Our Policy 

Estuary View Private Medical Services is committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This privacy policy explains how we collect, use, store, and protect your personal data when you use our services.

 

Who We Are

Estuary View Private Medical Services
Estuary View Medical Centre
Boorman Way
Whitstable
Kent
CT5 3SE

  • Phone: 01227 202834
  • Data Protection Officer: GMS Manager
  • ICO Registration Number: Z601742X

We are a registered healthcare provider regulated by the Care Quality Commission (CQC).

 

What Information We Collect

We collect the following personal information to provide safe and effective care:

Personal Data:

  • Name, date of birth, address, phone number, email
  • NHS number (if applicable)
  • Emergency contact details
  • Payment and billing details 

Health Information (Special Category Data):

  • Medical history and health conditions
  • Medications and allergies
  • Treatment plans and progress notes
  • Diagnostic images (e.g. x-ray, ultrasound, photographs)
  • Correspondence with other healthcare providers
 

Why We Collect Your Data

We collect and process your personal and health data to:

  • Provide medical care and treatment
  • Keep accurate and up-to-date medical records
  • Communicate with you about appointments and care
  • Refer you to other healthcare providers where necessary
  • Meet our legal, regulatory, and professional obligations
  • Process payments and manage accounts
 

Lawful Basis for Processing

Under the UK GDPR, we process your data based on the following lawful bases:

  • Article 6(1)(b) – Contract (providing care and treatment)
  • Article 6(1)(c) – Legal obligation (e.g. CQC regulations)
  • Article 6(1)(f) – Legitimate interests (clinical audits, service improvement)
  • Article 9(2)(h) – Provision of health or social care
 

How We Store Your Data

Your data is stored securely using encrypted practice management systems (EMIS Web, SimplyBook) and secure servers. We do not collect or store paper records. We retain data in line with CQC requirements. 

 

Sharing Your Information 

We only share your data where necessary and with your consent (unless required by law), including: 

  • GPs, consultants, or hospitals involved in your care
  • Pathology/laboratory services
  • Regulators (e.g. CQC, ICO) when required
  • Our IT and administrative service providers (under strict contracts)

We do not share your data for marketing or with third parties unrelated to your care.

 

Your Rights

You have the right to:

  • Access your medical records
  • Correct inaccuracies
  • Request deletion of your data (where applicable)
  • Restrict or object to processing
  • Data portability (where relevant)
  • Withdraw consent (if processing is based on consent)
  • Lodge a complaint with the Information Commissioner’s Office (ICO)
 

Website and Cookies

If you use our website, we may collect limited personal data via forms or cookies.

 

How to Contact Us

If you have any questions or concerns about this privacy policy or how your data is used, please contact: 

Estuary View Medical Services – Data Protection Lead .Phone: 01227 202834

 

Policy Updates

We may update this policy periodically. The latest version will always be available on our website.