GDPR & Privacy Policy

Last updated: 30 July 2026

This policy explains how Dunford Health handles personal information when you use this website, contact us, book an appointment or receive care. Dunford Health is the data controller for the personal information it decides how and why to use.

Contact details

Dunford Health
35 Green End, Whitchurch, Shropshire SY13 1AD, United Kingdom
Telephone: 01948 233 132
Email: contact@dunfordhealth.co.uk

Information we may collect

  • Identity and contact details, such as your name, address, telephone number, email address and date of birth.
  • Appointment, enquiry, correspondence and payment information.
  • Health and clinical information you provide or that is created during your care, including symptoms, medical history, assessments, treatment plans, consent and clinical notes.
  • Website technical and usage data, such as IP address, device/browser information, pages visited and cookie choices.
  • Information supplied by another healthcare professional, insurer, representative or family member where lawful and appropriate.

Why we use your information and our lawful bases

We use information to respond to enquiries, arrange and administer appointments, provide safe clinical care, maintain records, process payments, communicate about your care, meet professional and legal duties, defend legal claims, secure and improve our services, and—with consent where required—measure website use or send optional communications.

Depending on the purpose, we rely on one or more lawful bases under UK data protection law: taking steps at your request or performing a contract; complying with a legal obligation; our legitimate interests in running a safe and effective clinic; protecting vital interests in an emergency; or your consent.

Health information is special category data. Where we process it, we generally rely on the condition permitting processing for health or social care and the management of health services by, or under the responsibility of, a professional subject to confidentiality obligations. Other conditions may apply where necessary, such as establishing or defending legal claims or protecting vital interests.

When providing information is required

We may need certain identity, contact and health information to assess you safely, provide treatment, keep required records and administer an appointment. If you do not provide necessary information, we may be unable to offer or continue a particular service.

Who we may share information with

Where necessary and lawful, information may be shared with:

  • Cliniko and other providers that support appointments, clinical records, communications, payments, website hosting, IT, security and professional administration.
  • Healthcare professionals involved in your care, your GP or another referrer, normally with your knowledge unless law or safety requires otherwise.
  • Insurers, professional advisers, regulators, courts, law-enforcement bodies or public authorities where required or permitted by law.
  • A parent, guardian, carer or authorised representative where appropriate and lawful.

Service providers may only use information for agreed purposes and must protect it appropriately.

International transfers

Some technology providers may process information outside the UK. Where this happens, we require an appropriate lawful transfer mechanism, such as UK adequacy regulations or approved contractual safeguards, together with suitable protections. You may contact us for more information about relevant safeguards.

How long we keep information

We keep personal information only as long as needed for the purpose collected and to meet legal, tax, insurance and professional record-keeping obligations. Clinical record periods depend on the type of care, the patient’s age and applicable professional requirements. Enquiries that do not lead to care are generally kept for a shorter period. We periodically review and securely delete or anonymise information that is no longer required.

Security

We use reasonable organisational and technical measures to protect personal information against accidental loss, unauthorised access, alteration or disclosure. Access is limited to people and providers who need it for legitimate purposes. No internet service can be guaranteed completely secure, so please avoid sending unnecessary sensitive information by ordinary email.

Your data protection rights

Depending on the circumstances and lawful basis, you may have rights to access your information, correct inaccurate information, request erasure, restrict processing, object to processing, receive certain information in a portable format, and withdraw consent at any time where consent is relied upon. Withdrawing consent does not affect processing that was lawful before withdrawal. Some rights are subject to legal and clinical record-keeping exceptions.

Your right to object: where we rely on legitimate interests, you may object to that processing. You can object to direct marketing at any time.

To exercise a right, contact contact@dunfordhealth.co.uk. We may need to verify your identity before responding.

Complaints

Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.

Cookies and third-party websites

See our Cookie Policy for information about website cookies, analytics and embedded services. When you use a third-party website, including Cliniko or Google Maps, that provider’s own privacy policy also applies.

Changes to this policy

We may update this policy when our services, providers or legal obligations change. The date at the top shows when it was last reviewed.

GDPR & Privacy Policy