Privacy Policy

DrOnline Ltd

Policy Document Updated: April 2026
Registered in England and Wales | Company No: 14539523 | CQC Registration: 1-15863116390

This Privacy Policy explains how DrOnline Ltd collects, uses, stores, and shares your personal data when you access or use our services. Please read it carefully. By using our Platform or services, you confirm that you have read and understood this policy.

1. Introduction

DrOnline Ltd (“DrOnline,” “we,” “us,” or “our”) is a private online GP platform providing healthcare services including video consultations, general practice services, weight management, mental wellness support, Flow Neuroscience headset clinical support, and related subscription services.

We are committed to protecting your privacy and processing your personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).

Company Details:

  • Company Name: DrOnline Ltd
  • Company Number: 14539523
  • Registered Office: 20-22 Wenlock Road, London, N1 7GU
  • CQC Registration Number: 1-15863116390
  • ICO Registration Number: ZB528997
  • Email: info@dronline.uk

This policy applies to all personal data we process about patients, website visitors, job applicants, and any other individuals who interact with us.

2. Data Controller

Under the UK GDPR and the DPA 2018, DrOnline Ltd is the data controller for all personal data we collect and process. As data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring it is handled lawfully and securely.

For the purpose of healthcare services, the attending clinician also holds professional responsibilities in respect of patient data under their GMC registration and applicable professional standards.

3. Data Protection Officer

We have appointed a Data Protection Officer (DPO) responsible for overseeing our data protection compliance and acting as the primary point of contact for all data protection matters.

Data Protection Officer: Zara Ahmed
Email: zara.ahmed@dronline.com
Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU

Please contact the DPO if you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your personal data is being handled.

4. Personal Data We Collect

4.1 Information You Provide Directly

When you register, book appointments, complete clinical questionnaires, or otherwise interact with our services, we may collect:

  • Identity Data: Full name, date of birth, gender, and photograph (for identity verification purposes)
  • Contact Data: Email address, telephone number, and postal address
  • Health and Clinical Data: Medical history, presenting symptoms, current medications, allergies, family medical history, lifestyle information, weight and BMI data, and other health information you share during consultations or through clinical questionnaires (see Section 4.4 for how we handle this special category data)
  • Identity Verification Data: Copies of photographic identification documents (such as a passport or driving licence) and, where required for prescription purposes, proof of address
  • Payment Data: Payment card details, billing address, and transaction records. Full card details are processed exclusively by our payment provider Stripe and are not stored by DrOnline
  • Account Data: Username, password, account preferences, and subscription information
  • Communications: Records of correspondence between you and DrOnline, including emails, support queries, and complaints

4.2 Information We Collect Automatically

When you use our Platform, we automatically collect:

  • Technical Data: IP address, browser type and version, device type, operating system, and time zone settings
  • Usage Data: Pages visited, time spent on pages, click patterns, and search queries within the Platform
  • Consultation Records: Clinical notes, prescriptions issued, referral letters, and documents generated during or following a consultation

4.3 Information from Third Parties

We may receive personal data from:

  • Referral Partners: Where a patient is referred to us by a partner organisation, subject to your consent and appropriate data sharing agreements
  • Pharmacies: Confirmation of prescription dispensing and collection
  • Flow Neuroscience: Patient data relating to headset usage and stimulation protocol settings where relevant to your clinical care

4.4 Special Category Data – Health Information

Health and medical data is classified as ‘special category data’ under Article 9 of the UK GDPR and is subject to enhanced legal protections. As a healthcare provider, processing health data is central to our ability to deliver clinical services to you.

We process special category health data under the following legal bases:

  • Article 9(2)(h) UK GDPR: Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care, or the management of health or social care systems
  • Schedule 1, Part 1, Paragraph 2 DPA 2018: Processing for health or social care purposes
  • Where applicable, your explicit consent for specific processing activities

All health data is handled with the highest standard of care and is accessible only to authorised clinical and administrative staff with a legitimate need.

5. How We Use Your Personal Data

5.1 Providing Healthcare Services

We use your personal data to deliver the clinical services you have requested, including:

  • Conducting GP consultations, weight management appointments, and other clinical services
  • Making and documenting clinical decisions about your care
  • Issuing prescriptions, sick notes, referral letters, and other clinical documentation
  • Managing your appointments, subscriptions, and account
  • Communicating with you about your care, treatment, and appointments

Legal basis: Article 6(1)(b) UK GDPR (performance of a contract); Article 9(2)(h) UK GDPR and Schedule 1, Part 1, Paragraph 2 DPA 2018 (provision of health care).

5.2 Identity Verification and Safety and Regulatory Compliance

We use identity data to:

  • Verify your identity as required by our CQC registration and clinical governance obligations
  • Confirm you are physically located within the United Kingdom at the time of consultation, as required by our regulatory obligations
  • Prevent fraud, protect patient safety, and ensure prescriptions are issued only to verified individuals

Legal basis: Article 6(1)(c) UK GDPR (legal obligation); Article 6(1)(e) UK GDPR (public task in connection with our regulated activities).

5.3 Account and Subscription Management

We use your personal data to:

  • Create and manage your patient account
  • Process payments, subscriptions, and refunds
  • Respond to your enquiries, complaints, and subject access requests
  • Manage the transition of your clinical records from our previous EHR platform (Semble) to our current platform (Healthie)

Legal basis: Article 6(1)(b) UK GDPR (performance of a contract).

5.4 Clinical Governance, Audit, and Service Improvement

We use anonymised or pseudonymised personal data for:

  • Clinical audit and quality assurance activities
  • Training and professional development of our clinical team
  • Improving the quality and safety of our services
  • Analysing usage patterns to improve the patient experience on our Platform

Legal basis: Article 6(1)(f) UK GDPR (legitimate interests in improving patient safety and service quality, where this does not override your rights and interests); Article 9(2)(h) UK GDPR for health data used in clinical audit.

5.5 Legal and Regulatory Obligations

We process personal data as required by law or regulation, including:

  • Responding to regulatory inspections and enquiries from the CQC
  • Cooperating with professional regulatory bodies (GMC, GPhC) where required
  • Responding to lawful requests from law enforcement or courts
  • Managing legal claims and dispute resolution, including chargeback and complaint processes

Legal basis: Article 6(1)(c) UK GDPR (legal obligation); Article 9(2)(f) UK GDPR (establishment, exercise or defence of legal claims) for health data.

5.6 Marketing Communications

We may send you information about our services, offers, and updates where you have provided explicit consent. You can withdraw consent at any time (see Section 13).

We will always send you service-related communications necessary to deliver our services, including appointment confirmations, prescription notifications, renewal reminders, and important account updates. These are not marketing communications.

Legal basis for marketing: Article 6(1)(a) UK GDPR (consent). Legal basis for service communications: Article 6(1)(b) UK GDPR (contract performance) and Article 6(1)(f) UK GDPR (legitimate interests).

6. Data Sharing and Third-Party Processors

6.1 Our Approach to Data Sharing

We share your personal data only where necessary, proportionate, and subject to appropriate contractual and technical safeguards. All third-party providers who process personal data on our behalf are bound by Data Processing Agreements (DPAs) under Article 28 UK GDPR, which contractually require them to process data only in accordance with our documented instructions, maintain appropriate security measures, and notify us of any data breaches.

6.2 Third-Party Service Providers

We currently share personal data with the following categories of processors:

Provider

Purpose

Data Shared

Location

Healthie

Primary EHR and clinical patient management platform

Health data, identity data, consultation records, appointment data

US (IDTA/SCCs + supplementary measures)

SignatureRx

Electronic prescription service

Prescription data, identity data, contact data

UK

Stripe

Payment processing and subscription management

Payment data, identity data, billing address

US (IDTA/SCCs + supplementary measures)

Brevo

Marketing and service email communications

Contact data, marketing preferences

EU (UK adequacy decision applies)

Google Workspace

Internal business operations and document management

Business documents and internal correspondence (not patient clinical records)

EU/US (IDTA/SCCs)

Slack

Internal team communications

Limited contact data for support-related communications

US (IDTA/SCCs + supplementary measures)

Talkdesk

Customer support helpdesk telephony

Contact data and support query records

EU (UK adequacy decision applies)

Flow Neuroscience

Headset stimulation protocol management (Flow subscription patients only)

Stimulation protocol data and clinical oversight notes

EU (UK adequacy decision applies)

 

Note on platform transition: DrOnline has migrated its primary EHR from Semble to Healthie. Patient records created on Semble have been migrated to Healthie in accordance with our data migration plan and applicable data protection requirements. If you have questions about your records migration, please contact our DPO.

6.3 Healthcare Professionals and Pharmacies

We share clinical data with:

  • Pharmacies: Prescription information necessary for the dispensing of medication
  • Specialist Healthcare Providers: Where you have been referred, we share the clinical information necessary to facilitate that referral
  • Diagnostic Partners (e.g. Medneo, TopMRI): Where you have consented to a self-referral for diagnostic services, we share the minimum necessary data to facilitate your referral

6.4 Regulatory and Legal Authorities

We may be required to disclose your personal data to:

  • The Care Quality Commission (CQC) for regulatory inspection or investigation purposes
  • The General Medical Council (GMC) or General Pharmaceutical Council (GPhC) where required in connection with our regulated activities
  • Law enforcement agencies or courts where we are subject to a legal obligation to disclose
  • Other parties in connection with legal proceedings, where we have a legitimate legal basis to disclose

6.5 Your NHS GP

We do not automatically share information with your NHS GP. We strongly encourage you to inform your NHS GP of any private consultations you have with DrOnline. Upon request, we can provide you with a summary of your consultation to share with your NHS GP or other treating clinicians.

6.6 What We Will Never Do

DrOnline will never:

  • Sell your personal data to any third party
  • Share your health data for commercial advertising or marketing purposes without your explicit consent
  • Share your data with third parties outside the scope of the purposes described in this Privacy Policy without a lawful basis

7. International Data Transfers

7.1 Transfers Outside the UK

Some of our third-party service providers, including Healthie, Stripe, Google, and Slack, are based in or operate infrastructure in the United States. Where we transfer personal data outside the UK to countries that have not received a UK adequacy decision, we ensure appropriate safeguards are in place.

7.2 Transfers Within the EEA

Our customer support and administrative team includes members based in Portugal and Italy who access patient records through our secure EHR and administrative systems. The European Economic Area (EEA) benefits from a UK adequacy decision, meaning the UK government has determined that EEA countries provide an adequate level of data protection equivalent to UK standards.

7.3 Safeguards for US Transfers

For transfers to the United States and other third countries, we rely on one or more of the following safeguards:

  • UK International Data Transfer Agreements (IDTAs) with the relevant service providers
  • Standard Contractual Clauses (SCCs) approved under UK data protection law
  • Supplementary technical and organisational measures including end-to-end encryption, access controls, and data minimisation
  • Provider-level certifications and binding security commitments

You may request further information about the specific safeguards in place for any transfer by contacting our DPO.

8. Data Retention

8.1 Retention Principles

We retain your personal data only for as long as necessary for the purposes for which it was collected, subject to applicable legal, regulatory, and professional obligations. Where data is no longer required, it is securely deleted or irreversibly anonymised.

8.2 Retention Periods

Data Type

Retention Period

Basis

Adult patient health records

10 years from last contact, or 8 years from date of death if sooner

NHS Records Management Code of Practice / professional regulatory requirements

Children’s health records

Until the patient’s 25th birthday, or 26th birthday if aged 17 at conclusion of treatment; or 10 years from date of death if sooner

NHS Records Management Code of Practice

Mental health and mental wellness records

20 years from last contact, or 8 years from date of death if sooner

NHS Records Management Code of Practice

Identity verification documents

10 years from the end of the clinical relationship

Regulatory and anti-fraud requirements

Payment and financial records

7 years from the transaction date

HMRC financial record-keeping requirements

Marketing consent records

Duration of consent plus 2 years following withdrawal or expiry

ICO accountability guidance

Website and platform usage data

26 months

Analytics and service improvement

Complaint and dispute records

6 years from resolution

Limitation Act 1980 (potential legal claims)

 

8.3 EHR Migration Records

Patient records previously held on our Semble platform have been migrated to Healthie. Semble records will be retained for a transitional period of 12 months from the migration date to ensure continuity and facilitate any reconciliation queries, after which they will be securely deleted. If you have queries about your specific records, please contact our DPO.

9. Data Security

9.1 Technical and Organisational Measures

DrOnline implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Our measures include:

  • Encryption: All data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption
  • Access Controls: Role-based access permissions ensuring staff can only access data necessary for their role; multi-factor authentication for all system access
  • Audit Logging: All access to patient records is logged and subject to regular review
  • Staff Training: All staff and clinicians complete mandatory data protection training upon appointment and at regular intervals
  • Third-Party Security Assessment: All third-party processors are assessed for security compliance before appointment and on an ongoing basis
  • Incident Response: Documented data breach response procedures with clear escalation pathways
  • Business Continuity: Regular data backups and disaster recovery procedures

9.2 Your Responsibilities

You play an important role in keeping your data secure. You are responsible for:

  • Keeping your account login credentials confidential and not sharing them with anyone
  • Ensuring you access the Platform on a secure device and network
  • Logging out of the Platform after each session
  • Notifying us immediately at info@dronline.uk if you suspect any unauthorised access to your account or any security incident involving your personal data

10. Your Data Protection Rights

Under the UK GDPR, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month, which may be extended by a further two months for complex or multiple requests (we will notify you if an extension is required).

10.1 Right of Access (Subject Access Request)

You have the right to request a copy of the personal data we hold about you, including health records and consultation notes. Requests should be submitted to our DPO. We will verify your identity before processing any request. We do not charge a fee for subject access requests unless they are manifestly unfounded or excessive.

10.2 Right to Rectification

You have the right to request correction of any inaccurate personal data or completion of any incomplete data we hold about you. Clinical records are subject to professional documentation standards and may include a note of your request for correction alongside the original record where amendment is not clinically appropriate.

10.3 Right to Erasure

You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose it was collected. However, we may be required to retain certain data to fulfil our legal, regulatory, and professional obligations, including our obligation to maintain patient health records for the periods set out in Section 8. We will explain any limitations on erasure at the time of your request.

10.4 Right to Restrict Processing

You have the right to request that we restrict or pause processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or have objected to processing pending verification of our legitimate grounds.

10.5 Right to Data Portability

You have the right to receive personal data you have provided to us in a structured, commonly used, machine-readable format (such as PDF or structured data export), and to request that we transmit it directly to another controller where technically feasible. This right applies to data processed on the basis of consent or contract.

10.6 Right to Object

You have the right to object at any time to processing of your personal data where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. You have an absolute right to object to processing for direct marketing purposes, and we will always honour this immediately.

10.7 Rights Related to Automated Decision-Making

You have the right not to be subject to decisions made solely by automated processing that produce legal or similarly significant effects. DrOnline does not currently use automated decision-making in our clinical services. All clinical decisions are made by qualified, registered clinicians.

10.8 Right to Withdraw Consent

Where we process your data on the basis of your consent (including for marketing communications), you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.

10.9 How to Exercise Your Rights

To exercise any of the above rights, please contact our Data Protection Officer:

  • Email: zara.ahmed@dronline.com
  • Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU

We will ask you to verify your identity before processing your request. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.

11. Cookies

We use cookies and similar tracking technologies on our Platform to enable essential functionality, remember your preferences, analyse usage, and where consented, to deliver relevant marketing. Our full Cookie Policy, including details of the specific cookies we use, their purposes, and how to manage your preferences, is available at https://dronline.uk/cookie-policy/.

You can update your cookie preferences at any time via the consent management tool displayed on our Platform.

12. Children’s Privacy

We provide healthcare services to patients of all ages, including children under 18. Where services are provided to a child:

  • A parent or legal guardian must register and manage the child’s account
  • We process children’s data with additional safeguards appropriate to their age and vulnerability
  • Health records for children are retained in accordance with NHS guidance as set out in Section 8
  • We do not send marketing communications to children
  • Parental or guardian consent is required for all consultations involving a patient under 18, and the parent or guardian must be present during the consultation

Where a child is competent to make their own healthcare decisions (Gillick competence), we will handle their data in accordance with applicable professional and regulatory guidance.

13. Marketing and Communications

13.1 Marketing Communications

We will only send marketing communications where you have given explicit consent. You can withdraw consent and opt out of marketing communications at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Updating your communication preferences in your account settings
  • Contacting us at info@dronline.uk

Opting out of marketing will not affect your receipt of service communications necessary for the delivery of your healthcare.

13.2 Service Communications

We will always send you service-related communications necessary for the management of your care and account, including appointment confirmations and reminders, prescription and referral notifications, subscription renewal reminders (at least 7 days before renewal), important changes to our services or these policies, and responses to your queries and complaints. These communications are not marketing and cannot be opted out of while you remain a patient.

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, DrOnline will:

  • Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, where required under Article 33 UK GDPR
  • Notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, under Article 34 UK GDPR
  • Take immediate steps to contain and mitigate the impact of the breach
  • Document all breaches in our internal breach register, regardless of whether notification to the ICO or individuals is required

If you become aware of any potential security issue or suspected data breach involving your DrOnline account or personal data, please notify our DPO immediately at zara.ahmed@dronline.com.

15. Legitimate Interests Assessment

Where we rely on legitimate interests as our legal basis for processing, we have carried out a balancing test to ensure our interests do not override your fundamental rights and freedoms. Processing activities covered by our legitimate interests assessment include service improvement and clinical audit (using anonymised data), fraud prevention, chargeback and dispute management, and internal administrative and operational functions.

You have the right to request a copy of any legitimate interests assessment we have carried out. Please contact our DPO to make this request.

16. Complaints

If you are dissatisfied with how we have handled your personal data, or if you believe we have not complied with our obligations under UK GDPR or the DPA 2018, we ask that you contact our DPO in the first instance so that we have the opportunity to address your concerns.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at any time:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk
Online reporting form: https://ico.org.uk/make-a-complaint/

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal requirements, or operational practices. Material changes will be communicated to you via the Platform and/or by email at least 14 days before the change takes effect.

The revision date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically. Continued use of our services after the effective date of any update constitutes acknowledgement of the revised policy. The current version is always available at https://dronline.uk/privacy-policy/.

18. Contact Us

For all data protection enquiries, to exercise your rights, or to raise a concern:

Data Protection Officer: Zara Ahmed
Email: zara.ahmed@dronline.com
Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU

For general enquiries:

Email: info@dronline.uk
Phone: 07893 947543