Privacy Policy
DrOnline Ltd
Policy Document Updated: April 2026
Registered in England and Wales | Company No: 14539523 | CQC Registration: 1-15863116390
This Privacy Policy explains how DrOnline Ltd collects, uses, stores, and shares your personal data when you access or use our services. Please read it carefully. By using our Platform or services, you confirm that you have read and understood this policy.
1. Introduction
DrOnline Ltd (“DrOnline,” “we,” “us,” or “our”) is a private online GP platform providing healthcare services including video consultations, general practice services, weight management, mental wellness support, Flow Neuroscience headset clinical support, and related subscription services.
We are committed to protecting your privacy and processing your personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
Company Details:
- Company Name: DrOnline Ltd
- Company Number: 14539523
- Registered Office: 20-22 Wenlock Road, London, N1 7GU
- CQC Registration Number: 1-15863116390
- ICO Registration Number: ZB528997
- Email: info@dronline.uk
This policy applies to all personal data we process about patients, website visitors, job applicants, and any other individuals who interact with us.
2. Data Controller
Under the UK GDPR and the DPA 2018, DrOnline Ltd is the data controller for all personal data we collect and process. As data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring it is handled lawfully and securely.
For the purpose of healthcare services, the attending clinician also holds professional responsibilities in respect of patient data under their GMC registration and applicable professional standards.
3. Data Protection Officer
We have appointed a Data Protection Officer (DPO) responsible for overseeing our data protection compliance and acting as the primary point of contact for all data protection matters.
Data Protection Officer: Zara Ahmed
Email: zara.ahmed@dronline.com
Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU
Please contact the DPO if you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your personal data is being handled.
4. Personal Data We Collect
4.1 Information You Provide Directly
When you register, book appointments, complete clinical questionnaires, or otherwise interact with our services, we may collect:
- Identity Data: Full name, date of birth, gender, and photograph (for identity verification purposes)
- Contact Data: Email address, telephone number, and postal address
- Health and Clinical Data: Medical history, presenting symptoms, current medications, allergies, family medical history, lifestyle information, weight and BMI data, and other health information you share during consultations or through clinical questionnaires (see Section 4.4 for how we handle this special category data)
- Identity Verification Data: Copies of photographic identification documents (such as a passport or driving licence) and, where required for prescription purposes, proof of address
- Payment Data: Payment card details, billing address, and transaction records. Full card details are processed exclusively by our payment provider Stripe and are not stored by DrOnline
- Account Data: Username, password, account preferences, and subscription information
- Communications: Records of correspondence between you and DrOnline, including emails, support queries, and complaints
4.2 Information We Collect Automatically
When you use our Platform, we automatically collect:
- Technical Data: IP address, browser type and version, device type, operating system, and time zone settings
- Usage Data: Pages visited, time spent on pages, click patterns, and search queries within the Platform
- Consultation Records: Clinical notes, prescriptions issued, referral letters, and documents generated during or following a consultation
4.3 Information from Third Parties
We may receive personal data from:
- Referral Partners: Where a patient is referred to us by a partner organisation, subject to your consent and appropriate data sharing agreements
- Pharmacies: Confirmation of prescription dispensing and collection
- Flow Neuroscience: Patient data relating to headset usage and stimulation protocol settings where relevant to your clinical care
4.4 Special Category Data – Health Information
Health and medical data is classified as ‘special category data’ under Article 9 of the UK GDPR and is subject to enhanced legal protections. As a healthcare provider, processing health data is central to our ability to deliver clinical services to you.
We process special category health data under the following legal bases:
- Article 9(2)(h) UK GDPR: Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, the provision of health or social care, or the management of health or social care systems
- Schedule 1, Part 1, Paragraph 2 DPA 2018: Processing for health or social care purposes
- Where applicable, your explicit consent for specific processing activities
All health data is handled with the highest standard of care and is accessible only to authorised clinical and administrative staff with a legitimate need.
5. How We Use Your Personal Data
5.1 Providing Healthcare Services
We use your personal data to deliver the clinical services you have requested, including:
- Conducting GP consultations, weight management appointments, and other clinical services
- Making and documenting clinical decisions about your care
- Issuing prescriptions, sick notes, referral letters, and other clinical documentation
- Managing your appointments, subscriptions, and account
- Communicating with you about your care, treatment, and appointments
Legal basis: Article 6(1)(b) UK GDPR (performance of a contract); Article 9(2)(h) UK GDPR and Schedule 1, Part 1, Paragraph 2 DPA 2018 (provision of health care).
5.2 Identity Verification and Safety and Regulatory Compliance
We use identity data to:
- Verify your identity as required by our CQC registration and clinical governance obligations
- Confirm you are physically located within the United Kingdom at the time of consultation, as required by our regulatory obligations
- Prevent fraud, protect patient safety, and ensure prescriptions are issued only to verified individuals
Legal basis: Article 6(1)(c) UK GDPR (legal obligation); Article 6(1)(e) UK GDPR (public task in connection with our regulated activities).
5.3 Account and Subscription Management
We use your personal data to:
- Create and manage your patient account
- Process payments, subscriptions, and refunds
- Respond to your enquiries, complaints, and subject access requests
- Manage the transition of your clinical records from our previous EHR platform (Semble) to our current platform (Healthie)
Legal basis: Article 6(1)(b) UK GDPR (performance of a contract).
5.4 Clinical Governance, Audit, and Service Improvement
We use anonymised or pseudonymised personal data for:
- Clinical audit and quality assurance activities
- Training and professional development of our clinical team
- Improving the quality and safety of our services
- Analysing usage patterns to improve the patient experience on our Platform
Legal basis: Article 6(1)(f) UK GDPR (legitimate interests in improving patient safety and service quality, where this does not override your rights and interests); Article 9(2)(h) UK GDPR for health data used in clinical audit.
5.5 Legal and Regulatory Obligations
We process personal data as required by law or regulation, including:
- Responding to regulatory inspections and enquiries from the CQC
- Cooperating with professional regulatory bodies (GMC, GPhC) where required
- Responding to lawful requests from law enforcement or courts
- Managing legal claims and dispute resolution, including chargeback and complaint processes
Legal basis: Article 6(1)(c) UK GDPR (legal obligation); Article 9(2)(f) UK GDPR (establishment, exercise or defence of legal claims) for health data.
5.6 Marketing Communications
We may send you information about our services, offers, and updates where you have provided explicit consent. You can withdraw consent at any time (see Section 13).
We will always send you service-related communications necessary to deliver our services, including appointment confirmations, prescription notifications, renewal reminders, and important account updates. These are not marketing communications.
Legal basis for marketing: Article 6(1)(a) UK GDPR (consent). Legal basis for service communications: Article 6(1)(b) UK GDPR (contract performance) and Article 6(1)(f) UK GDPR (legitimate interests).
6. Data Sharing and Third-Party Processors
6.1 Our Approach to Data Sharing
We share your personal data only where necessary, proportionate, and subject to appropriate contractual and technical safeguards. All third-party providers who process personal data on our behalf are bound by Data Processing Agreements (DPAs) under Article 28 UK GDPR, which contractually require them to process data only in accordance with our documented instructions, maintain appropriate security measures, and notify us of any data breaches.
6.2 Third-Party Service Providers
We currently share personal data with the following categories of processors:
Provider | Purpose | Data Shared | Location |
|---|---|---|---|
Healthie | Primary EHR and clinical patient management platform | Health data, identity data, consultation records, appointment data | US (IDTA/SCCs + supplementary measures) |
SignatureRx | Electronic prescription service | Prescription data, identity data, contact data | UK |
Stripe | Payment processing and subscription management | Payment data, identity data, billing address | US (IDTA/SCCs + supplementary measures) |
Brevo | Marketing and service email communications | Contact data, marketing preferences | EU (UK adequacy decision applies) |
Google Workspace | Internal business operations and document management | Business documents and internal correspondence (not patient clinical records) | EU/US (IDTA/SCCs) |
Slack | Internal team communications | Limited contact data for support-related communications | US (IDTA/SCCs + supplementary measures) |
Talkdesk | Customer support helpdesk telephony | Contact data and support query records | EU (UK adequacy decision applies) |
Flow Neuroscience | Headset stimulation protocol management (Flow subscription patients only) | Stimulation protocol data and clinical oversight notes | EU (UK adequacy decision applies) |
Note on platform transition: DrOnline has migrated its primary EHR from Semble to Healthie. Patient records created on Semble have been migrated to Healthie in accordance with our data migration plan and applicable data protection requirements. If you have questions about your records migration, please contact our DPO.
6.3 Healthcare Professionals and Pharmacies
We share clinical data with:
- Pharmacies: Prescription information necessary for the dispensing of medication
- Specialist Healthcare Providers: Where you have been referred, we share the clinical information necessary to facilitate that referral
- Diagnostic Partners (e.g. Medneo, TopMRI): Where you have consented to a self-referral for diagnostic services, we share the minimum necessary data to facilitate your referral
6.4 Regulatory and Legal Authorities
We may be required to disclose your personal data to:
- The Care Quality Commission (CQC) for regulatory inspection or investigation purposes
- The General Medical Council (GMC) or General Pharmaceutical Council (GPhC) where required in connection with our regulated activities
- Law enforcement agencies or courts where we are subject to a legal obligation to disclose
- Other parties in connection with legal proceedings, where we have a legitimate legal basis to disclose
6.5 Your NHS GP
We do not automatically share information with your NHS GP. We strongly encourage you to inform your NHS GP of any private consultations you have with DrOnline. Upon request, we can provide you with a summary of your consultation to share with your NHS GP or other treating clinicians.
6.6 What We Will Never Do
DrOnline will never:
- Sell your personal data to any third party
- Share your health data for commercial advertising or marketing purposes without your explicit consent
- Share your data with third parties outside the scope of the purposes described in this Privacy Policy without a lawful basis
7. International Data Transfers
7.1 Transfers Outside the UK
Some of our third-party service providers, including Healthie, Stripe, Google, and Slack, are based in or operate infrastructure in the United States. Where we transfer personal data outside the UK to countries that have not received a UK adequacy decision, we ensure appropriate safeguards are in place.
7.2 Transfers Within the EEA
Our customer support and administrative team includes members based in Portugal and Italy who access patient records through our secure EHR and administrative systems. The European Economic Area (EEA) benefits from a UK adequacy decision, meaning the UK government has determined that EEA countries provide an adequate level of data protection equivalent to UK standards.
7.3 Safeguards for US Transfers
For transfers to the United States and other third countries, we rely on one or more of the following safeguards:
- UK International Data Transfer Agreements (IDTAs) with the relevant service providers
- Standard Contractual Clauses (SCCs) approved under UK data protection law
- Supplementary technical and organisational measures including end-to-end encryption, access controls, and data minimisation
- Provider-level certifications and binding security commitments
You may request further information about the specific safeguards in place for any transfer by contacting our DPO.
8. Data Retention
8.1 Retention Principles
We retain your personal data only for as long as necessary for the purposes for which it was collected, subject to applicable legal, regulatory, and professional obligations. Where data is no longer required, it is securely deleted or irreversibly anonymised.
8.2 Retention Periods
Data Type | Retention Period | Basis |
|---|---|---|
Adult patient health records | 10 years from last contact, or 8 years from date of death if sooner | NHS Records Management Code of Practice / professional regulatory requirements |
Children’s health records | Until the patient’s 25th birthday, or 26th birthday if aged 17 at conclusion of treatment; or 10 years from date of death if sooner | NHS Records Management Code of Practice |
Mental health and mental wellness records | 20 years from last contact, or 8 years from date of death if sooner | NHS Records Management Code of Practice |
Identity verification documents | 10 years from the end of the clinical relationship | Regulatory and anti-fraud requirements |
Payment and financial records | 7 years from the transaction date | HMRC financial record-keeping requirements |
Marketing consent records | Duration of consent plus 2 years following withdrawal or expiry | ICO accountability guidance |
Website and platform usage data | 26 months | Analytics and service improvement |
Complaint and dispute records | 6 years from resolution | Limitation Act 1980 (potential legal claims) |
8.3 EHR Migration Records
Patient records previously held on our Semble platform have been migrated to Healthie. Semble records will be retained for a transitional period of 12 months from the migration date to ensure continuity and facilitate any reconciliation queries, after which they will be securely deleted. If you have queries about your specific records, please contact our DPO.
9. Data Security
9.1 Technical and Organisational Measures
DrOnline implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Our measures include:
- Encryption: All data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption
- Access Controls: Role-based access permissions ensuring staff can only access data necessary for their role; multi-factor authentication for all system access
- Audit Logging: All access to patient records is logged and subject to regular review
- Staff Training: All staff and clinicians complete mandatory data protection training upon appointment and at regular intervals
- Third-Party Security Assessment: All third-party processors are assessed for security compliance before appointment and on an ongoing basis
- Incident Response: Documented data breach response procedures with clear escalation pathways
- Business Continuity: Regular data backups and disaster recovery procedures
9.2 Your Responsibilities
You play an important role in keeping your data secure. You are responsible for:
- Keeping your account login credentials confidential and not sharing them with anyone
- Ensuring you access the Platform on a secure device and network
- Logging out of the Platform after each session
- Notifying us immediately at info@dronline.uk if you suspect any unauthorised access to your account or any security incident involving your personal data
10. Your Data Protection Rights
Under the UK GDPR, you have the following rights in relation to your personal data. We will respond to all valid requests within one calendar month, which may be extended by a further two months for complex or multiple requests (we will notify you if an extension is required).
10.1 Right of Access (Subject Access Request)
You have the right to request a copy of the personal data we hold about you, including health records and consultation notes. Requests should be submitted to our DPO. We will verify your identity before processing any request. We do not charge a fee for subject access requests unless they are manifestly unfounded or excessive.
10.2 Right to Rectification
You have the right to request correction of any inaccurate personal data or completion of any incomplete data we hold about you. Clinical records are subject to professional documentation standards and may include a note of your request for correction alongside the original record where amendment is not clinically appropriate.
10.3 Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose it was collected. However, we may be required to retain certain data to fulfil our legal, regulatory, and professional obligations, including our obligation to maintain patient health records for the periods set out in Section 8. We will explain any limitations on erasure at the time of your request.
10.4 Right to Restrict Processing
You have the right to request that we restrict or pause processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or have objected to processing pending verification of our legitimate grounds.
10.5 Right to Data Portability
You have the right to receive personal data you have provided to us in a structured, commonly used, machine-readable format (such as PDF or structured data export), and to request that we transmit it directly to another controller where technically feasible. This right applies to data processed on the basis of consent or contract.
10.6 Right to Object
You have the right to object at any time to processing of your personal data where we rely on legitimate interests as our legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. You have an absolute right to object to processing for direct marketing purposes, and we will always honour this immediately.
10.7 Rights Related to Automated Decision-Making
You have the right not to be subject to decisions made solely by automated processing that produce legal or similarly significant effects. DrOnline does not currently use automated decision-making in our clinical services. All clinical decisions are made by qualified, registered clinicians.
10.8 Right to Withdraw Consent
Where we process your data on the basis of your consent (including for marketing communications), you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal.
10.9 How to Exercise Your Rights
To exercise any of the above rights, please contact our Data Protection Officer:
- Email: zara.ahmed@dronline.com
- Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU
We will ask you to verify your identity before processing your request. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
11. Cookies
We use cookies and similar tracking technologies on our Platform to enable essential functionality, remember your preferences, analyse usage, and where consented, to deliver relevant marketing. Our full Cookie Policy, including details of the specific cookies we use, their purposes, and how to manage your preferences, is available at https://dronline.uk/cookie-policy/.
You can update your cookie preferences at any time via the consent management tool displayed on our Platform.
12. Children’s Privacy
We provide healthcare services to patients of all ages, including children under 18. Where services are provided to a child:
- A parent or legal guardian must register and manage the child’s account
- We process children’s data with additional safeguards appropriate to their age and vulnerability
- Health records for children are retained in accordance with NHS guidance as set out in Section 8
- We do not send marketing communications to children
- Parental or guardian consent is required for all consultations involving a patient under 18, and the parent or guardian must be present during the consultation
Where a child is competent to make their own healthcare decisions (Gillick competence), we will handle their data in accordance with applicable professional and regulatory guidance.
13. Marketing and Communications
13.1 Marketing Communications
We will only send marketing communications where you have given explicit consent. You can withdraw consent and opt out of marketing communications at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your communication preferences in your account settings
- Contacting us at info@dronline.uk
Opting out of marketing will not affect your receipt of service communications necessary for the delivery of your healthcare.
13.2 Service Communications
We will always send you service-related communications necessary for the management of your care and account, including appointment confirmations and reminders, prescription and referral notifications, subscription renewal reminders (at least 7 days before renewal), important changes to our services or these policies, and responses to your queries and complaints. These communications are not marketing and cannot be opted out of while you remain a patient.
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, DrOnline will:
- Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, where required under Article 33 UK GDPR
- Notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms, under Article 34 UK GDPR
- Take immediate steps to contain and mitigate the impact of the breach
- Document all breaches in our internal breach register, regardless of whether notification to the ICO or individuals is required
If you become aware of any potential security issue or suspected data breach involving your DrOnline account or personal data, please notify our DPO immediately at zara.ahmed@dronline.com.
15. Legitimate Interests Assessment
Where we rely on legitimate interests as our legal basis for processing, we have carried out a balancing test to ensure our interests do not override your fundamental rights and freedoms. Processing activities covered by our legitimate interests assessment include service improvement and clinical audit (using anonymised data), fraud prevention, chargeback and dispute management, and internal administrative and operational functions.
You have the right to request a copy of any legitimate interests assessment we have carried out. Please contact our DPO to make this request.
16. Complaints
If you are dissatisfied with how we have handled your personal data, or if you believe we have not complied with our obligations under UK GDPR or the DPA 2018, we ask that you contact our DPO in the first instance so that we have the opportunity to address your concerns.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk
Online reporting form: https://ico.org.uk/make-a-complaint/
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, legal requirements, or operational practices. Material changes will be communicated to you via the Platform and/or by email at least 14 days before the change takes effect.
The revision date at the top of this policy indicates when it was last updated. We encourage you to review this policy periodically. Continued use of our services after the effective date of any update constitutes acknowledgement of the revised policy. The current version is always available at https://dronline.uk/privacy-policy/.
18. Contact Us
For all data protection enquiries, to exercise your rights, or to raise a concern:
Data Protection Officer: Zara Ahmed
Email: zara.ahmed@dronline.com
Post: Data Protection Officer, DrOnline Ltd, 20-22 Wenlock Road, London, N1 7GU
For general enquiries:
Email: info@dronline.uk
Phone: 07893 947543
