Effective Date: 05/12/2025

MedLabs Diagnostics Ltd (“MedLabs”, “we”, “us”, “our”) is committed to protecting the privacy and confidentiality of your personal data. This Privacy Notice explains how we collect, use, store and protect your personal data when you:

● use our website: https://www.medlabs.uk,

● attend our clinic for ultrasound scans,

● attend our clinic for blood, urine or stool tests,

● contact us by phone, email or in writing.

This Notice also explains your legal rights and how the law protects you.

MedLabs Diagnostics Ltd is a private limited company registered in England and Wales (Company No. 13480826), operating from: 1–5 Portpool Lane, London, EC1N 7UU.

1. Important Information

1.1 Supplemental terms

This Privacy Notice supplements any other terms published on our website (including Cookies Policy and Terms & Conditions). It does not override them.

1.2 Controller

MedLabs Diagnostics Ltd is the data controller and is responsible for your personal data when you use our services.

1.3 Questions or contact

For any questions regarding this Notice or to exercise your rights, contact our Data Protection Officer (DPO):

Email: [email protected] Post: MedLabs Diagnostics, 1–5 Portpool Lane, London, EC1N 7UU

1.4 Complaints

You have the right to complain to the UK Information Commissioner’s Office (ICO) at any time (www.ico.org.uk). We would appreciate the opportunity to resolve your concerns first.

1.5 Who can use our Site

Our website is not intended for children. We do not knowingly collect children’s data unless it is provided by a parent/guardian for the purposes of a diagnostic test.

1.6 Keeping your data updated

It is important the data we hold about you is accurate. Please notify us of any changes.

1.7 Third-party links

Our website may contain links to external websites. We are not responsible for their privacy policies.

2. The Data We Collect About You

We may collect, use, store and transfer different types of personal data including:

2.1 Identity and Contact Data

● Full name

● Date of birth

● Address

● Email

● Phone number

2.2 Health & Diagnostic Data (special category data)

● Information you provide for Diagnostic and Screening Procedures

● Ultrasound referral information

● Blood, urine and stool test results

● Clinical notes and reports

● Relevant past medical history

This data is collected because you request diagnostic services from us.

2.3 Transaction & Financial Data

● Payments made

● Invoices and receipts

2.4 Technical Data

● IP address

● Browser type

● Usage data when you access our website

2.5 Marketing and Communication Data

● Preferences for receiving updates or promotional information

2.6 Aggregated data

We may collect aggregated statistical data but it does not identify you personally.

2.7 Special Category Data

We only process special category data with your explicit consent or where processing is necessary to provide diagnostic healthcare.

3. How We Collect Your Personal Data

3.1 Direct interactions

You may provide data when booking appointments, attending the clinic, or contacting us by phone/email.

3.2 Clinician-generated data

Ultrasound reports, laboratory results, and clinical notes produced during your visit.

3.3 Third parties

● Your GP or clinician (when you provide consent)

● Your employer, if they have referred you for occupational health testing

● Other healthcare providers involved in your care

3.4Automated technologies

We collect technical data through cookies—see our Cookies Policy.

4. How We Use Your Personal Data

We will only process your personal data when legally permitted. Most commonly:

4.1 To deliver diagnostic services

● Performing ultrasound scans

● Collecting and analysing blood, urine and stool samples

● Producing clinical reports

● Issuing results to you or your referring clinician

4.2 Regulatory requirements

To comply with regulatory requirements; Including obligations under:

● The Health and Social Care Act 2012

● Care Quality Commission (CQC) regulations

● Clinical governance and audit requirements

4.3 Appointments

● To manage appointments, payments, customer queries

4.4 Improvements

● For service improvement, auditing, training and quality control

4.5 Marketing

You will only receive marketing materials if:

● you have purchased a service from us, or

● you have opted-in to marketing communications.

We never share your data with third-party marketers.

4.6 Change of purpose

We only use your personal data for the purpose it was collected, unless lawful grounds allow otherwise

5. Sharing Your Personal Data

We may share your data with:

5.1 Clinicians

● Clinicians involved in your diagnostic care. Included, but not limited to, Sonographers, phlebotomists and laboratory professionals.

5.2 Accredited laboratories

● When tests are processed externally.

5.3 Service providers

● IT, software and payment providers.

5.4 Professional advisers

● Accountants, lawyers, insurers.

5.5 Regulators

● CQC, HMRC, or other authorities when legally required.

We require all third parties to respect your privacy and process data only as instructed.

6. International Transfers

If your data is processed outside the UK (e.g., cloud hosting), we ensure appropriate safeguards, such as:

● Adequacy decisions

● Standard contractual clauses

7. Data Security

We implement strong organisational and technical measures to protect your data, including:

● Restricted access

● Encrypted systems

● Staff confidentiality agreements

● Secure storage and disposal protocols

8. Data Retention

We retain personal data only as long as necessary, including:

● Ultrasound and laboratory records, stored in accordance with healthcare regulatory requirements (usually minimum 6 years)

● Financial records: 6 years for HMRC compliance

We may anonymise data for audit or research purposes.

9. Your Legal Rights

You have the right to:

● Access your data

● Request correction

● Request deletion

● Object to processing

● Request restriction

● Request data transfer

● Withdraw consent

We may ask for proof of identity before responding.

10.⁠ ⁠User Responsibilities

We may update this Privacy Notice periodically. The latest version will always appear on our website.

Contact Information

If you have any questions or concerns about these Terms, please contact us at:

MedLabs Diagnostic

1-5 Portpool Lane EC1N 7UU, London

Tel: +447745795699

Tel: +44 (0) 2080581556

Email: [email protected]

Website: www.medlabs.uk