Privacy Policy 
 
1. INTRODUCTION 
 
This privacy notice provides you with details of how we collect and process your personal data at Mind Body Medical and through your use of our websites www.mindbodymedical.co.uk and www.drsamwatts.com, including any information you may provide via email, over the phone, in person, or through our sites when you purchase a product or service, make an enquiry, sign up to our newsletter, or take part in a prize draw or competition. 
 
Mind Body Medical, trading as Mind Body Medical, is the data controller, and we are responsible for your personal data (referred to as “we”, “us”, or “our” in this privacy notice). 
 
If you have any questions about this privacy notice or our use of your personal data, please contact us at: 📧 info@drsamwatts.com 
 
If you are not happy with any aspect of how we collect and use your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues: www.ico.org.uk. We would appreciate the opportunity to resolve your concerns before you approach the ICO, so please contact us first. 
 
It is very important that the information we hold about you is accurate and up to date. Please let us know if your personal information changes by emailing us at the above address. 
 
We keep our Privacy Notice under regular review. This version was last updated in January 2025. 
 
2. WHAT DATA DO WE COLLECT ABOUT YOU 
 
Personal data means any information capable of identifying an individual. It does not include anonymised data. 
 
We may process the following categories of personal data about you: 
 
Identity Data: Includes first name, maiden name, last name, username, marital status, title, date of birth, and gender. 
 
Contact Data: Includes billing address, delivery address, email address, and telephone numbers. 
 
Financial Data: Includes bank account and payment card details. Payments for products and services are securely processed using Stripe. Mind Body Medical does not directly store or process full card details on its servers. A card may only be stored securely with your explicit consent, and each transaction requires express consent via email. (See Stripe’s privacy policy here.) 
 
Transaction Data: Includes details about payments made by you. 
 
Technical Data: Includes IP address, browser type and version, time zone setting and location, operating system, platform, and other technology used to access our websites. 
 
Usage Data: Includes information about how you use our websites, products, and services. 
 
Marketing and Communications Data: Includes your preferences for receiving marketing communications from us and third parties, and your communication preferences. Our newsletters are managed using MailChimp and Kartra (see MailChimp’s privacy policy). 
 
We may also process Aggregated Data, such as statistical or demographic data. If Aggregated Data is linked to your personal data so you can be identified, it will be treated as personal data. 
 
Sensitive Data 
 
Given the nature of our healthcare services, we may collect health-related data such as: 
 
Health history, diet and lifestyle information, supplement and medication details, test results, clinic notes, and health plans. 
 
Sensitive data will only be collected with your explicit consent and used strictly for providing healthcare services. The legal basis for processing such data is legitimate interest and/or the performance of a contract for services. 
 
If you refuse to provide certain data, we may be unable to provide a product or service and will notify you at that time. 
 
3. HOW WE COLLECT YOUR PERSONAL DATA 
 
You provide data to us through: 
 
Completing a patient history form. 
 
Signing a terms of engagement form. 
 
During a consultation. 
 
Email, telephone, or social media communications. 
 
Providing credit card or online payment details. 
 
3.1 Emails 
 
If you contact us by email, your information will be stored securely within our email systems. Please be aware that you are responsible for ensuring that any email you send is lawful. 
 
3.2 Patient Consultations 
 
We offer consultations at our clinic, via Zoom, and over the telephone. 
 
Client information is collected and securely stored in the Write Upp client relationship management (CRM) system. Handwritten notes, if taken, are subsequently stored electronically and securely destroyed. 
 
Data may also be stored on encrypted, password-protected computers used only by authorised Mind Body Medical staff. 
 
We retain patient records for 7 years following the last appointment, as required by our professional association, the CMA. Records are then securely destroyed. 
 
4. HOW WE USE YOUR PERSONAL DATA 
 
We act as a data controller when using your personal data to provide healthcare services, and as a controller and processor when handling third-party data (e.g., lab testing, payment processing). 
 
We will always ensure that processing your personal data is lawful, fair, and necessary for: 
 
Providing healthcare services (contract performance). 
 
Fulfilling a legitimate interest (e.g., managing services). 
 
Meeting legal obligations. 
 
Protecting vital interests (e.g., safeguarding). 
 
Marketing communications are only sent with your explicit consent, which you can withdraw at any time via the unsubscribe link in our emails or by contacting us. 
 
5. DO WE SHARE YOUR INFORMATION WITH THIRD PARTIES? 
 
We will keep your information confidential, only sharing with third parties where: 
 
Required by law (e.g., regulatory or legal obligations). 
 
Necessary for healthcare provision with your explicit consent. 
 
Necessary for IT, system administration, or professional services. 
 
In life-threatening situations, where sharing is based on vital interests. 
 
Third-party examples include: 
 
CMA (for complaint investigations). 
 
Laboratories (for testing with your consent). 
 
IT service providers. 
 
Legal and financial advisers. 
 
HM Revenue & Customs. 
 
We require all third parties to respect your personal data and process it according to the law. 
 
Case studies may occasionally be shared in anonymised form for educational purposes (e.g., supervision meetings). 
 
6. INTERNATIONAL TRANSFERS 
 
Some of our third-party providers (e.g., MailChimp) are based outside the UK and EEA. When we transfer your personal data internationally, we ensure appropriate safeguards are in place, such as: 
 
Transfers to countries with adequacy decisions. 
 
Use of standard contractual clauses approved by the ICO. 
 
Additional safeguards as necessary. 
 
We will seek your explicit consent if no appropriate safeguard exists. 
 
7. YOUR LEGAL RIGHTS 
 
Under UK GDPR, you have the right to: 
 
Request access to your personal data. 
 
Request correction or erasure of your personal data. 
 
Object to processing. 
 
Request restriction of processing. 
 
Request transfer of your personal data to you or a third party. 
 
Withdraw consent at any time (where consent is the basis for processing). 
 
You can learn more about your rights here. 
 
To exercise any of these rights, email us at info@drsamwatts.com 
 
We aim to respond within one month but may require additional time for complex requests. 
 
8. DATA SECURITY 
 
We are committed to ensuring that your information is secure. To prevent unauthorised access or disclosure, we have implemented suitable physical, electronic, and managerial procedures to safeguard the information we collect. 
 
Our IT systems are encrypted and password protected, and all external data processors are contractually required to protect your information. 
 
9. COOKIES 
 
Our websites use cookies to enhance your user experience. 
 
Cookies are small files placed on your device that help us analyse web traffic and improve our websites. We may use: 
 
Necessary cookies (essential for the website to function properly). 
 
Analytical cookies (e.g., Google Analytics to understand usage patterns). 
 
Marketing cookies (to deliver relevant advertising). 
 
You can set your browser to refuse all or some cookies or to alert you when websites set cookies. Please note that disabling cookies may impact your experience. 
 
For more details, please refer to our Cookie Policy.