MEDii Health · 脉德医疗

MEDii Health · 脉德医疗

Privacy Policy

Version 2.0 · Last updated: 1 August 2026

本隐私政策的权威版本为英文版。以下为英文正式文本;如需中文说明或任何协助,请联系我们的数据保护负责人(admin@mediihealth.com)。如中英文之间存在任何差异,以英文版本为准。

MEDii Ltd, trading as MEDii Health (“we”, “our” or “us”), is committed to protecting your privacy and handling your personal data lawfully, fairly and transparently. This policy explains what personal data we collect, why we collect it, how we use, share, store and protect it, and the rights you have.

This policy applies to patients and their representatives, website visitors, callers and anyone else whose personal data we process in the course of providing our services.

1. Who we are

MEDii Ltd (company number 11125755), trading as MEDii Health, is a doctor-led private healthcare clinic providing outpatient services including consultations, diagnostics, health screening, IV therapies, dermatological and gynaecological procedures, ultrasound, aesthetic treatments and care coordination.

  • Registered address and clinic: 18 Duke's Road, London WC1H 9PY
  • We are the data controller for your personal data and are registered with the Information Commissioner's Office (ICO), registration number ZA493602.
  • We are Cyber Essentials certified — our technical and organisational security controls are independently assessed against the UK government-backed scheme.
  • Data Protection Lead: admin@mediihealth.com
  • General enquiries: info@mediihealth.com — www.mediihealth.com

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the common-law duty of confidentiality, and we apply the Caldicott Principles to patient information.

2. The information we collect

  • Identity and contact details — name, date of birth, sex, address, phone number, e-mail address, emergency contact details, GP or consultant details.
  • Health information (special category data) — your medical history, symptoms, examination findings, test and imaging results, diagnoses, medication and allergies, treatment records, and information you provide on consent and screening forms.
  • Payment and billing information — payment card details (processed securely by our payment provider), invoices, and insurance details including your policy and authorisation numbers.
  • Communications — correspondence with us by e-mail, post, telephone, website forms, or our WeCom customer-care channel (used only to handle your enquiry before you make a booking); when you call us, we record the number you called from.
  • Website and technical data — IP address, browser type and version, device and operating system information, and information about how you use our website, collected via cookies (see our Cookie Policy).
  • CCTV images — our clinic premises are protected by CCTV for the safety of patients, staff and property.

We collect this information directly from you (in person, by phone, via forms or our website), from a parent or guardian where you are a child, and, where relevant to your care, from your GP, referring clinicians, diagnostic providers or your medical insurer.

3. How and why we use your information

UK data protection law requires us to have a lawful basis for using your personal data, and an additional condition for health data. We rely on the following:

PurposeLawful basis (Art. 6 UK GDPR)Health data condition (Art. 9)
Providing you with healthcare — assessments, treatment, prescriptions, referrals and follow-upPerformance of our contract with youProvision of health care (Art. 9(2)(h)), by professionals bound by confidentiality
Checking your suitability for treatments (e.g. IV therapy, procedures) and obtaining your informed consentContract; legal obligation (CQC Regulation 11)Provision of health care (Art. 9(2)(h)); explicit consent for elective treatments
Billing your medical insurer, pre-authorisation and claims (incl. via Healthcode)Legitimate interests / contractYour explicit consent
Sharing information with your GP for continuity of careConsentYour explicit consent
Appointments, administration, payments, accounts and taxContract; legal obligationN/A (or Art. 9(2)(h) where clinical detail is involved)
Complaint handling, clinical governance, audit and learningLegitimate interests; legal obligationHealth/social care management (Art. 9(2)(h)); legal claims (Art. 9(2)(f))
Keeping our premises secure (CCTV) and our website safeLegitimate interestsN/A
Sending you marketing about services that may interest youConsent (opt-in only)N/A
Protecting your vital interests in an emergencyVital interestsVital interests (Art. 9(2)(c))

We will only send you marketing if you have opted in, and you can withdraw that consent at any time by contacting us or using the unsubscribe option. We never make decisions with legal or similarly significant effects about you by automated means.

4. Who we share your information with

We share your personal data only where necessary for your care, to meet a legal obligation, or with your consent:

  • Your private medical insurer — for pre-authorisation, claims and billing. We share only what is needed to process the claim (your identifiers, treatment codes, dates, clinician and cost).
  • Healthcode Limited — the healthcare industry's secure electronic billing service, used for standardised insurer billing.
  • Treating clinicians and specialists, diagnostic laboratories, imaging providers, and private hospitals — where referral, investigation or treatment forms part of your care.
  • Your GP or other primary-care provider — with your consent, to ensure continuity of care.
  • Our service providers (processors) — such as Microsoft (secure cloud services), our IT managed service provider, payment providers and our telephone/CCTV providers. They act on our written instructions under data processing agreements and cannot use your data for their own purposes.
  • Regulators and authorities — the Care Quality Commission, General Medical Council, Nursing and Midwifery Council, the ICO, and HMRC, where required to meet our legal and regulatory obligations.
  • Courts and law enforcement — only where required by law or a valid legal order.

We do not sell your personal data. We do not share your data for marketing purposes without your explicit consent. We do not enter your personal, medical or payment information into AI tools.

5. Where your information is stored and international transfers

Your data is held in secure cloud systems with United Kingdom data residency by default, including Microsoft 365 and Microsoft Azure services hosted in UK data centre regions. There are no on-premises servers at our clinic, and paper forms are digitised and confidentially shredded.

We do not intentionally transfer your personal data outside the UK. Where a cloud provider processes limited support or telemetry data overseas, this is protected by safeguards recognised under UK GDPR Article 46, such as the UK International Data Transfer Agreement or Addendum and Standard Contractual Clauses.

6. How we protect your information

  • Cyber Essentials certification, covering firewalls, secure configuration, access control, malware protection and security updates.
  • Multi-factor authentication on every account, encryption of data in transit (TLS/HTTPS) and at rest (AES-256), and full-disk encryption on all devices.
  • Your clinical information is created, stored and shared through our secure, encrypted MEDii management system — never through social or messaging apps.
  • Strict need-to-know access controls: unique named accounts, role-based access, prompt removal of leavers' access, and regular access reviews.
  • Company-owned, centrally managed devices only; staff receive data protection and security training.
  • Suspected breaches are investigated immediately and reported to the ICO within 72 hours where required, and to you where there is a high risk to your rights.

7. How long we keep your information

We retain records in line with the NHS Records Management Code of Practice as applied to private healthcare providers:

Type of recordRetention period
Adult patient clinical records8 years after your last treatment
Clinical records of children and young peopleUntil the patient's 25th birthday (or 26th if aged 17 at last treatment)
Financial and billing records6 years after the end of the relevant financial year
Insurance claim recordsAs required by your insurer — minimum 6 years
CCTV footageUp to 30 days
Marketing consent recordsUntil you withdraw consent, plus 12 months

When the retention period ends, records are securely deleted from all systems, including backups, and any paper is destroyed by confidential shredding.

8. Children and young people

Where we treat children and young people, a parent or legal guardian will normally provide consent. Young people under 16 who show sufficient maturity and understanding (Gillick competence) may consent to their own treatment; our clinicians assess and document this carefully. We keep children's records for the periods described above and apply the same standards of confidentiality and security.

9. Your rights

Under UK data protection law you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data in certain circumstances (medical records are often subject to legal retention requirements, which we will explain if they apply).
  • Restriction — ask us to limit how we use your data in certain circumstances.
  • Portability — receive certain data in a portable format or have it transmitted to another provider.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.

Exercising your rights is free of charge. To protect your information we will ask for proof of identity. We will respond within one month; if your request is complex, we may extend this by up to two months and will tell you if so. To exercise any right, contact our Data Protection Lead at admin@mediihealth.com or write to MEDii Ltd, 18 Duke's Road, London WC1H 9PY.

10. Cookies and third-party links

Our website uses cookies to distinguish you from other users and improve your experience. For details of the cookies we use and how to manage them, please see our Cookie Policy. Our website may contain links to other websites; we are not responsible for their privacy practices, so please review their policies before submitting personal data.

See our Cookie Policy, or .

11. Complaints

If you have a concern about how we handle your personal data, please contact us first at info@mediihealth.com or admin@mediihealth.com — we take every concern seriously and follow our published Complaints Policy, which includes independent adjudication through the Independent Sector Complaints Adjudication Service (ISCAS) for service complaints.

You also have the right to complain at any time to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — www.ico.org.uk — helpline 0303 123 1113. We would appreciate the chance to address your concerns before you approach the ICO.

12. Changes to this policy

We keep this policy under review and will post any updates on this page with a revised “last updated” date. Significant changes will be highlighted on our website or communicated to you directly where appropriate.

13. Contact us

Questions, comments and requests regarding this policy are welcome:

  • MEDii Ltd (trading as MEDii Health), 18 Duke's Road, London WC1H 9PY
  • E-mail: info@mediihealth.com
  • Data Protection Lead: admin@mediihealth.com