Effective Date: 14th June 2025
Organisation Name: Kerrymount Limited
Trading As: The Long COVID Clinic
Data Controller: Mark Kane
Data Protection Officer: Mark Kane
Contact Email: info@thelongcovidclinic.co.uk
1. Introduction
At The Long COVID Clinic, we are committed to protecting your personal data and respecting your privacy. This policy outlines how we collect, use, store, and protect your information in accordance with the UK General Data Protection Regulation (UK GDPR).
2. Information We Collect
We may collect and process the following personal data:
-
Full name
-
Date of birth
-
Contact details (email, phone number, address)
-
Medical history and health information
-
NHS number
-
Emergency contact information
-
IP address and website cookies
-
Payment details
We also collect special category data (such as health information) in accordance with Article 9(2)(h) of UK GDPR — for the provision of health care.
3. How We Collect Your Data
Your information is collected through:
-
Online forms (e.g. via Google Forms, Website Forms)
-
Patient consultations
-
Website cookies and analytics tools
-
Email and phone correspondence
-
Referrals from healthcare providers
-
Third-party providers (e.g. diagnostic labs)
4. Why We Collect Your Data
We collect and use your data to:
-
Book appointments and manage your care
-
Provide medical consultations and clinical services
-
Communicate with you effectively
-
Maintain internal administrative records
-
Comply with legal and insurance obligations
-
Send updates or newsletters (with your consent)
-
Support clinical research
-
Improve our services
-
Analyse website usage
5. Legal Bases for Processing
We rely on the following lawful bases under UK GDPR:
-
Consent – for marketing communications and cookies
-
Contract – to provide clinical services to you
-
Legal obligation – for compliance with health regulations
-
Vital interests – in cases of medical urgency
-
Legitimate interest – to operate and improve our services
-
Provision of health care – under Article 9(2)(h) for special category data
6. Data Storage and Security
Your data is stored securely using:
-
UK-based servers
-
Google Drive
-
Clinic software
-
Web hosting databases
-
Email inboxes
We implement strict access controls, encryption where required, and ensure that only authorised personnel can access sensitive data.
7. Data Sharing
We may share your data with the following, where necessary:
-
Our internal staff and clinical team
-
NHS services and healthcare professionals
-
Partner diagnostic labs
-
Payment processors (e.g. Stripe)
-
IT service providers (e.g. Google, web hosts)
-
Marketing platforms (e.g. Mailchimp)
We ensure that all third parties comply with applicable data protection laws.
8. Data Retention
We retain your personal and health data for 7 years from the date of your last treatment or contact, in accordance with NHS and professional clinical guidelines.
9. Cookies and Analytics
We use cookies and analytics tools to improve website functionality and understand user behaviour. This includes:
-
Google Analytics
-
YouTube embeds
-
A visible cookie consent banner
You can manage your cookie preferences through your browser or our website banner.
10. Children’s Data
We provide clinical services to individuals under the age of 18. In these cases, we obtain explicit parental or guardian consent before collecting or processing any personal data.
11. Your Rights
Under UK GDPR, you have rights including:
-
Access to your personal data
-
Correction of inaccurate data
-
Request deletion (“right to be forgotten”)
-
Restriction or objection to processing
-
Data portability
-
Withdrawal of consent (for marketing or cookies)
To exercise any of these rights, contact us at: info@thelongcovidclinic.co.uk
12. Changes to This Policy
We may update this policy from time to time. Any changes will be posted on this page, and where appropriate, notified to you by email.