AEOM Health - Privacy Policy
AEOM Health Limited is committed to protecting and respecting your privacy. This privacy policy explains what personal data we collect, how we use it, and the rights you have in relation to it.
By using our website or our services, you agree that we may use your personal data as described in this policy.
-
Who we are
In this policy, "we", "us" and "our" refer to AEOM Health Limited, a company registered in England under company number 15089115, with its registered office and trading address at 116 Seymour Place, London, W1H 1NW.
We are registered with the Information Commissioner's Office under registration number ZC073276, and we are the data controller responsible for your personal data.
-
Contact
If you have any questions about this policy or how we handle your personal data, please contact:
Yusuf Khan
AEOM Health Limited
116 Seymour Place, London, W1H 1NW
Email: info@aeomhealth.com
-
What is personal data?
"Personal data" means any information from which you can be identified. It does not include data where your identity has been removed (anonymous data). Certain data, such as information about your health, is "special category" data and is given a higher level of protection under UK data protection law.
-
The personal data we collect and why
Data collected through our website
When you use our website or complete an online enquiry or contact form, we collect:
|
Data |
Purpose |
Lawful basis |
|
Name and surname |
To respond to your enquiry and contact you |
Legitimate interests / steps prior to entering a contract |
|
Contact details (email, telephone) |
To respond to your enquiry and contact you |
Legitimate interests / steps prior to entering a contract |
We also collect limited technical data automatically through cookies, see our Cookie Policy.
Data collected through the clinic
When you register as a patient or attend a consultation or treatment, we collect:
|
Data |
Purpose |
Lawful basis |
|
Identity and contact details, date of birth |
To identify you and provide our services |
Performance of a contract |
|
Emergency contact / next of kin |
For your safety during treatment |
Performance of a contract; protecting vital interests |
|
Payment details (where applicable) |
To process payment for services |
Performance of a contract; legal obligation |
|
Health questionnaires and consultation records |
To assess suitability and provide safe, appropriate treatment |
Performance of a contract; provision of health care |
|
Clinical images taken for treatment purposes |
To plan, deliver and review treatment |
Provision of health care; explicit consent where required |
|
Health data from consultations, diagnostics and treatments, including bloodwork and, where undertaken, genetic and epigenetic testing |
To provide clinical care and diagnostic services |
Provision of health care; explicit consent where required |
-
Special category (health) data
Information about your health, and genetic data, are "special category" data. We process this data on the basis of:
-
Provision of health care — Article 9(2)(h) of the UK GDPR permits processing of health data for the provision of healthcare and treatment by, or under the responsibility of, a health professional bound by a duty of confidentiality; and
-
Explicit consent — where we rely on your consent (for example, for certain diagnostic testing or the use of clinical images), we will make this clear and you may withdraw it at any time.
All clinical data is handled by, or under the supervision of, registered health professionals bound by professional duties of confidentiality.
-
How we collect your data
-
Directly from you — when you enquire through our website, register as a patient, or complete questionnaires and consultation forms.
-
Automatically — technical and usage data via cookies when you use our website (see our Cookie Policy).
-
From third parties — for example, diagnostic results from the laboratories that carry out testing on our behalf.
If you do not provide your data
Some data is needed to allow us to provide our services or to meet our legal and clinical obligations (such as keeping adequate medical records). If you do not provide it, we may not be able to treat you.
-
Who we share your data with
We share your data only where necessary to provide our services, and we require all third parties to protect it and use it only for the purposes we specify. Our processors and partners include:
-
Pabau: our clinical record and practice management system
-
Stripe: payment processing for treatments
-
GoCardless: recurring payment processing for memberships
-
Third-party laboratories: for bloodwork, and genetic and epigenetic testing
-
Professional advisers and insurers: where necessary to manage legal or clinical risk
-
Regulators and authorities: where we are required to by law
We do not sell your personal data, and we do not share it with third parties for their own marketing.
-
Where your data is processed
We store and process your data within the UK and the European Economic Area (EEA). Some of our processors, including Pabau (our clinical record system) and Stripe (payment processing). may process data within the EEA as well as the UK. All laboratory testing is carried out by UK-based laboratories. Where data is processed outside the UK, it remains protected by UK-approved data protection safeguards, and the EEA is recognised by the UK as providing an equivalent level of protection.
-
Data security
We take appropriate technical and organisational measures to keep your personal data secure, with access limited to those who need it to provide your care and run our services. Our systems and processors are selected with data protection and security in mind.
-
How long we keep your data
We keep your personal data only for as long as necessary for the purposes for which it was collected, and to meet our legal and clinical obligations.
-
Clinical and treatment records — retained for 10 years from the date of last treatment (or, for any records relating to a person who has died, 10 years after death), in line with professional medical record-keeping standards.
-
Enquiry and marketing data — retained only for as long as necessary, and deleted when you withdraw consent or it is no longer needed.
-
Financial and transaction records — retained as required by law (currently six years for tax purposes).
When data is no longer needed, we securely delete or anonymise it.
-
Marketing
We will only send you marketing communications where you have asked us to, or have otherwise consented. You can opt out at any time using the unsubscribe link in any message, or by contacting us. We will always obtain your explicit opt-in consent before using your data for marketing, and we will never share it with third parties for their marketing.
-
Your rights
Under UK data protection law you have the right to:
-
Access your personal data (a "subject access request")
-
Correct inaccurate or incomplete data
-
Request erasure of your data where there is no continuing reason for us to hold it
-
Object to or restrict processing in certain circumstances
-
Request transfer of your data to another provider
-
Withdraw consent at any time, where we rely on your consent
To exercise any of these rights, please contact us using the details above. We will respond within one month.
Please note that where data forms part of your clinical record, our ability to erase it may be limited by our legal and professional obligations to retain medical records.
-
Complaints
If you have concerns about how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or by calling 0303 123 1113.
-
Changes to this policy
We keep this policy under regular review. It was last updated on 1st July 2026