Last updated: 30.12.2025
The GP Clinic Ltd (“we”, “us”, “our”) is an online GP service providing medical consultations, advice, and related healthcare services via secure digital platforms.
To provide our services, we need to collect and process personal data. This Privacy Policy explains how we use personal data, how we protect it, and your rights under UK data protection law.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, The GP Clinic Ltd is the Data Controller. This means we decide how and why your personal data is processed.
We have appointed a Data Protection Officer to oversee compliance with data protection law.
Data Protection Officer:
Dr Mohammed Sulaiman Shah
The GP Clinic Ltd
124 City Road
London EC1V 2NX
United Kingdom
If you believe there has been a data breach or you have concerns about how your personal data is handled, you may contact the DPO using the details above.
Personal data collected by The GP Clinic Ltd is processed electronically. Appropriate technical and organisational measures are in place to ensure security, confidentiality, and compliance with applicable legislation.
We may process your personal data:
We primarily collect personal data directly from you when you:
We may also receive limited personal data from third parties where necessary to provide healthcare services (e.g. laboratories, pharmacies, or referral partners).
Under UK GDPR, we must have a lawful basis to process your personal data.
| Purpose of Processing | Legal Basis |
|---|---|
| Verifying patient identity | Legal and regulatory obligation |
| Providing medical consultations and services | Performance of a contract |
| Processing health and medical data | Provision of health or social care and/or explicit consent |
| Retaining medical records | Legitimate interests and legal obligations |
| Marketing communications | Consent |
| Audit and regulatory compliance | Legal obligation |
To provide medical care, we may need to process special category personal data, including health information.
We process such data only where:
We may share personal data with trusted third parties where necessary to provide our services, including:
All third parties are required to implement appropriate security measures and process personal data only in accordance with our instructions and contractual obligations.
We are bound by professional duties of medical confidentiality and will not share your personal data without justification unless required by law.
In most cases, your personal data will be processed within the UK.
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
If no safeguards are available, data will only be transferred where legally permitted or with your explicit consent.
We take data security seriously and implement appropriate technical and organisational measures to protect personal data against:
Measures include secure systems, access controls, encryption, and staff training.
We retain personal data only for as long as necessary.
Where we rely on consent (e.g. for marketing), you may withdraw your consent at any time.
Withdrawing consent will not affect your access to medical services.
Under UK GDPR, you have the right to:
To exercise your rights, contact:
Data Protection Officer
The GP Clinic Ltd
124 City Road
London EC1V 2NX
We may need to verify your identity before responding.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner’s Office (ICO).
We may update this Privacy Policy from time to time to reflect legal, regulatory, or operational changes. Any updates will be published on our website.