Start your journey to healthier veins today!

Privacy Policy

Healthy Veins Limited
Last updated: 26.12.2025

Healthy Veins Limited (“we”, “us”, “our”) is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are (Data Controller)

Healthy Veins Limited is the data controller for personal data collected through this website and during patient interactions.

  • Organisation: Healthy Veins Limited

  • Nature of service: Consultant-led, private varicose vein services

  • Contact email: info@healthyveins.co.uk

2. What Personal Data We Collect

We may collect and process the following categories of personal data:

a) Website users
  • Name

  • Email address

  • Telephone number

  • IP address

  • Cookies and usage data

b) Patients and enquirers
  • Contact details

  • Medical history and health information (special category data)

  • Appointment and treatment details

  • Correspondence with our clinic

3. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Consent – for enquiries, cookies, and marketing (where applicable)

  • Contract – to provide medical services

  • Legal obligation – healthcare record keeping

  • Vital interests – where required for patient safety

  • Legitimate interests – service improvement and website functionality

Special category health data is processed in accordance with Article 9(2)(h) UK GDPR for the provision of healthcare.

4. How We Use Your Information

We use personal data to:

  • Respond to enquiries

  • Arrange and manage appointments

  • Provide safe and effective medical care

  • Maintain accurate medical records

  • Comply with legal and regulatory obligations

  • Improve our services and website performance

5. Data Storage and Security (CQC Relevant)
  • Patient data is stored securely using password-protected systems

  • Access is restricted to authorised clinical and administrative staff

  • Staff receive data protection and confidentiality training

  • We have procedures in place to identify, report, and manage data breaches

  • Medical records are retained in line with NHS and CQC guidance

6. Data Sharing

We only share personal data when necessary, including with:

  • Healthcare professionals involved in your care

  • Regulatory bodies (e.g. CQC) if legally required

  • IT and website service providers under data processing agreements

We never sell personal data.

7. Your Rights Under UK GDPR

You have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure (where applicable)

  • Restrict or object to processing

  • Data portability

  • Withdraw consent at any time

Requests can be made by contacting us using the details above.

8. Complaints

If you are unhappy with how your data is handled, you may contact:

  • Healthy Veins Limited directly

  • Or the Information Commissioner’s Office (ICO): www.ico.org.uk

9. Policy Review

This policy is reviewed regularly and updated as required to remain compliant with legislation and CQC expectations.