BIO
CHECK
HEALTH
UK Healthcare
Biocheck Health

Privacy Notice

1. Introduction

BioCheck Health Ltd is committed to protecting patient privacy, confidentiality and trust. As a private healthcare clinic in central London, BioCheck Health Ltd handles personal information relating to patients, prospective patients, self-pay clients, insured patients, international visitors, companions, interpreters, referrers, healthcare professionals, suppliers, visitors and website users.

This Privacy Notice explains what information we collect, why we use it, the lawful basis for processing, who we may share it with, how long we keep it, how we protect it and how individuals can exercise their data protection rights.

This notice should be read alongside BioCheck Health Ltd policies and procedures for confidentiality, Caldicott principles, information sharing, cyber resilience, records management, CCTV, audio-visual/photography, complaints, safeguarding, clinical governance and incident reporting.

Important distinction - clinical consent and data protection Consent to examination, treatment, vaccination, blood tests, imaging referral or report sharing is a clinical and confidentiality matter. It is not always the same as the UK GDPR lawful basis for using health information. BioCheck Health Ltd must still identify an Article 6 lawful basis and, for health information, an Article 9 condition. Where we rely on consent for optional activities such as marketing, testimonials or non-essential photography, you can withdraw that consent at any time.

2. Who We Are

For the purposes of UK data protection law, BioCheck Health Ltd is normally the data controller for personal information processed in connection with its private healthcare services, unless a written contract or commissioned arrangement states otherwise.

AreaDetails
Data ControllerBioCheck Health Ltd
Clinic / Registered AddressUnit 1, 4A Monck Street, London SW1P 2BQ
Company Number16418624
ICO Registration NumberZC094499
Websitehttps://www.biocheckhealth.com
Main Contactenquiry@biocheckhealth.co.uk
Data Protection LeadCynthia Xu email: cynthia.xu@biocheckhealth.com
Data Protection OfficerBioCheck Health Ltd has not appointed a statutory DPO and the Data Protection Lead is the contact point

Patients and other individuals can use the contact details above to ask questions about this notice, exercise data protection rights, raise privacy concerns or request copies of personal information held by BioCheck Health Ltd.

3. Scope of This Notice

This notice applies to personal information processed by BioCheck Health Ltd in relation to:

private GP consultations, nurse consultations, phlebotomy, vaccinations, health checks, biomarker testing, referrals, imaging referral coordination, psychological counselling and related private clinic services;

patient enquiries, appointment booking, registration, triage, consent, identity checks, clinical records, diagnostic results, reports, prescriptions, referrals, follow-up and recall arrangements;

payments, invoicing, insurance administration, debt recovery, refunds, finance, accounting, complaints, incident management and legal or regulatory obligations;

communications in English, Mandarin or other languages where clinically or operationally appropriate, including use of interpreters, translated reports or bilingual patient communication;

website enquiries, marketing preferences, events, feedback, testimonials, social media enquiries and non-essential communications where permitted;

premises security, CCTV, visitor management, contractors and health and safety arrangements.

A separate employee, worker and recruitment privacy notice should be used for staff, applicants, contractors and occupational health information. This notice may still apply where those individuals use BioCheck Health Ltd services as patients or visitors.

4. Personal Information We Collect

The types of information we collect depend on the service requested, the clinical situation, the method of communication and the legal or regulatory requirements that apply. We only collect information that is relevant and proportionate to the purpose.

CategoryExamples
Identity and contact detailsName, date of birth, gender/sex where clinically relevant, address, email, telephone number, emergency contact, NHS/private ID where applicable, preferred language and communication preferences.
Clinical and health informationSymptoms, medical history, medications, allergies, vaccination status, family history, lifestyle information, mental health information, consultation notes, care plans, clinical advice, referrals and follow-up arrangements.
Diagnostics and reportsBlood test requests and results, biomarker results, pathology reports, imaging referrals and reports, clinician interpretation, risk flags, recall actions and related correspondence.
Special category informationHealth data, genetic data where relevant, biometric data where used for identification, ethnicity, religion or cultural needs where relevant to care, sex life or sexual orientation where clinically relevant.
Payment and administrationInvoices, payment status, refund information, insurance details, corporate billing details, appointment attendance, correspondence and service records. Payment card details should be processed through approved secure payment providers and not stored unnecessarily by BioCheck Health Ltd.
Communication recordsEmails, letters, SMS, call notes, portal messages, consent records, translation notes, complaints, feedback, SARs, privacy requests and records of decisions.
Safeguarding, incident and regulatory recordsInformation needed to manage safeguarding concerns, complaints, incidents, duty of candour, professional concerns, CQC or other regulatory enquiries, legal claims or insurance matters.
Digital, website and premises dataWebsite enquiry data, online forms, IP address, cookies or analytics information where used, CCTV images, visitor logs and access-control records.

5. How We Collect Information

BioCheck Health Ltd may collect information directly from you and from other appropriate sources where necessary for care, safety, administration or legal compliance.

directly from patients, prospective patients, parents, guardians, attorneys, representatives, companions or interpreters;

from clinicians, nurses, healthcare assistants, laboratories, imaging providers, pharmacies, hospitals, GPs, consultants, counselling providers or other healthcare organisations involved in care;

from insurers, corporate clients, payment providers or third-party administrators where the patient has requested or authorised involvement, or where the arrangement is necessary for service administration;

from public authorities, safeguarding bodies, emergency services, regulators, courts, professional bodies or legal advisers where lawful and necessary;

from website forms, emails, telephone calls, SMS, portals, booking systems, patient questionnaires, consent forms, feedback forms and CCTV/security systems.

6. Why We Use Information and Our Lawful Bases

BioCheck Health Ltd will identify an Article 6 UK GDPR lawful basis for all personal data processing and, where special category health information is involved, an additional Article 9 condition. The most relevant legal bases are summarised below. The exact basis may vary according to the circumstances.

PurposeExamplesArticle 6 basisArticle 9 condition
Providing healthcare and direct careRegistration, consultation, assessment, diagnosis, treatment, vaccination, phlebotomy, diagnostic testing, referral, results review, follow-up and clinical handover.Article 6(1)(b) contract; Article 6(1)(f) legitimate interests; Article 6(1)(c) legal obligation where applicable.Article 9(2)(h) health or social care; DPA 2018 Schedule 1 condition for health or social care.
Patient safety and clinical governanceClinical audit, quality improvement, incident review, complaints, significant event review, training with anonymised data where possible, supervision and professional assurance.Article 6(1)(f) legitimate interests; Article 6(1)(c) legal obligation where applicable.Article 9(2)(h) health or social care; Article 9(2)(f) legal claims where relevant.
Appointments, administration and paymentsBooking, reminders, identity checks, service administration, invoicing, payment processing, refunds, accounting, debt management and insurance administration.Article 6(1)(b) contract; Article 6(1)(c) legal obligation; Article 6(1)(f) legitimate interests.Article 9(2)(h) where health details are necessary; Article 9(2)(f) for legal claims.
Referrals and external providersSharing relevant information with laboratories, imaging providers, consultants, pharmacies, GPs, hospitals, emergency services or other providers involved in your care.Article 6(1)(b); Article 6(1)(f); Article 6(1)(c) where required by law.Article 9(2)(h) health or social care; common law confidentiality principles apply.
Safeguarding, emergencies and public protectionProtecting children or adults at risk, responding to serious risk, medical emergencies, threats to life, infectious disease duties or public protection concerns.Article 6(1)(c) legal obligation; Article 6(1)(d) vital interests; Article 6(1)(f) legitimate interests.Article 9(2)(c) vital interests; Article 9(2)(g) substantial public interest; Article 9(2)(i) public health where applicable.
Legal, regulatory and insurance mattersCQC compliance, professional obligations, medical defence, legal claims, insurance notifications, court orders, police requests and regulatory investigations.Article 6(1)(c) legal obligation; Article 6(1)(f) legitimate interests.Article 9(2)(f) legal claims; Article 9(2)(h) health or social care; substantial public interest where applicable.
Marketing and optional communicationsNewsletters, events, service updates, testimonials, photography, video, social media and non-essential promotional communication.Consent or legitimate interests where permitted; PECR rules apply to electronic marketing.Explicit consent will normally be required where special category health information is used for marketing, testimonials or identifiable publicity.
Website, security and premises safetyWebsite operation, cookies/analytics where used, cyber security, CCTV, visitor management, health and safety, crime prevention and incident investigation.Article 6(1)(f) legitimate interests; consent for non-essential cookies where required; legal obligation where applicable.Usually not special category unless used to infer health or other protected information; Article 9 condition will be identified if needed.
When consent is used Where BioCheck Health Ltd relies on consent, we will tell you what you are consenting to and how to withdraw it. Withdrawal does not usually affect processing that has already happened lawfully, and it does not automatically require deletion of clinical records that BioCheck Health Ltd must retain for safety, legal, professional, regulatory or insurance reasons.

7. Sharing Your Information

BioCheck Health Ltd will share personal information only where necessary, lawful, proportionate and consistent with confidentiality duties. Information shared for direct care should be limited to what the recipient needs to know.

Recipient categoryWhat may be shared
Patients and authorised representativesCopies of reports, letters, invoices and clinical information may be shared with the patient or someone the patient has authorised. Identity and authority must be checked before disclosure.
Clinicians and care providersDoctors, nurses, counsellors, healthcare assistants, consultants, GPs, hospitals, pharmacies, laboratories, imaging providers and emergency services involved in care.
Diagnostic partnersLaboratories, imaging centres, phlebotomy providers, courier services and reporting clinicians where needed to request tests, receive results and manage abnormal or urgent findings.
Interpreters and translation supportInterpreters, translators or bilingual staff may support communication where appropriate. Identifiable information must be limited to what is necessary and confidentiality must be protected.
Insurers, corporate clients or third-party payersInformation will be shared only where necessary for the service arrangement, payment, pre-authorisation, claims handling or where the patient has authorised disclosure. Employers should not receive clinical details without an appropriate lawful basis and patient authorisation.
IT, communication and business suppliersClinical system providers, secure email/portal providers, cloud hosting, cyber security, payment processing, accounting, document management, shredding, waste disposal and professional advisers. Appropriate processor contracts and security checks must be used.
Regulators, authorities and legal bodiesCQC, ICO, professional regulators, NHS bodies where relevant, safeguarding authorities, police, courts, coroners, public health bodies, insurers, medical defence organisations or legal advisers where lawful and necessary.

BioCheck Health Ltd does not sell patient health information. We will not give identifiable clinical information to family members, employers, insurers, embassies, media organisations or other third parties merely because they ask for it. Disclosure requires patient authority or another lawful justification.

8. Confidentiality and Direct Care

Patients have a right to expect that their personal information will be treated as confidential. Clinical staff must follow professional confidentiality duties and BioCheck Health Ltd information governance arrangements. Relevant information may be shared for direct care where the patient would reasonably expect this and has not objected, unless another lawful basis applies.

Patients can ask BioCheck Health Ltd to explain who may see their information and why.

Patients may object to certain information sharing. BioCheck Health Ltd will consider objections carefully, but may need to explain where withholding information could affect safe care or where disclosure is required by law.

Staff must not access patient records unless they have a legitimate work-related reason.

Staff must record significant information-sharing decisions, especially where the decision is unusual, urgent, contested or made without consent.

9. International Patients and International Transfers

BioCheck Health Ltd may provide services to international visitors or communicate with patients who are overseas. We may also use suppliers or systems that involve data processing outside the UK. Any international transfer of personal information must be assessed and protected in accordance with UK data protection law.

Where a patient asks us to send information to an overseas doctor, insurer, embassy, family member or provider, we will check the request, the recipient and the information needed before sending it.

Where suppliers process personal data outside the UK, BioCheck Health Ltd will use appropriate safeguards such as adequacy regulations, International Data Transfer Agreements, approved contractual clauses or other lawful mechanisms.

Patients should tell BioCheck Health Ltd if they have concerns about international communication, overseas email access or sharing records with non-UK providers.

10. How Long We Keep Information

BioCheck Health Ltd keeps personal information only for as long as necessary for the purpose for which it was collected, including clinical safety, continuity of care, legal, professional, regulatory, insurance, accounting, complaint handling and audit requirements. The approved BioCheck Health Ltd Records Retention Schedule should set out the exact retention periods.

Record typeRetention approach
Clinical and patient recordsRetained in line with professional, regulatory, insurance and healthcare records management requirements. The NHS Records Management Code of Practice may be used as a benchmark where relevant, particularly where NHS data, referrals or shared care are involved.
Diagnostic results and reportsKept as part of the clinical record where used for assessment, diagnosis, advice, referral, follow-up or safety-netting.
enquiries and non-patient communicationsKept only as long as needed to respond, manage service interest, evidence consent or support legitimate business records, unless the individual becomes a patient.
Finance, invoices and accountingKept in line with accounting, tax, audit, payment dispute and legal requirements. Health detail should be minimised in finance records.
Complaints, incidents and legal mattersKept long enough to investigate, evidence actions, manage learning, respond to regulators, manage insurance/claims and meet legal limitation periods.
CCTV and security recordsKept for a short period as stated on local CCTV signage and the CCTV policy, unless required for an incident, investigation, legal claim or regulatory purpose.
Marketing preferencesKept while consent or lawful marketing relationship continues, and suppression records retained where needed to respect opt-out requests.
Data rights and privacy requestsKept to demonstrate how BioCheck Health Ltd handled the request, verified identity, met deadlines and made disclosure or refusal decisions.

When information is no longer required, it must be securely deleted, destroyed, anonymised or archived in accordance with BioCheck Health Ltd records management and information security procedures.

11. Your Data Protection Rights

Subject to legal conditions and exemptions, individuals have rights in relation to their personal information. These rights are not absolute and may operate differently for clinical records, legal claims, safeguarding, regulatory requirements or information that also relates to another person.

RightWhat it means
Right to be informedTo be told how personal information is collected and used. This Privacy Notice supports that right.
Right of accessTo ask whether BioCheck Health Ltd holds your personal information and request a copy, also known as a subject access request.
Right to rectificationTo ask for inaccurate personal information to be corrected. Clinical opinion may be supplemented rather than deleted where it was recorded accurately at the time.
Right to erasureTo ask for deletion in certain circumstances. This may not apply where records must be retained for clinical safety, legal, regulatory or insurance reasons.
Right to restrictionTo ask us to limit processing in certain circumstances while a concern is checked.
Right to objectTo object to processing based on legitimate interests or direct marketing. Objections to direct care sharing will be considered carefully and documented.
Right to data portabilityTo request certain information in a structured, commonly used, machine-readable format where the legal conditions apply.
Right to withdraw consentTo withdraw consent where consent is the basis for processing, for example certain marketing, photography, testimonials or optional communications.
Right to complainTo complain to BioCheck Health Ltd and to the Information Commissioner's Office if you are unhappy with how your information is handled.

BioCheck Health Ltd will normally respond to a subject access request within one month, unless an extension is permitted by law because the request is complex or multiple requests have been made. We may need proof of identity before releasing information.

12. How to Exercise Your Rights or Raise a Concern

Requests and privacy concerns should be sent to the Data Protection Lead using the contact details in Section 2. To help us respond promptly, please include your full name, date of birth, contact details, the information or right you are asking about, any relevant date range, and how you would prefer to receive the response.

We may ask for additional information to confirm identity or authority, especially where health records or third-party representatives are involved.

Parents, guardians, attorneys or representatives must provide evidence of authority. The patient's capacity, confidentiality and best interests must still be considered.

Where a request includes information about another person, BioCheck Health Ltd may need to redact or withhold third-party information unless disclosure is lawful and appropriate.

If you are dissatisfied with our response, you may escalate the concern internally and may complain to the Information Commissioner's Office.

13. Children, Young People and Adults Who May Lack Capacity

BioCheck Health Ltd will handle information about children, young people and adults who may lack capacity with particular care. We will consider age, understanding, Gillick competence where relevant, parental responsibility, the Mental Capacity Act 2005, best interests, safeguarding duties and professional guidance.

Where a parent, guardian, attorney, deputy, carer or representative requests information, BioCheck Health Ltd will check authority and consider whether disclosure is in the patient's best interests and consistent with confidentiality and data protection requirements.

14. Security, Confidentiality and Staff Access

BioCheck Health Ltd uses technical, organisational and physical measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures should be proportionate to the sensitivity of health information and the private clinic environment.

role-based access to clinical and administrative systems;

passwords, multi-factor authentication where available, secure configuration and device protection;

staff confidentiality agreements, induction and information governance training;

secure email, portals or encrypted transfer methods for sensitive information where appropriate;

locked storage, controlled access to paper records and secure confidential waste disposal;

supplier due diligence, processor contracts and data processing terms;

audit trails, access reviews, incident reporting and breach management procedures.

Any suspected privacy incident, unauthorised access, misdirected email, lost device, incorrect disclosure, cyber incident or breach of confidentiality must be escalated immediately to the Practice Manager, Data Protection Lead and Clinical Lead as appropriate.

15. Personal Data Breaches

If a personal data breach occurs, BioCheck Health Ltd will assess what happened, who is affected, the sensitivity of the information, the likely risk to individuals, immediate containment actions and whether notification to the ICO or affected individuals is required.

Where a breach is likely to result in a risk to individuals' rights and freedoms, BioCheck Health Ltd must notify the ICO where feasible within 72 hours of becoming aware of it. Where there is a high risk to individuals, affected individuals must also be informed without undue delay unless an exemption applies.

16. CCTV, Audio, Video and Photography

BioCheck Health Ltd may use CCTV for premises security, crime prevention, staff and patient safety, incident investigation and protection of property. CCTV use must be signposted, proportionate, access controlled and managed in accordance with the CCTV and Audio-Visual/Photography Policy.

Clinical photography, audio recording, video recording, testimonials, marketing images and social media content require a clear purpose, appropriate clinical or explicit consent where required, secure storage, defined retention and the ability to withdraw consent for optional non-clinical use. Patients and visitors must not record staff or other patients in a way that breaches confidentiality, privacy or safety.

17. Direct Marketing, Website and Cookies

BioCheck Health Ltd may send service communications that are necessary for appointments, care, safety, administration or contract performance. These are not marketing messages.

Marketing communications, newsletters, events, offers, health promotion campaigns, testimonials and social media communications will be managed separately and in accordance with data protection and electronic marketing rules. Individuals can opt out of marketing at any time.

Where the BioCheck Health Ltd website uses cookies or similar technologies, a separate cookie notice or banner should explain what cookies are used, which are essential, which are optional, and how users can manage preferences. Non-essential cookies should not be placed unless the required consent has been obtained.

18. Automated Decision-Making, AI and Digital Tools

BioCheck Health Ltd does not intend to make decisions about patients based solely on automated processing where the decision produces legal or similarly significant effects. If automated decision-making, profiling or AI-supported tools are introduced, BioCheck Health Ltd must complete appropriate governance review, data protection impact assessment, clinical safety assessment, transparency information and human oversight arrangements before use.

Digital tools may be used to support booking, administration, communication, document handling, clinical coding, translation or workflow management. Staff remain responsible for checking accuracy, confidentiality, clinical relevance and safety before using or sharing information.

19. Governance Context

This Privacy Notice is informed by UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality, professional confidentiality duties, Caldicott principles, CQC governance requirements, ICO guidance on the right to be informed, ICO guidance on special category data, health records management guidance and NHS data security requirements where BioCheck Health Ltd has access to NHS patient data or systems.

Where BioCheck Health Ltd provides services under an NHS or public-sector contract, accesses NHS patient data or systems, or participates in shared care pathways, additional contractual, NHS information governance, records management and Data Security and Protection Toolkit requirements may apply.

20. Review of This Notice

BioCheck Health Ltd will review this Privacy Notice at least annually and sooner where there are significant changes to services, systems, suppliers, data-sharing arrangements, premises security, law, ICO guidance, CQC requirements, NHS information governance requirements or clinical governance findings.

The latest version should be available to patients and service users through appropriate channels such as the website, reception area, patient registration materials and on request. Staff should be trained to direct patients to this notice and escalate privacy questions to the Data Protection Lead.

Appendix 1 - Patient Privacy Summary

QuestionSummary answer
Who uses your information?BioCheck Health Ltd, as data controller for its private healthcare services unless stated otherwise.
Why is it used?To provide healthcare, manage appointments, process tests/referrals/results, communicate with you, handle payments, keep records, manage safety and meet legal/regulatory duties.
What information is used?Identity, contact, clinical, diagnostic, payment, communication, safety, CCTV/visitor and governance information relevant to your care or interaction with the clinic.
Who might it be shared with?Clinicians, laboratories, imaging providers, pharmacies, hospitals, GPs, emergency services, interpreters, payment/IT suppliers, insurers where authorised, regulators or authorities where lawful.
How can you ask questions?Contact the Data Protection Lead using the details in Section 2. You may request access to your information or raise a privacy concern.

Appendix 2 - Data Rights Request Record

This internal record may be used by BioCheck Health Ltd staff to log and monitor data rights requests. It should be stored securely and completed by the Data Protection Lead or delegated person.

FieldRecord
Requester name and contact details
Patient name/date of birth/private ID if different
Relationship/authority checked
Type of requestAccess / rectification / erasure / restriction / objection / portability / withdrawal of consent / complaint / other
Date received and method
Identity verification completedYes / No / Not required - details:
Clarification needed
Deadline and extension decision
Information searched and systems checked
Third-party information review/redaction
Decision and response issued
Learning or governance actions

Appendix 3 - Privacy Incident Initial Triage

Triage areaInitial considerations
What happened?Describe the incident, date/time discovered, date/time occurred if known, systems/records involved and how it was found.
What information is affected?Identify whether health data, financial data, identity data, contact details, children's data, safeguarding information or other sensitive information is involved.
Who is affected?Number of people, patient/staff/visitor status, vulnerability, risk factors and whether affected individuals can be contacted.
Containment actionsRecover, delete, recall, disable access, isolate device, reset credentials, contact recipient, notify supplier, preserve evidence.
Risk assessmentAssess likelihood and severity of harm, distress, identity fraud, confidentiality breach, discrimination, clinical safety impact or financial loss.
Notification decisionICO notification required? Affected individual notification required? CQC, insurer, police, NHS, supplier or contractual notification required?
Learning actionsPolicy update, staff training, technical controls, supplier review, audit, communication or disciplinary/professional escalation where appropriate.