Privacy Policy

Privacy Policy & GDPR Notice

Date: Tuesday, 30 June 2026

Legal Entity: Menopause Specialist Clinics Ltd (company number 14750789) (trading as MenoCareHealth)

ICO Registration: ZB531191 (Menopause Specialist Clinics Ltd) / ZB655798 (Mr Silas Gimba, FRCOG, Consultant Gynaecologist, MSCP)

1. Who We Are (Data Controller)

Menopause Specialist Clinics Ltd (company number 14750789) is the Data Controller. This means we decide how and why your personal data is used, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We trade as MenoCareHealth, a CQC-regulated online specialist menopause clinic (CQC Provider ID: 1-18381827157).

Registered Business Address: Littleowls, Waltham Road, Brigsley, Grimsby DN37 0RQ

ICO Registration Number: ZB531191

Data Protection Lead: Mr Silas Gimba, FRCOG, Consultant Gynaecologist, MSCP (Clinical Director, GMC: 4340441) — contactable via secretary@menocarehealth.com

  • Contact for Data Queries: secretary@menocarehealth.com

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at secretary@menocarehealth.com or write to us at the address above.

Website: menocarehealth.com

Admin voicemail & callback line: 01482 298942

Patient Call Line: 0330 043 9505

Booked Patient WhatsApp: 07822 010882

Main email: secretary@menocarehealth.com

Registered Manager / regulatory contact (CQC): sg@sgimba.net

2. What Personal Data We Collect

We collect and use the following types of personal data:

2.1 Information You Provide Directly

Identity data: Full name, date of birth, title, gender, NHS number

  • Contact data: Home address, email address, telephone number(s), emergency contact

Medical/Health data (Special Category Data): Menopausal symptoms, medical history, medication history, family history, laboratory/diagnostic test results, blood pressure, BMI, smoking status, allergies, contraceptive history, surgical history, mental health history, and any other clinical information provided during consultations

GP/Practice data: GP name, practice name, practice address and contact details (for shared care arrangements)

  • Financial data: Payment card details (processed via our third-party payment processor — we do not store full card numbers)

2.2 Information Collected Automatically

Technical data: IP address, browser type/version, device information, operating system

Usage data: How you interact with our website (menocarehealth.com), booking system, and patient portal

Communications data: Records of emails, messages sent via our patient platform, and consultation recordings/notes

3. How We Use Your Personal Data (Lawful Basis)

Purpose Lawful Basis (UK GDPR) Special Category Condition

Providing online menopause consultations and clinical care Performance of a contract (Art. 6(1)(b)) Provision of healthcare / Health & Social Care purposes (Art. 9(2)(h))

Diagnosis, assessment, and treatment recommendations Performance of a contract (Art. 6(1)(b)) Provision of healthcare (Art. 9(2)(h))

Prescribing and monitoring of HRT and associated medicines Performance of a contract / Legal obligation (Art. 6(1)(b)/(c)) Provision of healthcare (Art. 9(2)(h))

Communicating with your GP for shared care arrangements Performance of a contract (Art. 6(1)(b)) Provision of healthcare (Art. 9(2)(h))

Sending appointment reminders and follow-up messages Legitimate interests (Art. 6(1)(f)) Necessary for healthcare provision (Art. 9(2)(h))

  • Responding to complaints or queries Legal obligation / Legitimate interests (Art. 6(1)(c)/(f)) Necessary for legal claims / healthcare (Art. 9(2)(h)/(f))

Improving our services and clinical outcomes Legitimate interests (Art. 6(1)(f)) — (anonymised/aggregated data only)

Complying with legal and regulatory obligations (CQC,ICO, HMRC) Legal obligation (Art. 6(1)(c)) Necessary for legal claims / substantial public interest (Art. 9(2)(g)/(f))

4. Third-Party Tools & Data Processors

To provide our online care, we use a small number of trusted third-party suppliers (called “Processors” under data protection law). We have contracts in place to make sure they only use your data for providing services to us and keep it secure.

Processor Purpose Data Transferred Security

  • Pabau (pabau.com) Clinical records (EMR), patient management, online booking, consultation notes, messaging, billing Full identity, contact, medical data, appointment history Appropriate contractual, access-control and technical safeguards are applied.
  • Microsoft 365 / SharePoint (Microsoft UK) Email communications, document storage, governance evidence files Identity, contact, clinical correspondence, policies Appropriate contractual, access-control and technical safeguards are applied.

Video consultation platform (a secure, encrypted video consultation platform provided through our clinical system (Pabau)) Secure online video consultations Identity, limited clinical discussion data (transient — not recorded unless consented) Appropriate contractual, access-control and technical safeguards are applied.

  • Stripe (stripe.com/gb) Payment processing Name, payment card data (tokenised) Appropriate contractual, access-control and technical safeguards are applied.
  • WordPress / Hostinger (website and hosting infrastructure) Hosting of menocarehealth.com Technical data (IP, browsing) Appropriate contractual, access-control and technical safeguards are applied.
  • Google Workspace (where in use) Internal communications, scheduling Limited identity and contact data Appropriate contractual, access-control and technical safeguards are applied.

Pharmacy and dispensing: Where a prescription is clinically appropriate, relevant identity, prescription and delivery information may be shared with CloudRx or another patient-nominated regulated pharmacy. The dispensing pharmacy acts under its own legal and professional obligations. Data Transfers outside the UK: Sometimes a supplier may store or access information outside the UK. If that happens, we make sure the right legal safeguards are in place (for example, a UK International Data Transfer Agreement, Standard Contractual Clauses, or an adequacy decision). Contact us if you want more detail.

5. How We Store & Protect Your Data

We take protecting your information seriously. We use practical security measures to help keep your data safe, including: Confidential clinical information sent by email is shared through Beyond Encryption / BeSecureMail or another approved secure route, with identity checks and an audit trail where appropriate.

  • Appropriate contractual, access-control and technical safeguards are applied.

Multi-factor authentication on our clinical and administrative systems

Role-based access controls (so only authorised clinicians/staff can access medical records)

Regular security checks and staff training

Secure deletion processes

Retention Periods:

Medical records (clinical notes, consultation summaries, prescriptions): Retained for 8 years after the last episode of care (in line with GMC guidance) or until the patient’s 25th birthday if younger, whichever is longer

  • Financial records: Retained for 6 years plus current financial year (HMRC requirement)

Correspondence (GP letters, shared care agreements): Retained for 8 years

Marketing/consent preferences: Retained until you withdraw consent or opt out

Website analytics: Retained for a maximum of 26 months

After the retention period, all data will be securely deleted or anonymised.

GMC registration (Clinical Director): Mr Silas Gimba, FRCOG, Consultant Gynaecologist, MSCP (GMC: 4340441)

6. Your Rights Under UK GDPR

As a data subject, you have the following rights:

Right What It Means

Right to be informed You have the right to be told how we use your data (this Privacy Policy fulfils this).

Right of access (Subject Access Request) You can request a copy of the personal data we hold about you.

Right to rectification You can ask us to correct inaccurate or incomplete data.

Right to erasure (‘right to be forgotten’) You can request deletion of your data, subject to legal/regulatory retention obligations.

Right to restrict processing You can ask us to limit how we use your data in certain circumstances.

Right to data portability You can request a machine-readable copy of data you provided, for transfer to another service.

Right to object You can object to processing based on legitimate interests or direct marketing.

Rights in relation to automated decision-making You have the right not to be subject to solely automated decisions with significant effects.

To exercise any of these rights, please contact us at secretary@menocarehealth.com. We will respond within one calendar month (extendable by two months for complex requests).

No fee usually required — but we may charge a reasonable fee if a request is manifestly unfounded or excessive.

7. Sharing Your Data

  • We may share your personal data in the following circumstances:

With your GP / primary care provider: for shared care and clinical safety. Appropriate contractual, access-control and technical safeguards are applied. We will tell you before contacting your GP unless it’s an emergency or there is another serious safety reason.

With other healthcare providers: if you ask us to, or where you give clear consent for a referral or coordinated care. Appropriate contractual, access-control and technical safeguards are applied.

With regulatory bodies: such as the CQC, ICO, or GMC, when we have to by law or regulation. Appropriate contractual, access-control and technical safeguards are applied.

With our processors: as listed in Section 4, only where needed to run our service and under contract. Appropriate contractual, access-control and technical safeguards are applied.

For legal compliance and safety: for example, if required by law, a court order, or to protect someone’s vital interests. Appropriate contractual, access-control and technical safeguards are applied.

  • We will never sell your personal data to third parties.

8. Cookies & Website Tracking

Our website (menocarehealth.com) uses essential cookies for operation and optional cookies for analytics and functionality. Optional analytics and marketing tags are intended to load only after the relevant consent has been given. You can manage your cookie preferences on our website via the cookie consent banner.

  • You can manage your cookie preferences using the cookie consent banner on our website.

9. Automated Decision-Making

We do not use solely automated decision-making (including profiling) for clinical decisions. All treatment decisions are made by Mr Silas Gimba, FRCOG, Consultant Gynaecologist, MSCP following an individual clinical assessment.

10. Complaints About Data Handling

If you are unhappy with how we have handled your personal data, please contact us first at secretary@menocarehealth.com so we can try to put things right.

  • You can also complain to the Information Commissioner’s Office (ICO):
  • Information Commissioner’s Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Tel: 0303 123 1113

Website: ico.org.uk

11. Changes to This Policy

  • We may update this Privacy Policy from time to time. If we make important changes, we will let you know by email or on our website. The date of the latest revision is shown at the top of this document.