PRIVACY POLICY
Data Controller
DW Dietetics LTD
Privacy Policy
DW Dietetics Ltd respects your privacy and is committed to protecting your personal information. This notice explains what information we collect, why we use it, who we may share it with, how long we keep it and your rights.
1. Who we are
DW Dietetics Ltd is the data controller for the personal information used to provide our private dietetic and nutrition services.
Company number: 15938051
Registered office: ask for detials
Data protection contact: Daniel Webb
Email: danieljameswebb433@gmail.com
2. Information we collect
We may collect your name, date of birth, contact details, address, emergency contact details, appointment information, referral details, payment and insurance information, and correspondence with us.
To provide dietetic care, we may also collect health information such as diagnoses, symptoms, medical history, medications, test results, weight and body measurements, dietary intake, allergies, activity and training information, treatment plans and clinical progress. Health information is special category personal data and receives additional protection.
We may receive information directly from you or from a person involved in your care or funding, such as a parent or guardian, GP, consultant, other healthcare professional, insurer or authorised representative.
3. Why we use your information and our lawful bases
We use personal information to respond to enquiries, arrange appointments, assess your needs, provide dietetic care, prepare plans and clinical correspondence, communicate with you, manage referrals, process payments and insurance claims, maintain appropriate clinical and business records, handle complaints, protect legal rights and meet professional, tax and regulatory requirements.
For ordinary personal information, we mainly rely on processing that is necessary to take steps at your request or perform our contract with you, compliance with legal obligations, and our legitimate interests in safely operating and protecting the practice.
For health information, we mainly rely on Article 9(2)(h) of the UK GDPR because the information is necessary for the provision and management of health care by registered health professionals who are subject to professional confidentiality. Where relevant, we may also process information for the establishment, exercise or defence of legal claims.
We do not normally rely on consent to keep the core records needed to provide care. We will ask for consent where a use is optional, such as marketing or sharing information with someone who is not otherwise involved in your care or funding.
4. Who we may share information with
We only share information where there is a valid reason and limit it to what is necessary. This may include dietitians and authorised staff working for DW Dietetics Ltd, your GP, consultant or other healthcare professional, a referring organisation, an insurer or funding body, an accountant or professional adviser, IT and communications providers acting on our instructions, and regulators or authorities where required by law.
We may share relevant information without prior permission where this is necessary to protect you or another person from serious harm, to meet safeguarding duties, or where disclosure is required by law. We do not sell personal information.
5. Systems and service providers
We currently use Google services for email, document storage and spreadsheets; WhatsApp for agreed communications and support; a Calendly-type service for booking; IONOS for website hosting and contact forms; banks and accounting services for payments and financial records; and insurer or referrer systems where applicable. These providers may act as data processors or separate controllers depending on the service.
Some providers may process information outside the United Kingdom. Where this happens, we use providers and contractual arrangements intended to provide an appropriate level of protection, such as an adequacy regulation or UK-approved transfer safeguards.
6. How we protect information
We use access controls, individual user accounts, passwords, two-step verification, restricted sharing, device security, backups and data-minimisation measures. Access is limited to people who need the information for their role.
Please avoid sending unnecessary medical detail through website forms or booking forms. Email and messaging can never be guaranteed to be completely secure, so we take care to minimise sensitive information and verify recipients before sharing.
7. How long we keep information
We keep information only for as long as it is needed for care, professional accountability, legal claims, tax and regulatory requirements. Our standard periods are:
• Adult clinical records: 8 years after the last clinical contact.
• Children’s clinical records: until the 25th birthday, or the 26th birthday where treatment ended at age 17.
• Unsuccessful enquiries that do not proceed to care: 12 months after the last contact.
• Routine appointment and administrative messages: 12 months after the end of care, unless they form part of the clinical record.
• Company accounting and tax records: at least 6 years from the end of the financial year to which they relate.
Records may be retained longer where there is a complaint, legal claim, safeguarding concern, regulatory requirement or another documented reason. Information is securely deleted or destroyed when the retention period ends.
8. Your rights
Depending on the circumstances, you may have the right to ask for access to your information, correction of inaccurate information, restriction of use, objection to certain uses, data portability, or deletion. These rights are not absolute, and we may need to retain clinical or financial information where there is a lawful reason to do so.
To exercise a right, contact Daniel Webb at danieljameswebb433@gmail.com. We may need to confirm your identity. We normally respond to valid requests within one month.
9. Marketing
We will only send optional marketing messages where we have an appropriate lawful basis, normally your consent. You can unsubscribe at any time. Service messages about your care, appointments or payments are not marketing.
10. Website cookies and embedded services
Our website uses essential technologies needed to operate the site and may use optional third-party content, such as embedded maps, subject to your cookie choices. You can manage optional cookies through the website cookie settings and your browser.
11. Complaints
Please contact us first if you are concerned about how we use your information. You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator.
12. Changes to this notice
We may update this notice when our services, systems or legal obligations change. The latest version will be published on our website.
Last updated: 30 July 2026.