Privacy Policy.
How we collect, use and protect your personal information — including the special category health data we hold as your healthcare provider.
About us and this policy
My Health & Wellbeing Clinics Ltd is a company incorporated in England and Wales. Our company number is 14811638 and our trading address is 97–99 Whitechapel Road, London E1 1DT. Throughout this document, references to "we", "our" or "us" refer to My Health & Wellbeing Clinics Ltd.
We are committed to protecting the privacy, confidentiality, and integrity of all personal data entrusted to us. As a healthcare provider, we recognise that we process highly sensitive information, including special category data relating to health, and we therefore apply a high standard of care in how such information is handled.
We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all associated legislation, guidance and regulatory expectations. This includes adherence to the Records Management Code of Practice for Health and Social Care and alignment with Care Quality Commission (CQC) expectations regarding information governance.
For the purposes of data protection law, My Health & Wellbeing Clinics Ltd acts as the data controller. This means that we determine the purposes for which, and the manner in which, your personal data is processed. Any queries relating to this policy or the processing of your data can be directed to us at info@mhwclinic.co.uk.
Note on AI tools
As part of delivering modern, efficient and safe healthcare services, we use secure digital systems including AI-supported tools. These technologies are implemented to support, not replace, human staff and clinicians. They operate under strict governance frameworks and are subject to human oversight at all times. They do not make independent clinical decisions, and all outputs are reviewed and validated by appropriately qualified professionals. See our AI Policy for full details on how we use AI safely.
What information we collect
We collect personal information in a number of ways. This includes information that you provide directly to us when you complete forms on our website, book an appointment, contact us by telephone or email, or attend a consultation. The information you provide may include your name, date of birth, address, email address, telephone number, and any medical or health information that is relevant to your care.
As a healthcare provider, much of the information we process falls into the category of special category data under UK GDPR, meaning that it is afforded additional protection due to its sensitive nature.
In addition to the information you provide directly, we may collect technical information when you use our website, including your IP address, browser type, operating system, and information about how you interact with the website. We may also receive information about you from other sources involved in your care, such as laboratories, diagnostic providers or specialists.
Lawful basis for processing
We process your personal data on the basis of lawful grounds set out in UK GDPR. For general personal data, this includes processing that is necessary for the performance of a contract (such as providing you with medical services), as well as processing required to comply with legal obligations and to support our legitimate interests, such as maintaining service quality and preventing fraud.
For health data and other special category data, we rely on Article 9(2)(h) of UK GDPR, which permits processing where it is necessary for the purposes of medical diagnosis, the provision of healthcare, and treatment.
How we use your data
We use your personal data in order to deliver healthcare services, maintain accurate clinical records, communicate with you regarding your care, arrange referrals and investigations, process payments, and comply with legal and regulatory obligations. We may also use data in an anonymised or aggregated form to improve our services, monitor performance, and support quality improvement initiatives.
We do not carry out solely automated decision-making that produces legal or similarly significant effects. While AI systems may assist in processing information, all clinical decisions are made by qualified healthcare professionals.
We will only send marketing communications where you have provided explicit consent. You have the right to withdraw this consent at any time.
How long we keep your data
We retain your personal data only for as long as necessary and in accordance with legal and regulatory requirements. In healthcare, retention periods are guided by the Records Management Code of Practice for Health and Social Care.
In general, adult medical records are retained for a minimum period of eight years following the last contact. In certain cases, such as where treatment involves children or where there are ongoing legal or clinical considerations, records may be retained for longer. Retention decisions are based on a combination of clinical need, legal requirements, and patient safety considerations.
Who we share your data with
We may share your personal data with third parties where this is necessary for your care or where we are required to do so by law. This includes:
- Laboratories and imaging providers (for tests we order on your behalf)
- Specialists and other clinicians (for referrals)
- Pharmacies (for prescriptions)
- IT providers (under contract as our data processors)
- Regulatory bodies such as the Care Quality Commission or the Information Commissioner's Office, where required
- AI providers including Lyngo AI and ambient voice technologies, strictly within the scope of their role as data processors under Article 28 UK GDPR
We do not sell your personal data to third parties.
In some cases, your data may be transferred outside the United Kingdom or the European Economic Area. Where this occurs, we ensure that appropriate safeguards are in place, such as the use of Standard Contractual Clauses, to ensure that your data remains protected to an equivalent standard.
How we protect your data
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it. These include secure clinical systems, encryption, access controls, and staff training on confidentiality and data protection. However, it is important to note that the transmission of information via the internet is not completely secure, and there are inherent risks associated with electronic communication.
Your rights
You have a number of rights in relation to your personal data under UK GDPR:
- Right of access — request a copy of the data we hold about you
- Right to rectification — request correction of inaccurate information
- Right to erasure — request deletion in certain circumstances (note: health records have statutory retention periods)
- Right to restrict processing — ask us to limit how we use your data
- Right to object — particularly for direct marketing or processing based on legitimate interests
- Right to data portability — receive your data in a structured, commonly used format
Requests will be handled in accordance with legal requirements, typically within one month. To exercise any of these rights, email info@mhwclinic.co.uk with the relevant subject line (for example, "Subject Access Request" or "Data Erasure Request").
How to complain
If you have concerns about how your data is handled, please contact us first at info@mhwclinic.co.uk. We aim to acknowledge data protection concerns within 7 working days.
You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
- Website: ico.org.uk
- Helpline: 0303 123 1113