PRIVACY STATEMENT

This is the privacy notice of Brookhaven Medical Centre. In this document, “we”, “our”, or “us” refers to Brookhaven Medical Centre.

Our practice is located at Brookhaven Medical Centre, Corduff Primary Care Centre, Blackcourt Road, Blanchardstown, Dublin 15.

We operate the brookhavenmedicalcentre.ie website. When you use the brookhavenmedicalcentre.ie website to book a consultation, request a prescription or any other service we offer, you enter personal information that allows us to process your request.

We process your personal information on the website to allow you to book and pay for our services. Our website gathers only the most essential information from you that we need to offer the service. We do not store any of your medical history or medical records on the website except as set out below. Your medical notes are not connected in any way with the brookhavenmedicalcentre.ie website.

  • This is a notice to inform you of our policy about all information that we record about you. It sets out the conditions under which we may process any information that we collect from you, or that you provide to us. It covers information that could identify you (“personal information”) and information that could not. In the context of the law and this notice, “process” means collect, store, transfer, use or otherwise act on information.
  • If there are one or more points below with which you are not happy, your only recourse is to leave our website and not use it to book appointments or request any other services.
  • We take seriously the protection of your privacy and confidentiality. We understand that all visitors to our website are entitled to know that their personal data will not be used for any purpose unintended by them, and will not accidentally fall into the hands of a third party.
  • We undertake to preserve the confidentiality of all information you provide to us.
  • Our policy complies with the Data Protection Act 2018 (Act) accordingly incorporating the EU General Data Protection Regulation (GDPR).
  • The law requires us to tell you about your rights and our obligations to you in regards to the processing and control of your personal data. We do this now, by requesting that you read the information provided at www.knowyourprivacyrights.org
  • Except as set out below, we do not share, or sell, or disclose to a third party, any information collected through our website.
The basis on which we process information about you

The law requires us to determine under which basis we process different categories of your personal information, and to notify you of the basis for each category. If a basis on which we process your personal information is no longer relevant, then we shall immediately stop processing your data. If the basis changes then if required by law we shall notify you of the change and of any new basis under which we have determined that we can continue to process your information.

Information we process because we have a contractual obligation with you

When you book an appointment or request a service using the website a contract is formed between you and us. In order to carry out our obligations we must process the information you give us. Some of this information may be personal information. We may use it in order to:

  • verify your identity
  • enable us to provide you with our services
  • process your payments

We process this information on the basis there is a contract between us. Provided there is no legal basis for us to retain your personal information, then on request we will delete your personal information. You can make a request by contacting us at the address above.

Information we process with your consent

Through certain actions when otherwise there is no contractual relationship between us, such as when you browse our website or ask us to provide you more information about our business, including our services, you provide your consent to us to process information that may be personal information. Wherever possible, we aim to obtain your explicit consent to process this information, for example, by asking you to agree to our use of cookies. Sometimes you might give your consent implicitly, such as when you send us a message by e-mail to which you would reasonably expect us to reply. We continue to process your information on this basis until you withdraw your consent or it can be reasonably assumed that your consent no longer exists. You may withdraw your consent at any time by instructing us by contacting us at the address above.

Information we process for the purposes of legitimate interests

We may process information on the basis there is a legitimate interest, either to you or to us, of doing so. Where we process your information on this basis, we do after having given careful consideration to:

  • whether the same objective could be achieved through other means
  • whether processing (or not processing) might cause you harm
  • whether you would expect us to process your data, and whether you would consider it reasonable to do so

For example, we may process your data on this basis for the purposes of:

  • record-keeping for the proper and necessary administration of our business.
  • responding to unsolicited communication from you to which we believe you would expect a response
Specific uses of information you provide to us.
Information provided on the understanding that it will be used by the GP or Nurse

Our website allows you to provide information with a view to that information being read, copied, downloaded, and used by your GP or Nurse to provide the service. Your GP will be able to access the following personal information relating to your appointment booking

  • Name
  • Address
  • Email address
  • Mobile phone number
  • Time and date of appointment
  • Service requested
  • Price paid
  • List of medications (optional)

Provided there is no legal basis for us to retain your personal information, then on request we will delete your personal information. You can make a request  by contacting us at the address above.

Information relating to your method of payment

Credit/Debit card information is processed but not retained by us. Your credit/debit card number, expiry date and CVV are collected and processed directly by the payment processor, Stripe. You can refer to Stripes privacy policy for further details

Use of information we collect through automated systems when you visit our website
Cookies

Cookies are small text files that are placed on your computer’s hard drive by your web browser when you visit any website. They allow information gathered on one web page to be stored until it is needed for use on another, allowing a website to provide you with a personalised experience and the website owner with statistics about how you use the website so that it can be improved. Some cookies may last for a defined period of time, such as one day or until you close your browser. Others last indefinitely. Your web browser should allow you to delete any you choose. It also should allow you to prevent or limit their use. Our website uses cookies. They are placed by software that operates on our servers, and by software operated by third parties whose services we use. We use cookies to track how you use our website.

Personal identifiers from your browsing activity

Requests by your web browser to our servers for web pages and other content on our website are recorded. We record information such as your geographical location, your Internet service provider and your IP address. We also record information about the software you are using to browse our website, such as the type of computer or device and the screen resolution. We use this information in aggregate to assess the popularity of the webpages on our website and how we perform in providing content to you. If combined with other information we know about you from previous visits, the data possibly could be used to identify you personally, even if you are not signed in to our website.

Disclosure and sharing of your information

Our website is hosted on a virtual private server located in Ireland. The data centre and network meets the requirements of the most security-sensitive organisations.  Your data is stored in Ireland and is not processed outside of the EU.

Access to your personal information

To obtain a copy of the personal information we retain, you may send us a request at the address above. After receiving the request, we will tell you when we expect to provide you with the information, and whether we require any fee for providing it to you.

Removal of your information

If you wish us to remove personally identifiable information from our website, you may contact us at the address above.

Verification of your information

When we receive any request to access, edit or delete personal identifiable information we shall first take reasonable steps to verify your identity before granting you access or otherwise taking any action. This is important to safeguard your information.

Other matters
Use of site by children

We do not provide services for purchase by children. If you are under 18, you may use our website only with consent from a parent or guardian.

Encryption of data sent between us

We use Secure Sockets Layer (SSL) certificates to verify our identity to your browser and to encrypt all data in transit between your browser and the website. All data at rest is also encrypted. 

Whenever information is transferred between us, you can check that it is done so using SSL by looking for a closed padlock symbol or other trust mark in your browser’s URL bar or toolbar.

How you can complain

If you are not happy with our privacy policy or if have any complaint then you should tell us by contacting us at the address above. If a dispute is not settled then we hope you will agree to attempt to resolve it by engaging in good faith with us in a process of mediation or arbitration. If you are in any way dissatisfied about how we process your personal information, you have a right to lodge a complaint with the Data Protection Commissioner. This can be done at https://www.dataprotection.ie/docs/complaints/1592.htm

Retention period for personal data

Except as otherwise mentioned in this privacy notice, we keep your personal information only for as long as required by us:

  • to provide you with the services you have requested;
  • to comply with other law, including for the period demanded by our tax authorities;
  • to support a claim or defence in court.
Review of this privacy policy

We may update this privacy notice from time to time as necessary. The terms that apply to you are those posted here on our website on the day you use our website. We advise you to print a copy for your records. If you have any question regarding our privacy policy, please contact us at the address above.