You are here:
Data Protection

Standard Data Privacy Notice

How Medocta collects, processes, stores, and protects your personal and health information in compliance with UK GDPR and healthcare regulations.

Last Updated: March 29, 2026

UK GDPR Compliant

Governed by UK data protection law and GDPR regulations

Encrypted at Rest

All data encrypted in transit and at rest with industry-standard protocols

NHS Standards

Compliant with NHS Data Security and Protection Toolkit

Your Control

Full rights to access, correct, delete, and port your data

Medocta is committed to protecting your privacy and ensuring the security of your personal and health data. This Data Privacy Notice explains how we collect, use, store, and protect your information when you use our healthcare marketplace platform, including our weight management, dietitian, and care coordination services. We process your data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable NHS information governance standards.

1. Applicable Law

This Data Privacy Notice is governed by English law. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) to ensure your personal data is handled lawfully, fairly, and transparently.

Where our services are provided through or funded by the National Health Service (NHS), we also comply with the NHS Data Security and Protection Toolkit, the Caldicott Principles, and the Common Law Duty of Confidentiality.

Medocta acts as the Data Controller for personal data processed through our platform unless otherwise stated. Where we process data on behalf of healthcare organisations or NHS bodies, we may act as a Data Processor under a Data Processing Agreement.

Medocta is registered with the Information Commissioner's Office (ICO) under registration reference C1898621.

2. Categories of Personal Data

We may collect and process the following categories of personal data depending on the services you use:

Personal Information

  • • Full name, date of birth, gender, and title
  • • Home address and postcode
  • • Email address and telephone number
  • • NHS number (where applicable)
  • • Emergency contact details
  • • GP practice name and address
  • • Ethnicity (for health equity monitoring)

Health & Clinical Data

  • • Medical conditions and diagnoses
  • • Current medications and prescriptions
  • • Body measurements (weight, BMI, blood glucose, blood pressure)
  • • Dietary information and meal plans
  • • Wellbeing assessment scores (PHQ-9, GAD-7, SWEMWBS)
  • • Treatment notes and care plans
  • • Lab test results
  • • Safeguarding information (where relevant)

Technical & Usage Data

  • • Device type, operating system, and browser information
  • • IP address and approximate location
  • • Pages visited, features used, and session duration
  • • Cookies and similar tracking technologies
  • • Referral source and navigation paths

Communication & Interaction Data

  • • Messages exchanged with healthcare professionals
  • • Video and audio call records (with consent)
  • • Appointment booking and attendance history
  • • Notification preferences
  • • Feedback, reviews, and support correspondence

Payment & Billing Data

  • • Billing name and address
  • • Payment card details (processed securely via Stripe/Paystack)
  • • Subscription and invoice history
  • • Insurance or corporate billing references

Pseudonymised & Aggregated Data

  • • De-identified data shared with NHS bodies for service administration and commissioning
  • • Aggregated analytics for service improvement and reporting
  • • Anonymised research datasets (with appropriate approvals)

3. Uses Made of Your Information

We use your personal data for the following purposes:

Healthcare Service Delivery

  • • Delivering weight management, dietitian, and care coordination services
  • • Matching you with appropriate healthcare professionals
  • • Managing appointments, consultations, and follow-ups
  • • Creating and maintaining treatment plans, meal plans, and care records
  • • Monitoring health outcomes and wellbeing assessments

NHS-Funded Service Provision

  • • Verifying eligibility for NHS-funded programmes
  • • Reporting outcomes to commissioning bodies
  • • Coordinating with GP practices and referral pathways
  • • Complying with NHS contractual reporting requirements

Platform Operations

  • • Managing your account and authentication
  • • Processing payments and subscriptions
  • • Sending service notifications and reminders
  • • Providing customer support
  • • Ensuring platform security and preventing fraud

Improvement & Research

  • • Improving our services and user experience
  • • Conducting anonymised clinical audits and quality assurance
  • • Supporting approved research (only with your explicit consent or in anonymised form)
  • • Generating aggregate statistics for health system reporting

4. Disclosure of Your Information

We may share your personal data with the following parties only where there is a lawful basis and legitimate need to do so:

Who We May Share Your Data With

  • Healthcare professionals — Dietitians, care professionals, and other clinicians involved in your direct care through our platform
  • NHS bodies and commissioners — Including Integrated Care Boards (ICBs), GP practices, and referral services where required for NHS-funded care
  • Corporate employers — Where your organisation has arranged services on your behalf (limited to programme participation status only, not clinical data)
  • Payment processors — Stripe and Paystack for secure payment processing (they do not have access to your health data)
  • Technology service providers — Cloud hosting, email delivery, and analytics providers who process data on our behalf under strict Data Processing Agreements
  • Regulatory and legal authorities — Where required by law, court order, or to protect vital interests
  • Emergency services — Where there is an immediate risk to life or serious harm

Important: We will never sell your personal data to third parties. We will never share your health data for marketing purposes. All third-party processors are contractually bound to process your data only on our instructions and in compliance with UK GDPR.

5. Where Your Data is Stored

Your personal data is stored on secure servers hosted within the United Kingdom and the European Economic Area (EEA). We use industry-leading cloud infrastructure providers that maintain ISO 27001 certification and comply with NHS information governance requirements.

Where it is necessary to transfer data outside the UK/EEA (for example, to provide technical support), we ensure that appropriate safeguards are in place, including:

  • • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs)
  • • Adequacy decisions by the UK Secretary of State or European Commission
  • • Binding Corporate Rules where applicable

All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256 encryption. Database backups are also encrypted and stored in geographically separate UK/EEA data centres for disaster recovery.

6. Data Retention Period

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods include:

Data TypeRetention PeriodBasis
Clinical/health records8 years after last treatmentNHS Records Management Code of Practice
Account informationDuration of account + 2 yearsLegitimate interest
Payment and billing records7 yearsHMRC tax obligations
Communication records3 years after last interactionLegitimate interest / complaint resolution
Technical/cookie data13 months maximumPECR / consent
Safeguarding records25 years or indefinitelyNHS safeguarding retention guidance

When retention periods expire, data is securely deleted or anonymised so that it can no longer be linked to you.

7. NHS Number and Personal Demographic Service

Where you are referred to Medocta through the NHS or use NHS-funded services, we may use your NHS number to identify you accurately and coordinate your care. The NHS number is a unique 10-digit identifier used across the health and social care system in England.

We may access the Personal Demographic Service (PDS) — a national electronic database maintained by NHS England — to verify and update your demographic details (such as name, address, date of birth, and GP registration) to ensure accuracy in your care records.

How We Use Your NHS Number

  • • To accurately identify you when coordinating care with NHS services
  • • To link your records across different parts of the health system
  • • To report programme outcomes to NHS commissioners
  • • To verify eligibility for NHS-funded pathways

You have the right to opt out of your data being shared for purposes beyond your direct care through the NHS National Data Opt-Out programme. You can register your opt-out preference at nhs.uk/your-nhs-data-matters or by contacting our Data Protection Officer.

8. GP Connect

Where clinically appropriate and with proper authorisation, Medocta clinicians may use GP Connect — a secure NHS service — to access relevant information from your GP medical record. This may include your medications, allergies, and medical conditions to ensure safe and informed care.

GP Connect access is strictly limited to authorised healthcare professionals providing your direct care. Access is logged, audited, and compliant with NHS information governance requirements. It is only used when necessary for the safe delivery of your treatment.

If you do not wish your GP record to be accessed via GP Connect, please inform your clinician or contact our Data Protection Officer.

10. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect against unauthorised access, alteration, disclosure, or destruction.

Technical Measures

  • • TLS 1.2+ encryption for all data in transit
  • • AES-256 encryption for all data at rest
  • • Web Application Firewall (WAF) protection
  • • Regular penetration testing and vulnerability scanning
  • • Multi-factor authentication for staff access
  • • Automated threat detection and monitoring

Organisational Measures

  • • Role-based access controls (principle of least privilege)
  • • Mandatory data protection training for all staff
  • • Confidentiality agreements for all employees and contractors
  • • Regular audits and compliance reviews
  • • Documented incident response procedures
  • • Annual NHS Data Security and Protection Toolkit assessment

11. Your Rights Regarding Personal Data

Under UK GDPR, you have the following rights in relation to your personal data. You can exercise any of these rights by contacting our Data Protection Officer.

Right of Access

You have the right to request a copy of the personal data we hold about you (Subject Access Request). We will respond within one calendar month.

Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure ("Right to be Forgotten")

You may request deletion of your personal data where there is no compelling reason for continued processing. Note: clinical records may need to be retained for legal or safety reasons.

Right to Restrict Processing

You can request that we limit the processing of your data in certain circumstances, such as while a complaint or accuracy dispute is being resolved.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to have it transferred to another controller.

Right to Object

You can object to processing based on legitimate interest or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects. We do not currently use automated decision-making for clinical purposes.

Right to Complain

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

How to exercise your rights: Submit a request to our Data Protection Officer by email at privacy@medocta.com or by post to the address below. We may ask you to verify your identity before processing your request. We aim to respond to all requests within one calendar month.

12. Changes to This Notice

We may update this Data Privacy Notice from time to time to reflect changes in our practices, legal requirements, or service offerings. Where changes are significant, we will notify you via email or through a prominent notice on our platform. We encourage you to review this notice periodically.

The "Last Updated" date at the top of this page indicates when this notice was last revised.

Contact Information

Data Protection Officer

  • Email: privacy@medocta.com
  • Phone: +44 (0)800 MEDOCTA
  • Post: Data Protection Officer, Medocta Ltd, [Registered Address], United Kingdom

Supervisory Authority

You have the right to lodge a complaint with the UK's data protection authority:

  • Information Commissioner's Office (ICO)
  • Wycliffe House, Water Lane, Wilmslow, SK9 5AF
  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Medocta ICO Registration Ref: C1898621