Privacy
Privacy Policy
Last updated: 1 January 1970
This Privacy Policy explains how Dr Amar Shah ("I", "me", "my") collects, uses, stores and protects your personal data, including special-category health data, when you use this website, send an enquiry, or attend a consultation. It is written in line with the UK GDPR and the Data Protection Act 2018.
1. Who I am (Data Controller)
Data Controller: Dr Amar Shah, Consultant Respiratory & Sleep Physician.
Email: info@dramarshah.co.uk
Phone: +44 7778 502349
Data Protection Officer: Dr Amar Shah (same email).
ICO registration number: ZC148012.
2. The data I collect
- Identity & contact: name, date of birth, email address, phone number.
- Health data (special category): reason for visit, clinical notes you provide, and any information related to your respiratory or sleep health.
- Insurance details: insurer, membership number, pre-authorisation code (if applicable).
- Payment data: I do not take card payments through this website. Fees are settled with the CQC-registered hospital hosting your appointment, or in clinic — I never see or store your card details.
- Technical data: IP address, browser, and basic logs needed to operate the site securely.
If you use the contact form, I collect your name, email address, your message and (optionally) your preferred location. Enquiries are stored securely and used only to reply to you. Please do not include sensitive medical information — symptoms, test results, medication lists or scans — in the form or by email; I will contact you to discuss anything clinical securely.
3. Why I use it and the lawful basis
- To deliver care (booking, reminders, clinical follow-up): UK GDPR Article 6(1)(b) — performance of a contract — and Article 9(2)(h) — provision of health care, supported by your explicit consent at the point of booking.
- To respond to website enquiries: Article 6(1)(a) — your consent, given by ticking the box on the contact form — and Article 9(2)(a) — explicit consent, where you choose to include health information.
- To administer fees and invoicing: Article 6(1)(b) — contract.
- To meet legal/regulatory duties (clinical record-keeping, accounting): Article 6(1)(c) — legal obligation.
- To keep the website secure: Article 6(1)(f) — legitimate interests.
4. Who I share it with (processors)
I share your data only with the trusted suppliers needed to run this service:
- Lovable Cloud / Supabase — secure database and hosting for this website and enquiry records (EU region).
- Stackmail (Hostinger) — my email service, used to send and receive professional email, including appointment correspondence and enquiry alerts.
Each is bound by a written Data Processing Agreement and uses appropriate safeguards for any international transfers.
When you book an appointment, your name, date of birth and contact details are shared with the CQC-registered hospital hosting your appointment — currently HCA The Wellington Hospital or Chase Lodge Hospital — so they can process your booking, admission and any on-site care. Bookings made through a hospital's own booking system are handled under that hospital's privacy terms; each hospital acts as an independent controller for the services it provides.
I also share information, with your consent, with your insurer (to obtain pre-authorisation and settle invoices) and with your GP or referring clinician, so that your care can be coordinated.
This website displays a patient review rating widget provided by Doctify. Loading the widget means your browser connects to Doctify's servers, and Doctify may set its own cookies and process technical data such as your IP address. Doctify collects and publishes patient reviews as an independent controller under its own privacy policy; I do not receive identifiable information about who has viewed the widget.
If you message me on WhatsApp, that conversation takes place on WhatsApp’s platform (WhatsApp Ireland Limited, part of Meta) and is not stored by this website. WhatsApp is an independent controller for the messages held on its service, under its own terms and privacy policy. WhatsApp messages are end-to-end encrypted, but please keep them brief and avoid sending detailed medical history — I will move the conversation to the secure patient portal or a consultation where clinical detail is needed.
I do not sell your data, and I do not use it for marketing or profiling.
5. Sleep studies and CPAP therapy
If your care involves a sleep study (for example a home sleep-study kit) or CPAP therapy, these services are not delivered from this website. They are arranged and handled through The London Sleep Apnoea Clinic and its clinical partners, who supply the diagnostic equipment and CPAP devices, delivery and ongoing therapy support.
Where that applies, the relevant details you have given me are shared with The London Sleep Apnoea Clinic and, where you choose to proceed, with its diagnostic and CPAP partners. Those organisations act as independent controllers for the services they provide and handle your data under their own privacy terms, which are set out on The London Sleep Apnoea Clinic's privacy policy. This sharing only happens with your consent, and equipment registration (including any bank or Direct Debit details) passes directly between you and the supplier — I never see or store it.
6. How long I keep it
Adult clinical and appointment records are retained for a minimum of eight years from the last episode of care, in line with GMC guidance and NHS records-management standards. Payment and accounting records are kept for six years to meet HMRC requirements. Website logs are held for up to 30 days for security purposes.
Contact-form enquiries that do not lead to a booking are kept for 12 months and then deleted. If your enquiry becomes an appointment, it is retained with your clinical record.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data I hold about you
- Ask me to correct inaccurate data
- Ask me to erase data (subject to my legal duty to retain clinical records)
- Restrict or object to processing
- Data portability, where applicable
- Withdraw consent at any time
To exercise any of these rights, please see Request my data, or email me at info@dramarshah.co.uk.
8. Security
All data is transmitted over HTTPS. Card data is handled by the hospital or card terminal provider and never touches my systems. Access to records is restricted, stored data is encrypted, and row-level database security is used so information is only returned to those entitled to see it. No system can be guaranteed 100% secure, but I take reasonable and proportionate steps to keep your information safe.
9. Children
This service is provided to adults. If care is arranged for a young person, a parent or guardian must consent on their behalf.
10. International transfers
Your data is stored and processed in the UK / European Economic Area (EEA). Where a processor (for example an email or hosting provider) is based outside the UK/EEA, transfers are protected by appropriate safeguards under UK GDPR — typically the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
11. Automated decision-making
I do not make decisions about your care using solely automated processing, and I do not carry out profiling that produces legal or similarly significant effects.
12. Links to other websites
This site links to third-party sites (for example host clinics, The London Sleep Apnoea Clinic, insurers and the ICO). Once you leave this site, I have no control over those sites and am not responsible for their privacy practices. Please review the privacy policy of each site you visit.
13. Cookies
I only use cookies strictly necessary to operate this website. I do not use advertising or third-party tracking cookies. See the Cookie Policy for the full list.
14. Personal data breaches
If you suspect a breach involving your personal data (for example a suspicious email pretending to be from me, or unauthorised access to your record), please contact me immediately at info@dramarshah.co.uk.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, I will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to you, I will also contact you directly without undue delay (Article 34) and explain what happened, what data was affected, what I am doing about it, and what steps you can take.
15. Changes to this policy
I may update this policy from time to time. The "Last updated" date at the top of this page shows when it was last revised, and material changes will be highlighted here.
16. Contact and complaints
For any privacy question, contact me at info@dramarshah.co.uk.
If you are not satisfied with my response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
Dr Amar Shah