Healthcare and Lifestyle Medicine Clinic
Privacy Policy
Last updated: 26 August 2026
Who we are
Medical Wellness is a private medical clinic providing doctor-led weight management, testosterone replacement therapy and private blood testing at our clinics in Yarm and Harrogate, and by remote consultation.
For the purposes of UK data protection law, the data controller is Medical Weight Care Ltd, a company registered in England and Wales under company number 14337133, whose registered office is Suite 4.07, Windsor House, Cornwall Road, Harrogate HG1 2PW.
Medical Weight Care Ltd trades as both Medical Weight Care and Medical Wellness. This policy covers your information however you came to us — through either name, either website, or either clinic.
We are registered with the Information Commissioner's Office under registration number ZB512577, and with the Care Quality Commission under provider ID 1-15197627604.
Your care is provided by Dr Vas Kavadas, registered with the General Medical Council under number 4298348. This is a single-doctor practice: the doctor who sees you is the doctor who holds your record.
Who is responsible for your information
Dr Vas Kavadas is the person responsible for data protection at this practice. Any question, request or concern about your information comes to her. We have not appointed a statutory Data Protection Officer; a practice of this size is not required to, and we would rather tell you who is actually accountable than name a role that does not exist here.
How to contact us about your data
Email: info@medwellness.co.uk
Post: Medical Wellness, First Floor (above Oxfam), 75a High Street, Yarm, TS15 9BG
Phone: 07860 936668, Monday to Friday 9am to 6pm
What this policy covers
This policy explains what personal information we collect about you, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers information we collect when you visit this website, enquire about our services, book or attend an appointment, or receive treatment or testing from us.
The information we collect
When you enquire or book
-
Your name, date of birth, email address, telephone number and postal address
-
How you found us, and what you are asking about
-
Anything you choose to include in an enquiry form, email or WhatsApp message
When you become a patient
Some of this is special category data — information about your health. The law treats it as deserving extra protection, and so do we.
-
Your medical history, current and past conditions, and relevant family history
-
Current and previous medication, allergies and adverse reactions
-
Height, weight, BMI, waist measurement, blood pressure and other clinical measurements
-
Lifestyle information relevant to your care — diet, activity, alcohol, smoking, sleep
-
Blood test results and other investigation results
-
Notes made by the doctor during your consultations
-
Details of treatment, prescriptions issued and medication dispensed to you
-
Correspondence with you, and with your GP or other clinicians where you have agreed to it
About payments
-
The amount, date and method of payment, and what it was for
-
We do not store your full card details. Payments taken through our online booking system are processed by Stripe, which Semble uses as its payment provider. Stripe handles your card data under its own privacy notice; we never see or hold the full card number.
-
Invoices are raised and our financial records kept in Xero, our accounting software. Xero holds your name, contact details, the amount and date of the invoice and a description of what it was for. Where that description identifies the treatment, medication or test you paid for, it tells Xero something about your health, so we keep those descriptions to the minimum needed for tax and accounting purposes. Your medical record itself is held in Semble, not in Xero.
Automatically, when you use this website
This website is built and hosted on Wix. Wix sets cookies and collects technical information including your IP address, device and browser type, the pages you view and how you arrived. See Cookies and this website below.
Why we are allowed to use your information
UK data protection law requires a lawful basis for using your personal data, and a separate, additional basis for using health data. Ours are:
-
Answering your enquiry — legitimate interests, responding to someone who has contacted us. No additional health-data basis is usually needed.
-
Arranging and holding your appointment — performance of our contract with you, and Article 9(2)(h), provision of health care.
-
Providing your care, prescribing, dispensing and monitoring — performance of our contract with you, and Article 9(2)(h), provision of health care and treatment.
-
Keeping accurate medical records — legal obligation, and our legitimate interest in safe care, and Article 9(2)(h).
-
Taking payment and keeping financial records — performance of our contract with you, and legal obligation for tax. Where an invoice description identifies the care you received, Article 9(2)(h), management of health care services, also applies.
-
Meeting our regulatory duties to the CQC and GMC — legal obligation, and Article 9(2)(h), and Article 9(2)(i) where public health applies.
-
Responding to a complaint or a claim — legitimate interests, and establishing or defending legal claims, and Article 9(2)(f).
-
Using an AI tool to draft your consultation notes — your consent, asked for at each consultation, under Article 9(2)(a), explicit consent, alongside Article 9(2)(h) for the underlying care.
-
Sending you marketing about our services — your consent. No health-data basis applies.
Where we rely on your consent — for marketing, for sharing information with your GP, and for using the AI note-taking tool — you can withdraw it at any time and we will stop. Withdrawing consent does not affect anything we did lawfully beforehand, and it does not affect our ability to keep your medical records, which we are separately required to retain.
We will never sell your personal data, and we do not use it for automated decision-making or profiling.
Who we share your information with
We share your information only where it is necessary, and only with:
-
The laboratory that analyses your blood samples. Depending on the test, this will be INUVI, The Doctors Laboratory (TDL) or Eurofins, each a UKAS-accredited laboratory or Medichecks. They receive the sample and the clinical details needed to interpret it. Your doctor will tell you which laboratory is being used if you ask.
-
A pharmacy or supplier, where medication is dispensed to you. For testosterone replacement therapy, medication is dispensed either by Dr Kavadas or by a GPhC-registered pharmacy, depending on the medication. For weight management it is usually dispensed by Dr Kavadas directly. Where a pharmacy or supplier is involved, they receive only what is needed to fulfil and deliver the order.
-
Your GP or another clinician, where you have asked us to or agreed to it, or where we judge that not sharing would put you at serious risk of harm.
-
Our regulators — the Care Quality Commission and, where relevant, the General Medical Council, in the exercise of their statutory functions.
-
Our professional advisers — our medical indemnity provider, insurers, accountants and solicitors, where they need it in order to advise us. Our accountants have access to our accounting records in Xero, including invoices, for the purpose of preparing our accounts and tax returns.
We also use technology suppliers, who process data on our behalf under written contract and may not use it for their own purposes:
-
Semble Technology Limited — our clinical records system and online booking
-
Xero — our accounting and invoicing system
-
Stripe — card payment processing, via Semble
-
Amazon Web Services — hosting for Semble, AWS London region
-
Heidi Health Ltd — AI transcription and note drafting, described below
-
Google (Google Workspace) — our email
-
Google (Google Analytics) — understanding how this website is used
-
Doctify — collection and display of patient reviews
-
Wix.com Ltd — website hosting and forms
-
INUVI, TDL and Eurofins — laboratory analysis of blood samples
One company is different, and we would rather be clear about it. We use the Meta Pixel to measure our advertising. Meta does not act only on our instructions: it also uses what it receives for its own purposes. It is loaded only if you consent to advertising cookies, and if you decline it is not loaded at all. See Cookies and this website below.
Patient reviews
The patient reviews shown on this website are collected and verified by Doctify, an independent review service, not by us. Patients are asked by Doctify, under Doctify's own consent process, and we cannot add, edit or remove an individual review. The widget that displays them loads from Doctify's own servers.
Our clinical records system — Semble
We use Semble, provided by Semble Technology Limited, to host and manage our electronic practice management system. This holds patient profile details, medical records, consultation notes, appointment bookings, invoicing and communication history.
For everything held in Semble, we are the data controller — we decide what is collected and why. Semble is a data processor: they handle your information only on our instructions and only for the purposes set out here. They do not use it for their own purposes and they do not sell it.
What is held there: your name, date of birth, gender and contact details; your clinical record, meaning medical history, consultation notes, prescriptions, laboratory results and treatment plans; and administrative information, meaning appointments, communication preferences, and billing and invoicing history.
How it is protected:
-
Where it is stored — on Amazon Web Services infrastructure in the AWS London region, so your records are held in the United Kingdom. Semble backs data up daily within that region, and also copies backups periodically to a separate cloud provider. Where any of our suppliers stores data outside the UK, the transfer is protected by one of the safeguards described in Sending information outside the UK below.
-
Encryption — AES-256 while stored, and TLS 1.2 or 1.3 with 2,048-bit keys or better in transit
-
Access — role-based access on the principle of least privilege, with multi-factor authentication required for Semble's own staff, whose access to a customer portal is granted only on a time-limited basis when support requires it
-
Independent assurance — Semble holds ISO 27001 certification, commissions third-party penetration testing at least annually, and commits to notifying us of any breach affecting our data within 72 hours
A Data Processing Agreement is in place, forming part of Semble's master service terms, which restricts them from using or accessing your data for their own purposes. Semble uses its own sub-processors, such as cloud hosting providers, each bound by written confidentiality and data-protection terms.
If you want a copy of your records, or want something corrected or deleted, ask us — not Semble. We are the data controller, so the request comes to us and we deal with it. Semble cannot action it on your behalf, and sending it to them will only delay things. Our contact details are at the top of this policy.
Messages you send us by WhatsApp
We offer WhatsApp as a way of getting hold of us, and in practice patients sometimes send clinical information that way — a question about medication, a description of a symptom, occasionally a photograph. We would rather tell you plainly how that works than leave you to assume.
WhatsApp is a consumer messaging service operated by Meta, not part of our clinical records system. Messages are encrypted while they travel, so their content is not readable by Meta in transit, but Meta does hold information about the fact that you messaged us. The messages themselves sit on your phone and on ours, and they may be included in whatever backup your own phone makes.
Anything clinically relevant is copied into your medical record in Semble, which is where your record properly lives. Until it is copied across, a WhatsApp message is not part of your record and should not be relied on as though it were.
What this means for you, in practical terms:
-
Do not use WhatsApp for anything urgent. It is not monitored continuously and we do not provide urgent or out-of-hours care. If you need help urgently, contact your GP or call NHS 111. In an emergency, call 999.
-
If you would rather not send health information through WhatsApp, please don't — email us, or raise it at your appointment. Your care is not affected either way.
-
You can ask us to delete a WhatsApp exchange, and we will, though anything already copied into your medical record is retained as part of that record.
Artificial intelligence and your consultation notes
We want to be straightforward about this, because it is not obvious and you are entitled to know.
Your doctor uses Heidi, provided by Heidi Health Ltd (registered in England and Wales, company number 15878893), to help write up the notes from your consultation. It listens, transcribes what is said, and produces a draft note. Your doctor reviews, corrects and approves everything before it becomes part of your record. The AI makes no decision about your care, and nothing it produces is used without the doctor reading it.
You are asked first, every time. Your doctor will ask before using it. If you would rather it was not used, say so — it will not be, and your care will not be affected in any way.
The recording is not kept. The audio is transcribed and then discarded once the note has been drafted. Heidi's data processing agreement states that no identifiable recordings are stored or will be accessible.
Where it is processed. Heidi Health Ltd is a UK company, and your consultation data is hosted in the United Kingdom on Amazon Web Services. Some of Heidi's supporting suppliers, for authentication, customer support and analytics, operate in Ireland, Belgium and Germany, all within the EEA. Transfers are governed by the UK Addendum to the EU Standard Contractual Clauses.
Independent assurance. Heidi holds ISO 27001:2022, Cyber Essentials and SOC 2 certification, and has completed the NHS DCB0129, DTAC and DSPT assessments. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit. Heidi commits to notifying us of any breach affecting our data within 24 hours.
We hold the record, not Heidi. Your notes belong to this practice, and we decide how long they are kept. If Heidi's service ended, they are contractually required to delete all of our data within ten business days and confirm it within twenty-one.
We may also disclose information where we are required to by law, or by a court.
Sending information outside the UK
Some of our suppliers store or process data outside the UK. Where that happens, the transfer is protected by one of the safeguards UK law allows — either the receiving country is covered by UK adequacy regulations, or the transfer is made under the UK International Data Transfer Agreement, or under the UK Addendum to the EU Standard Contractual Clauses.
Specifically:
-
Semble, which holds your clinical record — United Kingdom, in the AWS London region. There is no transfer for the primary record. Backups copied to a separate cloud provider are covered by Semble's own data-protection terms.
-
Heidi, which drafts consultation notes — United Kingdom, with some supporting suppliers in Ireland, Belgium and Germany, under the UK Addendum to the EU Standard Contractual Clauses.
-
Google, our email and website analytics — United States and elsewhere. Google LLC is certified under the EU-US Data Privacy Framework including its UK Extension, and also relies on the EU Standard Contractual Clauses.
-
Meta, advertising measurement — United States and elsewhere. Meta Platforms is certified under the EU-US Data Privacy Framework including its UK Extension.
-
Wix, this website — data centres in the United States and Ireland, with group companies and processors elsewhere, under Standard Contractual Clauses together with additional technical and organisational safeguards, as set out in Wix's Data Processing Agreement.
-
Stripe, card payments — United States and elsewhere, under Stripe's own data processing terms and transfer safeguards.
-
Xero, our accounting and invoicing software — customer data is hosted on Amazon Web Services infrastructure in the United States, with some processing in New Zealand, a country covered by UK adequacy regulations. Transfers to the United States and elsewhere are made under the UK Addendum to the EU Standard Contractual Clauses, as set out in Xero's data processing terms.
You can ask us for details of the safeguard used for any specific transfer.
How long we keep it
Clinical records are retained in line with UK guidance on health records retention, and then securely destroyed. The benchmark we follow is the Records Management Code of Practice, which sets the retention periods used across UK health care.
For everything else:
-
Your medical records — in line with UK guidance on health records retention, the recognised standard for health records in the UK
-
Complaints records — in line with UK guidance on health records retention. The CQC expects complaints to be recorded and reviewable.
-
Enquiries that did not become appointments — 12 months, long enough to answer a follow-up and no longer
-
Financial and payment records, held in Xero — 7 years from the end of the accounting period, an HMRC requirement
-
Consultation audio used by the AI note-taking tool — not retained. It is transcribed, then discarded once the note is drafted, and no identifiable recordings are stored.
-
WhatsApp messages — deleted once anything clinically relevant has been copied into your medical record
-
Marketing consents and preferences — until you withdraw consent, plus a record of the withdrawal, so we can show we stopped when you asked
-
Website analytics and cookie data — as set by Wix, see their cookie notice
When a retention period ends we securely delete or destroy the record.
Keeping it secure
Our measures include access controls so that only people who need to see your record can, encryption of data in transit, secure password practice, locked physical storage for any paper records at the clinic, and written data-processing contracts with every supplier listed above.
No system is completely secure. If a breach of your personal data occurs and it is likely to result in a risk to your rights, we will report it to the ICO within 72 hours and tell you without undue delay.
Your rights
You have the right to:
-
Be told what we do with your data — that is what this policy is for
-
Get a copy of the personal data we hold about you, usually within one month and free of charge. This includes your medical records.
-
Have inaccurate data corrected. Note that a clinical opinion recorded at the time cannot be erased because you disagree with it, but we will record your disagreement alongside it.
-
Ask us to delete your data. We often cannot delete medical records, because we are required to retain them, but we will explain why in each case.
-
Ask us to restrict how we use your data while a concern is being resolved
-
Object to our using your data where we rely on legitimate interests
-
Withdraw consent at any time, where consent is what we rely on
-
Receive your data in a portable format, where we rely on consent or contract
-
Not be subject to solely automated decisions with a significant effect on you. We do not make any.
To exercise any of these, contact us using the details at the top of this policy. We may ask you to confirm your identity first — we are not going to hand your medical record to someone who says they are you.
Send the request to us, not to our suppliers. Your records are held in Semble, and Semble cannot action a request on your behalf — we are the data controller, so it has to come to us. Sending it to them will only delay it.
Complaints
If you are unhappy with how we have handled your information, please tell us first and we will try to put it right. Our complaints procedure is at Patient Complaints Information.
You also have the right to complain to the Information Commissioner's Office at any time:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline 0303 123 1113
ico.org.uk/make-a-complaint
Cookies and this website
This website uses cookies — small files stored on your device. Some are necessary for the site to work; others help us understand how the site is used, or support booking and forms.
This site is hosted on Wix, which sets its own essential cookies. Our online booking is provided by Semble, which may set cookies when you use it. Patient reviews are displayed by Doctify, which loads them from its own servers.
We also use Google Analytics, to understand how the site is used, and the Meta Pixel, to measure our advertising. Neither of these loads, and neither sets a cookie, until you have given consent through the cookie banner. If you decline, they are not loaded at all. We do not use a live-chat tool.
You can manage your preferences through the cookie banner when you first visit, and change them later through your browser settings. Blocking essential cookies may stop parts of the site working.
Changes to this policy
We review this policy at least annually and whenever our processing changes. The date at the top shows when it was last updated. If we make a significant change we will say so on this page.