Medical and Website Privacy Policies combined

Thames Valley Surgical Services is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal data — both when you visit our websites and when you contact or receive treatment from us.

1. Who We Are

This policy applies to the following websites operated by Thames Valley Surgical Services:

We are a private healthcare provider offering minor surgical treatments. For data protection purposes, we act as the data controller under the UK General Data Protection Regulation (UK GDPR).

2. What Personal Data We Collect

a) Website Visitors

  • IP address and browser type
  • Pages visited and time spent on site
  • Data from cookies and analytics tools (e.g. Google Analytics)
  • Media files you upload via enquiry forms (e.g. images)

b) Contact Form Users and Enquirers

  • Name, email address, phone number
  • Any medical information you voluntarily include in your enquiry

Note: We do not routinely collect medical information via our websites. Any such data is provided voluntarily by the user and handled confidentially.

c) Patients Receiving Medical Treatment

  • Contact details
  • Medical history and clinical correspondence
  • Appointment and treatment records

3. How We Use Your Data

Purpose Data Used Legal Basis
Respond to enquiries Name, contact info, enquiry content Consent
Book/manage appointments Contact and medical data Contract
Provide healthcare services Medical records Legal obligation
Maintain clinical records Treatment and consultation notes Legal obligation
Website analytics IP address, device info, cookies Legitimate interest

4. Cookies and Analytics

We use cookies and Google Analytics to understand how users interact with our websites. This includes:

  • Traffic and visitor patterns
  • Device and browser type
  • Page views and time spent on site

You can manage your cookie preferences via your browser or our website’s cookie banner.

➡️ Please see our full Cookie Policy for detailed information.

5. Embedded Content and Third-Party Services

Our websites may include embedded content (e.g. videos, maps, or images). These third-party services (such as YouTube or Google Maps) may:

  • Collect your data
  • Use cookies
  • Monitor your interaction with the content
  • Track you if you are logged in to their service

We also use:

  • Spam protection for form submissions
  • Secure communication and booking platforms

6. Data Sharing

We do not sell your data. We may share your data with trusted third parties solely to deliver our services, including:

  • Clinical staff providing your care
  • Diagnostic labs or medical partners
  • Booking and communication software providers

All partners and processors meet UK GDPR standards.

7. Data Retention

Type of Data Retention Period
Medical records Retained in line with UK healthcare regulations
Enquiry/contact form data Deleted when no longer needed for its original purpose
Analytics data Retained in anonymised form for statistical purposes

8. Your Rights

You have the right to:

  • Access any personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of data where appropriate
  • Withdraw consent where processing is based on consent
  • Object to processing based on legitimate interest
  • Lodge a complaint with the Information Commissioner’s Office (ICO)

9. Contact Us

If you have any questions or would like to exercise your rights, please contact:

Email: office@tvvs.uk