This Privacy Policy provides details of how we collect and process your personal data at Kiam Clinic based in London. It is effective from 11th July 2025 in accordance with the UK General Data Protection Regulation (UK GDPR). We take data protection and confidentiality very seriously and aim to be transparent about how your data is used. We hope this policy answers any questions you may have; however, please refer to the contact details below if you have any further concerns or queries.
Last updated: 22nd September 2025
Data Controller:
KAZYS LTD (t/a Kiam Clinic)
Address:
Kiam Clinic
13 Worple Road
Epsom
KT18 5EP
United Kingdom
Email: info@kiamclinic.com
Phone: +44 1372 660580
KAZYS LTD is registered with the Information Commissioner’s Office (ICO) under registration number ZA859797.
Scope of This Privacy Policy
This Privacy Policy explains how we collect, use, store and protect your personal information when you:
- visit our website
- contact us
- book or attend appointments
- receive healthcare services from Kiam Clinic
Our services are only provided to adults aged 18 and over.
Personal Information We Collect
Personal Information
This may include:
- name
- date of birth
- contact details (email, phone number, address)
- GP details
- emergency contact details
Health Information
During the course of providing care we may collect sensitive medical information such as:
- medical history
- mental health information
- medication information
- clinical assessments
- consultation notes
- treatment plans
- correspondence with other healthcare professionals
Health information is classified as special category data under UK GDPR and is handled with additional safeguards.
Website Information
When you visit our website, we may collect:
- IP address
- browser type
- pages visited
- website usage statistics
This information is collected using Google Analytics.
How We Collect Your Information
We collect information when you:
- complete forms on our website
- book an appointment
- communicate with us via email or phone
- complete medical questionnaires
- attend consultations
- provide documentation relating to your care
Some information may also be provided by other healthcare professionals if you are referred to our service.
Data Storage and Security
Patient records are stored securely using our clinical management system Cliniko.
Cliniko uses secure encrypted infrastructure and industry-standard security measures to protect patient information.
Access to patient records is restricted to authorised staff and clinicians who require the information to provide care.
All electronic communication and storage systems used by the clinic are protected by appropriate technical and organisational safeguards.
Payment Processing
Payments for services may be processed using Stripe via the Cliniko platform.
Payment card information is handled directly by Stripe and Kiam Clinic does not store your card details.
Stripe processes payment data in accordance with their own privacy and security standards.
Sharing Your Information
Your personal data will not be shared with third parties unless necessary for the provision of care or where required by law.
Your information may be shared with:
- other healthcare professionals involved in your care
- your GP
- regulatory authorities where legally required
We will not share information with your GP without your explicit consent, unless required by law or where there is a serious risk to patient safety.
Data Retention
We retain medical records in accordance with UK healthcare record retention guidelines.
In most cases, adult medical records are retained for a minimum of 8 years after the last clinical contact, unless a longer retention period is required by law or for medico-legal reasons.
When records are no longer required, they are securely destroyed or anonymised.
Cookies and Website Analytics
Our website uses cookies to improve user experience and analyse website traffic.
We use Google Analytics to collect anonymous usage data about how visitors interact with the website.
You may control cookie settings through your browser preferences.
Your Data Protection Rights
Under UK data protection law you have the right to:
- access your personal data
- request correction of inaccurate data
- request deletion of data where appropriate
- restrict processing of your data
- object to certain types of processing
- request transfer of your data to another provider
To exercise any of these rights, please contact us at:
Security
We apply technical (SSL, secure hosting) and organisational (training, access controls) measures to protect your data. All staff and processors are GDPR-compliant and contractually obligated to maintain confidentiality.
Children’s Data
Our site is not intended for under-18s, and we do not knowingly collect data from children.
Policy Updates
We may update this policy occasionally. Revised versions will be dated and posted here; significant changes may also be communicated directly.
