Privacy and Cookie Policy
This privacy policy sets out how this website (hereafter "the Site") uses and protects any information that you give the Site while using this website. The Site is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using this website, then you can be assured that it will only be used in accordance with this privacy statement. The Stite may change this policy from time to time by updating this page. You should check this page from time to time to ensure that you are happy with any changes.
What we collect
We may collect the following information:
name
contact information including email address
Address
Organisation name
Your unique ID no.
demographic information such as postcode, preferences and interests
other information relevant to customer surveys and/or offersGenerated privacy notice - health and social care
Scanguards customer privacy notice
This privacy notice tells you what to expect us to do with your personal information.
· What information we collect, use, and why
· Lawful bases and data protection rights
· Where we get personal information from
· How long we keep information
· Who we share information with
Contact details
Telephone
076548792
Email
info@scanguards.co.uk
What information we collect, use, and why
We collect or use the following information to services and other goods:
· Name, address and contact details
· Health information (including medical conditions, allergies, medical requirements and medical history)
We also collect the following information services and other goods:
· Health information
We collect or use the following personal information for information updates, marketing or market research purposes:
· Names and contact details
· Marketing preferences
· IP addresses
We collect or use the following personal information for dealing with queries, complaints or claims:
· Names and contact details
· Address
· Account information
· Purchase or service history
· Relevant information from previous investigations
· Customer or client accounts and records
Lawful bases and data protection rights
Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.
Which lawful basis we rely on may affect your data protection rights which are in brief set out below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:
· Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for
You can read more about this right here.· Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete.
You can read more about this right here.· Your right to erasure - You have the right to ask us to delete your personal information.
You can read more about this right here.· Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information.
You can read more about this right here.· Your right to object to processing - You have the right to object to the processing of your personal data.
You can read more about this right here.· Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you.
You can read more about this right here.· Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time.
You can read more about this right here.If you make a request, we must respond to you without undue delay and in any event within one month.
To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.
Our lawful bases for the collection and use of your data
Our lawful bases for collecting or using personal information to provide service and other goods are:
· Legitimate interest:
o we are collecting infromation so as we can contact the person or organisation to supply or resupply mouth guards.
Our lawful bases for collecting or using personal information for information updates, marketing or market research purposes are:
· Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
o so as we can update you on promotions and offers
Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:
· Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
Where we get personal information from
· Directly from you
· Schools, colleges, universities or other education organisations
· Website forms
How long we keep information
[Insert information about how long you store personal information here.]
[Paste your retention schedule here.]
Who we share information with
Others we share personal information with
· Suppliers and service providers in order to manufacture your mouth guard
Duty of confidentiality
We are subject to a common law duty of confidentiality. However, there are circumstances where we will share relevant health and care information. These are where:
· you’ve provided us with your consent (we have taken it as implied to provide you with care, or you have given it explicitly for other uses);
· we have a legal requirement (including court orders) to collect, share or use the data;
· on a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime);
· If in England or Wales – the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied; or
· If in Scotland – we have the authority to share provided by the Chief Medical Officer for Scotland, the Chief Executive of NHS Scotland, the Public Benefit and Privacy Panel for Health and Social Care or other similar governance and scrutiny process.
List of cookies we collect
Below is a list of cookies we use:
_acloggedin
Supports login by Acuity Scheduling client if the client has an account
Cookie
January 1, 2025
ACUITY_CART
Stores details about a client's package, gift, or subscription purchase, including the item purchased and the quantity
Only applies to the new scheduler
localStorage
No expiration
_client_acloggedin
Supports login by Acuity Scheduling client if the client has an account
Cookie
January 1, 2025
_dd_cookie_test
Tests if cookies are supported
Cookie
Expires instantly
_dd_s
Tracks browser errors
Cookie
Four hours
_dd_site_test
Tests if cookies are supported
Cookie
Expires instantly
_grecaptcha
Helps reduce spam in Acuity Scheduling
localStorage
No expiry
_ssid
Remembers devices for anti-fraud purposes
Cookie
Four years
CART
Shows when a visitor adds a product to their cart
Cookie
Two weeks
CHECKOUT_WEBSITE
Identifies the correct site for checkout when checkout on your domain is disabled
Cookie
Session
client_username
Remembers a logged in Acuity Scheduling client's username between visits
Cookie
One year
clientUser
Stores the Acuity Scheduling client's username, OAuth2 Access Token, and OAuth2 Refresh Token. This cookie is required for functionality of logged-in clients
Cookie
30 days
Commerce-checkout-state
Stores state of checkout while the visitor is completing their order in PayPal
sessionstorage
Session
Crumb
Prevents cross-site request forgery (CSRF)
Cookie
Session
hasCart
Tells Squarespace that the visitor has a cart
Cookie
Two weeks
Locked
Prevents the password-protected screen from displaying if a visitor enters the correct site-wide password.
Cookie
Session
orderStatusSessionToken
Authenticates a visitor who logs into an order status page.
Cookie
One year
PHPSESSID
Securely authenticates a visitor during their checkout in Acuity Scheduling
Cookie
One month
RecentRedirect
Prevents redirect loops if a site has custom URL redirects. Redirect loops are bad for SEO.
Cookie
30 minutes
remember_client
Remembers Acuity Scheduling client’s login details if they have an account
Cookie
365 days
siteUserCrumb
Prevents cross-site request forgery (CSRF) for logged in site users
Cookie
Three years
SiteUserInfo
Identifies a visitor who logs into a customer account
Cookie
Three years
SiteUserSecureAuthToken
Authenticates a visitor who logs into a customer account
Cookie
Three years
squarespace-announcement-bar
Prevents the announcement bar from displaying if a visitor dismisses it
localStorage
Persistent
squarespace-likes
Shows when you've already "liked" a blog post
localStorage
Persistent
squarespace-popup-overlay
Prevents the promotional pop-up from displaying if a visitor dismisses it
localStorage
Persistent
squarespace-video-player-options
Remembers video player selected preferences ( volume, playback speed, and quality) for videos uploaded directly to Squarespace
localStorage
Persistent
ss_cookieAllowed
Remembers if a visitor agreed to placing analytics cookies on their browser if a site is restricting the placement of cookies
Cookie
30 days
ss_sd
Ensures that visitors on the Squarespace 5 platform remain authenticated during their sessions
Cookie
Session
Test
Investigates if the browser supports cookies and prevents errors
Cookie
Session
TZ
Enables a Acuity Scheduling client’s appointments to display correctly based on their time zone preferences.
localStorage
Persistent
Cross-site request forgery (CSRF)
CSRF is an attack vector that tricks a browser into taking unwanted action in an application when someone’s logged in.
Analytics and performance cookies
We use analytics and performance cookies to collect information on your behalf about how visitors interact with your site. Storing these cookies is how we populate the data you find in Squarespace analytics, such as traffic sources, unique visitors, and cart abandonment.
You can disable Squarespace analytics and performance cookies at any time.
Cookie Name, Duration and Purpose
ss_cid
Two years
Identifies unique visitors and tracks a visitor’s sessions on a site
ss_cpvisit
Two years
Identifies unique visitors and tracks a visitor’s sessions on a site
ss_cvisit
30 minutes
Identifies unique visitors and tracks a visitor’s sessions on a site
ss_cvr
Two years
Identifies unique visitors and tracks a visitor’s sessions on a site
ss_cvt
30 minutes
Identifies unique visitors and tracks a visitor’s sessions on a site
How to have your data erased
Please email info@scanguards.co.uk and request that all your data is removed. We aim to respond within 3 working days to confirm all data we hold for you is erased.
How to complain
If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.
If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint
Last updated
22 November 2024