Our Privacy Policy
1. INTRODUCTION
This Privacy Policy explains how Apollo Health Collective (“the Clinic”, “we”, “us”, “our”) collects, uses, stores, and protects personal data.
We are committed to handling personal data in accordance with:
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Applicable professional and regulatory standards
We process personal data lawfully, fairly, and transparently, ensuring it is used only for appropriate and necessary purposes.
2. DATA CONTROLLER
Apollo Health Collective is the Data Controller for the purposes of UK data protection legislation.
Contact Details:
Apollo Health Collective
Waterbank House, Station Approach, Sheringham, NR26 8RA
01603 736238
admin@apollohc.co.uk
For all data protection queries, including exercising your rights, please contact us using the details above.
3. HOW WE WORK (IMPORTANT INFORMATION)
Apollo Health Collective operates with a team of practitioners who may be:
Self-employed
Independent practitioners
Operating across multiple clinic locations
Depending on the service provided, practitioners may act as:
Independent Data Controllers, or
Joint Data Controllers with the Clinic
Further information can be provided on request.
4. PERSONAL DATA WE COLLECT
4.1 Identity and Contact Information
Full name
Date of birth
Address
Telephone number(s)
Email address
Emergency contact details
4.2 Health and Clinical Information (Special Category Data)
Medical history
GP details
Presenting complaints
Clinical notes and treatment records
Diagnostic information
Referral letters and correspondence
Relevant lifestyle information
This data is classified as special category data and is subject to enhanced protection.
4.3 Administrative and Financial Information
Appointment records
Payment records (excluding full card details)
Insurance details (where applicable)
4.4 Technical Data (Website Users)
IP address
Browser type and version
Device information
Website usage data (via cookies where applicable)
5. LAWFUL BASIS FOR PROCESSING
We rely on the following lawful bases:
5.1 Provision of Healthcare
Article 6(1)(b) – Performance of a contract
Article 9(2)(h) – Provision of health care
5.2 Legal Obligations
Article 6(1)(c) – Compliance with legal and regulatory duties
5.3 Legitimate Interests
Article 6(1)(f) – Practice management and service improvement
Where applicable, we rely on recognised legitimate interests in line with current UK data protection legislation, ensuring these do not override your rights and freedoms.
5.4 Consent
Used for marketing and optional communications
Can be withdrawn at any time
6. HOW WE USE YOUR INFORMATION
We use personal data to:
Provide safe and effective healthcare
Maintain accurate clinical records
Manage appointments and treatment plans
Process payments and insurance claims
Communicate with you regarding your care
Respond to enquiries and complaints
Comply with legal and regulatory obligations
Improve our services
Communication Methods
We may contact you via:
Telephone
Email
SMS
Messaging platforms (e.g. WhatsApp)
We will only use these methods where appropriate and in line with your preferences.
Automated Decision-Making
We do not carry out solely automated decision-making that produces legal or similarly significant effects.
7. SHARING OF PERSONAL DATA
We may share your data where necessary with:
GPs and other healthcare professionals involved in your care
Insurance providers
Regulatory bodies
Legal or regulatory authorities
Third-Party Processors
We also use trusted third parties, including:
Practice management and booking systems
Payment processors
IT and cloud storage providers
Communication platforms
All third parties are required to process data securely and in accordance with UK GDPR.
We do not sell personal data.
8. INTERNATIONAL TRANSFERS
We do not routinely transfer personal data outside the UK.
Where this occurs, appropriate safeguards will be used, such as:
UK adequacy regulations
International Data Transfer Agreements (IDTAs)
9. DATA SECURITY
We implement appropriate technical and organisational measures, including:
Secure electronic record systems
Role-based access controls
Password protection
Encryption where appropriate
Secure storage of paper records
Staff confidentiality obligations
Data breaches are managed in accordance with legal requirements.
10. DATA RETENTION
We retain data in line with professional guidance.
As a general principle:
Adult records: minimum 8 years after treatment ends
Children’s records: until age 25 (or 26 if aged 17 at end of treatment)
Data is securely destroyed once no longer required.
11. YOUR RIGHTS
You have the right to:
Access your personal data
Request correction of inaccurate data
Request erasure (where applicable)
Restrict processing
Data portability
Object to processing
Withdraw consent
Requests can be made in writing or via email.We aim to respond within one month.
12. COMPLAINTS
If you have concerns about how we use your data, please contact us first.
We operate an internal complaints procedure:
Complaints will be acknowledged within 5 working days
A full response will be provided within one calendar month
If you remain dissatisfied, you may contact the Information Commissioner’s Office (ICO):
Website: https://www.ico.org.ukTelephone: 0303 123 1113
13. WEBSITE AND COOKIES
Where applicable, our website uses cookies to improve user experience.
A separate Cookie Policy provides further details.
Marketing communications comply with the Privacy and Electronic Communications Regulations (PECR).
14. POLICY REVIEW
This policy will be reviewed annually or sooner if legislation or operational changes require it.
Approved by:
Chris Greenslade
Director

