How Stonebridge Communities collects, uses and protects personal data in line with the UK GDPR and Data Protection Act 2018.

Introduction

At Stonebridge Communities, we are committed to protecting your privacy and handling personal data lawfully, transparently and securely. This page explains what personal data we collect, why we process it, who we share it with, how long we keep it and your rights under the UK GDPR.

Data Controller & Contact Details

If you have questions about this page or about how we use your personal data, contact our data protection officer or the person responsible for data protection:

Purposes & Lawful Bases for Processing

We only process personal data for explicit and legitimate purposes. Below are the primary processing activities, data categories and the legal bases we rely on.

Purpose Categories of Data Lawful Basis Retention / Notes
Client intake, assessment & treatment Identity, DOB, contact details, health & clinical notes, medical history, emergency contacts Consent & performance of a contract; where necessary for medical purposes Kept for the duration of treatment and the legally or clinically required period thereafter (see Retention).
Administration, invoicing & billing Identity, contact, payment and billing records Performance of a contract; legal obligation Kept in line with accounting and audit regulations.
Communications (appointments, follow-ups) Contact details; communication preferences Consent; legitimate interests (where appropriate) Until consent withdrawn or no longer necessary.
Research, service evaluation (anonymised) Pseudonymised / aggregated data Legitimate interests; consent if data is identifying Anonymised data may be retained long-term for evaluation and improvement.
Safeguarding, legal compliance & audits Relevant identity & clinical data Legal obligation; public interest As required by law and regulatory guidance.

Lawful Processing & Consent

When we rely on consent, it will be freely given, specific, informed and unambiguous. You can withdraw consent at any time — withdrawal does not affect processing already lawfully carried out before withdrawal. In some cases we rely on legitimate interests, or other legal bases such as performance of a contract, vital interests or legal obligations.

If we process special category data (for example health or addiction information) we will normally seek explicit consent or rely on a permitted condition under the Data Protection Act for health and social care purposes.

Categories of Personal Data & Recipients

Types of data we may process

  • Identity & demographic details (name, date of birth)
  • Contact details (address, phone, email)
  • Health, clinical and treatment records
  • Emergency contacts and next of kin
  • Financial & billing information
  • Communications and consent preferences
  • Technical data (device, IP address, cookies) where applicable

 

Who we may share data with

We share information only where necessary and on a need-to-know basis, for example:

  • Internal care teams and clinicians involved in your treatment
  • Third-party healthcare providers, labs and referral partners (with consent where required)
  • Safeguarding agencies, social services or regulatory bodies where required by law
  • Payment processors, auditors, insurers for administrative purposes
  • IT and hosting providers who process data under contract and Data Processing Agreements
  • Legal and professional advisers when required for legal proceedings or compliance

All third parties are required to keep your information secure and only process it for the specified purposes. Where appropriate we have Data Processing Agreements in place.

 

International / Cross-Border Transfers

Where data is transferred outside the UK/EEA we will ensure appropriate safeguards such as UK-approved Standard Contractual Clauses, adequacy decisions or technical measures (e.g. encryption) are in place prior to transfer. We will inform you in advance if any transfer of your personal data outside the UK/EEA is required for your care or administration.

 

Data Security & Storage

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These measures include:

  • Role-based access controls and user authentication
  • Encryption in transit (TLS) and where appropriate at rest
  • Secure backups and tested disaster recovery
  • Regular security testing and staff training
  • Data minimisation — we only collect what is necessary

If a personal data breach occurs which poses a risk to your rights and freedoms we will comply with our obligations to notify the Information Commissioner’s Office and any affected individuals where required by law.

 

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes set out above or as required by law. After that, personal data is either securely deleted or irreversibly anonymised.

  • Clinical / treatment records: Retained for the duration of treatment and for the clinically or legally required period thereafter (e.g. typically 7 years after discharge for adults; please check local guidance for specific periods).
  • Billing / financial records: Retained in line with accounting and audit requirements.
  • Consent / communications logs: Retained for a period necessary to demonstrate compliance.
  • Anonymised datasets: May be retained for service evaluation indefinitely.

 

Your Rights

Under the UK GDPR you have a number of rights in relation to your personal data, subject to applicable exemptions:

  1. Right to be informed — about how your data is used.
  2. Right of access — you may request a copy of personal data we hold about you.
  3. Right to rectification — you can ask us to correct inaccurate or incomplete data.
  4. Right to erasure — in certain circumstances you can request data deletion.
  5. Right to restrict processing — ask us to limit processing in specified situations.
  6. Right to data portability — request structured, machine-readable copies of data we hold, where applicable.
  7. Right to object — object to certain processing including direct marketing.
  8. Rights in relation to automated decision-making — where applicable.
  9. Right to withdraw consent — for processing based on consent.

To exercise any of these rights, please contact us at dpo@stonebridge.rehab or by telephone at +44 [INSERT PHONE NUMBER]. We may need to verify your identity before responding. Where required by law we aim to respond within one month; this can be extended by up to two further months in complex cases.

 

Complaints & Supervisory Authority

If you are unhappy with our handling of your personal data, please contact us first so we can attempt to resolve your concern. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

 

Changes to this page

We may update this GDPR Compliance page from time to time to reflect changes to our practices or to reflect legal updates. Where changes are significant we will provide a notice on our site or notify you directly if we hold your contact details.

Last updated: 6th October, 2025

If you want a version customised to your CMS, or to have the contact placeholders filled, tell me which values to insert and I’ll produce the updated HTML. I can also provide a plain-text / printable PDF export on request.