Privacy Policy

How we collect, use and protect your personal and health data

Last updated: 9 June 2026

1. Data Controller

Dr Antonio Creta Cardiology ("we", "us", "our") is the data controller for personal data collected through this website and during the provision of clinical services. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the common law duty of confidentiality that applies to all clinical information.

You can contact our data controller at pa@drcretacardiology.com.

2. Personal Data We Collect

We collect only the data needed to respond to your enquiry and to provide safe clinical care. This may include:
Identity & contact data — name, date of birth, postal address, email address and telephone number.
Clinical data — symptoms, medical history, medications, investigations, imaging, ECGs and clinical correspondence.
Insurance & billing data — insurer name, policy / membership number, billing address.
Technical data — IP address, browser type, device information, pages visited and approximate location, collected via cookies and similar technologies (see our Cookie Policy).
Correspondence — any messages, emails or form submissions you send to us.

3. How We Use Your Data

We use your personal data to:
respond to enquiries and arrange consultations;
provide clinical assessment, diagnosis, investigations and treatment;
communicate with your GP, referring clinicians and other healthcare providers where clinically necessary;
process payments and liaise with your private medical insurer;
maintain accurate medical records as required by professional regulators;
comply with legal, regulatory and clinical governance obligations;
improve our website and services (using anonymised analytics where you have consented).

4. Legal Basis for Processing

Under UK GDPR we rely on the following lawful bases:
Consent (Art. 6(1)(a)) — for non-essential cookies and marketing communications.
Contract (Art. 6(1)(b)) — to provide the clinical services you have requested.
Legal obligation (Art. 6(1)(c)) — to comply with regulatory record-keeping and tax requirements.
Vital interests (Art. 6(1)(d)) — in a medical emergency where you cannot consent.
Legitimate interests (Art. 6(1)(f)) — to administer the practice, secure our website and prevent fraud, where these interests are not overridden by your rights.

5. Special Category (Health) Data

Health data is "special category" personal data and receives additional protection. We process it under:

  • Article 9(2)(h) UK GDPR — provision of health care and treatment by, or under the responsibility of, a healthcare professional bound by the duty of confidentiality;
  • Article 9(2)(a) UK GDPR — your explicit consent, where required.

6. Who We Share Data With

We share data only where necessary and with appropriate safeguards. Recipients may include:
your GP and other clinicians involved in your care;
NHS and private hospitals where investigations or procedures are performed (e.g. Barts Heart Centre, UCLH, Welbeck, BUPA Canary Wharf, Cromwell Hospital);
diagnostic providers (laboratories, imaging services, device-monitoring services);
your private medical insurer, where you have authorised billing through them;
our secretarial, IT, billing and clinical-records providers, acting as data processors under written contracts;
regulators, professional bodies and courts where required by law.
We do not sell your personal data and we do not share it for advertising purposes.

7. International Transfers

Where personal data is transferred outside the UK (for example to cloud service providers), we ensure appropriate safeguards are in place, such as adequacy decisions, the UK International Data Transfer Agreement or Standard Contractual Clauses with additional measures.

8. How Long We Keep Data

We retain personal data only for as long as necessary:
  • Medical records — retained in line with NHS / Department of Health guidance, typically a minimum of 8 years after the last episode of care for adults, and until age 25 (or 26 if the last entry was at age 17) for children.
  • Billing & financial records — 6 years (HMRC requirement).
  • Enquiry correspondence — up to 24 months unless it becomes part of a clinical record.
  • Website analytics — up to 14 months in aggregated, pseudonymised form.

9. Data Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, secure UK / EEA-hosted clinical record systems, staff confidentiality training and a documented breach-response process. In the unlikely event of a personal data breach likely to result in risk to your rights, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform you where required.

10. Your Rights

Under UK GDPR you have the right to:
be informed about how your data is used;
access a copy of your data (Subject Access Request);
request rectification of inaccurate or incomplete data;
request erasure, where one of the legal grounds applies (note: clinical record-keeping obligations usually override this for medical data);
restrict or object to processing;
data portability for data you have provided to us;
withdraw consent at any time where we rely on consent;
not be subject to solely automated decisions with legal or similarly significant effects (we do not carry out such processing).

To exercise any of these rights, email pa@drcretacardiology.com. We will respond within one month.

11. Children's Data

This website is not directed to children under 13 and we do not knowingly collect personal data from them through the site. Where Dr Creta treats young patients, data is processed under parental responsibility in line with the duty of confidentiality.

12. Changes to This Policy

We may update this policy from time to time to reflect changes to our services or the law. The "last updated" date at the top of this page shows the most recent revision. Material changes will be highlighted on the website.

13. Contact & Complaints

For privacy questions or to exercise your rights, contact pa@drcretacardiology.com.

You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO): ico.org.uk · 0303 123 1113.