Policies
Policies
Privacy Policy
Welcome to the privacy policy of Advanced Weight Solutions Ltd - t/a Weight Medics
Advanced Weight Solutions Ltd - t/a Weight Medics respects your privacy and is committed to protecting your personal data. This privacy policy (“Policy”) will inform you as to how we look after your personal data and tell you about your privacy rights and how the law protects you.
This Policy explains when and why we collect personal information about when people use our services, how we use it, the conditions under which we may disclose it to others and how we keep it secure. All personal information provided by you to us will be treated confidentially and in compliance with applicable data protection legislation.
We may change this Policy from time to time so please check with us occasionally to ensure that you are happy with any changes. By making a booking with us, you are agreeing to be subject to the terms of this Policy.
Who are we?
We are Weight Medics, founded in 1987 with clinics across the UK, specialising in doctor-led weight loss programmes. We have helped thousands of patients successfully achieve a healthy weight and reduce their risk of type II diabetes and hypertension. Weight Medics is the trading name of Advanced Weight Solutions Ltd a company registered in England with company number 15609697 and whose registered office is at 88 Kings Way, London, WC2B 6AA.
When we collect and use your personal data, we are subject to the General Data Protection Regulation (GDPR) (EU) 2016/679 (“the Regulation”) and for the purposes of the Regulation, Advanced Weight Solutions Ltd is the ‘data controller’, that is, the company which is responsible for and controls the processing of your personal data.
The Department of Health recommends minimum retention periods for health records. Weight Medics will follow these at all times.
What type of information in collected from you?
When you register as a patient of Weight Medics, attend a consultation, make certain enquiries, or engage in our services, we may collect a variety of information and personal data from you. We do not store any payment card information.
When you use our website the personal information we collect might include your IP address, and information regarding what website pages are accessed and when.
We collect specific personal data (including your name, address, email, contact number, date of birth) that is required if you choose to enquire about, or engage in our services, as you may be asked to provide your personal information. In addition, you will be required to bring a form of photo identification, (such as a passport or driving licence) with you to your consultation as proof of identity.
It is necessary to collect this information so that we can provide our services to you in a safe, effective and responsible way.
As a provider of medical services, we also collect sensitive data relating to your health and medical history. Such sensitive data includes data relating to your health and medical history (which will be updated each consultation). We need to collect that information to be able to assess the suitability of our products or services and to highlight any potential risks based on your medical history.
Where we collect information about your health or medical circumstances, we have a legal obligation to collect this information for health and safety and insurance purposes. We will only collect this data with your explicit consent. We will only use health related information for the purposes described in our forms or in this Policy.
How is your information used?
The personal information we collect allows us to ensure we provide a safe, effective service while complying with our legal and regulatory responsibilities. Our doctors use your medical information to ensure you are medically suitable to benefit from treatments and that any associated risks are minimised.
We also use your personal information for internal purposes such as auditing, data analysis and research so that we can comply with legal and regulatory responsibilities and so that we can ensure our services are continually reviewed for effectiveness and safety.
In exceptional circumstances, we may use your personal information to inform you of important safety notices, for example, in the event of a medication recall. Because this information relates to patient safety, you may not opt out of receiving these communications.
We will with your explicit written consent share your personal information with your GP or other health adviser as part of our legal, regulatory and ethical responsibilities to your health and safety.
We may also use it for:
Seeking your views or comments on the service we provide.
Processing, booking and confirming appointments that you have requested.
With your consent sending you requested product or service information. If you do not want to receive this information, you may opt out at any time by contacting us by phone, email, using our website contact options, or by using the unsubscribe link on our emails.
Notifying you of changes to our service.
Processing a job application.
We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out below:
Purpose/Activity | Type of data | Lawful basis for processing including basis of legitimate interest |
To register you as a new customer and manage your bookings | (a) Identity
(b) Contact | Performance of a contract with you |
To process and deliver your order including:
(a) Manage payments, fees and charges (b) Collect and recover money owed to us (c ) Subject to your agreement, video conference calls to deliver our service, | (a) Identity
(b) Contact (c) Financial (d) Transaction (e) Marketing and Communications | (a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us) |
To manage our relationship with you which will include:
(a) Notifying you about changes to our terms or privacy policy (b) Asking you to leave a review or take a survey (c) Providing login details for our social media forums or apps (d) Reviewing your medical records (e) Contacting pharmacy suppliers in relation to recommended prescriptions (f) Blood test referrals to third party laboratories (g) Contacting your GP for the purposes of requesting copies of GP summaries | (a) Identity
(b) Contact (c) Profile (d) Marketing and Communications | (a) Performance of a contract with you
(b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services) |
To enable you to partake in a prize draw, competition or complete a survey | (a) Identity
(b) Contact (c) Profile (d) Usage (e) Marketing and Communications | (a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business) |
To administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity
(b) Contact (c) Technical | (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation |
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you | (a) Identity
(b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical | Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences | (a) Technical
(b) Usage | Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
To make suggestions and recommendations to you about goods or services that may be of interest to you | (a) Identity
(b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and Communications | Necessary for our legitimate interests (to develop our products/services and grow our business) |
Purpose/Activity
Type of data
Lawful basis for processing including basis of legitimate interest
To register you as a new customer and manage your bookings
(a) Identity
(b) Contact
Performance of a contract with you
To process and deliver your order including:
(a) Manage payments, fees and charges
(b) Collect and recover money owed to us
(c ) Subject to your agreement, video conference calls to deliver our service,
(a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us)
To manage our relationship with you which will include:
(a) Notifying you about changes to our terms or privacy policy
(b) Asking you to leave a review or take a survey
(c) Providing login details for our social media forums or apps
(d) Reviewing your medical records
(e) Contacting pharmacy suppliers in relation to recommended prescriptions
(f) Blood test referrals to third party laboratories
(g) Contacting your GP for the purposes of requesting copies of GP summaries
(a) Identity
(b) Contact
(c) Profile
(d) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
To enable you to partake in a prize draw, competition or complete a survey
(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and our website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
(a) Identity
(b) Contact
(c) Technical
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(f) Technical
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
(a) Technical
(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you
(a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
Necessary for our legitimate interests (to develop our products/services and grow our business)
Who has access to your information?
Weight Medics, as the data controller, controls and processes your personal information for the purposes laid out in this privacy notice.
Weight Medics uses sub-processors to support the delivery of our services to our customers. A sub-processor can be defined as a third-party data processor engaged by Weight Medics that may store and process personal data of our customers. Weight Medics may remove, replace or appoint suitable and reliable sub processors, and shall update this policy at least (10) days before engaging any new sub-processors to access or participate the processing of your data. Please contact us if require further information on our sub-processors, of which have been set out in the table below:
Infrastructure and Sub-processor Table | ||||
Entity | Service provided to Weight Medics | Location of Sub-processor | Purpose of Processing | Additional Details |
Zoom Video Communications, Inc. | Video and Audio calls | USA | Data processed when Weight Medics uses video conferencing.
Video conferences are not recorded or stored on the sub-processor’s software. The extent of data is controlled and at the discretion of Weight Medics. | Applies EU Standard Contractual Clauses, a GDPR protection for data transfers between EU and non-EU counties |
Klaviyo | Website and contact system management | USA | Customer data only processed where customer support or troubleshooting is required by Weight Medics.
The extent of data is controlled and at the discretion of Weight Medics. | Applies EU Standard Contractual Clauses, a GDPR protection for data transfers between EU and non-EU counties |
Zhero Limited | Cloud services and Virtual Private Network (VPN) provider | UK | Customer data shall be stored on a Cloud File Storage and Sharing server through the use of a VPN. All data hosted on the Cloud is secured through the use of firewalls with encryption and threat protection. | All data will be stored at UK data centres. Where required to transfer data, Zhero applies EU Standard Contractual Clauses, a GDPR protection for data transfers between EU and non-EU counties Access to the VPN by Weight Medics is encrypted with AES256 and 3DES and the VPN can only be accessed with domain credentials. |
Egress Software Technologies Limited | The transfer of files from the Customer’s GP Doctor | UK, EEA and US | Customer data will be processed when Weight Medics receives or sends GP Doctor’s notes and summaries of Weight Medics customers. | Egress is certified under the EU-U.S. and Swiss-U.S. Privacy Shield frameworks, for any transfer of data from countries in the EEA, Switzerland, US and the UK. Where a data transfer occurs to a country outside of the UK and Privacy Shield, Egress will ensure that any such transfer or processing is subject to appropriate legal and technical safeguards, in line with local law requirements. |
How will we share your information?
We will only share your personal information with third parties in the ways that are described in this Policy.
We share your personal data with medical practitioners, pharmacists and laboratories as listed in the table above for the purposes of fulfilling our contract with you and providing services.
We may provide your personal information to Klaviyo that help us with our business activities such as delivering email newsletters. They are authorised to use your name and email only as necessary to provide these services. You can find out more about how they protect your data here:
https://www.klaviyo.com/legal/privacy/privacy-notice
We may also share your personal information as required by law or to respond to a government request, or in connection with a corporate change.
We will not provide your details to any other third party or service provider which is not set out in this Policy without your prior consent.
Security precautions in place to protect against the loss, misuse or alteration of your information
We store your personal data electronically and use patient management systems which store information securely, adhering to strict accessibility and resilience policies. Electronic data access is limited to Weight Medics employees and designated support staff only. Our electronic data is routinely backed up to prevent damage or loss.
When you use some of Weight Medics’ services (for example, our social media or other online pages or forums), the personal information and content you share is visible to other users and can be read, collected, or used by them. You are responsible for the personal information you choose to share or submit in these instances. Please take care when using these features.
When you give us personal information, we take steps to ensure that it is treated securely. Any sensitive information is protected.
Non-sensitive details (your email address etc.) are transmitted normally over the Internet, and this can never be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems.
Integrity and retention of personal information
Weight Medics endeavours to keep your personal information accurate, complete, and up to date. Providing a medical service means that we have obligations to keep certain recorded information for specific lengths of time, so we will retain your personal information only for as long as is required to provide requested services to you, or as is required by law or regulation, or as is legitimately required to protect your health and safety
Your choices
If your personal data is held by Weight Medics, you hold particulars rights over it, as follows:
1 You may request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
2 You may request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. We reserve the right to
3 You may object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
4 You may request a restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
– If you want us to establish the data’s accuracy.
– Where our use of the data is unlawful but you do not want us to erase it.
– Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
– You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
You may request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
You may withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
You have a choice about whether or not you wish to receive information from us. If you do not want to receive direct marketing communications from us about weight loss, nutrition, lifestyle, wellbeing and our exciting products, services and special offers then you can select your choices by ticking the relevant boxes situated on the form on which we collect your information.
We will not contact you for marketing purposes by email, phone or text message unless you have given your prior consent. We will not contact you for marketing purposes by post if you have indicated that you do not wish to be contacted. You may change your marketing preferences at any time by contacting us by email: hello@weightmedics.co.uk or telephone on +44(0)207 760 760.
How you can access and update your information
The accuracy of your information is important to us. We are working on ways to make it easier for you to review and correct the information that we hold about you. In the meantime, if you change email address, or any of the other information we hold is inaccurate or out of date, please email us at: hello@weightmedics.co.uk, or write to us at: Advanced Weight Solutions Ltd- t/a Weight Medics, 88 Kings Way, London, WC2B 6AA. Alternatively, you may telephone +44(0)207 760 760.
You are entitled to request a copy of any personal information we hold relating to you as an individual. You will not have to pay a fee to access your personal data . However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances. We may need to request specific information from you to help us to confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We aim to respond to all legitimate requests within 30 days; if it is the case that it could take us longer we will notify you and keep you updated. Requests should be made either in writing, or by email to our head office or to your local clinic.
Profiling
We may analyse your personal information to create a profile of your interests and preferences so that we can contact you with information relevant to you. We may make use of additional information about you when it is available from external sources to help us do this effectively. We may also use your personal information to detect and reduce fraud and credit risk.
Use of ‘cookies’
Like many other websites, Weight Medics’ website uses cookies.
‘Cookies’ are small pieces of information sent by an organisation to your computer, or any similar device you use to access the internet and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. This helps us to improve our website and deliver a better more personalised service.
You may set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.
A number of cookies used by our website last only for the duration of your web session and they will expire when you close your browser.
More information may be found here:
http://www.google.co.uk/intl/en/analytics/privacyoverview.html
Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Links to other websites
Our website may contain links to other websites run by other organisations. This Policy applies only to our website, so we encourage you to read the privacy statements on the other websites you visit. We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our website.
In addition, if you linked to our website from a third party site, we cannot be responsible for the privacy policies and practices of the owners and operators of that third party site and we recommend you check the policy of that third party site.
Changes to this Policy
By using our site or engaging our Services, you agree to the terms of this Policy. We may amend this Policy at any time. If we plan to make a significant change to the way in which we collect, use, and/or share your personal information, we will send an email to users who have provided an email address or post a notice on our site prior to the change becoming effective. Please review this page from time to time for the latest information on our Policy.
Contacting us
If you have questions or concerns regarding this Policy, you can contact us by writing to us:
Advanced Weight Solutions - t/a Weight Medics
88 Kings Way, London, WC2B 6AA
Review of this Policy
We keep this Policy under regular review. This Policy was last updated in January 2025.