Privacy Policy

This policy explains how Dr Wycliffe Mbagaya, Consultant in Metabolic Medicine, including the website www.metabolicmedicine.co.uk, uses your personal information to provide safe, effective medical care in line with UK data protection laws, including the UK GDPR and the Data Protection Act 2018.

Who I Am

I am the data controller for the personal data you share with me. My practice includes outpatient services delivered across multiple private hospital settings.

Contact for data queries

Why I Collect Your Information

I collect and hold your personal and medical information to:

  • Provide you with high-quality care and treatment
  • Make appropriate diagnoses and recommendations
  • Share clinical findings with other healthcare professionals involved in your care
  • Fulfil legal, regulatory, and professional obligations
  • Maintain accurate records for continuity of care
  • Improve and audit the quality of care I deliver

What Data I Collect

Depending on your interaction with the practice, I may collect:

  • Personal details (e.g. name, date of birth, contact information)
  • Medical history, symptoms, diagnoses, test results, scans, prescriptions
  • Information sent by your GP, other specialists, or referring clinicians
  • Health insurance information (if applicable)
  • Appointment and billing data

How Your Information Is Used

Your data is used to support your medical care, manage referrals, order investigations, write clinical reports, and coordinate follow-up.

With your consent or when necessary, your information may be shared with:

  • Your GP
  • Other consultants or healthcare providers involved in your treatment
  • Diagnostic or pharmacy services

Where required by law (e.g. safeguarding or court orders), information may be shared without consent.

Your personal information is used solely for the legitimate interest of considering or delivering personal healthcare to you and it will never be used for anything else or passed onto anyone not directly concerned with your healthcare. We will never share your information with any organisation for commercial purposes, marketing or market research.

Third-Party Services Used

We may share data with trusted service providers (such as Semble, Phoenix Hospital Group, and Spire Hospitals) where necessary to deliver services or coordinate your care. All partners are expected to comply with data protection regulations.

Links to Other Websites

There are some links to other websites on the site and once you have clicked these links and left the website, we can accept no responsibility for the content or your privacy on those sites as you are not governed by this privacy statement.

Cookies

We use cookies to enhance your experience using our website, as almost all websites do today. Cookies are small text files that store information on your computer for a variety of functions.

We use cookies to:

  • Keep the website running as you would expect
  • Remember which pages or items you like the best, so we can show you personalised content
  • Let you share things you like on your social networks
  • Store some of your details, such as your log in details (but only if you want us to)

Cookies also help us evaluate our website. Knowing visitor levels, what device our visitors are using, which pages people like the best and how they like to move through the website, social network shares and how people have found us (search engines and links for example) helps us to make the website better for us and for you!

We will never use cookies to:

  • Store your personal information (unless you want us to, for example by asking to join the website)
  • Pass on your information to third parties

Types of cookies and what we use each one for

  • First Party: These are cookies set by us and only usable by us. They are the ones that keep you logged in during a browsing session.
  • Third Party: These are cookies set by third parties that we use. The only third party cookies we use are for evaluating our website (we use Google Analytics and Bing Analytics for this), and those that allow you to share things on your social media sites.
  • Session Cookies: These are temporary cookies that are deleted when you close your browser. These are the ones that keep you logged in as you browse from page to page.

If you do not want us to use cookies, that is fine. Even though most browsers automatically accept cookies, you can modify most browsers to decline cookies if you prefer, but it might prevent you from taking full advantage of the website.

Your Rights

You have the right to:

  • Access the information I hold about you
  • Request correction of any inaccuracies
  • Object to the sharing of your data in some cases
  • Request erasure of your data (where legally applicable)
  • Make a complaint to the Information Commissioner's Office (ICO) if you have concerns about how your data is used

Information Commissioner's Office (ICO)

Lawful Basis for Processing

My legal basis for processing your personal and health data is:

  • Provision of direct care under Article 6(1)(e) and Article 9(2)(h) of UK GDPR
  • Legal obligation to maintain medical records
  • Legitimate interest in managing practice administration

Data Security & Retention

Your data is stored securely in password-protected and encrypted systems.

I retain your records in accordance with current GMC and Department of Health guidelines, typically for at least 8 years, or longer if required for continuity of care.

Updates to This Notice

This privacy notice may be updated periodically. The most current version will always be available on this website.

Last updated: November 2025