Home
Language EN
Contact Us

Privacy Policy

We are Diamed London Clinic Ltd, a company incorporated in England and Wales.

  • Company Number: 13728403
  • Registered Address: 500 White Hart Lane, London, England, N17 7NA
  • Clinic Address: 83A High Street, Waltham Cross, EN8 7AF
  • Regulated by: the Care Quality Commission (CQC)

(“Diamed London Clinic Ltd” / “we” / “our” / “us”)

We are committed to ensuring that your privacy is protected. We comply with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”), together with all national implementing laws, regulations and secondary legislation as amended or updated from time to time in the UK, and any successor legislation (together “Data Protection Legislation”).

As a healthcare provider we are also bound by the common law duty of confidentiality, the Caldicott Principles, and the Records Management Code of Practice for Health and Social Care. Our clinicians are additionally bound by the confidentiality standards of their professional regulators, including the General Medical Council and the Nursing & Midwifery Council.

We are the data controller of the personal data described in this policy, and we are registered with the Information Commissioner’s Office as a data controller.

This Privacy Policy, together with our website terms and conditions and cookie policy, sets out how we collect personal information from you and how the personal information you provide will be processed by us.

By visiting our website at www.diamedclinic.com (the “Website”) you are accepting the practices described in this Privacy Policy in relation to your use of the Website. Where we rely on your consent for a specific activity, such as marketing, we will always ask for it separately and you may withdraw it at any time.


Our Data Protection Lead

Questions about how we handle your information, and requests to exercise your rights, should be sent to our Data Protection Lead:

Data Protection Lead Diamed London Clinic Ltd, 83A High Street, Waltham Cross, EN8 7AF Email: info@diamedclinic.com Telephone: 020 3807 5555


What Information Do We Hold?

Information You Give Us

You may give us information by completing enquiry or booking forms on the Website, by contacting us by telephone, email or WhatsApp, by attending an appointment, or by asking us to send you marketing information. This may include your name, date of birth, email address, postal address, telephone number and the reason for your enquiry.

Health and Other Special Category Information

If you become a patient, we will also hold information that is special category data under Article 9 of the UK GDPR, including:

  • Your medical history, symptoms, diagnoses and test results
  • Details of treatments, procedures, prescriptions and medicines
  • Consultation notes, referral letters and correspondence with other clinicians
  • Clinical photographs, scans and images, where these are relevant to your care
  • Allergies, family history and lifestyle information relevant to your treatment
  • Information about your race, ethnicity, religion or beliefs where this is relevant to your care or to our equality monitoring
  • Details of any complaint, safeguarding concern or incident involving you

We may also process criminal offence data in limited circumstances, for example where this is necessary for safeguarding.

Information We Collect About You Online

We may collect the following when you visit the Website:

Technical information, including your internet protocol (IP) address, login information, browser type and version, time zone setting, browser plug-in types and versions, and operating system and platform.

Information about your visit, including full Uniform Resource Locators (URL), clickstream to, through and from the Website, services you viewed or searched for, page response times, Website errors, length of visits to certain pages, page interaction information, methods used to browse away from the page, and any phone number used to call us.

Information We Receive from Other Sources

This includes information from your GP or another treating clinician, from a hospital or laboratory, from an insurer or employer where they are funding your treatment, and from anyone acting on your behalf with your consent.


Our Lawful Bases for Processing

We must have a lawful basis under Article 6 of the UK GDPR for all personal data, and an additional condition under Article 9 for health and other special category data.

What we do Article 6 basis Article 9 condition (special category data)
Providing your care and treatment Contract Article 9(2)(h) โ€” provision of health care and treatment, with DPA 2018 Schedule 1 Part 1 paragraph 2
Keeping accurate clinical records Legal obligation Article 9(2)(h)
Managing appointments, payments and invoicing Contract Not applicable
Safeguarding children and adults at risk Legal obligation / vital interests Article 9(2)(b), 9(2)(c) or DPA 2018 Schedule 1 Part 2 paragraph 18
Responding to a complaint or a claim Legitimate interests / legal obligation Article 9(2)(f) or 9(2)(h)
Meeting CQC and other regulatory requirements Legal obligation Article 9(2)(h) or 9(2)(i)
Clinical audit and service improvement Legitimate interests Article 9(2)(h)
Sending you marketing Consent Not applicable
Website analytics and security Legitimate interests / consent Not applicable

Where we rely on legitimate interests, our interests are in running a safe, efficient and secure clinic. We have assessed that this does not override your rights and freedoms, and you may object at any time.

Separately from data protection law, we handle your clinical information under the common law duty of confidentiality. This means we will not disclose information you give us in confidence unless you have consented, the law requires or permits it, or there is an overriding public interest.


How We Use Your Information

We use your information to:

  • Provide, plan and deliver your care and treatment
  • Maintain complete and accurate clinical records, as required by our regulators
  • Contact you about appointments, results, follow-up and aftercare
  • Take payment and issue invoices, and to liaise with your insurer where relevant
  • Investigate and respond to complaints, incidents and safeguarding concerns
  • Carry out clinical audit, review the quality and safety of our services, and train our staff
  • Comply with our legal and regulatory duties, including those owed to the CQC
  • Send you newsletters and marketing information, where you have consented
  • Monitor Website usage, keep our systems secure and prevent fraud

We do not use your health information for marketing, and we do not sell your data to anyone.


Who We Share Your Information With

Sharing to support your care

  • Your GP and other clinicians involved in your treatment, where you agree
  • Hospitals, laboratories, pharmacies, radiology and pathology providers acting on our instructions
  • Insurers, employers or embassies, where they are funding your treatment and you have authorised the disclosure
  • Interpreters, advocates, carers or family members you have asked us to involve

Sharing we are required or permitted by law to make

  • The Care Quality Commission, where necessary for its regulatory functions
  • The UK Health Security Agency and local public health teams, for notifiable diseases under the Health Protection (Notification) Regulations 2010
  • The police, local authority safeguarding teams and the courts, where required by law or where there is an overriding public interest
  • Professional regulators such as the General Medical Council, where we have a duty to report
  • Coroners and other statutory bodies exercising legal powers

Suppliers acting on our behalf (data processors)

We use trusted suppliers for clinical record systems, appointment booking, secure email and messaging, payment processing, IT support and hosting. They act only on our documented instructions and are bound by written contracts that meet Article 28 of the UK GDPR.

Website data

Analytics and advertising providers may receive non-clinical Website usage data where you have consented through our cookie banner. Your health information is never shared with advertisers or advertising networks.

We may also disclose personal information if we sell or buy business assets, where we are under a legal duty to comply with a legal obligation, or where we need to protect our rights, property or the safety of our patients and staff.


International Transfers

We aim to keep your data within the UK. Some of our suppliers, for example cloud hosting and email providers, may process data outside the UK. Where that happens, we only transfer data to a country covered by UK adequacy regulations, or under an appropriate safeguard such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

You may request details of the safeguards applied to any transfer by contacting our Data Protection Lead.


How Long We Keep Your Information

We keep your information for no longer than is necessary. Our retention periods follow the Records Management Code of Practice for Health and Social Care:

Record type Retention period
Adult clinical records 8 years after the last entry or after discharge
Children’s and young people’s clinical records Until the patient’s 25th birthday, or 26th if the last entry was made at age 17
Records of a deceased patient 8 years after death
Complaint records 10 years from resolution
Payment and financial records 6 years, as required by HMRC
Website enquiry forms 1 year
Marketing data Until you withdraw consent
Website analytics data Up to 26 months
CCTV footage, where operated 30 days, unless required for an investigation

At the end of the retention period, records are securely and confidentially destroyed.


Automated Decision-Making

We do not make decisions about your care using automated processing or profiling that produce legal effects concerning you or similarly significantly affect you. All clinical decisions are made by a qualified clinician.


Children’s Information

We provide services to children and young people. Where a child is competent to make their own decisions about their care, they hold their own data protection rights. Where they are not, a person with parental responsibility may exercise those rights on their behalf. We assess capacity and competence case by case, and we act in the best interests of the child.

We do not knowingly collect personal information from children through the Website without the involvement of a parent or guardian.


Cookies

The Website uses cookies to distinguish you from other users. Non-essential cookies are set only with your consent. For detailed information on the cookies we use and the purposes for which we use them, please see our Cookie Policy.


Keeping Your Information Safe

Protecting your security and privacy is important to us. We maintain organisational and technical measures appropriate to the risk, including:

  • Access controls, so staff can only see the records they need for their role
  • Encryption of data in transit and at rest, and secure email for clinical correspondence
  • Confidentiality clauses in every staff and contractor agreement
  • Information governance and data protection training for all staff
  • Regular review of our systems, suppliers and security arrangements
  • Secure storage and confidential destruction of paper records

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high.

Please note: transmission of information over the Internet is not completely secure. Any transmission you make to us over an unencrypted channel is at your own risk.


Third Party Sites

Our Website may contain links to third party websites. We do not check, endorse, approve or agree with such third-party websites nor the products and services offered on them, and we have no responsibility for their content. Please review the terms and privacy policies of third-party websites before use.


Your Rights

Under Data Protection Legislation, you have the right to:

  • Be informed about how we use your data, which is the purpose of this policy
  • Access your personal data and your health records, through a subject access request
  • Rectify inaccurate data, or have incomplete data completed
  • Request erasure of your data in certain circumstances
  • Restrict processing in certain circumstances
  • Object to processing based on our legitimate interests
  • Object to direct marketing at any time, which is an absolute right
  • Data portability for data you provided to us, where processing is automated and based on consent or contract
  • Withdraw consent at any time where we rely on it
  • Not be subject to solely automated decision-making with legal or similarly significant effects

Important limits on these rights in a healthcare setting. The right to erasure does not generally apply to your clinical records, because we hold them to comply with a legal obligation and for the provision of health care. For the same reason we cannot simply delete an entry from a clinical record that you dispute. If you believe a record is inaccurate, we will add a note recording your view alongside the original entry.

Access to a deceased person’s records is not covered by data protection law. It is dealt with under the Access to Health Records Act 1990, and may be requested by a personal representative or by someone with a claim arising from the death.

How to make a request. Contact our Data Protection Lead using the details above. We will respond within one month, free of charge. We may extend this by up to two further months for complex requests, and we will tell you if we do. We may ask you for proof of identity before releasing information.


Complaints

If you have a concern about how we have handled your personal data, please contact our Data Protection Lead first so that we can put it right. You can also use our Complaints Procedure.

You have the right to complain to the supervisory authority. In the UK this is the Information Commissioner’s Office (ICO):

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 Website: ico.org.uk

Concerns about the quality or safety of our clinical services can be raised with the Care Quality Commission on 03000 616161 or at www.cqc.org.uk.


Changes to This Policy

We review this policy at least annually and whenever our processing changes. Any changes will be posted on this page with a revised update date. Where changes are significant, we will tell you directly.


Contact Us

If you have any questions about this Privacy Policy, please contact us:

Last updated: 4 September 2026