Skip to main content

Policy · Data & privacy

Privacy notice

What personal information the college collects, why it holds it, how long it keeps it, who else sees it, and what you can require us to do with it.

Version [0.X] · Owner [DATA PROTECTION LEAD] · Last reviewed [DATE] · Next review [DATE]

Working draft — not yet formally adopted

This notice is a working draft pending adoption by [COMMITTEE NAME] on [DATE]. Retention periods, named post-holders and registration numbers are placeholders. The college’s duties under the UK GDPR and the Data Protection Act 2018 apply now, whether or not this document has been formally adopted.

This notice explains how SCMAT UK — UK College of Chinese Medicine & Acupuncture Techniques (“the college”, “we”) handles personal information. It covers this website, enquiries and applications, enrolment and study, the teaching clinic and the college’s public events. It is written to be read by the people it applies to, not only by lawyers.

Section 1

Who we are

The college is the data controller for the personal information described here. That means we decide why it is held and how it is used, and we are accountable for it.

  • Controller: SCMAT UK — UK College of Chinese Medicine & Acupuncture Techniques, [REGISTERED COMPANY NAME AND NUMBER]
  • Registered address: SCMAT UK Head Office, 1 Example Square, London, EC1A 1AA
  • Contact for data matters: [DATA PROTECTION LEAD], enquiries@scmat.org.uk
  • ICO registration number: [ICO REGISTRATION NUMBER]
  • Data protection officer: [NAME / NOT APPOINTED — A DPO IS ONLY REQUIRED IN CERTAIN CIRCUMSTANCES]

In the short version: we collect what we need in order to teach, treat, administer and account for what we do; we do not sell personal information; and we do not use analytics or advertising cookies on this website.

Section 2

What we collect and why

The table below sets out the categories of information we hold, with examples and the reason we hold each one. If you would rather not give us a particular item, tell us — usually we can work around it, and where we cannot, we will say why.

Categories of personal information held by the college. Retention periods are shown in section 4.
CategoryExamplesWhy we hold it
Enquiries and correspondenceName, email address, telephone number, the content of your messageTo answer you, and to keep a record of what we said
Applicants and studentsContact details, date of birth, prior qualifications, references, identity documents, attendance, assessment marks, placement recordsTo assess an application, enrol you, teach you, assess you and issue an award
Clinical records (patients)Name, contact details, date of birth, presenting complaint, medical history, medication, examination findings, treatment given, adverse eventsTo provide safe care, to keep an accurate clinical record, and to meet professional and insurance requirements
Financial recordsInvoices, payments, instalment arrangements, refundsTo administer fees and to meet accounting and tax obligations
Special category dataInformation about health, disability, ethnicity or religious belief, where you choose to give itTo make reasonable adjustments, to provide safe clinical care, and to monitor equality of access
Safeguarding recordsNotes of concerns raised, decisions taken and referrals madeTo protect children and adults at risk, and to meet our legal duties
Website technical dataServer logs held by our hosting provider (IP address, browser type, pages requested)To keep the site available and secure
CCTV and building access[CONFIRM — WHETHER ANY CCTV IS IN OPERATION AT COLLEGE PREMISES]Site security and the safety of staff, students and visitors

Section 3

Our lawful bases

Under the UK GDPR we must have a lawful basis for everything we do with personal information. We rely on the following, and we tell you which applies when we collect information.

What we are doingLawful basis
Answering an enquiry you send usLegitimate interests (responding to you), or consent where you have asked to join a mailing list
Assessing an application and enrolling youPerformance of a contract, or steps taken at your request before entering a contract
Teaching, assessing and issuing an awardPerformance of a contract with the student
Providing clinical care in the teaching clinicProvision of health care (UK GDPR Article 9(2)(h)) and, where relevant, your explicit consent
Keeping financial and tax recordsLegal obligation
Recording and reporting accidents and clinical incidentsLegal obligation, and vital interests where someone's safety is at risk
Safeguarding children and adults at riskLegal obligation, and vital interests
Monitoring equality of access and outcomesLegitimate interests, using aggregated or anonymised data wherever possible
Keeping the website available and secureLegitimate interests

Where we rely on consent, you can withdraw it at any time. That does not affect anything done before you withdrew it.

Section 4

How long we keep it

We keep information only for as long as there is a reason to. The periods below are the college’s intended retention schedule and are placeholders pending formal adoption; where a period is fixed by law or by our insurers, we say so.

Indicative retention schedule. Confirm each period with the college's insurers and legal advisers before adoption.
Record typeIndicative retentionReason
Enquiries that do not lead to an application[XX months]Long enough to answer follow-up questions, then deleted
Unsuccessful applications[XX months]To answer questions about the decision and to meet admissions monitoring needs
Student academic records[XX years]To provide transcripts and references after graduation
Clinical records for adults[XX years from the last treatment]Professional and insurance requirements for clinical records
Clinical records for children[UNTIL AGE XX]Records are normally kept until the patient's majority plus the adult period
Financial records[XX years]Accounting and tax obligations
Safeguarding records[XX years]Kept separately, with access restricted to those who need it
Website server logs[XX days]Held by our hosting provider for security and diagnostics

Section 5

Who we share it with

We do not sell personal information, and we do not share it with advertisers or data brokers. We share it only where it is necessary, and only with the following kinds of recipient:

  • Awarding bodies and professional registers, to register an award, a qualification or a student membership.
  • External examiners and moderators, who see assessment material with candidate identifiers removed wherever that is possible.
  • Clinical supervisors and, in an emergency, other healthcare professionals treating you — sharing only what is needed for safe care.
  • Our insurers and legal advisers, when a claim or an incident is being handled.
  • Regulators, the police, local authority safeguarding partners and other public bodies, where the law requires or permits us to report.
  • Service providers who process information on our behalf — for example our hosting provider, IT support and accountancy — under written contracts that restrict them to our instructions.
  • HMRC and our auditors, for financial records.

Our full list of processors and the categories of recipient is available on request from [EMAIL].

Section 6

Your rights

You have the following rights over your personal information. They are not absolute — there are circumstances in which we must refuse a request, and if that happens we will explain why and tell you how to challenge the decision.

RightWhat it means in practice
AccessYou can ask for a copy of the information we hold about you, and for information about how we use it.
RectificationYou can have inaccurate information corrected, and incomplete information completed.
ErasureYou can ask us to delete information where we no longer have a good reason to keep it. Clinical and financial records usually have to be kept for their retention period.
RestrictionYou can ask us to stop using information while a dispute about its accuracy is resolved.
ObjectionYou can object to processing based on legitimate interests, and to direct marketing at any time.
PortabilityYou can ask for information you provided to us electronically to be given to you, or sent to another organisation, in a machine-readable format.
Withdraw consentWhere we rely on consent, you can withdraw it at any time.
Automated decisionsWe do not make decisions about you solely by automated means, and we do not carry out automated profiling for decisions that affect you.

To exercise any of these rights, write to [DATA PROTECTION LEAD] at enquiries@scmat.org.uk. We respond within one month, and we do not charge. We may ask you to confirm your identity first — we would rather ask than release someone else’s records. If a request is complex we may extend the period by up to two further months, and we will tell you within the first month if that is the case.

Section 7

Cookies and tracking

This website uses no analytics cookies and no tracking cookies. There is no Google Analytics, no advertising pixel, no social media plugin and no cross-site tracking of any kind. The site is served as static files, which is why it can work without them.

Because we set no cookies that are not strictly necessary, you will not see a consent banner on this site. A banner asking for consent we do not need would be theatre. If that changes — for example if the college later embeds a map, a video player or an analytics service — this section will be updated first, and any such content will be loaded only after you agree to it.

Any cookie you do receive from this site is strictly necessary and is set by our hosting provider for security and load balancing — [CONFIRM WITH HOST]. You can block or delete cookies in your browser settings at any time; doing so will not affect your ability to read anything here.

Our hosting provider keeps standard server logs, which include IP addresses, for security and diagnostics. Those logs are technical records rather than a profile of your browsing, and they are retained for [XX days].

Section 8

Transfers outside the UK

We do not routinely transfer personal information outside the UK. Where a service provider stores data outside the UK — for example a cloud backup or an email provider — the transfer is covered by an adequacy regulation or by the International Data Transfer Agreement or Addendum, and we keep a record of the safeguard used. Current providers and their locations: [LIST PROVIDERS AND SAFEGUARDS].

Section 9

How to complain

If you are unhappy with how we have handled your information, tell us first. Write to [DATA PROTECTION LEAD] at enquiries@scmat.org.uk and we will investigate. Most concerns are resolved at this stage, and you can also use the complaints procedure.

You have the right to complain to the Information Commissioner’s Office at any time, and you do not have to come to us first. The ICO can be contacted at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; by telephone on 0303 123 1113; or through ico.org.uk.

Section 10

Changes to this notice

This notice is reviewed at least every [XX months], and whenever the way we use information changes materially. The version number and review dates at the top of this page always show the current position. Material changes are announced on this page rather than made silently.

Questions about your data?

If you are not sure whether we hold information about you, or how to ask for it, contact the college office and we will explain the process.