Our Privacy Policy

1. INTRODUCTION

This Privacy Policy explains how Apollo Health Collective (“the Clinic”, “we”, “us”, “our”) collects, uses, stores, and protects personal data.

We are committed to handling personal data in accordance with:

  • UK General Data Protection Regulation (UK GDPR)

  • Data Protection Act 2018

  • Applicable professional and regulatory standards

We process personal data lawfully, fairly, and transparently, ensuring it is used only for appropriate and necessary purposes.

2. DATA CONTROLLER

Apollo Health Collective is the Data Controller for the purposes of UK data protection legislation.

Contact Details:

Apollo Health Collective

Waterbank House, Station Approach, Sheringham, NR26 8RA

01603 736238

admin@apollohc.co.uk

For all data protection queries, including exercising your rights, please contact us using the details above.

3. HOW WE WORK (IMPORTANT INFORMATION)

Apollo Health Collective operates with a team of practitioners who may be:

  • Self-employed

  • Independent practitioners

  • Operating across multiple clinic locations

Depending on the service provided, practitioners may act as:

  • Independent Data Controllers, or

  • Joint Data Controllers with the Clinic

Further information can be provided on request.

4. PERSONAL DATA WE COLLECT

4.1 Identity and Contact Information

  • Full name

  • Date of birth

  • Address

  • Telephone number(s)

  • Email address

  • Emergency contact details

4.2 Health and Clinical Information (Special Category Data)

  • Medical history

  • GP details

  • Presenting complaints

  • Clinical notes and treatment records

  • Diagnostic information

  • Referral letters and correspondence

  • Relevant lifestyle information

This data is classified as special category data and is subject to enhanced protection.

4.3 Administrative and Financial Information

  • Appointment records

  • Payment records (excluding full card details)

  • Insurance details (where applicable)

4.4 Technical Data (Website Users)

  • IP address

  • Browser type and version

  • Device information

  • Website usage data (via cookies where applicable)

5. LAWFUL BASIS FOR PROCESSING

We rely on the following lawful bases:

5.1 Provision of Healthcare

  • Article 6(1)(b) – Performance of a contract

  • Article 9(2)(h) – Provision of health care

5.2 Legal Obligations

  • Article 6(1)(c) – Compliance with legal and regulatory duties

5.3 Legitimate Interests

  • Article 6(1)(f) – Practice management and service improvement

Where applicable, we rely on recognised legitimate interests in line with current UK data protection legislation, ensuring these do not override your rights and freedoms.

5.4 Consent

  • Used for marketing and optional communications

  • Can be withdrawn at any time

6. HOW WE USE YOUR INFORMATION

We use personal data to:

  • Provide safe and effective healthcare

  • Maintain accurate clinical records

  • Manage appointments and treatment plans

  • Process payments and insurance claims

  • Communicate with you regarding your care

  • Respond to enquiries and complaints

  • Comply with legal and regulatory obligations

  • Improve our services

Communication Methods

We may contact you via:

  • Telephone

  • Email

  • SMS

  • Messaging platforms (e.g. WhatsApp)

We will only use these methods where appropriate and in line with your preferences.

Automated Decision-Making

We do not carry out solely automated decision-making that produces legal or similarly significant effects.

7. SHARING OF PERSONAL DATA

We may share your data where necessary with:

  • GPs and other healthcare professionals involved in your care

  • Insurance providers

  • Regulatory bodies

  • Legal or regulatory authorities

Third-Party Processors

We also use trusted third parties, including:

  • Practice management and booking systems

  • Payment processors

  • IT and cloud storage providers

  • Communication platforms

All third parties are required to process data securely and in accordance with UK GDPR.

We do not sell personal data.

8. INTERNATIONAL TRANSFERS

We do not routinely transfer personal data outside the UK.

Where this occurs, appropriate safeguards will be used, such as:

  • UK adequacy regulations

  • International Data Transfer Agreements (IDTAs)

9. DATA SECURITY

We implement appropriate technical and organisational measures, including:

  • Secure electronic record systems

  • Role-based access controls

  • Password protection

  • Encryption where appropriate

  • Secure storage of paper records

  • Staff confidentiality obligations

Data breaches are managed in accordance with legal requirements.

10. DATA RETENTION

We retain data in line with professional guidance.

As a general principle:

  • Adult records: minimum 8 years after treatment ends

  • Children’s records: until age 25 (or 26 if aged 17 at end of treatment)

Data is securely destroyed once no longer required.

11. YOUR RIGHTS

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure (where applicable)

  • Restrict processing

  • Data portability

  • Object to processing

  • Withdraw consent

Requests can be made in writing or via email.We aim to respond within one month.

12. COMPLAINTS

If you have concerns about how we use your data, please contact us first.

We operate an internal complaints procedure:

  • Complaints will be acknowledged within 5 working days

  • A full response will be provided within one calendar month

If you remain dissatisfied, you may contact the Information Commissioner’s Office (ICO):

Website: https://www.ico.org.ukTelephone: 0303 123 1113

13. WEBSITE AND COOKIES

Where applicable, our website uses cookies to improve user experience.

A separate Cookie Policy provides further details.

Marketing communications comply with the Privacy and Electronic Communications Regulations (PECR).

14. POLICY REVIEW

This policy will be reviewed annually or sooner if legislation or operational changes require it.

Approved by:

Chris Greenslade

Director