Privacy Policy
Who we are
The Duke Practice Ltd is a private GP practice based at 6b Sloane Square, London. We are registered with the Care Quality Commission and Dr Oscar Duke is the Registered Manager. We are registered with the Information Commissioner’s Office as a data controller (registration number ZB189535).
Data controller: The Duke Practice Ltd, 6b Sloane Square, London.
Contact for data protection questions, subject access requests, or complaints: pa@thedukepractice.com or 020 7730 3700.
We have not appointed a formal Data Protection Officer as we are not required to do so under UK GDPR Article 37. We take advice from external data protection specialists on complex matters.
What this notice covers
This notice explains:
- What personal information we collect about you
- Why we collect it and what we do with it
- Who we share it with
- How long we keep it
- Your rights over your information
- How to contact us or complain
This notice applies to patients of all ages. A specific section on Children and Young People sets out additional points that apply to patients under 18 and to those signing on their behalf.
We are committed to protecting your privacy and handling your information transparently and lawfully. This notice is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and our Common Law Duty of Confidentiality to you as our patient.
The information we collect
We collect and hold the following categories of personal data about you:
Identity and contact information
- Name, date of birth, home address, email address, telephone number(s)
- Next of kin details (name, contact number, relationship to you)
- Photograph, if provided
Clinical information (special category health data)
- Your medical history, current and past conditions
- Current medications and allergies
- Consultation notes made by Dr Duke
- Results of investigations (blood tests, imaging, other)
- Letters received from specialists, hospitals, and other clinicians
- Prescriptions issued
- Referrals made on your behalf
- Transcripts of consultations generated by AI-assisted documentation (see relevant section below)
Administrative information
- Details of your NHS GP (where applicable)
- Appointment history
- Correspondence with you (emails, letters, messages)
- Payment and billing records
Website usage information
- Basic analytics data when you visit our website (see Website section below)
We do not routinely collect biometric or genetic data. We do not use CCTV in the practice premises. We do not record telephone consultations. We do not save audio recordings of in-person consultations.
Why we collect your information and our lawful basis
Under UK GDPR we must have a lawful basis for processing your personal data. For your clinical care with us, our bases are:
- Article 6(1)(b): the processing is necessary for the performance of a contract to which you are a party (our contract to provide you with private medical care)
- Article 9(2)(h): processing is necessary for the provision of health care by a health professional
We also process your information under the Common Law Duty of Confidentiality, on the basis of your implied consent for us to use your information for your direct care.
Additional bases apply in specific circumstances:
- Legal obligation, where we must share information by law (for example safeguarding, notifiable diseases, court orders)
- Vital interests, in an emergency where you cannot consent
- Legitimate interests, for practice administration such as billing and IT security
- Consent, for optional communications such as newsletters
We use your information for:
- Providing you with medical care and treatment
- Referring you to specialists, hospitals, and other healthcare providers
- Sending prescriptions to your chosen pharmacy
- Ordering and receiving test results from pathology and imaging providers
- Communicating with you about appointments, results, and follow-up (you cannot opt out of these)
- Billing you and processing payment
- Complying with our legal and regulatory obligations, including CQC, GMC, and reporting notifiable diseases to Public Health authorities
- Practice administration and quality improvement
- Occasional practice updates and communications (you may opt out of these at any time)
Who has access to your information within the practice
Access to your records is strictly limited to:
- Dr Oscar Duke
- The Practice Manager / PA
Access is protected by individual accounts, strong passwords, and two-factor authentication. Access is logged and audited.
Use of AI-assisted clinical documentation (Heidi)
We use an AI-assisted clinical documentation tool called Heidi (provided by Heidi Health) to help Dr Duke create accurate clinical notes during your consultations. Heidi acts as a scribe only. Your permanent clinical record is stored in Semble.
How it works
- With your knowledge and consent, Heidi listens to your consultation and produces a real-time transcript
- Heidi automatically removes personal identifiers from the transcript before AI processing
- From the transcript, Heidi generates a draft clinical note
- Dr Duke reviews, edits, and approves the note, then transfers the final version into your record in Semble
- The final clinical record is Dr Duke’s professional record, held in Semble, not the AI’s
Data handling
- Audio is transcribed in real time and is not saved. No audio recording of your consultation is retained.
- Transcripts and draft notes are held on Heidi’s platform for 30 days and then automatically and permanently deleted. During that time they exist as working material only, while the finalised note is placed into your Semble record.
- All Heidi data for UK customers is hosted on servers located within the United Kingdom
- Data is encrypted end-to-end (TLS 1.2 or higher in transit; AES-256 at rest)
- Heidi does not use your data to train its AI models
- Heidi does not undertake automated decision-making or profiling
- Heidi is our data processor, contractually bound to protect your information
- Heidi holds independent certifications including ISO 27001, ISO 42001, SOC 2, Cyber Essentials, DTAC (Digital Technology Assessment Criteria for the NHS), DSPT (NHS Data Security and Protection Toolkit), DCB0129/DCB0160 (NHS clinical safety standards), and confirms UK GDPR and Data Protection Act 2018 compliance
Your choice
- You are informed at the time of booking that Heidi may be used
- You can decline the use of Heidi at any consultation, and your care will not be affected
- Please tell Dr Duke at the start of your appointment if you would prefer not to have Heidi used
Lawful basis for AI-assisted documentation
- Our lawful basis for using Heidi is the same as the rest of your clinical care: Article 6(1)(b) (contract) and Article 9(2)(h) (provision of healthcare)
Who we share your information with
We share your information with third parties only where necessary and lawful. These include:
For your direct clinical care
- Specialists and hospitals to whom we refer you (with your knowledge)
- Pathology providers who process your samples: HCA Laboratories, The Doctors Laboratory (TDL), Alliance
- Imaging providers where you have scans arranged through us
- Your chosen pharmacy for prescriptions
- Out-of-hours services if you need urgent care outside our hours
- Your NHS GP, where you have asked us to share information with them
- Other clinicians involved in your care as clinically appropriate
For practice operations (processors acting under our instructions)
- Semble (Heydoc Ltd), our clinical records system provider, which holds your electronic patient record
- Heidi Health, our AI-assisted clinical documentation provider (see AI-Assisted Clinical Documentation above)
- Google (Google Workspace), our email and document system, which handles practice correspondence
- Our payment processor for card transactions
- Our accountants for billing reconciliation (limited financial information only, no clinical data)
Where legally required or permitted
- The Care Quality Commission, for safety incidents we are legally required to report
- Public Health authorities, for notifiable infectious diseases
- Local safeguarding authorities, where there are safeguarding concerns for a child or adult at risk. The relevant local authority depends on where the individual lives
- The Police, where required by law, court order, or where necessary to prevent serious harm
- Insurance companies, only where you have specifically requested us to share information with your insurer
- HM Revenue and Customs, limited financial information for tax compliance
- Regulators (GMC, CQC), where required for inspection, investigation, or professional duty
We do not sell your data. We do not share your data for marketing purposes with third parties.
International transfers
Most of your data is held in the UK or European Economic Area. Semble and Heidi both host UK customer data on UK-based servers. Google Workspace may transfer certain data internationally in the course of providing its services; where this occurs, transfers are made under approved safeguards including UK Adequacy Regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses. We configure our systems to keep data within UK/EU regions where possible.
How long we keep your information
We retain your records in line with NHS Records Management Code of Practice guidance:
- Adult patient records: minimum 10 years from last contact with us
- Records of patients under 18: until 26th birthday, or 8 years after last contact if later
- Deceased patient records: 10 years from date of death
- Maternity records: 25 years after birth of last child
- Mental health records: 20 years after last contact, or 8 years after death
- Financial and billing records: 7 years (HMRC requirement)
- Website analytics data: 26 months (Google Analytics default)
- Heidi consultation transcripts and draft notes: held on Heidi’s platform for 30 days and then automatically and permanently deleted. The finalised clinical note (reviewed and approved by Dr Duke) is stored in your Semble record and retained per the periods above.
We may retain records longer where there is a clinical, legal, or contractual reason to do so. When retention periods expire, records are securely destroyed.
Security
We take the security of your information seriously and use a combination of technical and organisational measures including:
- Encrypted storage of clinical data. Semble is ISO 27001, Cyber Essentials Plus, and NHS DSPT certified. Heidi is ISO 27001, ISO 42001, SOC 2, Cyber Essentials, NHS DSPT, and DTAC certified with UK data hosting.
- Two-factor authentication on all staff accounts accessing patient data
- Encrypted devices (laptops, phones)
- Restricted physical access to the practice
- Regular access reviews and audit logging
- Staff training on information governance and confidentiality
- Written information security and confidentiality policies
- Incident response procedures in the event of a data breach
- Careful selection of certified processors (Semble, Heidi, Google Workspace) with appropriate contractual and technical safeguards
Your rights
Under UK data protection law, you have the following rights:
The right to be informed: this notice, and any updates to it.
The right of access: you can ask for a copy of the personal data we hold about you. This is known as a Subject Access Request. We will respond within one month. There is normally no charge.
The right to rectification: you can ask us to correct any inaccurate personal data. Note that this does not extend to changing clinical opinions or removing accurate clinical information from your record.
The right to erasure: in limited circumstances you can ask us to delete your personal data. This right is significantly limited for medical records, which we are required to retain for the periods above for clinical safety, legal, and regulatory reasons.
The right to restrict processing: in limited circumstances you can ask us to stop actively processing your data whilst keeping it stored.
The right to data portability: where processing is based on consent or contract and is automated, you can ask for your data in a portable electronic format.
The right to object: you can object to certain types of processing, including direct marketing (where relevant) and processing based on legitimate interests. You can also object at any consultation to the use of Heidi AI-assisted documentation.
Rights related to automated decision-making: we do not make decisions about your care using solely automated processing. Heidi produces draft clinical documentation which is always reviewed and approved by Dr Duke before being included in your record.
The right to withdraw consent: where processing is based on your consent, you can withdraw it at any time.
The right to lodge a complaint: see below.
To exercise any of these rights, contact us at pa@thedukepractice.com or 020 7730 3700. We will need to verify your identity before releasing information.
Children and young people
This section applies to patients under 18 and to those signing on their behalf. It should be read together with the rest of this notice.
Registration and consent for children
- A parent or legal guardian with parental responsibility under the Children Act 1989 must register a child under 16 and provide consent on their behalf
- The Practice may ask for evidence of parental responsibility where this is unclear
- Where parents share parental responsibility (for example after separation or divorce), each parent has equal rights unless a court order says otherwise
- Where a child has been placed in care, the local authority holds parental responsibility
Gillick competence
- A young person under 16 who is assessed as having sufficient understanding to make their own healthcare decisions (Gillick competent) can consent to their own care and control access to their information
- In such cases, Dr Duke may agree to see the young person independently and to keep certain information confidential from their parents, in line with GMC guidance
- At 16, young people are generally presumed capable of making their own healthcare decisions
Access to a child’s records
- Parents with parental responsibility can generally request access to the records of a child who is not Gillick competent, where this is in the child’s best interests
- Where a Gillick competent young person objects to their parents accessing their records, we will not release information without their consent, except where required by law or to prevent serious harm
- Where parents are separated and there is disagreement, we may require a court order before releasing information
Safeguarding
- We are legally and professionally required to share information where a child is at risk of harm, or where an adult at risk (including a parent) requires safeguarding
- Where a safeguarding concern arises about a child, we will report to the relevant local authority safeguarding team, and to the police where appropriate
- We will normally inform parents of a safeguarding referral unless doing so would place the child at greater risk
Use of AI-assisted clinical documentation (Heidi) with children
- Dr Duke uses discretion about whether to use Heidi in paediatric consultations, particularly for sensitive matters such as safeguarding disclosures or adolescent mental health
- Older children and young people will be told directly when Heidi is being used and can decline
- All other safeguards described in the AI-Assisted Clinical Documentation section apply equally
Retention of children’s records
- Records of patients under 18 are retained until their 26th birthday, or 8 years after last contact with the Practice, whichever is later
Transition to adult status
- When a young person reaches 16, they generally take on decision-making about their own care and information
- Practice communications will normally be directed to the young person rather than the parent from that point
- Parents wishing to remain involved in their child’s care after 16 must have the young person’s consent
Making a complaint
If you have a concern about how we have handled your data, please contact us first at pa@thedukepractice.com or 020 7730 3700 so we can try to resolve it.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
What we ask of you
Please tell us if any of your contact details change so we can keep our records accurate.
Please tell us as soon as possible if you think there is an error in your records or if you have concerns about how we use your information.
Website and cookies
Our website uses basic analytics (Google Analytics) to understand how visitors use the site. This may involve cookies. You can control cookies through your browser settings. Our website does not use advertising cookies or share data with third parties for marketing purposes.
Data breaches
If we experience a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Changes to this notice
We may update this notice from time to time. The current version and date are shown at the top. Material changes will be communicated to you by email or notice on our website.
The Duke Practice Ltd, Privacy Notice, Version 2.0, 28 August 2026