• Over 100,000 treatments Completed
  • 5-Star Rated Medical-Grade Machines
  • 0% Interest Packages to Spread Costs
Book Now
Call Us Now

The Laser Club

Information Governance & Data Security Policy

The Laser Club - Blog

1. Policy Statement

The Laser Club is committed to protecting the confidentiality, integrity, and availability of all personal and sensitive information we collect and process. We comply with the requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all relevant healthcare and professional guidelines.

2. Purpose & Scope

This policy sets out how The Laser Club ensures that patient and member data is securely and appropriately collected, stored, transmitted, retained, and disposed of. It applies to:

  • All staff, contractors, and volunteers
  • All data collected in relation to patients, members, and staff
  • All systems and media used to store and process data

3. Duties

  • Management Committee: Responsible for ensuring compliance with this policy and relevant legislation.
  • Data Protection Lead (DPL): Appointed to oversee data governance, advise on compliance, and respond to data protection queries and breaches.
  • All Staff and Volunteers: Responsible for handling information securely and following this policy at all times.

4. Types of Data Collected and Purpose

The Laser Club collects and processes the following types of personal data:

  • Patient data: medical history, treatment records, photographs (if required), contact details – collected to provide safe and effective treatment.
  • Member data: contact information, membership records, payment details – collected for membership management and communication.
  • Staff/volunteer data: employment and training records – collected for HR and safeguarding purposes.

We will only collect data that is necessary, relevant, and proportionate.

5. Data Storage

  • Electronic records are stored securely on password-protected systems with restricted access.
  • Paper records (if used) are stored in locked cabinets within secure areas of the premises.
  • Access is limited to authorised staff only.

6. Data Transmission & Sharing

  • Data shared electronically (e.g., with healthcare professionals, insurers, or regulators) is encrypted and transmitted securely.
  • Data will not be shared with third parties without patient consent unless there is a legal or safeguarding requirement.
  • No personal data will be transferred outside of the UK without adequate safeguards.

7. Retention Periods

  • Patient treatment records will be retained for a minimum of 7 years following completion of treatment, in line with clinical and legal requirements.
  • Records for children and young people will be retained until the patient’s 25th birthday, or 26th birthday if treatment was completed at age 17.
  • Membership and staff records will be retained for 6 years after leaving the club, unless required longer by law.

8. Disposal of Records

  • Electronic records will be securely deleted so they cannot be recovered.
  • Paper records will be cross-shredded or incinerated.
  • Disposal will always be documented and carried out by authorised personnel.

9. Review

This policy will be reviewed annually or sooner if required by changes in legislation or practice.

Newsletter Signup

Request a call back

Name
Consent(Required)
The Laser Club
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.