Privacy Policy & Health Record Security
NextDoorClinic is committed to safeguarding your medical data and personal information. This Privacy Policy details how we collect, process, encrypt, and manage patient records in compliance with UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and NHS Caldicott Principles.
Personal Data & Special Category Health Records
When you make an appointment or register a patient profile on NextDoorClinic, we collect information necessary to facilitate your clinical care:
- Contact Information: Full name, email address, mobile phone number, and residential address.
- Clinical Booking Details: Selected pharmacy/clinic, appointment date/time, treatment type, and voluntary consultation notes.
- Special Category Data: Pre-existing medical conditions, allergies, or NHS number provided voluntarily to assist your consulting clinician.
Lawful Basis & Clinical Communication
We process your personal data under the lawful basis of contract performance (to book your requested clinical service) and provision of healthcare under UK GDPR Article 9(2)(h).
Your data is transmitted securely to your chosen registered pharmacy or clinic so they can review your record prior to your appointment. We do not sell, rent, or trade patient health records to third-party advertisers.
Data Storage Security & NHS Toolkit Alignment
All patient data is stored within ISO 27001-certified UK data centers. Electronic data is encrypted using AES-256 encryption at rest and TLS 1.3 encryption in transit. Our infrastructure aligns with the NHS Data Security and Protection Toolkit (DSPT).
Cookie Usage & Consent Management (PECR)
We use strictly necessary cookies to deliver core platform services, including session authentication, cross-tab logout synchronization, and CSRF protection on booking forms.
With your consent, we also use functional and privacy-preserving analytics cookies to remember your location preferences and monitor system responsiveness. For complete details, cookie lists, and to customize your settings, please review our dedicated Cookie Policy & Inventory.
Subject Access Requests (SARs) & Data Portability
Under UK GDPR and the Data Protection Act 2018, you hold full statutory rights:
- Right to Access: Request a copy of your personal health and booking records processed by NextDoorClinic.
- Right to Rectification: Request correction of inaccurate contact or profile details.
- Right to Erasure: Request deletion of account data (subject to mandatory NHS/GPhC clinical record retention periods).
- Right to Restrict & Object: Object to specific non-essential processing activities at any time.
Retention Schedules & Incident Protection
Patient appointment booking metadata is retained in accordance with NHS Records Management Code of Practice guidelines. Communication logs (SMS/Email OTP verification tokens) are automatically purged or anonymized.
NextDoorClinic maintains immutable audit logs for all administrative record views, role modifications, and certificate issuances to prevent unauthorized data access.
Contact our Information Governance Team
For privacy inquiries, Subject Access Requests (SARs), or Caldicott guardian matters, please email our Data Protection Officer at privacy@nextdoorclinic.com or write to 100XREVENUE LTD (trading as NextDoorClinic), Rainham, United Kingdom, RM13 8NZ.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.