Privacy Policy
Effective Date: September 2026
Last Updated: 11/09/2026
- AMC Privacy Policy
- 1. About This Policy
- 2. Who We Are
- 3. What Data We Collect
- 4. How We Use Your Data
- 5. Legal Basis for Processing
- 6. Family Circles and Proxy Access
- 7. How We Share Your Data
- 8. Data Security
- 9. How Long We Keep Your Data
- 10. Your Rights
- 11. Children and Vulnerable Users
- 12. Automated Decision-Making
- 13. Cookies and Analytics
- 14. International Transfers
- 15. Updates to This Policy
- 16. Contact Us
1. About This Policy
This Privacy Policy explains how Archway Medical Centre (“Your GP”, “we”, “us”, or “our”) collects, uses, shares, and protects your personal information when you use the AMC app and related services.
We have a duty to store and process your information in a manner which complies with UK data protection law.
Because we handle your health information, which is classed as ‘special category’ data, we take extra steps to protect your privacy. This policy sets out clearly how we use your data, your rights, and the tools you have to control it.
2. Who We Are
AMC is the trading name of a group of doctors and nurses working together in partnership in a medical practice regulated by the Care Quality Commission to provide online diagnostic, screening, and treatment services.
If you have questions or concerns about how your personal data is handled, you can contact our Data Protection Officer:
Email: apct.admin@nhs.net
Post: 652, Holloway Road, London N19 3NU
Phone: 020 7272 0111
3. What Data We Collect
Depending on how you use AMC, we may collect the following types of personal data:
- Identity and Contact Data: Name, date of birth, NHS number, contact details, emergency contacts.
- Health Data (Special Category Data and Personal Health Information):
- NHS data: Health record content.
- Clinical Records: Consultation notes, conditions, previous medical history, prescriptions, diagnoses, , care plans.
- Technical Data: IP address, app usage, device identifiers, system logs.
How we collect this data:
- From your NHS record
- Through data you enter into the website
- During video or phone consultations with clinicians.
4. How We Use Your Data
We use your personal data to provide safe, personalised, and responsive digital healthcare. This includes:
- Monitoring and analysis: For health and health care purposes
- Clinical decision making: To provide medical care to you.
- Long-term condition management: We provide tailored plans for conditions such as diabetes, obesity, heart disease, and mental health.
- Emergency support: We may contact you or your nominated contact if urgent medical concerns arise.
We do not use your data for marketing.
5. Legal Basis for Processing
We process your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our legal bases include:
- Contractual necessity (UK GDPR Article 6(1)(b)): To deliver your healthcare services.
- Legal obligation (6(1)(c)): To meet clinical or regulatory requirements.
- Public interest in healthcare (6(1)(e) and 9(2)(h)): For diagnosis, treatment, and health protection.
- Explicit consent (6(1)(a) and 9(2)(a)): For specific uses with your consent.
These legal bases mean we only use your data where we have a valid reason — either to deliver your care, comply with the law, or because you’ve clearly said yes.
6. Family Circles and Proxy Access
7. How We Share Your Data
We only share your data when necessary to deliver your care or meet legal obligations. This may include:
- Clinicians and health professionals: For diagnosis, treatment, and monitoring.
- NHS systems: We may access or share relevant record data.
- Authorised family members or carers: Only with your consent or lawful authority.
- Emergency services: If we detect a clinical concern that poses serious risk.
- Regulators or authorities: Where required by law (e.g. the Care Quality Commission).
We never sell your data. All third-party access is carefully controlled and audited.
8. Data Security
Your health information deserves the highest level of protection. We implement robust technical and organisational measures including:
- End-to-end encryption for all data in transit and at rest.
- Role-based access control and two-factor authentication.
- Integration with NHS Login for secure identity verification.
- Immutable logs of all data access, including by proxy users.
- Regular security testing and ISO/IEC 27001:2022-aligned controls.
We are committed to transparency and continuous improvement of our security model.
9. How Long We Keep Your Data
We retain your personal data for:
- As long as you remain an active patient;
- A minimum of 8 years for clinical records, in line with UK medical recordkeeping guidance;
- Longer if required for regulatory or legal reasons.
You may request deletion of your account and data at any time. We will confirm what data can be deleted and what we must retain by law.
10. Your Rights
Under the UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate or incomplete data.
- Request deletion of your data where applicable.
- Restrict or object to certain types of processing (e.g. family sharing).
- Withdraw your consent, where it was required.
- Receive your data in a portable format.
- Complain to the Information Commissioner’s Office (www.ico.org.uk).
To exercise any of these rights, contact us at admin.apct@nhs.net or on HelpDesk. We will respond within one month.
11. Children and Vulnerable Users
12. Automated Decision-Making
13. Cookies and Analytics
Our website and app may use cookies or analytics technologies to:
- Measure app usage and performance.
- Improve service features.
- Debug issues or errors.
You can manage cookie settings via your browser or device. No tracking is done for advertising or profiling purposes.
14. International Transfers
We store and process your data in the UK. None of your data is transferred outside the UK.
15. Updates to This Policy
We may update this policy to reflect changes in law, our services, or how we process your data.
16. Contact Us
Archway Medical Centre
Data Protection Officer is Carole Hubbard.
Email: Apct.admin@nhs.net
Post: 652, Holloway Road, London N19 3NU
Phone: 020 7272 0111
Information Regulator: Information Commissioner’s Office (www.ico.org.uk)