Privacy Policy

This privacy policy explains how I use any personal information I collect about you as a past, present and future client or when you use my website.

 

What is GDPR?

From May 2018 GDPR (General Data Protection Regulation) is the legal framework that sets guidelines for the collection and processing of personal information of individuals within the European Union (EU). This is underpinned in Portugal by the Data Protection Law (2019). This privacy policy sets out how Dr Isabella Bernardo will comply with these laws.

Why do I collect information about you?

There are a number of lawful reasons that I can use (or 'process') your personal information. One of the lawful reasons is called 'legitimate interests'. Broadly speaking legitimate Interests means that I can process your personal information if:

  • I have a genuine and legitimate reason and I am not harming any of your rights and interests.

So, what does this mean? When you provide your personal details I use your information for our legitimate business interests (i.e. to deliver a psychology service to you/your child). Before doing this, though, I will also carefully consider and balance any potential impact on you and your rights.

Your personal information is only used to provide the services you have requested from me. I will only use personal contact details to respond to requests for psychological treatment, they will never be used for marketing purposes. If you do not provide the personal information requested, then I may be unable to provide a psychology service to you.

What information do I collect about you?

To be able to provide assessment and therapy services to you/your child I will need to collect information about you/your child. This may include the following:

  • Full name

  • Address

  • Contact details including phone number

  • Email address

  • Gender

  • Date of birth

  • Age

  • School

  • Relationships and children

  • Physical and mental health history

  • Contact with other professional/medical services

  • Payment preferences/bank details for invoicing

If you complete a web-based enquiry form, I will also collect any information you provide.

How do I store your information?

I take your privacy very seriously. I have put in place a number of security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Personal information is stored on an Apple Mac computer and on a secure server owned by Dr Isabella Bernardo. These are password protected. Malware and antivirus protection is installed on all computing devices. Mobile devices are protected with a passcode/thumbprint scanner, mobile security and antivirus software. Any written session notes are stored in a locked cabinet. All personal information provided is stored in compliance with EU General Data Protection Regulations (GDPR) rules. Personal information is minimised in phone and email communication. Sensitive personal data will be sent to clients in an email attachment that is password protected. I will not use open or unsecure Wi-Fi networks to send any personal data.

How long will I keep you information for?

I am required to keep records securely for a period of when the child is up to 26 years of age. Records will then be destroyed. This is in keeping with guidelines from The British Psychological Society (BPS; 2017)[1], The Health and Care Professions Council (HCPC; 2017)[2] and the Ordem de Psicólogos Portugueses (OPP).

Who do I share your personal information with?

I hold information about each of my clients and the service they receive in confidence. I will not normally share your personal information with anyone else. However, there are exceptions to this when there may be need for liaison with other parties:

  • If you are referred by your health insurance provider, or otherwise claiming through a health insurance policy to fund therapy, then I will share appointment schedules with that organisation for the purposes of billing. I may also share information with that organisation to provide treatment updates.

  • In accordance with British Psychological Society Guidelines I receive supervision from another registered Educational Psychologist. This Educational Psychologist is also bound by regulatory body rules of confidentiality. I will discuss details of our work and share sensitive data but will not disclose personal data.

In exceptional circumstances, I might need to share personal information with relevant authorities:

  • When there is need-to-know information for another health provider, such as your family doctor.

  • When disclosure is in the public interest, to prevent a miscarriage of justice or where there is a legal duty, for example a Court Order.

  • When the information concerns risk of harm to the client, or risk of harm to another adult or a child. I will discuss such a proposed disclosure with you unless I believe that to do so could increase the level of risk to you or to someone else.

What I will NOT do with your personal information.

I will not share your personal information with third-parties for marketing purposes under any circumstances.

What are your rights?

You have the right to request access to the data that I hold on you free of charge. You also have the right to request the correction or deletion of information that you believe to be inaccurate in accordance with the guidelines and requirements for record keeping by The British Psychological Society (BPS; 2017)[1] and The Health and Care Professions Council (HCPC; 2017)[2].

You are able to exercise certain rights in relation to your personal data that I process. These are set out in more detail here:

  • In relation to a Subject Access Right request, you may request that I inform you of the data I hold about you and how I process it.

  • I will not charge a fee for responding to this request unless your request is clearly unfounded, repetitive or excessive in which case I may charge a reasonable fee or decline to respond.

  • I will, in most cases, reply within one month of the date of the request unless your request is complex or you have made a large number of requests in which case I will notify you of any delay and will in any event reply within 3 months.

  • If you wish to make a Subject Access Request, please email info@bernardopsychology.com. You have a right to get your personal information corrected if it is inaccurate.

  • I am committed to protecting your personal data but if for some reason you are not happy with any aspect of how I collect and use your data, you have the right to complain to the Ordem de Psicólogos Portugueses (OPP). I should be grateful if you would contact me first by email info@bernardopsychology.com if you do have a complaint so that I can try to resolve it for you.

[1]The British Psychological Society (2017). Practice Guidelines Third Edition. Leicester: BPS.

[2]Health and Care Professions Council (2017). Confidentiality – guidance for registrants. London: HCPC.

Dr Isabella Bernardo Chartered Child and Educational Psychologist and Owner