Data Protection Policy

Our commitment to protecting personal information

Version

3.0

Effective Date

September 2026

Review Date

September 2027

Policy Owner

Data Protection Lead

1. Our commitment

1.1 CHE Health & Wellbeing Limited and its group companies, CHE Online Limited, CHE London Limited and CHE PRO Limited (together “CHE“, “we” and “us“), are committed to handling personal information lawfully, fairly and securely, in line with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.

1.2 CHE Health & Wellbeing Limited (company number 10722903) is the controller and is registered with the Information Commissioner’s Office under registration number ZB035578.

1.3 This statement summarises how we meet our obligations. How we use your information, and your rights, are explained in full in our Privacy and Cookie Policy and, for clinic patients, our Clinic Privacy Notice.

2. Our principles

2.1 We make sure personal information is:

  • used lawfully, fairly and transparently;
  • collected for specified, clear and legitimate purposes;
  • adequate, relevant and limited to what we need;
  • accurate and kept up to date;
  • kept no longer than necessary; and
  • kept secure.

2.2 We are responsible for, and can demonstrate, our compliance with these principles.

3. How we put this into practice

  • Record of processing: we keep a record of all our processing activities (UK GDPR Article 30) and review it every year.
  • Data Protection Lead: a named Data Protection Lead oversees compliance, advises staff and is the contact point for individuals and the ICO.
  • Retention: our Data Retention and Erasure Policy sets out how long we keep each type of information and how we securely delete it.
  • Health information: our Appropriate Policy Document explains how we protect special category information, and we have completed a data protection impact assessment for the CHE Homeopathy Clinic.
  • Legitimate interests: we carry out a legitimate interests assessment before relying on legitimate interests.
  • Suppliers: our Data Protection Lead approves new suppliers and systems before they hold personal information, and we use suppliers only under contracts that require them to protect it.
  • Security: our Information Security Rules apply to all staff, tutors and contractors, and include multi-factor authentication, role-based access, regular access reviews and same-day removal of access for leavers.
  • Training: staff and contractors who handle personal information receive data protection training.
  • Privacy by design: we consider data protection when we introduce new courses, systems or processes, and collect only what we need.

4. Personal data breaches

4.1 We keep a breach log and follow a written breach procedure. If a breach is likely to put people’s rights and freedoms at risk, we report it to the ICO within 72 hours of becoming aware of it. If it is likely to put people at high risk, we tell them without undue delay.

4.2 If you think your personal information has been lost or misused, please tell us straight away at [email protected].

5. Your rights

5.1 You have rights to access, correct and erase your information, to restrict or object to its use, to data portability, and to withdraw consent. To use any of these rights, email [email protected]. We respond within one month. Full details are in our Privacy and Cookie Policy.

5.2 If you are unhappy with how we have handled your information, please contact us first. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

6. Review

6.1 Our Data Protection Lead reviews this statement, our record of processing and our data protection documents every year, and sooner if the law or our activities change.

Data protection enquiries: Data Protection Lead (Marcus Fernandez), [email protected]

All other enquiries: [email protected] · 020 3405 4580