Privacy
Privacy Policy
Last updated: 16 August 2026
This Privacy Policy explains how The London Sleep Apnoea Clinic ("we", "us", "the Clinic") collects, uses, stores and protects your personal data, including special-category health data, when you use this website or book an appointment. It is written in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are (Data Controller)
Data Controller: Dr Nikesh Devani, trading as The London Sleep Apnoea Clinic.
Address: Suite RA01, 195–197 Wood Street, London, E17 3NU.
Email: referrals@drnikeshdevani.co.uk
Data Protection Officer: Dr Nikesh Devani (same email).
ICO registration: Registration in progress — number will be added on completion.
2. The data we collect
- Identity & contact: name, date of birth, email address, phone number.
- Health data (special category): reason for visit, clinical notes you provide, and any information related to your sleep, breathing or related health.
- Insurance details: insurer, membership number, pre-authorisation code (if applicable).
- Payment data: we do not take card payments through this website. Fees are settled with the CQC-registered hospital hosting your appointment, or in clinic — we never see or store your card details.
- Account data: for clinic staff only — email, password hash, role.
- Technical data: IP address, browser, and basic logs needed to operate the site securely.
If you use the contact form, we collect your name, email address, your message, and (for package enquiries) your preferred hospital and dates. Enquiries are stored securely in our own system and are visible only to signed-in clinic staff. Our clinicians receive an alert email that contains no personal data at all — only a notice that an enquiry has arrived and a link to sign in — so your enquiry never sits in an ordinary mailbox. Please do not include detailed medical history in the form; we will contact you to discuss it securely.
3. Why we use it and our lawful basis
- To deliver care (booking, reminders, clinical follow-up): UK GDPR Article 6(1)(b) — performance of a contract — and Article 9(2)(h) — provision of health care, supported by your explicit consent at the point of booking.
- To respond to website enquiries: Article 6(1)(a) — your consent, given by ticking the box on the contact form — and Article 9(2)(a) — explicit consent, where you choose to include health information.
- To administer fees and invoicing: Article 6(1)(b) — contract.
- To meet legal/regulatory duties (clinical record-keeping, accounting): Article 6(1)(c) — legal obligation.
- To keep the website secure: Article 6(1)(f) — legitimate interests.
4. Who we share it with (processors)
We share your data only with the trusted suppliers needed to run the service:
- Lovable Cloud / Supabase — secure database, authentication and hosting (EU region).
- Stackmail (Hostinger) — our email service, used to send and receive clinic email, including appointment confirmations, reminders and enquiry alerts.
Each is bound by a written Data Processing Agreement and uses appropriate safeguards for any international transfers.
When you book an appointment, we share your name, date of birth and contact details with the CQC-registered hospital hosting your appointment — currently The Wellington Hospital or Chase Lodge Hospital — so they can process your booking, admission and any on-site care. Each hospital acts as an independent controller for the services it provides and handles your data under its own privacy terms. This sharing only happens when you tick the dedicated hospital consent box at booking.
Clinic staff access this system using their NHSmail (nhs.net) accounts under the NHSmail Acceptable Use Policy. NHSmail is provided centrally by NHS England and is covered by NHS England's own data processing arrangements, so no separate agreement with a mail provider is required.
Card payments taken in clinic are processed on a card terminal provided by the hospital or by our card acquirer; no card numbers are ever stored in this system. The clinic only records the amount, the method used and a payment reference, so the appointment record matches the till.
If you book a home sleep study (the Sleep Diagnostic Study or the Complete Sleep Package), we share your name, date of birth and contact details with Zoll Medical UK Limited, who post the WatchPat home sleep-study kit to you and arrange its return. Zoll acts as an independent controller for kit logistics under its own privacy terms. This sharing only happens when you tick the dedicated consent box at booking. The study equipment is supplied by Zoll; your consultant remains responsible for interpreting the results and issuing your diagnostic report.
If, following your consultation, CPAP therapy is recommended and you choose to proceed, we share your name, date of birth and contact details with Dolby Vivisol, our CPAP partner, so they can supply, deliver and support your CPAP equipment and ongoing therapy. Dolby Vivisol acts as an independent controller for CPAP supply and support under its own privacy terms.
To register with Dolby Vivisol, we email you a PDF containing their service-offering form and Direct Debit mandate. You complete this form yourself and post it directly to Dolby Vivisol at the address printed on the form. The London Sleep Apnoea Clinic does not collect, see or store your bank details, delivery address, or signed mandate — that information passes only between you and Dolby Vivisol.
5. How long we keep your data
Clinical and appointment records are retained for 8 years from the date of your last appointment, in line with NHS records-management guidance. After that, your records are automatically anonymised: identifying fields (name, email, phone, DOB, reason, insurance) are erased, leaving only a non-identifying clinical/financial skeleton. Payment records are kept for 6 years for accounting purposes.
Contact-form enquiries that do not lead to a booking are kept for 12 months and then deleted. If your enquiry becomes an appointment, it is retained with your clinical record.
6. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Ask us to erase your data (subject to our legal/clinical retention duties).
- Receive a copy of your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
You can exercise the access and erasure rights instantly using our self-service page: Request my data. For anything else, email our DPO.
7. Security
All data is transmitted over HTTPS. Card data is handled by the hospital or card terminal provider and never touches our systems. Access to clinical records is restricted to authenticated clinic staff, and every admin view of a patient record is recorded in an audit log. We use row-level database security to ensure data is only ever returned to those entitled to see it.
8. Cookies
We only use cookies strictly necessary to keep you signed in and to operate the booking flow. We do not use analytics, advertising or third-party tracking cookies. See our Cookie Policy for the full list of cookies we use, their purpose and duration.
9. Complaints
If you are unhappy with how we have handled your data, please contact our DPO first. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10. Personal data breaches
We take the security of your data seriously. If you suspect a breach involving your personal data (for example a suspicious email pretending to be from us, or unauthorised access to your record), please contact our DPO immediately at referrals@drnikeshdevani.co.uk.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it, as required by UK GDPR Article 33. Where the breach is likely to result in a high risk to you, we will also contact you directly without undue delay (Article 34) and tell you what happened, what data was affected, what we are doing about it, and what steps you can take.
We keep an internal log of all suspected and confirmed incidents, including those that do not need to be reported, so we can learn from them and improve our safeguards.
11. Changes
We may update this policy from time to time. Material changes will be highlighted on this page.