Privacy Policy

Clerimis Limited

Clerimis Limited is committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect your personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Data Controller

Clerimis Limited is the Data Controller for the purposes of UK GDPR.

Clerimis Limited
39 The Green
Brafferton
Darlington
DL1 3LA

Email: clarewalton70@icloud.com
Phone: 07807 746346

2. What Personal Data We Collect

We may collect and process the following categories of personal data:

Personal Identification Information

  • Name

  • Address

  • Email address

  • Telephone number

  • Date of birth

Health and Medical Information (Special Category Data)

  • Medical history

  • Medication history

  • Treatment notes

  • Consultation records

  • Clinical photography (where consent is provided)

  • Treatment outcomes

Communication Data

  • Enquiries submitted via contact forms

  • Email correspondence

  • Telephone call notes

  • Appointment records

Technical Data

  • IP address

  • Browser type

  • Device information

  • Website usage data via cookies

Marketing Preferences

  • Records of consent to receive marketing communications

3. How We Collect Your Data

We collect data when you:

  • Complete contact or enquiry forms on our website

  • Attend a consultation or treatment

  • Complete medical or consent forms

  • Subscribe to our newsletter

  • Communicate with us via phone or email

  • Use our website (via cookies and analytics tools)

4. Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

Article 6 – Lawful Basis

We process personal data where:

  • It is necessary for the performance of a contract (providing consultation or treatment).

  • It is necessary to comply with a legal obligation.

  • It is necessary for our legitimate interests (such as clinic administration and service improvement), provided your rights do not override those interests.

  • You have provided consent (for marketing communications).

Article 9 – Special Category Data (Health Information)

We process health data under:

  • Article 9(2)(h): Processing necessary for the provision of health care or treatment.

  • Article 9(2)(a): Explicit consent, where required.

5. How We Use Your Data

We use your data to:

  • Provide medical consultations and treatments

  • Maintain accurate clinical records

  • Communicate regarding appointments and aftercare

  • Respond to enquiries

  • Manage complaints or incidents

  • Improve our services

  • Send marketing communications where you have opted in

We do not sell your personal data.

Health information is never used for marketing purposes.

6. Data Sharing

We may share your data with:

  • Clinicians and authorised staff involved in your care

  • IT service providers and website hosting providers

  • Booking and communication system providers

  • Payment processors

  • Professional advisers (e.g., insurers or legal advisers)

  • Regulatory or law enforcement authorities where required by law

All third parties processing data on our behalf are required to comply with data protection legislation and only process data in accordance with our instructions.

7. Data Retention

We retain personal data only for as long as necessary.

Clinical records are retained for a minimum of 8 years from the date of your last treatment, in line with professional guidance.

Enquiry data that does not result in treatment is retained for up to 12 months.

Marketing data is retained until consent is withdrawn.

Data may be retained longer where required by law or regulatory obligations.

8. Data Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction.

Access to clinical records is restricted to authorised personnel only.

9. Your Data Protection Rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request erasure of your data (subject to legal obligations)

  • Request restriction of processing

  • Object to processing

  • Request data portability

Subject Access Requests are free of charge. We will respond within one month of receiving your request.

To exercise your rights, please contact us using the details above.

10. Marketing

We will only send marketing communications where you have provided consent.

You may withdraw consent at any time by:

  • Clicking the unsubscribe link in emails

  • Contacting us directly

Withdrawing consent does not affect the lawfulness of processing carried out prior to withdrawal.

11. Cookies

Our website uses cookies to improve user experience and analyse website performance.

Cookies may collect technical and usage data such as IP address, browser type, and pages visited.

You can control cookies through your browser settings.

For further information about cookies, visit www.allaboutcookies.org.

12. Changes to This Policy

We keep this Privacy Policy under regular review and may update it from time to time.

Last updated: 16 February 2026

13. Complaints

If you have concerns about how we handle your data, please contact us in the first instance.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

Information Commissioner’s Office
www.ico.org.uk