Stonegate Medical Privacy Policy

PRIVACY POLICY

This page constitutes our privacy notice, and explains why we collect information about you, how that information may be used, how we keep it safe and confidential and what your rights are in relation to this.

  1. This document explains how York Private Medical Ltd (hereafter referred to as “Stonegate Medical Clinic”, ‘we’ or ‘us’) manages your personal information. We are dedicated to protecting your privacy and the information you share with us. You may receive additional privacy notices when sharing specific information with us, this is designed to supplement these, not replace them.
  2. For the purpose of this notice, The terms ‘personal information’ and ‘personal data’ are considered equivalent and may be used interchangeably.

About Stonegate Medical Clinic

  1. We are a limited company, registered in England and Wales. Company number 09745036, Information Commissioners Office (ICO) Registration number: ZA160103. Stonegate Medical Clinic is a trading name of York Private Medical Ltd). Our registered address is Stonegate Medical Clinic, 23 Stonegate, York, England, YO1 8AW. We are a data controller, responsible for determining how your personal information is obtained, stored, and used.
  2. We recognise the utmost importance of the confidentiality of your medical information and adhere strictly to UK data protection law (Data Protection Act 2018) and professional guidelines from (but not limited to) the General Medical Council and British Medical Association.

Scope of This Notice

  1. This Privacy Notice applies to everyone who receives healthcare services from Stonegate Medical Clinic, regardless of how you interact with us
    (in person, via email, through our website, by phone, etc.).
  2. It also applies to anyone who shares personal information with us via this website.

What Personal Information We Collect

  1. The personal information we collect may include basic information such as:
  • Name, address, date of birth, and contact details
  • Emergency contact details (including next of kin)
  • Financial information (including credit card details)
  • Occupation
  1. We also collect sensitive personal information (special category data) related to your physical and mental health such as:
  • Details of your current or former physical or mental health, including past and planned healthcare services from us and other providers (GPs, dentists, hospitals, clinics both private and NHS, both national and international)
  • Details of care you have received from us, including any images taken or shared
  • Nationality, race, and/or ethnicity
  • Religion
  • Examination/test results, including genetic or biometric data
  • Data concerning sex life and/or sexual orientation

Other People’s Personal Information

  1. If you provide personal information about another person, please ensure you inform them of this privacy notice.

Why We Process Your Personal Information

  1. We process your personal information with the following justifications:
  • Contract: to provide the best possible healthcare and services as agreed with you.
  • Legitimate interests: for quality assurance, record maintenance, service improvement, and medical research.
  • Legal obligation: to comply with relevant regulations.
  • Legal claims: to establish, exercise, or defend legal claims.
  • Consent: in accordance with your explicit consent (e.g. for marketing).
    You may withdraw your consent at any time, however this will not change any of the other
    justifications explained above regarding why we process your personal information.

How We Process Your Personal Information

  1. Processing your information involves collecting, changing, storing, retaining, and sharing it.
  1. Collecting: We may collect your personal information from a number of sources.
    This will always be in accordance with the justifications explained in paragraph 10.
  • Directly from you:
    you may give us data when you enter into a contract, use our services, have consultations, complete forms, send inquiries, correspond with us (whether electronically or otherwise), call us (calls may be recorded), or choose to participate in marketing activities. Information may also be shared without your explicit intent, simply by visiting our website, however in general this will be aggregate data which cannot be used to identify you, and as such is not regarded as personal information. Please see paragraph 21 for more explanation.
  • From other healthcare providers:
    we may collect data from any organisation involved in your care, such as your NHS GP, hospitals or clinics (private or NHS). This information may include (but not be limited to) consultation notes, examination or test results, diagnoses, and treatments (including medications).
  • From other third parties:
    we may collect data from third parties, if required to fulfil justifications explained in paragraph 10. These may include (but not be limited to): your next of kin / emergency contacts, employers, local authorities, educational providers, solicitors, insurance providers, credit reference agencies, debt collection agencies, and government agencies.
  1. Changing:
    we will update our systems with changes to your personal information as advised by you, or any of the sources listed in paragraph 12, but will generally also maintain a record of the originally submitted information.
  1. Storing:
    we have security measures designed to protect the information we store, and prevent accidental loss, unauthorised access, alteration or disclosure
  1. Retaining:
    we retain your personal information only for as long as necessary to fulfil the justifications explained in paragraph 10. When it is no longer needed, we securely destroy it.
  1. Sharing: 
    we may share your personal information with necessary third parties. The nature and extent of any information shared will be limited to what is required to satisfy the justifications explained in paragraph 10 and the role of the third party in said justification. We may share your personal information with:
  • Healthcare providers and professionals (e.g. when making referrals)
  • Medical service providers (e.g. when arranging investigations)
  • Delivery services (e.g. if we need to send something to your home, such as a test kit)
  • Employers
  • Regulators/safeguarding authorities/commissioners
  • Law enforcement agencies
  • IT service providers
  • Legal representatives
  • Emergency contacts
  • Insurance companies
  • Administration staff, doctors and other healthcare professionals at Stonegate Medical Clinic
  • New business owners in the event of a sale

International transfers

  1. Your personal information is not shared outside of the UK unless you, or someone you nominate, explicitly request it.
    For example, to support visa or employment applications abroad. Where this occurs, we ensure appropriate safeguards
    are in place to protect your information.

Communication

  1. We may communicate or respond to you (where we have your permission) via:
  • Post
  • Telephone (and voice messages, where we have permission)
  • SMS
  • Email
  • Other online communication methods like phone applications and social media.
    Whilst we may respond to you via social media or other online platforms if you initiate contact,
    we will never discuss personal health information in public forums. For anything confidential,
    we will direct you to a secure channel (e.g., phone, email, or in-person) as above. Clinical queries,
    bookings, or complaints should be made through official routes.
    We reserve the right to moderate or remove inappropriate content to protect staff and patients.
  1. Messages we send will be in accordance with the justifications explained in paragraph 10,  and may take the form of (but not be limited to):
  • Updates and reminders of appointments
  • Invoicing information
  • Information relevant to your healthcare (e.g. test results)
  • Patient surveys (as explained in paragraph 20)
  • Marketing (if you have specifically consented to this)

Patient Surveys, Audits, and Initiatives

  1. We may invite you to participate in surveys to help improve our services.
    These surveys are not for marketing purposes, and your participation is entirely voluntary, you can opt out at any point.

Aggregate Data:

  1. Aggregate data is derived from your personal information but is not considered personal information in law as it cannot
    be used to identify you. This is because in creating aggregate data, the separate elements of your personal information
    are split up and then combined (or aggregated) with the same elements from other people. Aggregate data is used to analyse
    trends and can be useful in planning service provision or marketing activities. Examples of aggregate data would be
    demographic groups. If aggregate data is transformed such that you can once again be identified from it, we process it
    in line with this privacy policy.

Data Breaches

  1. A ‘data breach’ can be broadly defined as a security incident that has affected the confidentiality, integrity or availability
    of personal data. As explained in paragraph 14, we have security measures in place to protect your personal information.
    Should a data breach occur, we will notify you and any applicable regulator (e.g. the Information Commissioner’s Office (ICO)),
    where we are legally required to do so.

Your Rights

  1. You have the right to:
  • Know if we hold or use your personal information, and how we do so
  • Request access to the personal information we hold
  • Get your personal information in a way that is accessible
  • Challenge the accuracy of our record of your personal information
  • Request that we remove your personal information from our records
  • Object to us processing your personal information
  • Limit how we use your personal information in certain circumstances
  • Prevent automated processing of your personal information in certain circumstances
  • Withdraw consent to the processing of your data
  • Make a data protection complaint, as explained in paragraphs 27 to 29
  1. You may exercise your rights at any time by contacting our Data Protection Officer (DPO) with any requests
    (contact details are found in paragraph 31). We will respond to your requests in writing. If you have corresponded
    with us electronically we will seek to continue with our response electronically where possible.
  1. We will respond to your request in line with time limits set by applicable regulators, for simple requests this limit is a month,
    but may increase to three months for complex requests. If we require information from you in order to process your request
    (such as proof of identity), the time limit will begin once we have received this.
  1. Generally, we will not charge you to meet a request; however we may charge, or alternatively may reasonably refuse a request,
    completely or in part, under certain circumstances. If this is the case we will always explain why. Reasons may include:
  • A large number of requests
  • Unreasonable requests
  • Requests involving another person’s information
  • Requests which put us in breach of applicable law or regulation
  • Requests which contradict justifications set out in paragraph 10
    (e.g. asking us to remove your personal information while we are still providing medical care as per contract)
  • Requests which affect our ability to exercise or defend legal claims

Making a Data Protection Complaint

  1. You can make a complaint to us, if you think we have not processed your personal information responsibly and in line with
    good practice. Complaints should be made in writing to our DPO using the contact details in paragraph 31. Email is preferred.
  1. We will respond within the timeframes explained in paragraph 24.
  1. If we do not respond to you, you can complain to the ICO , which is the UK’s independent regulator for data protection and
    information rights law (ico.org.uk); however we would appreciate the chance to help you with your complaint first.

External Websites

  1. Our website may link to other, external sites. We are not responsible for the privacy policies of linked external websites.
    Therefore, please make sure to read any relevant privacy policies before using these sites.

Our Data Protection Officer

  1. Our Data Protection Officer (DPO) is Dr William Robertson. You can contact him via the Stonegate Medical Clinic general email or reception.
    Please ensure any query is FAO Dr William Robertson:

Privacy explained for children

For children and young people who would like a simpler explanation of personal data and privacy, we recommend this child-friendly GDPR guide from BBC Bitesize.

 

Updates to This Privacy Notice

This notice may be updated periodically to ensure it remains accurate.

Last updated: 26th January 2026.