Privacy and Confidentiality

www.eihv.co.uk is owned and operated by Katherine Offer.

Katherine Offer is the data controller and can be contacted at connect@eihv.co.uk.

By signing my consent form you agree to the terms as detailed below.

How I Use Personal Data
The collecting and processing of your personal data is necessary for me to work as an independent health visitor for you. If you do not agree to sharing this information with me, I are unable to provide my services to you. I will not collect any personal data from you that I do not need in order for me to provide the services I have agreed to provide you with.

Who I Share Data With
Your personal data will ordinarily be seen by Katherine.
In order to provide the support you need, it may be necessary for me to contact a third party for further advice. I will not do this without seeking your permission first.
I will not share your data with third parties without your consent. However if I feel you or your child is at significant risk, I have a duty of care to share information with the Devon Multi Agency Safeguarding Hub (MASH). If this should occur, I will talk to you directly about my concerns unless I feel this puts your baby or myself at risk. My aim is to always work in collaboration with you.

How I Store Your Data
I use a record keeping software package called WriteUpp, a trusted supplier to NHS therapy services for over 10 years. WriteUpp is ISO27001 certified, a globally recognised information governance and security standard. WriteUpp’s systems and processes comply with this standard and are audited annually to ensure continued compliance. Your data is encrypted in flight and at rest and your navigation runs on 256 bit SSL encryption, giving you peace of mind your data is secure. WriteUpp uses two-factor authentication which provides an added layer of security.

How Long I Keep Your Data
All adult data will be kept for 8 years after our last contact with you. The data I hold for your baby will be kept for 25 years, as recommended by the BMA (British medical Association). WriteUpp has a feature that will inform me when your data is due to be destroyed so that I do not keep it longer than required.

Accessing Your Records
You are able to make a subject access request at any point. If you do this I have a legal requirement to provide you with a copy of your records within 30 days.

Destroying Your Data
WriteUpp provides a secure way to destroy your data if you no longer consent to us holding this data.