PRIVACY POLICY
Privacy Policy
Last updated: 27/10/2025
1. Introduction
Welcome to Dr Vahe Clinic (“we”, “us”, “our”).
We are committed to protecting and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our websites https://www.doctorvahe.com or https://www.drvaheclinic.com (“Website”), contact us, or use our medical and consultation services.
By using our Website or services, you agree to the practices described in this Privacy Policy.
If you have any questions, please contact us at:
info@doctorvahe.com
2. Who We Are
Dr Vahe Clinic is a private healthcare provider offering medical consultation and treatment services.
Data Controller: Dr Vahe Clinic
Email: info@doctorvahe.com
Address: 25 Ives Street, SW3 2ND, London
If you are a patient, we act as the Data Controller of your personal information. This means we decide how and why your data is processed.
3. Information We Collect
We collect and process personal information to provide high-quality medical care and to operate our business effectively.
3.1 Personal Information You Provide
When you contact us, register as a patient, or use our services, we may collect:
-
Full name
-
Contact details (email, phone number, postal address)
-
Date of birth
-
Medical history, symptoms, test results, or other health-related information
-
Insurance, payment, or billing details
-
Communications or correspondence with us
-
Any additional information you voluntarily provide through our contact forms, consultations, or email
3.2 Information Collected Automatically
When you visit our Website, we may automatically collect:
-
IP address and browser type
-
Device and operating system information
-
Pages visited, date/time of visit, and referring website
-
Cookies and similar technologies (see Section 8)
3.3 Special Category Data (Health Information)
We may collect and process data concerning your health for medical diagnosis, treatment, or care purposes.
Such information is handled in strict confidence under the UK GDPR Article 9(2)(h) - “processing necessary for the provision of health or social care or treatment.”
4. How We Use Your Information
We use your information to:
-
Provide medical advice, diagnosis, treatment, and follow-up care
-
Respond to your inquiries and manage appointments
-
Maintain accurate patient records
-
Process payments and manage billing
-
Ensure clinical safety and quality of care
-
Communicate relevant updates or service information
-
Improve our Website and services
-
Comply with our legal, professional, and regulatory obligations
We will never sell or rent your data to any third party.
5. Lawful Basis for Processing
Under the UK GDPR, we rely on the following lawful bases to process your personal data:
-
Consent — when you voluntarily provide information or agree to communications.
-
Contract — to deliver healthcare or related services you request.
-
Legal obligation — to comply with healthcare and record-keeping laws.
-
Vital interests — where processing is necessary to protect life or health.
-
Legitimate interests — to ensure service quality, security, and proper business management.
-
Public interest in healthcare — for medical diagnosis, treatment, or management of health systems (Article 9(2)(h)).
6. How Long We Keep Your Data
We retain personal data only as long as necessary for the purposes set out in this policy.
Health records are retained in line with NHS and Department of Health guidelines, typically for at least 8 years after the last treatment (or longer in specific cases such as paediatric or surgical records).
When data is no longer required, it will be securely deleted or anonymised.
7. Sharing Your Information
We only share information where necessary and lawful, including:
-
With doctors, clinicians, and administrative staff directly involved in your care
-
With laboratories, pharmacies, or other healthcare providers (with your consent)
-
With payment processors, insurers, or legal representatives where required
-
With IT service providers or secure data hosting partners who support our operations
-
With regulators, courts, or law enforcement, when legally required
All third parties are bound by confidentiality and data protection agreements.
8. Cookies and Tracking Technologies
Our Website uses cookies to:
-
Ensure proper site functionality
-
Analyse traffic and improve performance
-
Remember user preferences
You can manage or disable cookies in your browser settings.
For more information, please refer to our Cookie Policy (if available).
9. Data Security
We take appropriate technical and organisational measures to protect your personal data, including:
-
Secure servers and firewalls
-
Data encryption and secure email systems
-
Access restricted to authorised medical personnel only
-
Regular data protection and cyber-security reviews
Despite these safeguards, please note that no online system is entirely immune from risks.
10. Your Data Protection Rights
Under the UK GDPR, you have the following rights:
-
Right to access – Request a copy of the personal data we hold about you.
-
Right to rectification – Correct inaccurate or incomplete data.
-
Right to erasure – Request deletion of your data (subject to legal or medical record obligations).
-
Right to restriction – Limit processing in certain circumstances.
-
Right to data portability – Request transfer of your data to another provider.
-
Right to object – Object to certain types of processing.
-
Right to withdraw consent – Withdraw your consent at any time.
To exercise any of these rights, please email info@doctorvahe.com.
We will respond within one month as required by law.
If you are not satisfied with our response, you may complain to the Information Commissioner’s Office (ICO) at https://www.ico.org.uk.
11. International Data Transfers
If your personal data is transferred outside the United Kingdom, we ensure that such transfers are protected by appropriate safeguards — for example, by using:
-
Adequacy decisions issued by the UK Government, or
-
UK-approved Standard Contractual Clauses (SCCs) for international data transfers.
12. Children’s Privacy
Our services are primarily for adults.
We only collect information about children with the consent of a parent or legal guardian, and solely for the purpose of providing healthcare.
13. Third-Party Links
Our Website may include links to other websites.
We are not responsible for the privacy practices or content of these external sites.
Please review their policies before submitting any personal data.
14. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our operations.
Any updates will be posted on this page with a revised “Last Updated” date.
15. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Dr Vahe Clinic
Email: info@doctorvahe.com
Websites: https://www.doctorvahe.com
Address: 25 Ives Street, SW3 2ND
If you remain dissatisfied after contacting us, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Telephone: 0303 123 1113
Website: https://www.ico.org.uk
Legal Compliance Summary
This Privacy Policy complies with:
-
UK GDPR
-
Data Protection Act 2018
-
PECR 2003 (as amended)
-
GMC confidentiality principles for medical practitioners
