Marylebone Health Group Limited
Last Updated: August 2026
1. Who We Are & Overview
Marylebone Health Group Limited (“MHG”, “we”, “us”, or “our”) is committed to protecting the privacy, security, and confidentiality of the personal and health data shared with us.
This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you visit our website (www.marylebonehealthgroup.com), book appointments, receive clinical care, or interact with us via telephone, email, or in person.
Data Controller Details
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Marylebone Health Group Limited is the Data Controller for the personal data and clinical health data we collect about you.
- Company Name: Marylebone Health Group Limited
- Company Registration Number: 12872028 (Registered in England & Wales)
- Registered Office: 3rd Floor, Great Titchfield House, 14-18 Great Titchfield Street, London, W1W 8BD
- Clinical Facility: 76 Harley Street, London, W1G 7HH
- Email:info@marylebonehealthgroup.com
- Telephone: +44 (0)207 637 7677
2. Information We Collect
We collect personal data necessary to provide safe and effective healthcare services, manage online bookings, operate our clinic, and communicate with you.
A. General Personal Information
- Contact & Identity Details: Full name, title, date of birth, gender, home address, email address, telephone number, and emergency contact details.
- Financial & Billing Data: Payment card details, billing address, private medical insurance details (insurer name, policy number, authorization codes).
B. Special Category Data (Health & Medical Records)
As a healthcare provider, we collect and process “Special Category Data” protected under UK GDPR, including:
- Medical history, diagnostic reports, physician referrals, and clinical correspondence.
- Clinical notes, assessment details, rehabilitation plans, and treatment logs written by our clinicians.
- Images, scans, and diagnostic data (e.g., MRI, X-ray, ultrasound reports) uploaded or provided to us.
C. Technical & Usage Information
- Device & Online Identifiers: IP address, browser type, operating system, and domain information collected when you access our website.
- Website Interactions: Pages visited, form submissions, and analytics data collected via cookies.
3. How We Collect Your Data
We collect personal data through direct interactions, clinical consultations, and automated software tools:
- Direct Interactions: When you fill out new patient intake forms, schedule an appointment online or via telephone, subscribe to our newsletter, or speak to our clinical and administrative staff.
- Practice Management Systems (Splose): Online bookings, medical questionnaire submissions, appointment confirmations, and clinical notes entered into our practice management system.
- Third-Party Health Professionals: Medical reports, imaging, or referral letters sent directly to us by your GP, consultant, specialist, or private healthcare provider with your consent.
- Website & Digital Platforms: Automated cookie collection and web form entries when navigating our website.
4. Lawful Basis for Processing Your Personal Data
We only process your personal data when permitted by UK law.
| Data Category | Purpose of Processing | UK GDPR Lawful Basis |
| Personal Data (Identity, Contact, Billing) | Booking appointments, sending appointment reminders, processing payments, handling enquiries, fulfilling contracts. | Article 6(1)(b): Necessary for the performance of a contract or steps prior to entering a contract. Article 6(1)(f): Legitimate interests (efficient administration of our practice). |
| Special Category Data (Medical & Clinical Records) | Providing physiotherapy, medical diagnosis, clinical treatment, exercise rehabilitation, and healthcare management. | Article 9(2)(h): Necessary for health or social care purposes, medical diagnosis, and the provision of healthcare or treatment under professional duty of confidentiality. |
| Marketing Communications | Sending practice updates, educational newsletters, and promotional offers. | Article 6(1)(a): Consent (you may opt out at any time). |
| Legal & Regulatory Compliance | Maintaining statutory financial records, responding to legal claims, or regulatory compliance. | Article 6(1)(c): Compliance with a legal obligation. |
5. How We Store & Process Data: Our Technology Stack
We partner with third-party service providers who process data on our behalf to help run our healthcare practice. All third-party providers are bound by strict contractual obligations to maintain the confidentiality and security of your data in compliance with UK GDPR.
Practice Management & Electronic Health Records: Splose
We use Splose, a cloud-based practice management and CRM provider, to host our electronic health records (EHR), manage appointment bookings, process clinical forms, issue automated SMS/email appointment notifications, and generate invoices.
- Data Role: Splose acts as a Data Processor on behalf of Marylebone Health Group Limited.
- Security Standards: Splose employs industry-standard encryption protocols for data at rest and in transit, ISO-certified data center infrastructure, and restricted role-based access control.
Operational Service Providers
- Email & Communication Systems: We use ISO-certified cloud email platforms and transport encryption (TLS) to safeguard email communications.
- Email Marketing (Mailchimp): For patients who explicitly opt-in to marketing, we use Mailchimp to send newsletters. You can opt out at any time via the “Unsubscribe” link in any promotional email.
- Payment Processors: Payments processed online or in-clinic use PCI-DSS compliant payment gateways. We do not store full payment card numbers on our local servers.
6. Sharing Your Information
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We only share personal and medical data in the following circumstances:
- Healthcare Professionals & Referrers: With your consent, we share relevant medical reports or updates with your GP, referring medical consultants, surgeons, or allied health professionals involved in your care.
- Third-Party Service Providers: Trusted software vendors, cloud hosting providers, IT support, and administrative contractors bound by signed Data Processing Agreements.
- Partner Locations: If you attend an appointment at a partner facility, limited personal identifiers (e.g., name and booking time) are shared to allow site access. Clinical medical records remain restricted to MHG personnel.
- Private Medical Insurers: If your treatment is funded through private medical insurance, we share attendance dates, treatment codes, and diagnostic updates required by your insurer to process claims.
- Legal & Regulatory Obligations: If required by law, court order, regulatory bodies (e.g., Care Quality Commission, General Medical Council, Health and Care Professions Council), or to defend our legal rights.
7. Data Retention & Clinical Record Requirements
We retain personal and health data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, clinical, and regulatory requirements.
- Adult Clinical Records: Retained for a minimum of 8 years following the date of last treatment, in accordance with UK healthcare record retention standards and professional body guidelines (e.g., CSP, GMC).
- Children and Young Adults’ Clinical Records: Retained until the patient’s 25th birthday (or 26th birthday if the patient was 17 at the conclusion of treatment), or 8 years after the patient’s death if applicable.
- Financial & Transaction Records: Retained for 6 years plus the current financial year to comply with UK tax law (HMRC).
- Marketing Data: Retained until you withdraw consent or request erasure.
8. International Data Transfers
Your personal data is predominantly stored within the United Kingdom or the European Economic Area (EEA).
If any third-party processor transfers personal data outside the UK/EEA, we ensure appropriate legal safeguards are in place, such as:
- Transfers to countries recognized by the UK Government as providing an adequate level of data protection.
- Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) governing the transfer.
9. Your Legal Rights
Under UK data protection law, you have specific rights regarding your personal information:
- Right of Access (Subject Access Request): You have the right to request a copy of the personal and medical data we hold about you.
- Right to Rectification: You can request that incomplete or inaccurate information we hold about you be corrected.
- Right to Erasure (“Right to be Forgotten”): You can ask us to delete your personal data. Please note: This right is not absolute and does not apply to clinical healthcare records that we are legally mandated to retain under medical governance and regulatory standards.
- Right to Restrict Processing: You may request that we suspend processing your personal data under certain conditions.
- Right to Data Portability: You can request a machine-readable copy of the personal data you provided directly to us.
- Right to Object: You can object to data processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent (e.g., marketing), you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us in writing at info@marylebonehealthgroup.com
. We will respond to valid requests within one calendar month.
10. Cookies & Analytical Tools
Our website uses cookies and similar tracking technologies to ensure core website functionality, enhance user experience, and analyze site traffic.
- Essential Cookies: Necessary for the operation of our website, security, and online booking workflows.
- Analytics Cookies (Google Analytics): Collect aggregated, anonymous information about how visitors interact with our site to help us improve site navigation and functionality.
- Managing Cookies: You can set your browser to refuse all or some browser cookies or to alert you when websites set or access cookies. Disabling cookies may affect website functionality.
11. Security Safeguards
We maintain technical, physical, and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These measures include:
- Full data encryption in transit and at rest across clinical applications (including Splose).
- Strict internal access controls limiting data visibility only to staff members with a clinical or administrative need-to-know basis.
- ISO-certified server environments and routine system maintenance.
While we take all reasonable precautions, no transmission over the internet or electronic storage system can be guaranteed as 100% secure. If you suspect your data has been compromised, please contact us immediately.
12. Children’s Privacy
We provide healthcare services to children and young adults. When processing personal and clinical data relating to individuals under 16 years of age, we require verifiable consent from a parent, statutory guardian, or authorized legal representative, unless the child is assessed as Gillick competent under UK law to consent to their own medical treatment.
13. Third-Party Links
Our website may contain links to external third-party websites, plug-ins, or applications. Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.
14. Changes to This Privacy Policy
We review and update this Privacy Policy periodically to reflect changes in legal requirements, operational practices, or software tools. Any updates will be posted on this page with an updated “Last Updated” date.
15. How to Contact Us & Lodge a Complaint
If you have questions about this Privacy Policy, wish to exercise your legal rights, or have concerns about how we handle your personal data, please contact our Data Lead:
- Email: info@marylebonehealthgroup.com
- Phone: +44 (0)207 637 7677
- In Person / By Post:
Data Protection Lead
Marylebone Health Group
76 Harley Street, London, W1G 7HH
Supervisory Authority (ICO)
You have the right to make a complaint at any time to the UK’s independent regulator for data privacy:
Information Commissioner’s Office (ICO)
- Website:www.ico.org.uk
- Helpline: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to resolve your concerns directly before you approach the ICO, so please reach out to us first.
Copyright Notice
All text, graphics, clinical information, design elements, and underlying code on this website and within our digital assets are the copyrighted property of Marylebone Health Group Limited © 2026. All rights reserved. Unauthorised reproduction, distribution, or duplication of any material without express written consent is strictly prohibited.
