How we look after your information
A plain-English summary of what data is collected through this website, why, how long it is kept, and the rights you have under UK GDPR and the Data Protection Act 2018.
A plain-English summary of what data is collected through this website, why, how long it is kept, and the rights you have under UK GDPR and the Data Protection Act 2018.
This privacy notice explains how OS Clinic Ltd (the website “operator”) handles personal information collected through this website and how enquiries submitted through it are processed. The site supports the practice of Professor Nima Heidari, who treats patients at OS Clinic, The London Clinic and Cromwell Hospital. It is written to be read alongside, not in place of, the privacy notices published by each of those hospitals.
OS Clinic Ltd is the website operator and the data controller for the personal data submitted via this site (enquiries, booking requests, GP referrals).
Registered address: 45 Queen Anne Street, London W1G 9JF.
Professor Nima Heidari (Consultant Orthopaedic Surgeon, GMC-registered specialist in Trauma & Orthopaedic Surgery) is a treating clinician who works at OS Clinic and also holds practising privileges at The London Clinic and Cromwell Hospital. Each hospital where Professor Heidari sees patients is a separate data controller for the clinical records held at that hospital:
Once you become a patient, your medical record is held and controlled by the hospital where you are seen. Each hospital is a separate data controller for its own records and operates under its own privacy notice. Professor Heidari accesses those records as part of providing clinical care under each hospital’s practising-privileges arrangements.
If you would like to contact OS Clinic about this privacy notice, use the secure form at /contact or write to OS Clinic, 45 Queen Anne Street, London W1G 9JF. OS Clinic does not currently have a designated Data Protection Officer; under UK GDPR, no DPO is required for an organisation of this size and processing profile.
If your message includes information about your health, that is “special-category” data under Article 9 of the UK GDPR and is treated with additional care. We ask that you keep clinical detail in website messages to a minimum and share full clinical information only after a secure clinical channel has been established.
| Purpose | Lawful basis (Art 6) | Special category basis (Art 9, where relevant) |
|---|---|---|
| Responding to enquiries sent through the contact / booking form | Art 6(1)(b) — steps prior to entering a contract for treatment, and Art 6(1)(f) legitimate interests in operating the practice | Art 9(2)(h) — provision of healthcare, where the message includes health data |
| Providing clinical care once you become a patient | Art 6(1)(b) contract for care; Art 6(1)(c) legal obligations (medical records, regulatory) | Art 9(2)(h) provision of healthcare and treatment by a regulated health professional |
| Keeping the website secure (server logs, abuse prevention) | Art 6(1)(f) legitimate interests in protecting the site from misuse | n/a |
| Essential cookies and the “you’ve seen the banner” flag | Strictly necessary — PECR Reg 6(4); no consent required for cookies essential to the service you have requested | n/a |
| Marketing communications (e.g. occasional updates) | Art 6(1)(a) consent — only if you have explicitly opted in; you may withdraw consent at any time | n/a |
Where processing relies on consent, you may withdraw it at any time by contacting the practice. Withdrawal does not affect processing carried out before the withdrawal.
The practice shares the minimum information necessary to deliver care and run the practice. Recipients may include:
The practice does not sell personal information and does not share it for advertising or marketing purposes.
Some of the IT services that support this website are provided by suppliers based outside the UK. In particular, the website is hosted on infrastructure operated by Netlify, Inc. (United States), and email may pass through providers based outside the UK and EEA. Where personal data is transferred outside the UK, we rely on the UK Government’s adequacy regulations (where they apply) or on the UK International Data Transfer Agreement / EU Standard Contractual Clauses with the UK Addendum, together with appropriate supplementary measures.
Clinical records held by the hospitals named above are governed by each hospital’s own privacy notice and arrangements for international transfer.
Under UK GDPR you have the following rights in relation to the personal information that the practice controls:
To exercise any of these rights, please contact the practice via the secure message form. We will respond within one calendar month, and may ask for proof of identity before releasing information. Subject-access requests are normally free of charge.
If you are unhappy with how the practice has handled your personal information, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office:
The practice takes appropriate technical and organisational measures to protect personal information from loss, misuse, unauthorised access, disclosure, alteration, and destruction. No method of transmission over the internet is completely secure, however, and you should avoid sending highly sensitive information through unencrypted channels.
We may update this notice from time to time to reflect changes in our practice or in the law. The “last updated” date below shows when the current version took effect. Material changes will be highlighted at the top of this page for a reasonable period.