Privacy Policy
We are Diamed London Clinic Ltd, a company incorporated in England and Wales.
- Company Number: 13728403
- Registered Address: 500 White Hart Lane, London, England, N17 7NA
- Clinic Address: 83A High Street, Waltham Cross, EN8 7AF
- Regulated by: the Care Quality Commission (CQC)
(“Diamed London Clinic Ltd” / “we” / “our” / “us”)
We are committed to ensuring that your privacy is protected. We comply with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”), together with all national implementing laws, regulations and secondary legislation as amended or updated from time to time in the UK, and any successor legislation (together “Data Protection Legislation”).
As a healthcare provider we are also bound by the common law duty of confidentiality, the Caldicott Principles, and the Records Management Code of Practice for Health and Social Care. Our clinicians are additionally bound by the confidentiality standards of their professional regulators, including the General Medical Council and the Nursing & Midwifery Council.
We are the data controller of the personal data described in this policy, and we are registered with the Information Commissioner’s Office as a data controller.
This Privacy Policy, together with our website terms and conditions and cookie policy, sets out how we collect personal information from you and how the personal information you provide will be processed by us.
By visiting our website at www.diamedclinic.com (the “Website”) you are accepting the practices described in this Privacy Policy in relation to your use of the Website. Where we rely on your consent for a specific activity, such as marketing, we will always ask for it separately and you may withdraw it at any time.
Our Data Protection Lead
Questions about how we handle your information, and requests to exercise your rights, should be sent to our Data Protection Lead:
Data Protection Lead Diamed London Clinic Ltd, 83A High Street, Waltham Cross, EN8 7AF Email: info@diamedclinic.com Telephone: 020 3807 5555
What Information Do We Hold?
Information You Give Us
You may give us information by completing enquiry or booking forms on the Website, by contacting us by telephone, email or WhatsApp, by attending an appointment, or by asking us to send you marketing information. This may include your name, date of birth, email address, postal address, telephone number and the reason for your enquiry.
Health and Other Special Category Information
If you become a patient, we will also hold information that is special category data under Article 9 of the UK GDPR, including:
- Your medical history, symptoms, diagnoses and test results
- Details of treatments, procedures, prescriptions and medicines
- Consultation notes, referral letters and correspondence with other clinicians
- Clinical photographs, scans and images, where these are relevant to your care
- Allergies, family history and lifestyle information relevant to your treatment
- Information about your race, ethnicity, religion or beliefs where this is relevant to your care or to our equality monitoring
- Details of any complaint, safeguarding concern or incident involving you
We may also process criminal offence data in limited circumstances, for example where this is necessary for safeguarding.
Information We Collect About You Online
We may collect the following when you visit the Website:
Technical information, including your internet protocol (IP) address, login information, browser type and version, time zone setting, browser plug-in types and versions, and operating system and platform.
Information about your visit, including full Uniform Resource Locators (URL), clickstream to, through and from the Website, services you viewed or searched for, page response times, Website errors, length of visits to certain pages, page interaction information, methods used to browse away from the page, and any phone number used to call us.
Information We Receive from Other Sources
This includes information from your GP or another treating clinician, from a hospital or laboratory, from an insurer or employer where they are funding your treatment, and from anyone acting on your behalf with your consent.
Our Lawful Bases for Processing
We must have a lawful basis under Article 6 of the UK GDPR for all personal data, and an additional condition under Article 9 for health and other special category data.
| What we do | Article 6 basis | Article 9 condition (special category data) |
|---|---|---|
| Providing your care and treatment | Contract | Article 9(2)(h) โ provision of health care and treatment, with DPA 2018 Schedule 1 Part 1 paragraph 2 |
| Keeping accurate clinical records | Legal obligation | Article 9(2)(h) |
| Managing appointments, payments and invoicing | Contract | Not applicable |
| Safeguarding children and adults at risk | Legal obligation / vital interests | Article 9(2)(b), 9(2)(c) or DPA 2018 Schedule 1 Part 2 paragraph 18 |
| Responding to a complaint or a claim | Legitimate interests / legal obligation | Article 9(2)(f) or 9(2)(h) |
| Meeting CQC and other regulatory requirements | Legal obligation | Article 9(2)(h) or 9(2)(i) |
| Clinical audit and service improvement | Legitimate interests | Article 9(2)(h) |
| Sending you marketing | Consent | Not applicable |
| Website analytics and security | Legitimate interests / consent | Not applicable |
Where we rely on legitimate interests, our interests are in running a safe, efficient and secure clinic. We have assessed that this does not override your rights and freedoms, and you may object at any time.
Separately from data protection law, we handle your clinical information under the common law duty of confidentiality. This means we will not disclose information you give us in confidence unless you have consented, the law requires or permits it, or there is an overriding public interest.
How We Use Your Information
We use your information to:
- Provide, plan and deliver your care and treatment
- Maintain complete and accurate clinical records, as required by our regulators
- Contact you about appointments, results, follow-up and aftercare
- Take payment and issue invoices, and to liaise with your insurer where relevant
- Investigate and respond to complaints, incidents and safeguarding concerns
- Carry out clinical audit, review the quality and safety of our services, and train our staff
- Comply with our legal and regulatory duties, including those owed to the CQC
- Send you newsletters and marketing information, where you have consented
- Monitor Website usage, keep our systems secure and prevent fraud
We do not use your health information for marketing, and we do not sell your data to anyone.
Who We Share Your Information With
Sharing to support your care
- Your GP and other clinicians involved in your treatment, where you agree
- Hospitals, laboratories, pharmacies, radiology and pathology providers acting on our instructions
- Insurers, employers or embassies, where they are funding your treatment and you have authorised the disclosure
- Interpreters, advocates, carers or family members you have asked us to involve
Sharing we are required or permitted by law to make
- The Care Quality Commission, where necessary for its regulatory functions
- The UK Health Security Agency and local public health teams, for notifiable diseases under the Health Protection (Notification) Regulations 2010
- The police, local authority safeguarding teams and the courts, where required by law or where there is an overriding public interest
- Professional regulators such as the General Medical Council, where we have a duty to report
- Coroners and other statutory bodies exercising legal powers
Suppliers acting on our behalf (data processors)
We use trusted suppliers for clinical record systems, appointment booking, secure email and messaging, payment processing, IT support and hosting. They act only on our documented instructions and are bound by written contracts that meet Article 28 of the UK GDPR.
Website data
Analytics and advertising providers may receive non-clinical Website usage data where you have consented through our cookie banner. Your health information is never shared with advertisers or advertising networks.
We may also disclose personal information if we sell or buy business assets, where we are under a legal duty to comply with a legal obligation, or where we need to protect our rights, property or the safety of our patients and staff.
International Transfers
We aim to keep your data within the UK. Some of our suppliers, for example cloud hosting and email providers, may process data outside the UK. Where that happens, we only transfer data to a country covered by UK adequacy regulations, or under an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
You may request details of the safeguards applied to any transfer by contacting our Data Protection Lead.
How Long We Keep Your Information
We keep your information for no longer than is necessary. Our retention periods follow the Records Management Code of Practice for Health and Social Care:
| Record type | Retention period |
|---|---|
| Adult clinical records | 8 years after the last entry or after discharge |
| Children’s and young people’s clinical records | Until the patient’s 25th birthday, or 26th if the last entry was made at age 17 |
| Records of a deceased patient | 8 years after death |
| Complaint records | 10 years from resolution |
| Payment and financial records | 6 years, as required by HMRC |
| Website enquiry forms | 1 year |
| Marketing data | Until you withdraw consent |
| Website analytics data | Up to 26 months |
| CCTV footage, where operated | 30 days, unless required for an investigation |
At the end of the retention period, records are securely and confidentially destroyed.
Automated Decision-Making
We do not make decisions about your care using automated processing or profiling that produce legal effects concerning you or similarly significantly affect you. All clinical decisions are made by a qualified clinician.
Children’s Information
We provide services to children and young people. Where a child is competent to make their own decisions about their care, they hold their own data protection rights. Where they are not, a person with parental responsibility may exercise those rights on their behalf. We assess capacity and competence case by case, and we act in the best interests of the child.
We do not knowingly collect personal information from children through the Website without the involvement of a parent or guardian.
Cookies
The Website uses cookies to distinguish you from other users. Non-essential cookies are set only with your consent. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy.
Keeping Your Information Safe
Protecting your security and privacy is important to us. We maintain organisational and technical measures appropriate to the risk, including:
- Access controls, so staff can only see the records they need for their role
- Encryption of data in transit and at rest, and secure email for clinical correspondence
- Confidentiality clauses in every staff and contractor agreement
- Information governance and data protection training for all staff
- Regular review of our systems, suppliers and security arrangements
- Secure storage and confidential destruction of paper records
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.
Please note: transmission of information over the Internet is not completely secure. Any transmission you make to us over an unencrypted channel is at your own risk.
Third Party Sites
Our Website may contain links to third party websites. We do not check, endorse, approve or agree with such third-party websites nor the products and services offered on them, and we have no responsibility for their content. Please review the terms and privacy policies of third-party websites before use.
Your Rights
Under Data Protection Legislation, you have the right to:
- Be informed about how we use your data, which is the purpose of this policy
- Access your personal data and your health records, through a subject access request
- Rectify inaccurate data, or have incomplete data completed
- Request erasure of your data in certain circumstances
- Restrict processing in certain circumstances
- Object to processing based on our legitimate interests
- Object to direct marketing at any time, which is an absolute right
- Data portability for data you provided to us, where processing is automated and based on consent or contract
- Withdraw consent at any time where we rely on it
- Not be subject to solely automated decision-making with legal or similarly significant effects
Important limits on these rights in a healthcare setting. The right to erasure does not generally apply to your clinical records, because we hold them to comply with a legal obligation and for the provision of health care. For the same reason we cannot simply delete an entry from a clinical record that you dispute. If you believe a record is inaccurate, we will add a note recording your view alongside the original entry.
Access to a deceased person’s records is not covered by data protection law. It is dealt with under the Access to Health Records Act 1990, and may be requested by a personal representative or by someone with a claim arising from the death.
How to make a request. Contact our Data Protection Lead using the details above. We will respond within one month, free of charge. We may extend this by up to two further months for complex requests, and we will tell you if we do. We may ask you for proof of identity before releasing information.
Complaints
If you have a concern about how we have handled your personal data, please contact our Data Protection Lead first so that we can put it right. You can also use our Complaints Procedure.
You have the right to complain to the supervisory authority. In the UK this is the Information Commissioner’s Office (ICO):
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 Website: ico.org.uk
Concerns about the quality or safety of our clinical services can be raised with the Care Quality Commission on 03000 616161 or at www.cqc.org.uk.
Changes to This Policy
We review this policy at least annually and whenever our processing changes. Any changes will be posted on this page with a revised update date. Where changes are significant, we will tell you directly.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: info@diamedclinic.com
- Phone: 020 3807 5555
- Address: 83A High Street, Waltham Cross, EN8 7AF
Last updated: 4 September 2026