Privacy Policy

Last updated: 30/04/2025

 

1. Introduction

Your privacy is important to me. This Privacy Policy explains how Jennifer Thawley, a Registered Dietitian based in the UK, collects, uses, discloses and protects personal data when you engage with services provided by Jennifer Thawley Dietetic Consultancy.

 

2. Data Controller

Name: Jennifer Thawley of Jennifer Thawley Dietetic Consultancy

Address: Croft Cottage, 28 Jermyn Croft, Dodworth, Barnsley, South Yorkshire, S75 3LR

Email: Jen@jtdiet.co.uk

Phone: +44 (0)7757431071

 

3. Personal Data Collected

I will collect:

 

  • Identity Data: name, date of birth, gender
  • Contact Data: address, email, telephone number
  • Health & Lifestyle Data (Special Category): medical history, dietary requirements, lifestyle information, weight/height
  • Technical & Usage Data: If sharing information from apps related to CGM such as Freestyle Libre, Dexcom Clarity, Camdiab to view blood glucose data

 

 

4. Lawful Basis for Processing

 

  • Contract (Art. 6(1)(b) GDPR): to provide dietetic assessment and treatment.
  • Legal obligation (Art. 6(1)(c)): for record-keeping as required by professional standards.
  • Consent (Art. 6(1)(a) & Art. 9(2)(a)): to process special category health data. You are free to withdraw consent at any time (see section 8).

 

5. Disclosure to Third Parties

We may share data with:

 

  • Healthcare partners (e.g. GP, other allied professionals) but only with your explicit consent.
  • IT service providers. I use Halaxy to keep your health care record under GDPR law 
  • Regulatory authorities or law enforcement where required by law.

 

 

6. International Transfers

All data is stored on servers within the UK/EU. If I ever transfer outside the EEA, I will put in place standard contractual clauses to ensure adequate protection.

 

7. Your Rights

Under GDPR you have the right to:

  • Access your data (Subject Access Request)
  • Rectify inaccuracies
  • Erase (be forgotten), unless we have a legal reason to retain it
  • Restrict or object to processing
  • Data portability (to another provider)
  • Withdraw consent at any time (for health data and marketing)
  • Lodge a complaint with the ICO:  https://ico.org.uk

 

To exercise any right, please contact jen@jtdiet.co.uk

 

8. Data Retention

I retain client records for a minimum of 8 years from the date of last treatment (in line with professional guidelines). After this period data is securely deleted.

 

 

9. Security

I have implemented appropriate technical and organisational measures (encryption, access controls) to protect your data against accidental loss or unlawful access.

 

10. Changes to This Policy

I may update this policy from time to time. The “Last updated” date at the top will reflect the revision date. Significant changes will be notified by email or via my website.

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.