Privacy

Privacy Policy

Last updated: 1 January 1970

This Privacy Policy explains how Dr Amar Shah ("I", "me", "my") collects, uses, stores and protects your personal data, including special-category health data, when you use this website, send an enquiry, or attend a consultation. It is written in line with the UK GDPR and the Data Protection Act 2018.

1. Who I am (Data Controller)

Data Controller: Dr Amar Shah, Consultant Respiratory & Sleep Physician.
Email: info@dramarshah.co.uk
Phone: +44 7778 502349
Data Protection Officer: Dr Amar Shah (same email).
ICO registration number: ZC148012.

2. The data I collect

If you use the contact form, I collect your name, email address, your message and (optionally) your preferred location. Enquiries are stored securely and used only to reply to you. Please do not include sensitive medical information — symptoms, test results, medication lists or scans — in the form or by email; I will contact you to discuss anything clinical securely.

3. Why I use it and the lawful basis

4. Who I share it with (processors)

I share your data only with the trusted suppliers needed to run this service:

Each is bound by a written Data Processing Agreement and uses appropriate safeguards for any international transfers.

When you book an appointment, your name, date of birth and contact details are shared with the CQC-registered hospital hosting your appointment — currently HCA The Wellington Hospital or Chase Lodge Hospital — so they can process your booking, admission and any on-site care. Bookings made through a hospital's own booking system are handled under that hospital's privacy terms; each hospital acts as an independent controller for the services it provides.

I also share information, with your consent, with your insurer (to obtain pre-authorisation and settle invoices) and with your GP or referring clinician, so that your care can be coordinated.

This website displays a patient review rating widget provided by Doctify. Loading the widget means your browser connects to Doctify's servers, and Doctify may set its own cookies and process technical data such as your IP address. Doctify collects and publishes patient reviews as an independent controller under its own privacy policy; I do not receive identifiable information about who has viewed the widget.

If you message me on WhatsApp, that conversation takes place on WhatsApp’s platform (WhatsApp Ireland Limited, part of Meta) and is not stored by this website. WhatsApp is an independent controller for the messages held on its service, under its own terms and privacy policy. WhatsApp messages are end-to-end encrypted, but please keep them brief and avoid sending detailed medical history — I will move the conversation to the secure patient portal or a consultation where clinical detail is needed.

I do not sell your data, and I do not use it for marketing or profiling.

5. Sleep studies and CPAP therapy

If your care involves a sleep study (for example a home sleep-study kit) or CPAP therapy, these services are not delivered from this website. They are arranged and handled through The London Sleep Apnoea Clinic and its clinical partners, who supply the diagnostic equipment and CPAP devices, delivery and ongoing therapy support.

Where that applies, the relevant details you have given me are shared with The London Sleep Apnoea Clinic and, where you choose to proceed, with its diagnostic and CPAP partners. Those organisations act as independent controllers for the services they provide and handle your data under their own privacy terms, which are set out on The London Sleep Apnoea Clinic's privacy policy. This sharing only happens with your consent, and equipment registration (including any bank or Direct Debit details) passes directly between you and the supplier — I never see or store it.

6. How long I keep it

Adult clinical and appointment records are retained for a minimum of eight years from the last episode of care, in line with GMC guidance and NHS records-management standards. Payment and accounting records are kept for six years to meet HMRC requirements. Website logs are held for up to 30 days for security purposes.

Contact-form enquiries that do not lead to a booking are kept for 12 months and then deleted. If your enquiry becomes an appointment, it is retained with your clinical record.

7. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, please see Request my data, or email me at info@dramarshah.co.uk.

8. Security

All data is transmitted over HTTPS. Card data is handled by the hospital or card terminal provider and never touches my systems. Access to records is restricted, stored data is encrypted, and row-level database security is used so information is only returned to those entitled to see it. No system can be guaranteed 100% secure, but I take reasonable and proportionate steps to keep your information safe.

9. Children

This service is provided to adults. If care is arranged for a young person, a parent or guardian must consent on their behalf.

10. International transfers

Your data is stored and processed in the UK / European Economic Area (EEA). Where a processor (for example an email or hosting provider) is based outside the UK/EEA, transfers are protected by appropriate safeguards under UK GDPR — typically the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

11. Automated decision-making

I do not make decisions about your care using solely automated processing, and I do not carry out profiling that produces legal or similarly significant effects.

12. Links to other websites

This site links to third-party sites (for example host clinics, The London Sleep Apnoea Clinic, insurers and the ICO). Once you leave this site, I have no control over those sites and am not responsible for their privacy practices. Please review the privacy policy of each site you visit.

13. Cookies

I only use cookies strictly necessary to operate this website. I do not use advertising or third-party tracking cookies. See the Cookie Policy for the full list.

14. Personal data breaches

If you suspect a breach involving your personal data (for example a suspicious email pretending to be from me, or unauthorised access to your record), please contact me immediately at info@dramarshah.co.uk.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, I will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to you, I will also contact you directly without undue delay (Article 34) and explain what happened, what data was affected, what I am doing about it, and what steps you can take.

15. Changes to this policy

I may update this policy from time to time. The "Last updated" date at the top of this page shows when it was last revised, and material changes will be highlighted here.

16. Contact and complaints

For any privacy question, contact me at info@dramarshah.co.uk.

If you are not satisfied with my response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.