Privacy Policy

This privacy policy explains how The Dene Podiatry collects, uses, stores, and protects personal information. We are committed to handling all personal data responsibly and in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The Dene Podiatry is registered with the Information Commissioner’s Office (ICO) as a data controller.

Data Controller: Haroula Tsouloupas
Email: manager@thedenepodiatry.co.uk
Address: 19 The Dene, Cheam, Sutton, Surrey SM2 7EG

Information We Collect

In order to provide a podiatry service safely and effectively, we may collect and maintain the following information.

Patient Information

  • Name and title
  • Date of birth
  • Postal address
  • Telephone number and email address
  • Medical and treatment records
  • Clinical notes and assessments
  • Consent documentation
  • Details of your GP, consultant, or other healthcare professional
  • Appointment history
  • Payment and invoicing records
  • Emergency contact information
  • Correspondence between you and the clinic

Providing Your Information
In order to provide safe and effective podiatry treatment, you are required to provide certain personal and health information. If you choose not to provide this information, we may be unable to offer appropriate treatment or fulfil our professional obligations.

Website Data

When visiting our website, certain technical information may be collected, including:

  • IP address
  • Browser and device information
  • Cookie settings and preferences. Our website uses cookies to improve functionality and analyse website usage. Where required by law, non-essential cookies will only be used with your consent.
  • Website usage statistics gathered through analytics services

Why We Process Personal Information

We process personal data only where we have a lawful basis to do so.

These lawful bases may include:

Healthcare Provision

We process personal information where necessary to provide healthcare services, including assessment, diagnosis, treatment, clinical record keeping and ongoing patient care.
UK GDPR Article 6(1)(b), (c), (f) and Article 9(2)(h)

Consent

Where required, we will seek your consent before processing information, particularly for marketing communications.

UK GDPR Article 6(1)(a)

Legal Obligations

Certain information may be processed to meet statutory, regulatory, taxation, or professional requirements.

UK GDPR Article 6(1)(c)

Legitimate Interests

We may process limited information to improve our services, systems, and patient experience, provided this does not override your rights and freedoms.

UK GDPR Article 6(1)(f)

How We Use Your Information

Your information may be used for the following purposes:

  • Delivering podiatry assessment and treatment services
  • Maintaining accurate healthcare records
  • Managing appointments and sending reminders by telephone, SMS or email
  • Responding to enquiries and communications
  • Processing payments and managing accounts. Payment card details are processed securely by our payment provider Stripe and are not stored by The Dene Podiatry.
  • Meeting professional, legal, and regulatory obligations
  • Improving service quality and clinical governance

We do not carry out automated decision-making or profiling using your personal information.

Disclosure of Information

We will only share personal information where there is a valid reason to do so.

This may include:

  • Healthcare Providers

Information may be shared with GPs, consultants, hospitals, or other healthcare professionals involved in your care when appropriate and lawful.

  • Service Providers

We use trusted third-party suppliers to support clinic operations, such as practice management software, secure cloud storage providers, payment processors, and IT support services. All third-party processors act under written contracts requiring them to process personal information securely and only in accordance with our instructions

  • Regulatory Bodies

Information may be disclosed where required by organisations such as HMRC, the ICO, professional regulators, insurers, or auditors.

  • Legal Requirements

We may disclose information where necessary to establish, exercise, or defend legal rights, or where disclosure is required by law.

  • Safeguarding and Serious Risk

Where we believe there is a significant risk to your safety or the safety of another individual, information may be shared with appropriate authorities or healthcare professionals without consent where legally justified.

Appropriate contractual safeguards are in place with third-party processors for IT cloud based storage and payments processing to ensure personal information remains protected.

Retention of Information

We keep personal information only for as long as necessary to fulfil legal, regulatory, and clinical requirements.

Typical retention periods include:

  • Clinical records: eight years after the date of the last treatment, or until age 25 for patients treated as children, whichever period is longer
  • Financial and accounting records: six years

At the end of the applicable retention period, information will be securely deleted or destroyed.

Overseas Transfers

Some organisations that provide software or cloud-based services may process information outside the United Kingdom.

Where this occurs, we ensure appropriate safeguards are in place, including recognised adequacy arrangements, approved contractual protections, or other lawful transfer mechanisms.

Further information about these safeguards can be requested from us.

Your Rights

Under data protection law UK GDPR, you may have the right to:

  • Obtain access to personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion of information where legally applicable
  • Request restriction of certain processing activities
  • Object to specific forms of processing
  • Receive personal data in a portable format where applicable
  • Withdraw consent where consent is relied upon
  • Lodge a complaint with the Information Commissioner’s Office

Requests relating to your personal information should be directed to: manager@thedenepodiatry.co.uk

Security of Personal Information

We take security seriously and employ a range of technical and organisational safeguards, including:

  • Secure and encrypted systems
  • Password-protected devices and software
  • Access restrictions for authorised personnel only
  • Confidentiality obligations for staff
  • Ongoing monitoring, auditing, and security reviews
  • Data protection training and awareness measures

Data Breaches

Should a personal data breach occur, we will follow our legal obligations regarding investigation, containment, and notification, including reporting to the ICO and affected individuals where required.

Updates to This Notice

We may revise this Privacy Notice periodically to reflect changes in legal requirements, technology, or our services.

The latest version will always be available through our website and clinic communications.

Contact Us

If you have questions regarding this Privacy Notice or the way we handle personal information, please contact:

Haroula Tsouloupas
The Dene Podiatry
19 The Dene, Cheam, Sutton, Surrey SM2 7EG
Email: manager@thedenepodiatry.co.uk