How Stonebridge Communities collects, uses and protects personal data in line with the UK GDPR and Data Protection Act 2018.
Introduction
At Stonebridge Communities, we are committed to protecting your privacy and handling personal data lawfully, transparently and securely. This page explains what personal data we collect, why we process it, who we share it with, how long we keep it and your rights under the UK GDPR.
Data Controller & Contact Details
If you have questions about this page or about how we use your personal data, contact our data protection officer or the person responsible for data protection:
- Data Controller: Stonebridge Communities
- Address: 81 Locking Road, Weston Super Mare, BS23 3DW
- Email: info@stonebridge.rehab
- Telephone: 01934 311965
Purposes & Lawful Bases for Processing
We only process personal data for explicit and legitimate purposes. Below are the primary processing activities, data categories and the legal bases we rely on.
| Purpose | Categories of Data | Lawful Basis | Retention / Notes |
|---|---|---|---|
| Client intake, assessment & treatment | Identity, DOB, contact details, health & clinical notes, medical history, emergency contacts | Consent & performance of a contract; where necessary for medical purposes | Kept for the duration of treatment and the legally or clinically required period thereafter (see Retention). |
| Administration, invoicing & billing | Identity, contact, payment and billing records | Performance of a contract; legal obligation | Kept in line with accounting and audit regulations. |
| Communications (appointments, follow-ups) | Contact details; communication preferences | Consent; legitimate interests (where appropriate) | Until consent withdrawn or no longer necessary. |
| Research, service evaluation (anonymised) | Pseudonymised / aggregated data | Legitimate interests; consent if data is identifying | Anonymised data may be retained long-term for evaluation and improvement. |
| Safeguarding, legal compliance & audits | Relevant identity & clinical data | Legal obligation; public interest | As required by law and regulatory guidance. |
Lawful Processing & Consent
When we rely on consent, it will be freely given, specific, informed and unambiguous. You can withdraw consent at any time — withdrawal does not affect processing already lawfully carried out before withdrawal. In some cases we rely on legitimate interests, or other legal bases such as performance of a contract, vital interests or legal obligations.
If we process special category data (for example health or addiction information) we will normally seek explicit consent or rely on a permitted condition under the Data Protection Act for health and social care purposes.
Categories of Personal Data & Recipients
Types of data we may process
- Identity & demographic details (name, date of birth)
- Contact details (address, phone, email)
- Health, clinical and treatment records
- Emergency contacts and next of kin
- Financial & billing information
- Communications and consent preferences
- Technical data (device, IP address, cookies) where applicable
Who we may share data with
We share information only where necessary and on a need-to-know basis, for example:
- Internal care teams and clinicians involved in your treatment
- Third-party healthcare providers, labs and referral partners (with consent where required)
- Safeguarding agencies, social services or regulatory bodies where required by law
- Payment processors, auditors, insurers for administrative purposes
- IT and hosting providers who process data under contract and Data Processing Agreements
- Legal and professional advisers when required for legal proceedings or compliance
All third parties are required to keep your information secure and only process it for the specified purposes. Where appropriate we have Data Processing Agreements in place.
International / Cross-Border Transfers
Where data is transferred outside the UK/EEA we will ensure appropriate safeguards such as UK-approved Standard Contractual Clauses, adequacy decisions or technical measures (e.g. encryption) are in place prior to transfer. We will inform you in advance if any transfer of your personal data outside the UK/EEA is required for your care or administration.
Data Security & Storage
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These measures include:
- Role-based access controls and user authentication
- Encryption in transit (TLS) and where appropriate at rest
- Secure backups and tested disaster recovery
- Regular security testing and staff training
- Data minimisation — we only collect what is necessary
If a personal data breach occurs which poses a risk to your rights and freedoms we will comply with our obligations to notify the Information Commissioner’s Office and any affected individuals where required by law.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes set out above or as required by law. After that, personal data is either securely deleted or irreversibly anonymised.
- Clinical / treatment records: Retained for the duration of treatment and for the clinically or legally required period thereafter (e.g. typically 7 years after discharge for adults; please check local guidance for specific periods).
- Billing / financial records: Retained in line with accounting and audit requirements.
- Consent / communications logs: Retained for a period necessary to demonstrate compliance.
- Anonymised datasets: May be retained for service evaluation indefinitely.
Your Rights
Under the UK GDPR you have a number of rights in relation to your personal data, subject to applicable exemptions:
- Right to be informed — about how your data is used.
- Right of access — you may request a copy of personal data we hold about you.
- Right to rectification — you can ask us to correct inaccurate or incomplete data.
- Right to erasure — in certain circumstances you can request data deletion.
- Right to restrict processing — ask us to limit processing in specified situations.
- Right to data portability — request structured, machine-readable copies of data we hold, where applicable.
- Right to object — object to certain processing including direct marketing.
- Rights in relation to automated decision-making — where applicable.
- Right to withdraw consent — for processing based on consent.
To exercise any of these rights, please contact us at dpo@stonebridge.rehab or by telephone at +44 [INSERT PHONE NUMBER]. We may need to verify your identity before responding. Where required by law we aim to respond within one month; this can be extended by up to two further months in complex cases.
Complaints & Supervisory Authority
If you are unhappy with our handling of your personal data, please contact us first so we can attempt to resolve your concern. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):
- Information Commissioner’s Office (ICO)
- Website: https://ico.org.uk
- Telephone: 0303 123 1113
Changes to this page
We may update this GDPR Compliance page from time to time to reflect changes to our practices or to reflect legal updates. Where changes are significant we will provide a notice on our site or notify you directly if we hold your contact details.
Last updated: 6th October, 2025