We are Khela Medical Limited, trading as Private Medical Clinic, a company incorporated in England and Wales. Our company registration number is 13657410 and our registered office address is 5 Scott Road, Walsall, West Midlands, United Kingdom, WS5 3JN.
Private Medical Clinic is dedicated to safeguarding your privacy and upholding the highest standards of data protection. We acknowledge the trust you place in us by providing your personal information and recognise the importance of protecting and respecting your privacy. In full compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act in effect in the UK (“Data Protection Laws”), we adhere to established clinical and medical guidelines, including those periodically issued by the General Medical Council, specified Royal Colleges, and the Nursing and Midwifery Council.
Scope of our Privacy Policy
This privacy policy pertains to individuals who engage with our products and services in any manner, including but not limited to email communication, telephone conversations, or postal correspondence. It outlines the principles governing the collection, retention, and processing of personal data pertaining to you. We will elucidate our procedures concerning the acquisition, use, safekeeping, and disclosure of personal data that we collect from you and/or maintain about you. Additionally, it elucidates your rights in relation to your data.
Should you have any inquiries or concerns regarding the information contained in this policy or our approach to handling your data, please do not hesitate to contact us at info@privatemedicalclinic.co.uk.
We encourage you to carefully review the following details to understand how we handle your personal data. By using our website, providing your personal information to us, or using our services, website, or other online or digital platforms, you implicitly consent to the practices detailed or alluded to in this Privacy Policy. Wherever reference is made to “we,” “us,” or “our,” it signifies Private Medical Clinic. References to “you” or “your” denote any individual who interacts with us concerning our products and services.
Collection of Personal Information
In this policy, the term “personal data” denotes information that can identify you as an individual or has the potential to do so. We may gather this information directly from you or from a third party, including but not limited to family members, legal guardians, insurance companies, healthcare professionals, clinical referrers, and others.
To provide you with our services, we may accumulate information about you through various interactions with us, including visiting our website, digitally completing an enquiry form, or communicating with us via post, email, or telephone. Depending on the services you receive from us, this may encompass sensitive personal data related to your health.
Personal data collected from you may encompass the following:
We may also obtain information about you from the following sources:
Patients Under 18 Years
There may be instances when we need to collect and process personal data regarding a child under 18 years of age, especially if requested by their parent or guardian for treatment. In such cases, we will ensure that we obtain consent from the parent or guardian and only collect and process the relevant and necessary personal data to facilitate the provision of treatment. We will not use the child’s personal data for any unrelated purpose without prior notification to the parent or guardian, clear specification of the legal basis for processing, and obtaining consent. If the child’s personal data needs to be transferred to a third party assisting with the treatment, we will communicate this to the parent or guardian beforehand and ensure that the third-party processor implements appropriate measures to safeguard the personal data.
Automatic Collection of Personal Data
When you use our website, we may automatically gather personal data about you, including:
Lawful Basis of Processing
We typically process personal data concerning our customers and individuals receiving our services when we are either under a contract or in the process of negotiating one. Such processing is necessary for the execution of the contract or when specific steps are requested before entering into a contract.
Additionally, we may process limited personal data of contacts for the legitimate interests of our clinic. We possess a legitimate interest in maintaining contact with our customers and contacts, which may encompass sending targeted emails regarding updates about our business. We have weighed this legitimate interest against the rights of the individual and do not consider it unreasonable, as individuals at all times have the right to request the erasure of their personal data.
Categories of Personal Information
We process two categories of personal information and data about you:
Collection of Personal Data
We may collect personal data about you when you:
Health Information Collected During the Provision of Treatment or Services
Sensitive personal data, including information related to your health, will only be disclosed to third parties involved in your treatment or care with your explicit consent. If you become our patient, you will be asked for consent to share information with doctors, other medical professionals, and insurance companies.
Where applicable, such information may also be disclosed to individuals or organisations responsible for covering your treatment expenses or their agents. It may additionally be shared with external service providers and regulatory bodies (unless you object), specifically for the purposes of clinical audits aimed at ensuring the highest standards of care and record-keeping.
Medical Professionals Working With Us
We share clinical information about you with medical professionals associated with your treatment. These professionals may include our employees, independent consultants in private practice, or consultants and clinicians employed by the NHS. Independent consultants and other doctors or medical practitioners act as data controllers for your personal data, either independently or jointly with us. They are required to maintain their own records in accordance with Data Protection Laws and relevant clinical confidentiality guidelines and retention periods. In such cases, we may refer you to them to exercise your rights over your data. Our contractual agreements with these consultants obligate them to cooperate with such requests, and they will only process your personal data for purposes outlined in this Privacy Policy or as otherwise communicated to you.
Your GP
If the healthcare professionals treating you believe it to be clinically advisable, we may share information about your treatment with your GP. You have the option to decline this, subject to legal permissions. However, it is important to recognise that withholding comprehensive medical history from your GP can pose serious risks to your health, and we strongly discourage it.
Your Insurer
We may share information about your treatment, its clinical necessity, and its cost with your medical insurer, but only if they are covering all or part of your treatment with us. We will only provide the information to which they are entitled. If you raise a complaint or a claim, we may be required to share personal data with your medical insurer for the purpose of investigating such matters.
The NHS
If you are referred to us for treatment by the NHS, we will share details of your treatment with the NHS entity that referred you to us, as necessary to perform, process, and report on that treatment.
Medical Regulators
We may be requested, and in some cases, obligated, to share specific information (including personal data and sensitive personal data) about you and your care with medical regulators, such as the General Medical Council or the Nursing and Midwifery Council. This may occur, for instance, if you lodge a complaint, or if the conduct of a medical professional involved in your treatment is alleged to have fallen below the appropriate standards and the regulator wishes to investigate. We will ensure that we adhere to the legal framework and respect your privacy in such cases.
We participate in audits and initiatives aimed at ensuring that patients receive the best possible outcomes from their treatment and care. Your personal data will be treated with the utmost confidentiality in line with Data Protection Laws and confidentiality standards. Any data publication will be in anonymised, statistical form. Anonymous or aggregated data may be used by us or shared with third parties for research or statistical purposes.
Use of Your Personal Data
Your personal data will be kept confidential and secure, and unless you provide alternative consent, it will only be used for the purpose(s) for which it was collected and in accordance with this Privacy Policy, relevant Data Protection Laws, clinical records retention periods, and clinical confidentiality guidelines.
We process your personal information for several legitimate interests, including but not limited to:
Sensitive personal data related to your health will only be disclosed to those involved in your treatment or care or in alignment with UK laws and guidelines from professional bodies or for the purpose of clinical audits (unless you object). Further details regarding the use of health-related personal data are provided below:
Security of Your Personal Data
We safeguard all personal data in our possession by implementing suitable organisational and technical security measures to prevent unauthorised access or unlawful processing of personal data and to prevent data loss, destruction, or damage. Any personal data you provide to us will be retained only as long as necessary for the purpose for which it was collected and in accordance with all Data Protection Laws. Data protection regulations are harmonised throughout the European Economic Area (EEA), comprising EU member states, Norway, Iceland, and Liechtenstein. Countries outside the EEA generally do not offer the same level of personal information protection as those within the EEA. While we do not anticipate a need to transfer your data outside Europe, in the unlikely event that such a situation arises, we will keep you informed and ensure the existence of appropriate procedures to facilitate such transfers.
All information provided to us is securely stored. Payment transactions on our website are processed securely by third-party payment processors. We do not retain any form of personal financial or payment information ourselves. Upon request, we may occasionally transfer personal information to you via email, or you may opt to send information to us via email. It is important to note that email is not a secure method of information transmission, and if you choose to send or receive such information via email, you do so at your own risk.
Disclosure and Sharing of Your Personal Data
We may disclose your personal data under various circumstances as part of our regular business operations. This disclosure may include sharing your personal data with contracted organisations that support the delivery of our services. The following parties are examples of those with whom we may share your personal data:
When we work with third-party data processors, we ensure that they adhere to contractual restrictions regarding confidentiality and security, in addition to complying with Data Protection Laws. Additionally, there are situations where we may disclose your personal data to third parties, such as:
How Long We Keep Your Personal Information
The duration for which we retain your personal information is determined by several factors, including:
Here are specific retention periods for certain types of information:
For more information about data retention, you can contact us at info@privatemedicalclinic.co.uk
Non-Personal Information and Cookies; Other Websites
When you visit our website, cookies are used to enable various features and gather information. We may also use other companies to set cookies on our website and collect cookie-related data. Additionally, we may analyse Internet Protocol (IP) addresses or other anonymous data sources.
Cookies: Cookies are text files that contain small amounts of information downloaded to your device when you visit a website. They are sent back to the website on subsequent visits and help the website recognise your device. Cookies serve various functions, including improving user experience and ensuring relevant online advertisements.
Our websites use cookies for different purposes, categorised as follows:
Please note that third parties may also use cookies over which we have no control. You can learn more about managing cookies from the ICO website: https://ico.org.uk/for-the-public/online/cookies
Other Websites: Our website may contain links to partner networks’ and affiliates’ websites. These websites have their own privacy policies, and we are not responsible for their policies. Please review their policies before sharing any personal data.
Marketing
We may send you information about our products and services via mail, email, phone, or SMS if you’ve consented to it. You can opt out at any time by emailing info@privatemedicalclinic.co.uk. We request a reasonable notice period to update our systems.
Changes to Our Privacy Policy
Our Privacy Policy is regularly reviewed and may be amended without notice. We encourage you to review it periodically to stay informed.
Privacy Notice for Call Recording
We use phone call recordings at Private Medical Clinic and collect personal data during these recordings. The data collected includes digital recordings of telephone conversations, telephone numbers of both parties, and any personal data disclosed during calls, such as names and contact details. Call recordings are stored securely on a server hosted by our phone provider, accessible only to senior members of the management team with authorised access.
These call recordings serve various purposes:
We may share call recordings with Investigating Officers to address complaints or issues. Under Data Protection legislation, we may disclose call recordings, including personal data, without explicit consent in certain situations, including law enforcement, safeguarding investigations, regulation and licensing, criminal prosecutions, and court proceedings.
Legal Basis for Processing Personal Data
Our processing of personal data is based on the legal grounds provided by data protection legislation. These include:
Retention of Personal Data
Call recordings are held securely for no more than 28 days, unless required for investigations, legal reasons, or safeguarding concerns.
Your Rights in Relation to Your Information
You have several rights concerning your personal data, including:
To exercise your rights, please contact info@privatemedicalclinic.co.uk
Data Protection Contacts
If you have questions regarding our privacy policy, please contact us at info@privatemedicalclinic.co.uk or write to our Data Protection Officer at the following address:
Private Medical Clinic
You also have the right to make a complaint to the Information Commissioner’s Office (ICO). The ICO is the local privacy supervisory authority in the UK. Khela Medical Limited is registered with the ICO. You can find information about how to contact the ICO on their website, here: https://ico.org.uk/global/privacy-notice/how-you-can-contact-us/