Craniosacral Therapy is committed to protecting your Personal Data in accordance with our internal policies and applicable European legislation. “Personal Data” means personal information that identifies you as an individual or relates to an identifiable individual as defined under applicable European legislation (and in particular, the European General Data Protection Regulations 2016).
This Notice informs you of our practices from 25 May 2018 with respect to the collection, use and disclosure of Personal Data which you provide to us via our Platform (ie. www.cst-therapy.com). We may ask you for this Personal Data so we can effectively provide our products and/or services to you. There may be occasions where it may be reasonably necessary for us to contact you for administrative or operational reasons in relation to your registration or use of our Platform, your potential employment with us or use of or access to our Products and Services.
How we collect Personal Data and why?
The Data Controller is Craniosacral Therapy. We may collect your Personal Data in the following circumstances (this is not a definitive list):
- Marketing and Promotions
- Accessing, using or purchasing our products or services
- To perform our contractual obligations
- Or else in our legitimate business interests
What Personal Data do we collect?
Types of Personal Data we ask for may include, but is not limited to, combinations of information about:
- your name, postal address, email address (which may reveal your IP address), phone number, occupation and other contact information;
- sensitive Personal Data such as race or gender, when applying for a position with us – please see the Sensitive Personal Data section below;
- from where you heard about us;
- details of complaints;
- your dealings with us including information regarding your personal or professional interests, needs or opinions, demographics, experiences with our products or services and contact preferences;
- details of financial or accounting transactions carried out on our platforms or otherwise, including credit/debit card information, billing information and/or delivery address information;
- information from other sources, such as public databases, joint marketing partners, social media platforms (including from people with whom you are friends or otherwise connected) and from other third parties;
- technical information, including location information, the Internet Protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform. Where we use IP addresses, we do not link your IP address(es) to your other Personal Data;
- your online browsing behaviour on our Platforms; including the Uniform Resource Locators (URL) clickstream to, through and from our Platforms or Social Media Channels (including date and time), download errors, lengths of visits to certain pages, page interaction information (such as scrolling, clicks and mouse-overs) and methods used to browse away from the page; or
- any devices you have used to access our products and services (including the make, model and operating system, IP address, browser type and mobile device identifiers). In some circumstances, we may request additional Personal Data to help us to provide you with the most appropriate response. If you do not provide the Personal Data where requested, your access to the service, or our ability to assist you, may be restricted.
Sensitive Personal Data
We will not ask for your Sensitive Personal Data except as part of Craniosacral Therapy’s recruitment process. “Sensitive Personal Data” means Personal Data which may relate to: ethnic origin; political opinions; religious or other similar beliefs; trade union membership; physical or mental health or criminal record. Where you do provide Sensitive Personal Data, we will ask you for explicit consent for Craniosacral Therapy to use that information solely in connection with the purpose for which it has been provided.
Under the European General Data Protection Regulations 2016, you have rights over your Personal Data in certain circumstances. Those rights may include for example the right to request we amend or delete your Personal Data; the right to withdraw consent; the right to know the purposes for which your Personal Data is being processed and the recipients to whom your Personal Data may be disclosed (subject to legal and regulatory requirements). If you do not agree to your Personal Data being used in accordance with this Policy please do not submit your Personal Data to us through the platform or any other means. If you require further information on your rights or our use of your Personal Data, please contact us at office@cst-therapy.com.
Right to Rectification of Personal Data
We assume responsibility for keeping an accurate record of Personal Data once you have submitted the information, but not for confirming the on-going accuracy of your Personal Data if you do not update us. If you advise us that your Personal Data is no longer accurate, we will amend or update it (where practical and lawful to do so).
Right to Erasure or Restriction of Personal Data
You can ask us to delete or restrict your Personal Data in some circumstances such as where we no longer need it or you withdraw your consent (if consent is applicable). If we’ve shared it with others, where possible, we’ll let them know about the erasure.
Right to Withdraw Consent
If, at any time, you have consented to us processing your Personal Data in the circumstances or purposes described above, and you no longer wish to have your Personal Data processed in this way, you may unsubscribe by contacting us or Opting-Out by pressing unsubscribe on emails that we send to you.
Right to Opt-Out of Marketing and Promotions
You have the right to opt out of receiving direct marketing and promotion communications you have previously consented to
Rights in relation to Automated Decision-making and Profiling
You have the right not to be subject to a decision when it’s based on automatic processing or profiling. We only carry out this type of decision-making where the decision is necessary for the entry into or performance of a contract; or based on your explicit consent. We will always tell you if we do any such activity using your Personal Data.
Right to Copies of Personal Data
Where permitted by law, you may have the right to contact us to request a copy of Personal Data that we hold about you. Before responding to your request we may ask you to (i) verify your identity and (ii) provide further details so we can better respond to your request.
Children’s Personal Data
Our Platforms are not intended to target children under the age of 15. We will not knowingly collect or process Personal Data belonging to children via our platform.
Third Party Goods and Services
We will not send you information relating to third party goods and services from outside Craniosacral Therapy, unless specifically requested. Third Party websites where links from our Platforms are provided to non-CST websites, we are not responsible for those websites and nor do we imply endorsement of the linked websites. These third-party websites will be governed by different terms of use (including privacy notices) and you are solely responsible for viewing and using every such website in accordance with the applicable terms of use. We are not responsible for how your Personal Information is handled by such third party websites. These websites are not covered by this Notice.
Security of Personal Data
Your Personal Data (and commercial information) will be kept as confidential and as secure as possible. We employ appropriate technical and organisational measures consistent with our legal obligations and standard industry practice. Further, as required by the European General Data Protection Regulations 2016, we follow strict security procedures in the storage and disclosure of Personal Data that you have given to us, to prevent unauthorised access as far as reasonably possible. We use industry standard practices to safeguard the confidentiality of your Personal Data, including “firewalls” and Secure Socket Layers. We treat your Personal Data as an asset that must be protected against loss, alteration, destruction and unauthorised access, and which our employees must keep confidential. We use many different security techniques to protect your Personal Data from unauthorised access by users’ inside and outside of Craniosacral Therapy. We also use internal protections to limit access to users’ Personal Data to only those employees who need the Personal Data to perform a specific function. It is impossible to guarantee security, but we commit to taking appropriate action in the event of a breach.
Transfer of Personal Data
Other than to Third Party Data Processors governed by a data processing agreement which replicates the terms of this Notice, as elsewhere provided for in this Notice; where it is necessary to involve a third party service provider for the performance of our contractual obligations; or by operation of law, we will not transfer identifiable, non-aggregated Personal Data to third parties.
Data outside of the European Union (or outside of jurisdictions deemed “adequate” for data privacy by the European Union). We will not transfer your data outside of the European Union for any other reason than described in this Notice, unless we are required to do so by operation of law.
Sale or Merger
If Craniosacral Therapy or its assets are sold to or merge with another entity outside Craniosacral Therapy, you should expect that some or all of the Personal Data collected by Craniosacral Therapy may be transferred to the buyer/surviving company. If so, we will seek to obligate the acquiring company to use any Personal Data transferred in a manner consistent with applicable legislation and this Notice, but cannot guarantee that it will be able to impose that requirement or that the acquiring company will comply.
Retention of Personal Data
If you have provided us with Personal Data, your Personal Data will be retained for the duration of your relationship with us, the length of time required by applicable legislation, or otherwise a reasonable period of time. We or our third party data processors will amend or dispose of your Personal Data when it is no longer necessary.
Cookies
What Cookies we use, why we use them, and how they impact you. A cookie is a small text file, typically of letters and numbers (with an ID tag), which may be placed on your computer or mobile when you access our platform. Cookies generally allow a website to recognise your device and browsing activity if you return to it, or if you visit another website which recognises the same cookies. Different cookies perform different functions. Some help you navigate through pages, “storing preferences” information and generally making the website easier to use. Others identify products, goods or services you may be interested in and are used to provide you with tailored advertising. When you visit our platform: Persistent cookies allow our website to recognise you when you return to our site another time. This provides us with useful analytics that help us optimise our website and your visits. Session cookies exist just for the life of your current visit while you have your browser open. They are not stored on your hard disk and are erased when you exit your web browser. For general information on cookies, please see direct.gov.uk internet browser cookies page.
Google Analytics
We use this type of cookie to understand how our website is being used in order to improve the user experience. User data is all anonymous.
Social buttons
On many of the pages of our websites you will see ‘social buttons’. These allow you to share or bookmark pages on our site. Social media sites such as Twitter, Facebook, and LinkedIn may collect information about your internet activity. They may record if you visit our platforms and the specific pages you are on if you are logged into their services, even if you don’t click on the button. You should check the privacy and cookies policies of each of these sites to see how exactly they use your information and to find out how to opt-out, or delete, such information.
Further information: Facebook cookies
Manually managing cookies
There are a number of ways you can manually manage cookies on your computer/device. Read more on the About Cookies website. If you access the Internet from more than one computer/device it is important to ensure each browser is configured to suit your cookie preferences. Do Not Track – if you wish to block all cookies all the time you can set your browser to do this. It is important to note that blocking cookies may result in some parts of our site not working properly. This may affect your browsing experience. Our platform respects a DNT:1 signal as a valid browser setting communicating your preference.
How does Craniosacral Therapy ask for Cookies consent?
Craniosacral Therapy comply with applicable legislation on cookies. A popup box will appear when you first access our platform. This asks you whether you consent to cookies. If you do not consent to cookies, you are free to disable cookies at any time through your browser’s settings (for more information on how to do this please see the “how to delete cookies” tab at www.allaboutcookies.org/cookies. If you choose to disable cookies, please be aware that some parts of our platform may not work properly and it is likely that your platform usage won’t be counted and measured as described above, so we won’t be able to take your actions into account when analysing data or when seeking to improve our service based on that analysis.
Contact us
Should you wish to make any comments, complaints, enquiries, or if you have any questions relating to this Notice, your rights, the platform, our marketing and promotion materials or products or services we provide, you may contact Craniosacral Therapy by emailing or writing to Fulscot Manor, Didcot, OX11 9AA Oxfordshire; office@cst-therapy.com; mob: 07795 474542.
Changes to this Notice
This Notice is subject to periodic review to ensure it is in line with applicable legislation. We retain all applicable ownership rights to information we collect. We reserve the right to change, modify, add or remove provisions of this Notice. Any changes to this Notice will be posted here, and we encourage you to check back from time to time. Applicable Law: This Notice is governed and construed in accordance with English law.