How we look after your information
Serene Health Partners Ltd is committed to protecting your privacy. This policy explains what personal information we collect, why we need it, how we keep it safe, and the rights you have over it.
Last updated: this policy is reviewed annually and whenever our processing changes.
Who we are
Serene Health Partners Ltd ("we", "us") is a private healthcare provider registered in England and Wales (Company No. 16288055), We are registered with the Care Quality Commission.
We are the data controller for the personal information we hold about you. We are registered with the Information Commissioner's Office (ICO) as a data controller. If you have any question about this policy, please contact us at admin@serenehealthpartners.com.
The information we collect
Depending on the service you use, we may collect:
- Identity and contact details — your name, date of birth, address, email address and telephone number
- Health information — your medical history, symptoms, medication, test results, assessment findings, clinical notes and correspondence. This is "special category" data and is given additional protection in law
- GP and other clinician details — where relevant to your care
- Payment information — processed securely by our payment provider; we do not store your full card details
- Correspondence — emails, enquiry forms, and records of appointments and communications
- Website data — basic technical information such as your browser type and pages visited, used only to keep the site working properly
We collect this information directly from you, and sometimes — with your consent — from your GP, another clinician, or a family member or informant taking part in an assessment.
Why we use it, and our lawful basis
Under UK GDPR we must have a lawful basis for using your information. Ours are:
- To provide your care — assessment, diagnosis, treatment, prescribing and follow-up. Lawful basis: contract, and for health information, Article 9(2)(h) — the provision of health care by a professional bound by a duty of confidentiality
- To manage appointments and take payment — lawful basis: contract
- To meet our legal and regulatory obligations — including record-keeping, CQC regulation, safeguarding and clinical governance. Lawful basis: legal obligation
- To investigate complaints and improve our services — lawful basis: legitimate interests
- To send you service information about your care — such as appointment reminders. Lawful basis: contract
We do not send marketing emails unless you have specifically asked us to, and you can opt out at any time.
Who we share it with
We do not sell your information to anyone, ever. We may share it with:
- Our clinicians involved in your care
- Your GP or other NHS clinicians — normally only with your consent, though we may share information without consent where there is a serious risk to you or to someone else
- Our dispensing pharmacy partner where medication is prescribed and delivered to you
- Our practice management and payment providers — who process data on our instructions under written contracts
- Regulators, insurers or legal advisers where we are required or permitted to do so
- Anyone you ask us to — such as a solicitor, school or employer — with your written consent
Where a supplier processes data on our behalf, they act only on our instructions and cannot use your information for their own purposes.
How long we keep it
We retain adult health records in line with recognised professional guidance — generally for a minimum of eight years after your last contact with us. Records relating to children and young people are kept until their 25th birthday, or their 26th if the last entry was made when they were 17. Non-clinical records, such as enquiries that do not lead to an appointment, are held for a much shorter period and then securely destroyed.
Keeping your information safe
Clinical records are held in a secure, encrypted practice management system. Access is restricted to those who need it for your care, and is logged. Video consultations take place over encrypted connections. Payments are handled by a PCI DSS compliant provider, and we never see or store your full card number. Our staff and clinicians are trained in confidentiality and information governance, and all are bound by professional duties of confidence.
Your rights
Under UK data protection law you have the right to:
- Ask for a copy of the information we hold about you (a "subject access request")
- Ask us to correct anything that is inaccurate
- Ask us to delete information, though we cannot usually delete clinical records within their retention period
- Ask us to restrict how we use your information, or object to certain uses
- Ask for your information in a portable electronic format
- Withdraw consent at any time, where we relied on your consent
To exercise any of these rights, email admin@serenehealthpartners.com. We will respond within one month, and there is normally no charge.
Cookies and our website
Our website uses only the minimum technical cookies needed to function. If we add analytics or other non-essential cookies in future, we will ask for your consent first.
Storage outside the UK
Your information is normally stored within the UK or the European Economic Area. Where a supplier processes data elsewhere, we ensure appropriate safeguards recognised under UK data protection law are in place.
Complaints about your data
If you are unhappy with how we have handled your information, please tell us first so we can put it right — see our feedback and complaints page.
You also have the right to complain to the Information Commissioner's Office at any time — 0303 123 1113 or ico.org.uk.
Questions about this policy? Contact us at admin@serenehealthpartners.com. Written correspondence may be sent to Serene Health Partners Limited, Concord House, Nottingham Road, New Basford, Nottingham, NG7 7AA, though this address is not regularly monitored and email is faster.