Privacy Policy
Effective date: 7 September 2026 Last reviewed: 7 September 2026 Version: 2.0
Your health data is the most sensitive information you'll ever hand over. We treat it that way.
This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and what control you have. It applies to our website, our booking system, and every service we deliver in clinic.
We comply with the UK GDPR, the Data Protection Act 2018, and the common law duty of confidentiality that applies to all healthcare providers.
1. Who we are
Revive Medical is a doctor-led clinic providing IV therapy, diagnostics, blood testing, hormone health, vaccinations, and medical aesthetics.
Registered company: Revive Medical Performance Ltd, registered in England and Wales, company number 16488236
Trading as: Revive Medical
Clinic address: UFit Gym, Unit 1B, Trident Industrial Estate, Glass Avenue, Cardiff, CF24 5EN
Website: www.revivemed.uk
Email: info@revivemed.uk
WhatsApp: wa.me/447356169160
Medical Director: Dr Louise O'Gorman, GMC 7404743
Regulatory status: CQC & HIW registration in application
We are the data controller for the personal data described in this policy. That means we decide what data is collected and how it is used, and we are accountable for it. Our data protection lead is Angeline Sharp, Managing Director, contactable at info@revivemed.uk.
2. What we collect
Identity and contact data. Name, date of birth, address, email, phone number, emergency contact, and GP details where you choose to share them.
Health data (special category data). Medical history, current medications and allergies, symptoms and goals, consultation notes, prescribing decisions, treatment and infusion records, blood test requests and laboratory results, observations such as blood pressure and weight, consent forms, and clinical photography where relevant to your treatment.
Booking and transaction data. Appointments, treatments purchased, membership status, payment records, invoices, and refunds.
Marketing data. Your marketing preferences, and — only where you have signed a separate marketing consent form — testimonials, case study content, or images used in our materials.
Technical data. IP address, browser and device type, pages visited, and cookie data when you use our website.
We do not store your full card number. Payments are handled by our payment provider on their own secure systems.
3. How we collect it
Directly from you — enquiry forms, online booking, consultations, consent forms, and in-clinic paperwork.
Generated by us — clinical notes, prescriptions, and treatment records created during your care.
From our laboratory — blood test results returned to us by our diagnostics partner.
Automatically — cookies and analytics when you browse our website.
4. Why we use it, and our legal basis
Health data requires a lawful basis under both Article 6 and Article 9 of the UK GDPR. Ours are set out below.
Delivering your consultation, treatment, and diagnostics — Contract, and Article 9(2)(h), provision of healthcare by or under the responsibility of a health professional.
Maintaining your clinical record — Legal obligation and legitimate interests, and Article 9(2)(h).
Requesting and interpreting laboratory tests — Contract, and Article 9(2)(h).
Managing safety, incidents, and clinical governance — Legal obligation, and Articles 9(2)(h) and 9(2)(i).
Taking payment and keeping financial records — Contract and legal obligation.
Appointment reminders and aftercare instructions — Legitimate interests, and Article 9(2)(h).
Responding to regulators, insurers, or legal requests — Legal obligation, and Article 9(2)(f).
Marketing emails, texts, and social content — Consent, and explicit consent under Article 9(2)(a) where the content is health-related.
Website analytics and improvement — Consent for cookies, and legitimate interests.
We do not rely on consent to hold your clinical record. Your record is created and retained under our professional and legal obligations as a healthcare provider. Withdrawing consent to treatment stops future care — it does not delete the record of care already given, which we are required to keep.
Marketing is different. We only send marketing if you have opted in, and you can withdraw at any time using the unsubscribe link or by emailing info@revivemed.uk. We will never use your photographs, results, or story in marketing without a separate, specific, written marketing consent. That consent is entirely optional and has no effect on your care.
5. Who we share it with
We do not sell your data. We never share it for third-party advertising.
We share the minimum necessary with:
Our clinical software provider — Semble, which hosts our practice management system, clinical records, booking, and consent forms.
Our diagnostics partner — Eurofins Clinical Diagnostics, which processes your blood samples and returns results to us.
Our compounding pharmacy and suppliers — where a prescribed treatment must be dispensed for you specifically.
Our website and payment providers — Squarespace for website hosting, and our card payment provider.
Your GP or another clinician — only with your agreement, or where a clinically significant result means we have a professional duty to act.
Regulators and authorities — the CQC, HIW, GMC, MHRA, courts, or law enforcement, where we are legally required to disclose.
Our insurers and professional advisers — where necessary to handle a claim or legal matter.
All processors act under written contracts that require them to protect your data, use it only on our instructions, and delete or return it when the contract ends.
6. International transfers
Your data is primarily stored in the UK. Where a provider processes data outside the UK, we ensure an approved safeguard is in place — a UK adequacy decision, or the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses.
7. How long we keep it
We keep clinical records in line with the NHS Records Management Code of Practice, which is the accepted standard for private healthcare providers. Clinical records are held in Semble, our secure clinical record system.
Adult clinical records — 8 years from the date of last treatment
Records for under-18s — until the patient's 25th birthday, or 26th if treated at 17
Records where the patient has died — 8 years from date of death
Clinical photography and consent forms — held with the clinical record and retained on the same basis
Financial and tax records — 6 years plus the current financial year
Marketing consents and preferences — until withdrawn; suppression records kept indefinitely so we don't contact you again in error
Website analytics — 26 months
CCTV, where operated — 30 days, unless required for an incident
At the end of the applicable period we review the record and securely destroy it, unless there is a lawful reason to keep it for longer — for example an ongoing complaint, claim, or regulatory investigation.
8. Your rights
You have the right to:
Access the personal data we hold about you
Correct anything inaccurate
Erase data, where no legal or clinical retention duty applies
Restrict or object to processing in certain circumstances
Receive your data in a portable format
Withdraw consent at any time, where consent is our basis
Not be subject to decisions made solely by automated means — we don't make any
To exercise any of these, email info@revivemed.uk. We may ask you to verify your identity. We will respond within one calendar month, and will tell you if we need to extend that for a complex request. There is no charge for a routine request.
Requests for your clinical record are handled under the UK GDPR and, where relevant, the Access to Health Records Act 1990. Some information may be withheld where releasing it could cause serious harm, or would identify a third party who has not consented.
9. Keeping your data secure
We use encrypted, access-controlled clinical systems, individual staff logins, role-based access, and audit trails. Consent forms are locked once completed so they cannot be altered retrospectively. All staff are bound by confidentiality obligations and receive data protection training.
If a breach occurs that is likely to risk your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours and notify you directly where the risk is high.
10. Cookies
Our website uses cookies for essential functionality, analytics, and — where you consent — marketing. You can manage your preferences through the cookie banner or your browser settings. Blocking some cookies may affect how parts of the site work.
11. Children
Our services are for adults aged 18 and over. Where we treat a young person under 18, we do so only with appropriate consent and safeguarding processes in place, and we handle their data with the additional protections the law requires.
12. Changes to this policy
We review this policy at least annually and update it when our services, systems, or legal obligations change. The current version and effective date are always shown at the top of this page. Material changes will be notified by email where we hold your contact details.
13. Questions and complaints
Talk to us first — email info@revivemed.uk and we'll deal with it directly.
If you're not satisfied, you can complain to the UK's data protection regulator:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Helpline: 0303 123 1113 ico.org.uk
Complaints about clinical care are handled separately under our Complaints Policy. Contact info@revivemed.uk and it will be reviewed by our Medical Director.

