Privacy Policy
Privacy Policy
Last updated: 16/06/2026
This Privacy Policy explains how Dr.Derme Skin Clinics uses personal information about patients, prospective patients, website users and people who contact us.
Dr.Derme is operated by Medcas Group Limited, trading as Dr.Derme. Medcas Group Limited is the data controller.
Controller: Medcas Group Limited trading as Dr.Derme
Company number: 10391230
Registered office: Grove House, 55 Lowlands Road, Third Floor, Harrow, England, HA1 3AW
Privacy contact: info@drderme.com | 0800 009 6109
Website: drderme.com
1. Information we collect
We may collect and use:
- identity and contact details, such as name, date of birth, address, email and phone number;
- booking, appointment, payment, invoice, refund, package and membership information;
- health and clinical information, including medical history, medication, allergies, skin concerns, examination findings, treatment records, consent forms, prescriptions, aftercare, complications, complaints and correspondence;
- clinical photographs or images sent to us for assessment, treatment planning, records, aftercare, review or complaint handling;
- communications with us by email, phone, WhatsApp, SMS, website form, booking system or social media;
- messages, replies, enquiry details and interaction records from any automated assistant or bot used on our website, WhatsApp, SMS, email or other communication channels;
- website, cookie and marketing information, such as IP address, device information, website usage, cookie consent choices, source of enquiry, marketing preferences and campaign or referral information.
If you do not provide information needed for safe assessment or treatment, we may be unable to provide services.
2. Why we use your information
We use personal information to:
- respond to enquiries and manage bookings;
- use automated tools to respond to initial enquiries, answer simple questions, support appointment administration, route requests to our team and help staff manage customer-service communications;
- assess suitability for consultations, treatments, prescriptions and procedures;
- provide clinical care, treatment planning, aftercare and follow-up;
- keep accurate clinical, consent and treatment records;
- process payments, invoices, refunds, chargebacks and unpaid amounts;
- manage complaints, incidents, complications, safeguarding concerns and legal claims;
- meet legal, regulatory, tax, accounting, professional, insurance and clinical governance obligations;
- improve our services, systems, training and patient experience;
- send service messages, appointment reminders and important clinic updates;
- send marketing only where permitted by law.
3. Our lawful bases
We use personal information where necessary for one or more of the following lawful bases:
- contract, to provide or arrange services you request;
- legal obligation, to meet healthcare, tax, accounting, regulatory and data protection duties;
- legitimate interests, to run and protect the clinic, maintain records, improve services, manage complaints, recover unpaid sums and defend legal claims, provided your rights do not override those interests;
- vital interests, where needed to protect life or respond to a serious medical emergency;
- consent, where required, such as some marketing, non-essential cookies and optional use of identifiable images for marketing.
Health information and clinical images are special category data. We use these where necessary for medical diagnosis, healthcare or treatment, clinical record-keeping, legal claims, safeguarding, regulatory obligations, or where you have given explicit consent for a specific optional use.
Consent for treatment is separate from data protection consent. We may still need to keep clinical records even if you withdraw consent for marketing or ask us to delete information.
4. Who we share information with
We only share information where appropriate and lawful. This may include:
- clinicians, staff, contractors and host-clinic teams where involved in your care, appointment administration or premises support;
- providers of clinic-management, booking, consent, payment, customer-service automation, AI, email, telephone, SMS, WhatsApp, website, IT, hosting, secure storage and analytics systems;
- pharmacies, laboratories, pathology providers, suppliers or prescribers where needed;
- payment providers, card providers, debt-recovery providers, insurers, indemnity providers, lawyers, accountants, regulators, courts or public authorities where required or appropriate;
- your GP, NHS services, hospitals, emergency services or other healthcare professionals where clinically necessary, requested by you, or required for safety;
- safeguarding bodies where necessary.
Examples of systems we may use include clinic-management and booking software, secure clinical record systems, online forms, payment processors, email and messaging systems, website analytics tools and secure cloud storage.
Where we use AI or automation providers, we require appropriate confidentiality, security and data protection safeguards and take reasonable steps to ensure they process personal data under contract, in line with our instructions and applicable data protection terms.
We do not sell personal information.
Where suppliers process data for us, we require appropriate confidentiality, security and data protection safeguards.
Some software or cloud providers may process data outside the UK. Where this happens, we use appropriate safeguards, such as UK adequacy arrangements or approved contractual protections.
Where CCTV is operated by a host premises or landlord, their own privacy notice may also apply. If footage is shared with us for a lawful reason, we will use it only where necessary and proportionate.
5. How long we keep information
We keep information only for as long as needed for the purpose collected and for legal, clinical, regulatory, insurance and professional reasons.
Clinical records are usually kept for at least 8 years after the last contact, and longer where required for children, safeguarding, complaints, complications, legal claims or indemnity reasons. Financial records are usually kept for 6 years. Marketing information is kept until you unsubscribe, withdraw consent, or the information is no longer needed.
When information is no longer required, we securely delete, destroy or anonymise it.
6. Security
We use appropriate measures to protect personal information, including access controls, secure systems, confidentiality obligations, staff training, backups and secure disposal.
No system is completely risk-free. Please take care when sending sensitive information by email, WhatsApp or social media.
Please do not use web chat, WhatsApp, SMS, email or the automated assistant for medical emergencies or urgent post-treatment concerns.
7. Automated assistant and AI
We may use an automated assistant or AI-supported tools on our website, WhatsApp, SMS and email to respond to initial enquiries, answer general questions, support appointment administration, collect information you choose to provide and route enquiries to our team.
These tools may process message content, contact details, enquiry details and relevant appointment or service information. They may be provided by customer-service automation, messaging and AI providers, including GoHighLevel/HighLevel and OpenAI where used.
The automated assistant is for general information and administrative support only. It does not provide medical diagnosis, personalised clinical advice, prescriptions, treatment suitability decisions, emergency support or complication management.
Messages may be reviewed by our staff and stored with your enquiry or patient record where relevant. We do not use the automated assistant to make solely automated clinical decisions with legal or similarly significant effects.
8. Marketing and cookies
We may send marketing where you have consented or where the law allows. You can opt out at any time.
Our website uses cookies and similar technologies. Essential cookies help the website work and support security. Non-essential cookies, such as analytics, functional, advertising and embedded-content cookies, are only used where the required consent has been obtained.
You can manage or withdraw your cookie choices through our cookie banner or cookie settings. More information is available in our separate Cookie Policy: drderme.com/cookie-policy.
9. Your rights
You may have the right to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. These rights are not absolute. For example, we may need to keep clinical records for legal, regulatory, insurance or patient safety reasons.
You have an absolute right to object to direct marketing.
To exercise your rights, contact info@drderme.com. We may need proof of identity before responding.
10. Complaints
Please contact us first if you have a privacy concern.
You can also complain to the Information Commissioner’s Office:
ICO
Website: www.ico.org.uk
Telephone: 0303 123 1113
11. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be available on our website.



