Better healthcare booking,
almost here.
EveryClinic brings trusted UK clinics together in one place. Search, compare and book appointments in minutes. We're putting the finishing touches to it now.
EveryClinic brings trusted UK clinics together in one place. Search, compare and book appointments in minutes. We're putting the finishing touches to it now.
How EveryClinic collects, uses and protects your personal data
Version 2.0 (Model B — payments marketplace) · Supersedes v1.0 · Last updated: [date] · Draft — for solicitor review
What changed in this version
Payment is now taken through the Platform via our payment provider (Stripe), so this policy now describes payment-data processing and names Stripe as a recipient. The health-data legal basis now pairs Article 6 with Article 9; retention now points to our Data Retention Policy; and a data-protection complaints route and clearer children's-data basis have been added.
EveryClinic Ltd ("EveryClinic", "we", "us") is the data controller of personal data processed through the EveryClinic website and app (the "Platform"). Our registered office is at 2nd Floor College House, 17 King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE, and our ICO registration number is [ICO registration number].
This policy explains what personal data we collect from Patients and Clinic users, how we use it, who we share it with, and your rights under the UK GDPR and the Data Protection Act 2018.
This policy covers the Platform only. If you book an appointment, the Clinic will separately act as controller of the personal and health data you provide directly to it for your care — please also read the relevant Clinic's own privacy notice.
From Patients
From Clinics
Some information you provide when searching or booking — for example, the type of specialist or treatment you search for — can reveal something about your health, which UK GDPR treats as "special category data" requiring extra protection.
To process this data we rely on a lawful basis under Article 6 (usually performance of our contract with you to provide the Platform and your booking, or our legitimate interests in operating the Platform) together with a condition under Article 9. Our Article 9 condition is normally your explicit consent, which you give when you choose to search or book for health-related services.
You can withdraw consent at any time (see section 9). We do not use health-related search or booking data for targeted advertising, and we do not sell it.
We do not receive or store your clinical records, consultation notes or treatment history — those are held by the Clinic, as the appropriate data controller for your care.
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract with you |
| Processing and confirming Bookings, and sharing necessary details with the chosen Clinic | Performance of a contract with you |
| Taking and processing payment for your Booking through our payment provider | Performance of a contract with you |
| Responding to support queries and complaints | Legitimate interests (resolving your query) / contract |
| Improving and securing the Platform (analytics, fraud prevention) | Legitimate interests |
| Sending service messages (booking confirmations, reminders) | Performance of a contract / legitimate interests |
| Sending marketing communications | Consent (you can opt out at any time) |
| Processing special category (health-related) data as described in section 3 | Explicit consent (Article 9), together with performance of a contract or legitimate interests (Article 6) |
| Complying with legal and regulatory obligations | Legal obligation |
We do not sell your personal data, and we do not share special category (health-related) data with advertisers or data brokers.
We do not receive or store your full card details — those are handled directly by our PCI-DSS compliant payment provider (Stripe).
Where a service provider (including our payment provider or hosting provider) is located outside the UK, we ensure an appropriate safeguard is in place before your data is transferred — such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses, or reliance on a UK adequacy determination.
We use essential cookies to operate the Platform (e.g. keeping you logged in), and, with your consent, analytics and marketing cookies to understand usage and improve our service. You can manage cookie preferences through our cookie banner and your browser settings.
Full details of the cookies we use are set out in our separate Cookie Policy.
We keep personal data only for as long as necessary for the purposes described in this policy, in line with our Data Retention & Third-Party Sharing Policy. When a retention period ends, we delete or anonymise the data. You can ask us to delete your data earlier (section 9), unless we are required to keep it by law.
Under UK data protection law, you have the right to: (a) access the personal data we hold about you; (b) have inaccurate data corrected; (c) request erasure in certain circumstances; (d) restrict or object to certain processing; (e) receive your data in a portable format; and (f) withdraw consent at any time, without affecting processing carried out before withdrawal.
To exercise any of these rights, contact us at dataprotection@everyclinic.com. We will respond within one month, as required by law.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to resolve it directly first.
The Platform is intended for users aged 18 and over, and we do not knowingly collect personal data directly from anyone under 18.
Where you book on behalf of a child or dependant, you (not the child) are the account holder and confirm you are authorised to provide their information. We process that information only to facilitate the Booking you make and do not use it for any other purpose.
We use appropriate technical and organisational measures (encryption in transit, access controls, and staff training) to protect your data against unauthorised access, loss or misuse.
Your payment card details are captured and processed by our PCI-DSS compliant payment provider (Stripe) and are not stored on EveryClinic's own systems.
We may update this policy from time to time. We will post the updated version with a new "last updated" date, and notify you of material changes by email or in-app notice where appropriate.
Data controller: EveryClinic Ltd, 2nd Floor College House, 17 King Edwards Road, Ruislip, London, United Kingdom, HA4 7AE
ICO registration number: [ICO registration number]
Data Protection Officer: Lakhbir Dhillon, contactable at dataprotection@everyclinic.com