Privacy Policy

Effective Date: 7 July 2025

Last Updated: 7 July 2025

1. Introduction

Rakus Clinic, a trading name of Weymouth Limited, is committed to protecting and respecting your privacy. This Privacy and Cookie Policy explains how we collect, use, store, and protect your personal data when you interact with us—whether in person, through our website, or by other means.

Registered Address:
Rakus Clinic
34 Hans Road
London
SW3 1RW
United Kingdom

Company Number: 14641687

2. Who We Are

Rakus Clinic is a provider of advanced medical aesthetic treatments. We are a data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions regarding this policy or how your data is handled, please contact our Data Protection Officer (DPO):

Email: privacy@rakusclinic.com
Phone: [Insert clinic contact number]
Address: As above

3. What Information We Collect

We collect personal data directly from you when you interact with us, including:

a) Personal Identification Data:

  • Full name
  • Date of birth
  • Gender
  • Contact details (email, phone number, postal address)

b) Health and Medical Data:

  • Medical history
  • Treatment records
  • Photographs (before and after treatment, where appropriate)
  • Prescriptions and clinician notes

c) Payment & Financial Data:

  • Payment card information (processed securely via third-party payment providers)
  • Billing history

d) Website Usage Data:

  • IP address
  • Browser type and device information
  • Pages visited, session time, clickstream data
  • Cookie preferences (see Section 8)

4. How We Use Your Information

We use your personal data for the following purposes:

  • To provide and manage your treatment safely and effectively
  • To comply with medical and legal obligations
  • To maintain accurate clinical records
  • To communicate with you regarding appointments, treatments, and services
  • To improve the quality and performance of our website
  • For billing and payment purposes
  • With your consent, to send you marketing updates and offers

5. Legal Basis for Processing

We rely on one or more of the following lawful bases under the UK GDPR:

  • Consent – where you have given explicit permission (e.g. marketing emails)
  • Contract – when processing is necessary for the performance of a contract
  • Legal Obligation – for compliance with legal and regulatory requirements
  • Vital Interests – for matters of medical emergency
  • Legitimate Interests – for business functions that do not override your rights

For special category data (e.g., health data), we process under Article 9(2)(h) – medical diagnosis and provision of health care.

6. How We Store and Protect Your Data

Your data is stored securely on encrypted servers and within clinical management systems that comply with UK data protection laws.

We implement industry-standard security measures, including:

  • Role-based access controls
  • SSL encryption for online data transfers
  • Secure storage of medical records
  • Regular security audits and staff training

We retain personal data in accordance with NHS guidelines and legal obligations, typically for a minimum of 8 years after last contact or until age 25 if under 18 at last contact.

7. Sharing Your Data

We do not sell your personal data.

We may share your information with trusted third parties in the following circumstances:

  • With healthcare professionals involved in your care
  • With regulators (e.g., CQC, GMC, ICO) for compliance
  • With IT service providers under data processing agreements
  • With insurers or legal advisors where necessary

All third-party providers are subject to appropriate data protection and confidentiality obligations.

8. Cookies and Website Tracking

What Are Cookies?

Cookies are small text files placed on your device to help the website function properly and enhance user experience.

Types of Cookies We Use:

  • Strictly Necessary Cookies – Required for core functionality (e.g., security, log-in)
  • Performance Cookies – To monitor site performance and usage (e.g., Google Analytics)
  • Functionality Cookies – To remember your preferences
  • Targeting/Advertising Cookies – Only with your consent

Managing Cookies:

On your first visit, you’ll be asked to consent to the use of cookies. You can change your preferences at any time via our Cookie Settings or by adjusting your browser settings.

For more detailed cookie information, please see our [Cookie Notice] (link if hosted separately).

9. Your Rights

You have the following rights under the UK GDPR:

  • Right to Access – obtain a copy of your data
  • Right to Rectification – correct inaccurate or incomplete data
  • Right to Erasure – request deletion of data where no longer needed
  • Right to Restriction – limit processing in certain circumstances
  • Right to Data Portability – receive data in a commonly used format
  • Right to Object – to certain types of processing (e.g., marketing)
  • Right to Withdraw Consent – where processing is based on consent
  • Right to Lodge a Complaint – with the Information Commissioner’s Office (ICO)

ICO Contact:
Website: https://ico.org.uk
Phone: 0303 123 1113

10. Marketing Communications

With your consent, we may send you information about our services, events, and promotions. You can opt-out at any time by:

  • Clicking the “unsubscribe” link in emails
  • Emailing us at: privacy@rakusclinic.com

We will never send unsolicited marketing communications.

11. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, legal obligations, or service offerings. The latest version will always be available on our website.

Date last updated: 7 July 2025

12. Contact Us

If you have any concerns or wish to exercise your data rights, please contact:

Data Protection Officer
Rakus Clinic
34 Hans Road
London SW3 1RW

Email: clinic@drritarakus.com