Privacy Policy
Your privacy and confidentiality matter to us. This policy explains what personal and health information Fluence Clinic collects, how and why we use it, who we may share it with, how we protect it, and your rights under UK data protection law.
Last updated: 20 August 2026
1. About this policy
Fluence Clinic Ltd (“Fluence Clinic”, “we”, “us” or “our”) is committed to protecting personal information and respecting confidentiality.
This policy is intended to meet the transparency requirements of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and the Data (Use and Access) Act 2025.
Fluence Clinic Ltd is the data controller for the personal information processed through our UK clinic, including the website, referral pathway, patient portal, administrative systems and clinical records.
Company: Fluence Clinic Ltd, company number 16707940
CQC provider ID: 1-28071810990
ICO registration reference: ZB986429
Contact address: 107-111 Fleet Street, London, EC4A 2AB
Privacy contact: privacy@fluenceclinic.co.uk (please include “Data Protection” in the subject line)
Website: fluenceclinic.co.uk
Who does this policy cover?
This policy applies to personal information about:
- people who visit our website, use our fit checker, contact us or use live chat;
- people who make or are the subject of a self-referral or GP referral;
- patients and former patients;
- GPs, referrers and other healthcare professionals;
- carers, family members, support people, emergency contacts and people who provide collateral information;
- a person who arranges or pays for a service for somebody else;
- complainants and people making data protection requests; and
- clinicians, contractors and other professionals who apply to work with us or make a professional enquiry.
Our patient service is for adults. We do not intentionally invite referrals for people under 18. If a person under 18 contacts us, we will use only the information needed to respond, signpost or address a safeguarding concern. We ask for date of birth and may verify identity as part of referral and onboarding to confirm eligibility for the service.
2. What information do we collect?
The information we collect depends on how you use our service and what is relevant to your care. The examples below are not exhaustive, but we only collect information we need for a clear purpose.
- Contact and identity details: your name, date of birth, contact details, NHS number, GP and emergency contact details, communication preferences and any identity check needed.
- Health and care information: your referral, symptoms, medical and psychiatric history, medication, questionnaire answers, diagnoses, risk and safeguarding information, consultation notes, reports, prescriptions and relevant family history.
- Appointments, payments and administration: bookings, attendance, fees, invoices, payment status, payer details, complaints, feedback and incidents.
- Communications and technical information: emails, messages, webchat, call details and recordings, and information about use of our website and portal, such as device, cookie, access and security logs.
Health information is special category data and receives extra legal protection. Because of the nature of psychiatric care, a record may also include other sensitive information, such as ethnicity, religion, disability or sexual orientation, where it is relevant to care.
3. Where does your information come from?
We may receive information:
- directly from you, including through forms, consultations and messages;
- from your GP, referrer, pharmacist or another healthcare professional;
- from a family member, friend, carer, representative or person paying for your care; and
- from approved service providers and our website, portal, communications and security systems.
Some identity, referral, clinical and payment information is required so we can enter into or perform our contract with you, provide safe care or meet legal duties. We will tell you when information is required and why. Without it, we may be unable to assess a referral, verify identity, provide care or take payment.
Information from family, carers or others
If someone shares information to support a patient’s care, it may need to be discussed with the patient or included in their clinical record. Before disclosing it, we consider the patient’s rights alongside the privacy and safety of the person who provided it.
4.. Why do we use your information?
We use personal information to:
- answer enquiries and assess whether our service may be suitable;
- provide assessment, treatment, prescribing and follow-up care;
- keep clinical records and communicate with people involved in your care;
- manage appointments, payments and service messages;
- protect patients and others, meet legal duties and respond to safeguarding concerns;
- check identity, prevent fraud and keep our systems secure;
- handle complaints, incidents and regulatory enquiries, and improve our service; and
- obtain professional advice and manage a possible sale or reorganisation of the clinic.
5. Important uses to know about
Telephone calls and chat messages
We may record telephone calls for quality, training, safety, complaint handling and legal purposes. We tell you at the start of a recorded call. If you do not want the call recorded, tell us and we will discuss another channel where practicable. Webchat is retained as clinic correspondence.
Clinically relevant information from a call, voicemail or chat may be added to the clinical record.
Video consultations
Video consultations use an approved secure telehealth platform. We do not routinely record them. If a recording is proposed for a specific reason, we will explain this in advance.
AI-supported clinical documentation
Some psychiatrists may use an approved AI-assisted documentation tool, such as Heidi through our Semble clinical system, to help prepare draft consultation notes or letters. The clinician will tell you before using it. You can ask for it not to be used, and this will not affect your care.
The tool processes the consultation in real time to create a transcript and draft, but it does not make diagnoses, recommend treatment or make decisions about your care. No audio recording is retained. The psychiatrist reviews, corrects and approves the draft before the final note or letter is added to your clinical record and remains responsible for it.
Patient information is not used to train AI models. Any temporary transcript or draft held by the tool is deleted in accordance with our configured retention period after the final note or letter has been completed.
Qualified clinicians make final decisions about acceptance into care, diagnosis or prescribing; these decisions are not made by automated means.
Automated tools
Our website, fit checker, portal and workflows may use rules to display information, route forms, send reminders or flag a need for review. We do not make final decisions about acceptance into care, diagnosis or prescribing solely by automated means. Qualified clinicians make those decisions.
6. Who we might share information with
We share information only where it is necessary, proportionate and lawful. This may include:
- authorised clinicians and Fluence Clinic staff involved in care or running the service;
- your GP, pharmacist, referrer or another healthcare professional involved in your care;
- a representative, carer, support person or payer where you authorise this or the law permits it;
- emergency services, safeguarding bodies, regulators, courts or law enforcement where necessary or required by law; and
- professional advisers, prospective buyers or a successor if the clinic is sold or reorganised, subject to confidentiality and data protection safeguards.
We may share information without consent where it is necessary for your direct care, to protect someone from serious harm, meet a legal or regulatory duty, or deal with a legal claim. We share only what is needed.
If another person pays for care, we may share the patient name, service, amount and payment status. Paying does not give that person access to clinical information unless the patient authorises it or the law permits it.
Third-party service providers and international access
We use trusted providers to support services such as:
- clinical records, the patient portal, appointment booking, electronic prescribing and pharmacy services;
- payments and identity checks;
- video consultations, telephony, email, text messages and webchat;
- website hosting, data storage, IT support, security and AI-assisted documentation.
Where a provider processes information for us, it may use that information only to provide the agreed service, under our instructions and appropriate data-protection terms. We assess our providers and limit access to what is needed.
Some authorised providers, contractors and support personnel may securely access information from outside the UK where necessary for administrative, systems or technical support. This may include personnel working with our Australian group company or contracted technical support services.
Where a country is not covered by UK adequacy regulations, we protect the information using approved UK contractual safeguards, such as the International Data Transfer Agreement or UK Addendum, together with the required transfer assessment and security controls. You can contact us for more information about the providers handling your information or the safeguards we use.
7. How long do we keep your information?
Healthcare records are kept longer than many ordinary records because they may be needed for safe and continuous care, regulatory enquiries, complaints or legal claims.
- Clinical records: generally 20 years after the last contact, or 10 years after death, using the NHS Records Management Code of Practice 2021 as a healthcare benchmark.
- Financial records: usually six years after the relevant financial year.
- Other information: kept only for as long as needed for the purpose for which it was collected. We consider the type and sensitivity of the information, patient safety, legal and regulatory duties, and whether it is needed for a complaint, investigation or claim.
Information may be kept longer where a legal hold or other lawful reason applies. When it is no longer needed, we securely delete it, anonymise it or make it inaccessible.
8. How do we protect your information?
We treat patient information as confidential and use safeguards appropriate for sensitive healthcare data. These include encryption where appropriate, secure authentication, role-based access controls and activity logs.
Only authorised clinicians, staff, contractors and service providers may access information, and only when needed for their work. They are subject to confidentiality requirements and receive appropriate data-protection and security training. We review access regularly, remove it when no longer needed and assess providers before they handle patient information.
We maintain procedures for backups, service recovery and responding to security incidents. If a personal data breach occurs, we will investigate it promptly and notify affected people and the Information Commissioner’s Office where required by law.
9. What are your data protection rights?
Depending on the circumstances, you may have the right to:
- Access: ask for a copy of your personal information.
- Correction: ask us to correct inaccurate or incomplete information. For clinical records, we may add a correction or your statement while preserving what was recorded at the time.
- Deletion or restriction: ask us to delete information or limit how it is used in certain circumstances. We usually need to keep clinical records for care, safety and legal reasons, but we will explain the available options.
- Object: object to our use of information based on legitimate interests and object at any time to direct marketing.
- Portability: receive certain information you provided in a commonly used electronic format where the legal conditions apply.
- Withdraw consent: withdraw consent where it is the basis for a particular activity, without affecting earlier lawful use.
- Human review: ask for human involvement if a significant decision is made solely by automated means. We do not currently make clinical decisions in this way.
- Complain: raise a concern with us or the Information Commissioner’s Office.
To exercise a right, email privacy@fluenceclinic.co.uk with “Data Protection Request” in the subject line. You do not need legal wording. We may ask for proportionate information to confirm identity or authority. We normally respond within one calendar month and do not charge a fee.
We may lawfully refuse a request in limited cases and will explain why. Reasonable adjustments and alternative formats are available if needed.
10. What are our legal reasons for using your information?
Data protection law requires us to have a legal reason, called a lawful basis, whenever we use personal information. The main bases we rely on are:
- Contract: to respond to referrals, arrange and provide care, manage appointments and take payment.
- Legal obligations: to keep health records, meet regulatory duties, respond to lawful requests and safeguard people.
- Legitimate interests: to run a safe and efficient service, protect our systems, prevent fraud, record calls where appropriate, handle complaints, improve quality, obtain professional advice and manage a possible sale or reorganisation. We balance these interests against your rights.
- Vital interests: to protect someone’s life in an emergency.
- Consent: for optional marketing or another specific activity where consent is appropriate.
Health information and other sensitive information need an additional legal condition. We mainly rely on the condition that allows confidential health professionals to provide health care, under Article 9(2)(h) UK GDPR and Schedule 1 Part 1 paragraph 2 of the Data Protection Act 2018.
Other conditions may apply when necessary, including vital interests, legal claims or substantial public interest such as safeguarding.
Consent and clinical records
We do not rely on data protection consent to create or keep your clinical record. Consent to care and the professional duty of confidentiality are separate matters. Where we do rely on consent, you may withdraw it at any time without affecting earlier lawful use.
11. How do we use cookies and send marketing?
We use essential cookies for security and core website or portal functions. Optional preference, statistics or marketing technologies require consent and can be managed through our cookie controls. See our Cookie Policy for details.
Service messages about referrals, appointments, payments or care are not marketing. You can opt out of optional marketing at any time.
12. How can you contact us or make a complaint?
For privacy questions, rights requests or concerns, email privacy@fluenceclinic.co.uk and include “Data Protection” in the subject line, or write to the Data Protection Lead, Fluence Clinic Ltd, 107-111 Fleet Street, London, EC4A 2AB. We will investigate concerns without undue delay.
You may complain to the Information Commissioner’s Office at any time. You do not have to contact us first.
ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint
13. How will we tell you about changes?
We review this policy regularly and publish the current version on our website. The date the currently policy was published and became effective is available at the top of this page at all times. We will take reasonable steps to tell affected people about significant changes.
In this policy
- 1. About this policy
- 2. What information do we collect?
- 3. Where does information come from?
- 4. Why do we use information?
- 5. Communications & AI-tools
- 6. Who we might share information with
- 7. Information retention
- 8. Information protection
- 9. Your data protection rights
- 10. Legal basis for information
- 11. Cookies & marketing
- 12. Contact us & complaints
- 13. How we inform about changes
