Privacy Notice
1. Introduction
BioCheck Health Ltd is committed to protecting patient privacy, confidentiality and trust. As a private healthcare clinic in central London, BioCheck Health Ltd handles personal information relating to patients, prospective patients, self-pay clients, insured patients, international visitors, companions, interpreters, referrers, healthcare professionals, suppliers, visitors and website users.
This Privacy Notice explains what information we collect, why we use it, the lawful basis for processing, who we may share it with, how long we keep it, how we protect it and how individuals can exercise their data protection rights.
This notice should be read alongside BioCheck Health Ltd policies and procedures for confidentiality, Caldicott principles, information sharing, cyber resilience, records management, CCTV, audio-visual/photography, complaints, safeguarding, clinical governance and incident reporting.
2. Who We Are
For the purposes of UK data protection law, BioCheck Health Ltd is normally the data controller for personal information processed in connection with its private healthcare services, unless a written contract or commissioned arrangement states otherwise.
Patients and other individuals can use the contact details above to ask questions about this notice, exercise data protection rights, raise privacy concerns or request copies of personal information held by BioCheck Health Ltd.
3. Scope of This Notice
This notice applies to personal information processed by BioCheck Health Ltd in relation to:
private GP consultations, nurse consultations, phlebotomy, vaccinations, health checks, biomarker testing, referrals, imaging referral coordination, psychological counselling and related private clinic services;
patient enquiries, appointment booking, registration, triage, consent, identity checks, clinical records, diagnostic results, reports, prescriptions, referrals, follow-up and recall arrangements;
payments, invoicing, insurance administration, debt recovery, refunds, finance, accounting, complaints, incident management and legal or regulatory obligations;
communications in English, Mandarin or other languages where clinically or operationally appropriate, including use of interpreters, translated reports or bilingual patient communication;
website enquiries, marketing preferences, events, feedback, testimonials, social media enquiries and non-essential communications where permitted;
premises security, CCTV, visitor management, contractors and health and safety arrangements.
A separate employee, worker and recruitment privacy notice should be used for staff, applicants, contractors and occupational health information. This notice may still apply where those individuals use BioCheck Health Ltd services as patients or visitors.
4. Personal Information We Collect
The types of information we collect depend on the service requested, the clinical situation, the method of communication and the legal or regulatory requirements that apply. We only collect information that is relevant and proportionate to the purpose.
5. How We Collect Information
BioCheck Health Ltd may collect information directly from you and from other appropriate sources where necessary for care, safety, administration or legal compliance.
directly from patients, prospective patients, parents, guardians, attorneys, representatives, companions or interpreters;
from clinicians, nurses, healthcare assistants, laboratories, imaging providers, pharmacies, hospitals, GPs, consultants, counselling providers or other healthcare organisations involved in care;
from insurers, corporate clients, payment providers or third-party administrators where the patient has requested or authorised involvement, or where the arrangement is necessary for service administration;
from public authorities, safeguarding bodies, emergency services, regulators, courts, professional bodies or legal advisers where lawful and necessary;
from website forms, emails, telephone calls, SMS, portals, booking systems, patient questionnaires, consent forms, feedback forms and CCTV/security systems.
6. Why We Use Information and Our Lawful Bases
BioCheck Health Ltd will identify an Article 6 UK GDPR lawful basis for all personal data processing and, where special category health information is involved, an additional Article 9 condition. The most relevant legal bases are summarised below. The exact basis may vary according to the circumstances.
7. Sharing Your Information
BioCheck Health Ltd will share personal information only where necessary, lawful, proportionate and consistent with confidentiality duties. Information shared for direct care should be limited to what the recipient needs to know.
BioCheck Health Ltd does not sell patient health information. We will not give identifiable clinical information to family members, employers, insurers, embassies, media organisations or other third parties merely because they ask for it. Disclosure requires patient authority or another lawful justification.
8. Confidentiality and Direct Care
Patients have a right to expect that their personal information will be treated as confidential. Clinical staff must follow professional confidentiality duties and BioCheck Health Ltd information governance arrangements. Relevant information may be shared for direct care where the patient would reasonably expect this and has not objected, unless another lawful basis applies.
Patients can ask BioCheck Health Ltd to explain who may see their information and why.
Patients may object to certain information sharing. BioCheck Health Ltd will consider objections carefully, but may need to explain where withholding information could affect safe care or where disclosure is required by law.
Staff must not access patient records unless they have a legitimate work-related reason.
Staff must record significant information-sharing decisions, especially where the decision is unusual, urgent, contested or made without consent.
9. International Patients and International Transfers
BioCheck Health Ltd may provide services to international visitors or communicate with patients who are overseas. We may also use suppliers or systems that involve data processing outside the UK. Any international transfer of personal information must be assessed and protected in accordance with UK data protection law.
Where a patient asks us to send information to an overseas doctor, insurer, embassy, family member or provider, we will check the request, the recipient and the information needed before sending it.
Where suppliers process personal data outside the UK, BioCheck Health Ltd will use appropriate safeguards such as adequacy regulations, International Data Transfer Agreements, approved contractual clauses or other lawful mechanisms.
Patients should tell BioCheck Health Ltd if they have concerns about international communication, overseas email access or sharing records with non-UK providers.
10. How Long We Keep Information
BioCheck Health Ltd keeps personal information only for as long as necessary for the purpose for which it was collected, including clinical safety, continuity of care, legal, professional, regulatory, insurance, accounting, complaint handling and audit requirements. The approved BioCheck Health Ltd Records Retention Schedule should set out the exact retention periods.
When information is no longer required, it must be securely deleted, destroyed, anonymised or archived in accordance with BioCheck Health Ltd records management and information security procedures.
11. Your Data Protection Rights
Subject to legal conditions and exemptions, individuals have rights in relation to their personal information. These rights are not absolute and may operate differently for clinical records, legal claims, safeguarding, regulatory requirements or information that also relates to another person.
BioCheck Health Ltd will normally respond to a subject access request within one month, unless an extension is permitted by law because the request is complex or multiple requests have been made. We may need proof of identity before releasing information.
12. How to Exercise Your Rights or Raise a Concern
Requests and privacy concerns should be sent to the Data Protection Lead using the contact details in Section 2. To help us respond promptly, please include your full name, date of birth, contact details, the information or right you are asking about, any relevant date range, and how you would prefer to receive the response.
We may ask for additional information to confirm identity or authority, especially where health records or third-party representatives are involved.
Parents, guardians, attorneys or representatives must provide evidence of authority. The patient's capacity, confidentiality and best interests must still be considered.
Where a request includes information about another person, BioCheck Health Ltd may need to redact or withhold third-party information unless disclosure is lawful and appropriate.
If you are dissatisfied with our response, you may escalate the concern internally and may complain to the Information Commissioner's Office.
13. Children, Young People and Adults Who May Lack Capacity
BioCheck Health Ltd will handle information about children, young people and adults who may lack capacity with particular care. We will consider age, understanding, Gillick competence where relevant, parental responsibility, the Mental Capacity Act 2005, best interests, safeguarding duties and professional guidance.
Where a parent, guardian, attorney, deputy, carer or representative requests information, BioCheck Health Ltd will check authority and consider whether disclosure is in the patient's best interests and consistent with confidentiality and data protection requirements.
14. Security, Confidentiality and Staff Access
BioCheck Health Ltd uses technical, organisational and physical measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures should be proportionate to the sensitivity of health information and the private clinic environment.
role-based access to clinical and administrative systems;
passwords, multi-factor authentication where available, secure configuration and device protection;
staff confidentiality agreements, induction and information governance training;
secure email, portals or encrypted transfer methods for sensitive information where appropriate;
locked storage, controlled access to paper records and secure confidential waste disposal;
supplier due diligence, processor contracts and data processing terms;
audit trails, access reviews, incident reporting and breach management procedures.
Any suspected privacy incident, unauthorised access, misdirected email, lost device, incorrect disclosure, cyber incident or breach of confidentiality must be escalated immediately to the Practice Manager, Data Protection Lead and Clinical Lead as appropriate.
15. Personal Data Breaches
If a personal data breach occurs, BioCheck Health Ltd will assess what happened, who is affected, the sensitivity of the information, the likely risk to individuals, immediate containment actions and whether notification to the ICO or affected individuals is required.
Where a breach is likely to result in a risk to individuals' rights and freedoms, BioCheck Health Ltd must notify the ICO where feasible within 72 hours of becoming aware of it. Where there is a high risk to individuals, affected individuals must also be informed without undue delay unless an exemption applies.
16. CCTV, Audio, Video and Photography
BioCheck Health Ltd may use CCTV for premises security, crime prevention, staff and patient safety, incident investigation and protection of property. CCTV use must be signposted, proportionate, access controlled and managed in accordance with the CCTV and Audio-Visual/Photography Policy.
Clinical photography, audio recording, video recording, testimonials, marketing images and social media content require a clear purpose, appropriate clinical or explicit consent where required, secure storage, defined retention and the ability to withdraw consent for optional non-clinical use. Patients and visitors must not record staff or other patients in a way that breaches confidentiality, privacy or safety.
17. Direct Marketing, Website and Cookies
BioCheck Health Ltd may send service communications that are necessary for appointments, care, safety, administration or contract performance. These are not marketing messages.
Marketing communications, newsletters, events, offers, health promotion campaigns, testimonials and social media communications will be managed separately and in accordance with data protection and electronic marketing rules. Individuals can opt out of marketing at any time.
Where the BioCheck Health Ltd website uses cookies or similar technologies, a separate cookie notice or banner should explain what cookies are used, which are essential, which are optional, and how users can manage preferences. Non-essential cookies should not be placed unless the required consent has been obtained.
18. Automated Decision-Making, AI and Digital Tools
BioCheck Health Ltd does not intend to make decisions about patients based solely on automated processing where the decision produces legal or similarly significant effects. If automated decision-making, profiling or AI-supported tools are introduced, BioCheck Health Ltd must complete appropriate governance review, data protection impact assessment, clinical safety assessment, transparency information and human oversight arrangements before use.
Digital tools may be used to support booking, administration, communication, document handling, clinical coding, translation or workflow management. Staff remain responsible for checking accuracy, confidentiality, clinical relevance and safety before using or sharing information.
19. Governance Context
This Privacy Notice is informed by UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality, professional confidentiality duties, Caldicott principles, CQC governance requirements, ICO guidance on the right to be informed, ICO guidance on special category data, health records management guidance and NHS data security requirements where BioCheck Health Ltd has access to NHS patient data or systems.
Where BioCheck Health Ltd provides services under an NHS or public-sector contract, accesses NHS patient data or systems, or participates in shared care pathways, additional contractual, NHS information governance, records management and Data Security and Protection Toolkit requirements may apply.
20. Review of This Notice
BioCheck Health Ltd will review this Privacy Notice at least annually and sooner where there are significant changes to services, systems, suppliers, data-sharing arrangements, premises security, law, ICO guidance, CQC requirements, NHS information governance requirements or clinical governance findings.
The latest version should be available to patients and service users through appropriate channels such as the website, reception area, patient registration materials and on request. Staff should be trained to direct patients to this notice and escalate privacy questions to the Data Protection Lead.
Appendix 1 - Patient Privacy Summary
Appendix 2 - Data Rights Request Record
This internal record may be used by BioCheck Health Ltd staff to log and monitor data rights requests. It should be stored securely and completed by the Data Protection Lead or delegated person.
Appendix 3 - Privacy Incident Initial Triage