include your name, address, telephone number, email address, gender, date of birth, and employment details. The contact data may be processed for the purposes of performing our contract with you. Processing activities may include contacting you with reminders for appointments, vaccinations, treatments and with information about products or services you have purchased. We may also process your contact data in order to provide you with pet care advice and news about the practice that may affect you, and to request feedback, or that you complete a survey regarding our services. The legal basis for this processing is our legitimate interests in fulfilling our duty of care to you and providing you with the best service. Where you have provided your consent for us to do so, we may contact you regarding the latest promotions and offers regarding our products and services.
1.3 Website data.We may process data about your use of our website and services ("website data"). The website data may include your IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use. The source of the website data is our analytics tracking system. This website data may be processed for the purposes of analysing the use of the website and services. The legal basis for this processing is our legitimate interests, namely monitoring and improving our website and services.
1.4 Enquiry data.We may process information contained in any enquiry you submit to us regarding our products or services, or any available vacancies or career opportunities ("enquiry data"). The enquiry data may be processed for the purposes of offering, marketing and selling relevant products and/or services to you, or for discussing available vacancies or career opportunities with you. The legal basis for this processing is consent.
1.5 Correspondence data.We may process information contained in or relating to any communication that you send to us ("correspondence data"). The correspondence data may include the communication content and metadata associated with the communication. Our website will generate the metadata associated with communications made using the website contact forms. The correspondence data may be processed for the purposes of communicating with you and record-keeping. The legal basis for this processing is our legitimate interests, namely the proper administration of our website and business and communications with users.
1.6 Payment data.We may process payment information relating to goods and services that you purchase from us ("payment data"). The payment data may include your contact details, your card details and the transaction details. The payment data may be processed for the purposes of administering the payment, for the supply of the purchased goods and services, and keeping proper records of those payments. The legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract and our legitimate interests, namely our interest in the proper administration of our website and business.
1.7 Employment data.We may process information that you provide to us in connection with job vacancies and opportunities (“employment data”). This employment data may include your name, address, telephone number, email address, profile pictures, gender, date of birth, relationship status, interests and hobbies, educational details, employment history, immigration status, salary, curriculum vitae, job preferences and employment details.
We may also process your employment data in relation to job vacancies that you have applied for, generally processing any job applications, and facilitating the recruitment process. The legal basis for this processing is our legitimate interests in finding an appropriate person for a particular role. Where you are successful in your job application and we employ you to work for us, other employment data we might collect may include payment details, medical and health information, and other information that may be generated during the course of your employment such as flexible working requests and appraisals. The legal basis for this processing is for the performance of our employment contract with you. We may also collect and process information regarding your criminal record. We may only use information relating to criminal convictions where the law allows us to do so (this will usually be where such processing is necessary to carry out our obligations, for instance where we are required to carry out criminal record checks for particular roles), or where you have consented for us to do so.
1.8 Other processing activities.In addition to the specific purposes for which we may process your personal data set out above, we may also process any of your personal data where such processing is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. Please do not supply any other person's personal data to us, unless we prompt you to do so.
2. Providing your personal data to others
2.1 To our partner service providers.We may disclose your personal data to referral hospitals, our out-of-hours service provider NSVE (North Surrey Veterinary Emergencies), and laboratories insofar as reasonably necessary to ensure the health welfare of animals committed to our care. Where necessary, we may also disclose your personal data to organisations for reasons relating to the microchip registration of your pet. We may also disclose your personal data to Virtual Recall, provider of iRecall, our customer relationship management system whose functions include administering appointment and vaccination reminders to clients.
2.2 Our insurers/professional advisers.We may disclose your personal data to our insurers, professional advisers, and the debt collection agency we instruct insofar as reasonably necessary for the purposes of obtaining and maintaining insurance coverage, managing risks, obtaining professional advice and managing legal disputes.
2.3 For administrative services or staff benefits.We may disclose employee personal data to third parties such as those administering our payroll system or staff benefits (this will include the providers of pension schemes).
2.4 Where we provide your personal data to any third party.Where we share your personal data with any third party, we will ensure this processing is protected by appropriate safeguards including a suitable data processing agreement with that third party.
2.5 To comply with legal obligations.In addition to the specific disclosures of personal data detailed above, we may also disclose your personal data where such disclosure is necessary for compliance with a legal obligation we have to comply with, or in order to protect your vital interests or the vital interests of another individual.
3. Transfers of your personal data outside of the European Economic Area
3.1 Where your personal data is transferred outside of the EEA, we will ensure that either
(a) The European Commission has made an "adequacy decision" with respect to the data protection laws of the country to which it is transferred, or (
b) we have entered into a suitable data processing agreement with the third party situated in that country to ensure the adequate protection of your data. In all cases, transfers outside of the EEA will be protected by appropriate safeguards.
3.2 You acknowledge that personal data that you submit for publication through our website or services may be available, via the internet, around the world. We cannot prevent the use (or misuse) of such personal data by others.
4. Retaining and deleting personal data 4.1 Personal data that we process for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. As far as possible, we will always minimize the data that we hold about you.
4.2 Unless we contact you and obtain your consent for us to retain your personal data for a longer period, we will retain and delete your personal data as follows:
(a) Contact data will be retained for 7 years following the date of our last contact or dealing with you, at the end of which period it will be deleted from our systems. We are required to retain this data for at least 5 years for regulatory reasons. In our experience, retaining this data for longer allows us to provide better care to your pet over the course of its lifetime.
(b) Where enquiry data includes information relating to your pet’s health or clinical treatment, it will be retained for 7 years following the date of our last contact or dealing with you, at the end of which period it will be deleted from our systems. We are required to retain this data for at least 5 years for regulatory reasons. In our experience, retaining this data for longer allows us to provide better care to your pet over the course of its lifetime. Otherwise, enquiry data will be retained for 2 years following the date of our last contact or dealing with you, at the end of which period it will be deleted from our systems.