Legal

Privacy Notice

How we collect, use, and protect your personal data in accordance with UK data protection law.

ICO Registration: ZA303314  ·  Data Controller: Mr Bijan Khoubehi  ·  Last updated: 4 August 2026

Who We Are

London Urology Specialists (representing Mr Paul Cathcart, Professor Mark Emberton, Mr Bijan Khoubehi, Honorary Associate Professor Jeremy Ockrim, Mr Richard Nobrega, Mr Anthony Noah, Professor Clement Orczyk and Mr Alberto Coscione, subsequently referred to as 'we', 'us' or 'our') gather and process your personal information in accordance with this privacy notice and in compliance with the relevant data protection regulation and laws. This notice provides you with the necessary information regarding your rights and our obligations, and explains how, why, and when we process your personal data.

As a practice of our size, London Urology Specialists is not legally required to appoint a statutory Data Protection Officer. Data protection matters are overseen by our Data Controller, Mr Bijan Khoubehi, whose contact details are below.

Contact for data & privacy queries

Mr Bijan Khoubehi  ·  18 Devonshire Street, London, W1G 7AQ
Tel: 0300 302 0202  ·  Email: info@londonurologyspecialists.co.uk

Information We Collect

We process your personal information to meet our legal, statutory and contractual obligations and to provide you with our clinical services. We will never collect any unnecessary personal data from you and do not process your information in any way, other than as specified in this notice.

Personal data we collect

  • Name & date of birth
  • Home address
  • Personal and/or business email address
  • Home & mobile telephone numbers
  • Medical insurance policy details
  • Bank/card details when payments are taken
  • GP and other healthcare professional contact details (only with your consent)

Special category data

We also collect your health and specific medical information (special category data) to allow us to practise safely on your behalf. This is the most sensitive data we hold and is treated with the highest level of protection.

We collect this information through online forms, health questionnaires, your registration document, letters and emails from other clinicians, investigation results, and our own clinical notes and correspondence.

Telephone calls

Calls to and from our practice are recorded for training, quality assurance, and accurate record-keeping. You will be informed that the call is being recorded at the start of each call. Recordings are stored securely, retained only for as long as necessary for these purposes, and accessed only by authorised staff.

Data received from third parties

We also receive personal data about you from sources other than you directly — typically your GP or referring clinician, your medical insurer, other treating specialists, hospital test and imaging providers, and (where relevant) your next of kin. This data is shared with us to enable safe, co-ordinated clinical care, in accordance with Article 14 UK GDPR.

How We Use Your Personal Data

We take your privacy very seriously and will never disclose or share your data without your consent, unless required to do so by law. We only retain your data for as long as is necessary and for the purpose(s) specified in this notice. You are free to withdraw your consent at any time.

Communications with your GP and other relevant specialists to maintain coordinated care

Request forms for tests and scans, providing clinical context to allow accurate interpretation

Arrangement of hospital admissions and surgical procedures at partner facilities

Supplying clinical letters to hospitals as required by CQC regulations

Lawful Bases for Processing

Under UK GDPR we must have a valid legal basis to process your personal data. The bases we rely on are:

Contract

To deliver the clinical care you have engaged us to provide — including consultations, investigations, treatment, billing and follow-up.

Legal obligation

To comply with our statutory duties — for example, retaining financial records under UK tax law and meeting CQC clinical-record requirements.

Legitimate interests

For activities that are necessary to run the practice and that do not override your rights — such as communicating with your referring GP, recovering unpaid invoices, and protecting our systems against fraud or misuse.

Consent

Where we rely on your explicit agreement — for example, sending appointment reminders by text or email, or sharing information with parties other than your treating clinicians. You can withdraw consent at any time.

Health data — Article 9(2)(h)

For your medical records and other special category data, we rely on Article 9(2)(h) UK GDPR: processing necessary for the provision of health care by a regulated health professional, supported by the Data Protection Act 2018.

Children & Adolescents

Our Adolescent Urology service treats young people under the age of 18. Where a patient is a child, we process their personal and clinical data on the same basis as for adults — primarily Article 9(2)(h) UK GDPR for the provision of health care — but with additional safeguards:

Appointments are arranged by a parent or person with parental responsibility, who provides consent to treatment and to the processing of the child's data.

Where a young person is judged to have sufficient understanding (Gillick competence), their own views and confidentiality are respected as far as is clinically appropriate.

Children's records are held with the same security, retention rules and access controls as adult records, and are never used for marketing.

Once a patient reaches the age of 18 they can request access to and control over their own records directly.

Automated Decision-Making

We do not make decisions about you based on solely automated processing, and we do not use your data for profiling. All clinical decisions are made by a qualified clinician. Where we use AI-assisted tools (such as Heidi Health for consultation transcription), the output is reviewed by your treating clinician before being added to your record.

Your Rights

You have the right to access any personal information that we process about you and to request information about:

What personal data we hold about you

The purposes and legal basis for processing

Recipients to whom data has been disclosed

How long we intend to store your data

The right to correct or erase your data

The right to restrict processing or object to direct marketing

The right to data portability (receiving your data in a structured, commonly used format)

The right to withdraw consent at any time, without affecting the lawfulness of prior processing

If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request, to ensure your data is protected.

How to exercise your rights

To make a Subject Access Request or exercise any other right above, write to us at info@londonurologyspecialists.co.uk or by post to 18 Devonshire Street, London, W1G 7AQ. We will respond within one calendar month of receiving your request. We may extend this by a further two months for complex requests and will let you know if so. There is normally no charge, but we may charge a reasonable fee or refuse manifestly unfounded or excessive requests.

Sharing Your Information

We do not share or disclose any of your personal information without your consent, other than for the purposes specified in this notice or where there is a legal requirement. All third parties acting on our behalf process your data in accordance with our instructions and comply fully with data protection law.

Hospitals & Medical Centres

We use external hospitals and medical centres to perform surgeries and treatments. We share relevant information with them to enable your care. Facilities include:

Chelsea and Westminster, UCH, Imperial, The London Clinic, The Princess Grace Hospital, The Harley Street Clinic, The Hospital of St John and Elizabeth, The Lister, Chelsea Outpatient Centre, Welbeck, The Cromwell, Cleveland Clinic London, Guys and St Thomas.

WeType – Transcription

Encrypted digital dictation is transcribed and uploaded directly to our patient database. Innovation Centre, Innovation Drive, King's Lynn PE30 5BY  ·  info@wetype.uk

Heidi Health – AI Clinical Transcription

AI-powered clinical transcription used to assist with documentation during consultations. All data is stored within the UK and processed within the UK or EEA. Patient data is pseudonymised and is not used to train or improve AI models. Heidi Health Ltd complies with UK GDPR and the Data Protection Act 2018. 140 Goswell Road, London EC1V 7DY  ·  support@heidihealth.com  ·  Privacy Policy

Healthcode – Medical Insurance Invoicing

We use Healthcode to submit invoices to private medical insurers and to manage related communications and payments. When you are claiming treatment under a private medical insurance policy, we share the information necessary to process your claim — including your name, date of birth, policy details, treatment dates, procedure codes and invoice amount — with Healthcode and the relevant insurer. Healthcode is a UK-based clearing service for private healthcare and processes data in accordance with UK GDPR.  ·  healthcode.co.uk

Worldpay – Card Payment Processing

We use Worldpay to process card payments for consultations, procedures, and other services. When you pay by card, Worldpay handles your payment details directly through PCI-compliant infrastructure — we do not store full card numbers on our systems. Limited information (your name, billing address, transaction amount, and a reference) is shared with Worldpay to complete the transaction. Worldpay (FIS) is a UK-registered payment service provider regulated by the Financial Conduct Authority.  ·  worldpay.com

Kimberlee & Co – Accounting

Produce our management accounts. They have access to financial data which may include clinical activity descriptions. Peacock House, The Green, Cleeve Prior, Evesham, Worcs, WR11 8LE  ·  nick@kimberlee.co.uk

e4mationIT – IT Maintenance & Support

IT maintenance, support, and data backup services. May access systems containing patient data during technical support. 81 Malmains Way, Beckenham, Kent BR3 6SF  ·  info@e4mationit.co.uk

DGL Practice Manager – Patient Management Software

We use DGL Practice Manager as our clinical patient management system to record consultations, appointments, correspondence, and billing. The software runs on our own secure server in the UK, managed by our IT provider. DGL may access the system from time to time to provide software support, updates, and technical assistance, during which they may have access to patient data. All access is governed by their data processing agreement and UK GDPR.  ·  dglpm.co.uk

Zoom – Video Consultations

We use Zoom to deliver remote video consultations with patients. During a consultation, Zoom processes video, audio, and any chat messages exchanged between you and your consultant. Calls are encrypted in transit and we do not record consultations unless you have specifically agreed in advance. Zoom Video Communications, Inc. is a US-based provider; transfers of personal data outside the UK are protected by Standard Contractual Clauses and the UK International Data Transfer Addendum, in accordance with UK GDPR.  ·  zoom.us

Microsoft 365 – Email & Office Productivity

We use Microsoft 365 for our day-to-day email, calendars, and document handling. Personal data contained in emails and attachments is processed and stored within Microsoft's UK and EU data centres. Microsoft Corporation acts as a data processor on our behalf under the Microsoft Products and Services Data Protection Addendum, which incorporates UK GDPR-compliant safeguards.  ·  microsoft.com/privacy

Egress – Secure Email & Encryption

We use Egress to send and receive emails containing patient identifiable or clinical information securely. Egress encrypts message content in transit and at rest, ensuring that sensitive correspondence between our clinical team, patients, and other healthcare providers is protected. Egress Software Technologies Ltd is a UK-based provider and processes data in accordance with UK GDPR and the Data Protection Act 2018.  ·  egress.com

WhatsApp Business (Meta) – Patient Enquiries

If you choose to contact London Urology Specialists via the WhatsApp link available on our website, we use WhatsApp Business to receive and respond to your enquiry.

We ask that you only provide the information necessary for us to understand your enquiry and avoid sending detailed medical information or other sensitive personal data via WhatsApp. Where it is necessary to exchange sensitive or confidential information, we will ask you to continue the conversation through a more secure communication channel.

Messages sent via WhatsApp are end-to-end encrypted in transit. However, WhatsApp Ireland Limited (a Meta company) processes certain personal data associated with your use of the service, including your telephone number, profile information (where provided), message timestamps and delivery information, in accordance with its own Privacy Policy.

We process any personal data you provide through WhatsApp for the purpose of responding to your enquiry, answering your questions and, where appropriate, arranging an appointment or directing your enquiry to the appropriate member of our team.

Our lawful basis for processing this information is Article 6(1)(b) UK GDPR (processing necessary to take steps at your request prior to entering into a contract) and, where applicable, Article 6(1)(f) UK GDPR (our legitimate interests in responding to enquiries and administering our services).

Please note that WhatsApp is not intended for the transmission of sensitive health information. We ask that you do not send detailed medical information, copies of identification documents or payment information via WhatsApp unless specifically requested by us through an appropriate secure method.

Further information about how WhatsApp processes your personal data is available in WhatsApp's Privacy Policy: whatsapp.com/legal/privacy-policy.

Doctify – Patient Reviews

We invite patients to leave feedback on their experience via Doctify, an independent patient review platform. When you submit a review, Doctify processes your name (or chosen alias), the consultant you saw, and your free-text comments, in accordance with their own privacy policy. Reviews are then displayed on our website via Doctify's embedded carousel widget. Participation is entirely voluntary. Doctify Ltd is a UK-based company and processes data in accordance with UK GDPR.  ·  doctify.com

Formspree – Contact Form Processing

Our website contact form and consent form submissions are processed by Formspree, a third-party form handling service. When you submit a form on our website, your data (name, email, phone number, and message content) is transmitted securely to Formspree and forwarded to us. Formspree processes data in accordance with their privacy policy and does not use your data for any other purpose. Form submissions are also protected by Google reCAPTCHA to prevent automated spam abuse; this involves Google processing limited technical data (such as IP address and browser interaction signals) subject to the Google Privacy Policy and Terms.  ·  formspree.io

Netlify – Website Hosting

Our website is hosted by Netlify Inc., which delivers our pages globally through a content delivery network. In the course of serving pages, Netlify processes limited technical data including visitor IP addresses, request timestamps, user-agent strings, and referring URLs in its server access logs. Netlify Inc. is a US-based provider; transfers of personal data outside the UK are protected by Standard Contractual Clauses and the UK International Data Transfer Addendum, in accordance with UK GDPR. Netlify does not use visitor data for advertising or profiling.  ·  netlify.com/privacy

CCI Credit Management – Debt Recovery

Where an invoice remains unpaid after our standard reminder process, we may instruct CCI Credit Management to recover the outstanding debt on our behalf. In these cases we share only the information necessary for them to do so — typically your name, contact details, and the invoice amount and reference. No clinical or health information is disclosed. Our legal basis for this disclosure is our legitimate interest in recovering money owed to us.  ·  ccicm.com

Cookies & Website Technology

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners.

Our website uses the following types of cookies and similar technologies:

Essential cookies

Required for the website to function correctly (e.g. form submissions, navigation). These cannot be disabled.

Analytics & performance

We use Google Analytics 4 (GA4) and Google Tag Manager to understand how visitors use our website. These services set cookies that collect pseudonymised information about your visit — for example, the pages you view, how long you spend on the site, the type of device and browser you use, and a coarse geographic location. We use this data in aggregate to improve our content and services. We do not use it to identify you personally or to advertise to you. You can opt out by installing the Google Analytics Opt-out Browser Add-on, or by disabling cookies in your browser.

Third-party services

Our website uses Google Fonts for typography, Formspree for form processing, Google Maps (embedded on our contact page), and the Doctify review widget (embedded on our homepage). These services may set their own cookies and process data in accordance with their own privacy policies.

You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. Please note that disabling cookies may affect the functionality of some parts of this website.

For more information about cookies and how to manage them, visit www.aboutcookies.org.

Safeguarding Measures

We take your privacy seriously and take every reasonable measure and precaution to protect and secure your personal data. We have several layers of security in place including SSL/TLS encryption, pseudonymisation, restricted access, IT authentication, firewalls, and antivirus and malware protection.

Wherever possible, your personal data is stored within the UK or EEA. Some of the third-party services we use (for example Zoom for video consultations, and certain Microsoft 365 functions) may involve transfers of personal data outside the UK. Where this happens, transfers are protected by appropriate safeguards such as the UK International Data Transfer Addendum (IDTA), the EU Standard Contractual Clauses (SCCs), or transfers to countries the UK has determined offer an adequate level of protection. We may also transfer your records outside the EU where this is necessary for your continuity of care — for example if you reside abroad for part of the year.

Data breaches. In the unlikely event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with our obligations under UK GDPR. We will also report qualifying breaches to the Information Commissioner's Office (ICO) within 72 hours.

How Long We Keep Your Data

We only ever retain personal information for as long as is necessary and have strict review and retention policies in place.

6 years

Basic personal data (name, address, contact details) — required under UK tax law

8 years

Medical records — from the date of last contact with us

You are not obligated to provide your personal information to us; however, as this information is required to arrange investigations, treatment and provide safe co-ordinated clinical care, we may not be able to offer our services without it.

Lodging a Complaint

We only process your personal information in compliance with this privacy notice and in accordance with relevant data protection laws. If you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, you have the right to lodge a complaint with the supervisory authority.

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113  ·  www.ico.org.uk

Changes to This Notice

We keep our privacy notice under regular review and may update it from time to time to reflect changes in our practice, the services we use, or relevant data protection law. The "Last updated" date at the top of this page reflects the most recent revision. Where changes are material — for example, a new processor, a change in how we use your data, or a change in your rights — we will bring them to your attention through our website and, where appropriate, by direct communication. We recommend checking this page periodically to stay informed.