Privacy & Cookies
Privacy Policy – Smart rTMS Ltd
Last updated - June 2025
Smart rTMS Ltd respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, store, and protect your personal data when you interact with us, particularly in the context of providing healthcare services.
Introduction
We collect and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws governing the handling of sensitive health information. This policy explains how we handle your data when you visit our website, use our services, or engage with us in any capacity.
Who We Are
Smart rTMS Ltd is a healthcare provider specialising in Transcranial Magnetic Stimulation (TMS) therapy, a non-invasive treatment for mental health conditions. Smart rTMS Ltd is the data controller for your personal data.
What Personal Data We Collect
We may collect the following categories of personal and sensitive data:
-
Personal identification details: Full name, contact details, date of birth, identification numbers.
-
Medical information (Special Category Data): Mental and physical health history, treatment records, clinical notes, referral letters, and outcome measures.
-
Transactional data: Payment and billing information, appointment bookings.
-
Technical and usage data: IP address, browser type, site interaction (collected via cookies, if consented).
-
Communication records: Emails, telephone logs, messages, and other service-related correspondence.
Legal Basis for Processing Your Data
We process your data under the following legal bases:
-
Explicit Consent: Required for processing health data. You will be asked to provide written or electronic consent before we collect or share any medical information.
-
Performance of a Contract: To deliver services such as assessments, treatments, and follow-up care.
-
Legal Obligations: For compliance with healthcare regulations, safeguarding obligations, and insurance reporting.
-
Legitimate Interests: For business administration, improving clinical services, or handling customer service interactions, unless these are overridden by your rights.
Use of Your Data
We use your data for the following purposes:
-
To provide healthcare services, including consultations, treatments, and medical reporting.
-
To manage appointments, billing, and communication.
-
To ensure safety, continuity of care, and quality assurance.
-
To respond to enquiries, complaints, and patient feedback.
-
To send optional service updates and promotional content (with opt-out option).
Data Sharing
Your data may be shared with:
-
Healthcare professionals involved in your treatment.
-
Third-party service providers such as electronic health record systems, secure cloud storage, or payment processors—each contractually bound by confidentiality and data protection obligations.
-
Regulatory bodies or insurers, if legally required.
We do not sell your data to third parties.
Where Your Data Is Stored
Your personal and medical data may be stored:
-
On secure UK-based servers or in secure cloud environments located within the UK or EEA.
-
In compliance with NHS and ICO-approved standards for storing and accessing health data.
-
We implement encryption, restricted access, multi-factor authentication, and regular auditing to safeguard your data.
Data Retention
We retain your personal and medical data only as long as is necessary:
-
Medical records: Typically kept for 8 years after the last treatment (or longer if legally required).
-
General correspondence and non-health-related data: Retained for a shorter, proportionate period based on service history.
After the retention period, your data will be securely deleted or anonymised.
Your Rights
Under data protection law, you have the right to:
-
Access the personal data we hold about you.
-
Rectify incorrect or outdated information.
-
Withdraw consent where processing is based on consent.
-
Request erasure of your personal data, where applicable.
-
Object to or restrict processing in certain situations.
-
Request a copy of your data in a portable format.
To exercise your rights, contact us using the details below. We may need to verify your identity before processing your request.
Data Security
We take all reasonable technical and organisational steps to protect your data:
-
Encrypted communications and storage
-
Role-based access controls
-
Regular penetration testing and audits
-
Staff training on data protection and confidentiality
In the event of a data breach, we will notify you and the appropriate authorities in accordance with GDPR.
Updates to This Policy
We may update this Privacy Policy to reflect changes in legal obligations or service delivery. The most recent version will always be available on our website. We recommend reviewing it regularly.
Contact Us
If you have any questions or wish to make a request regarding your personal data:
Email: info@smarttms.co.uk
Address: Smart rTMS Ltd
9 Cirencester Business Park,
Tetbury Road, Cirencester,
GL7 6JJ, United Kingdom
Cookies Policy
Last updated: March 2025
This Cookies Policy explains how Smart rTMS Ltd uses cookies and similar technologies on our website. By using our website, you consent to the use of cookies in accordance with this policy.
What Are Cookies?
Cookies are small text files placed on your device to store information that allows our website to function efficiently and provide personalized experiences.
Types of Cookies We Use- Essential Cookies: These are necessary for the functioning of the website, such as for security or logging into your account.
- Analytical Cookies: These cookies track usage patterns to help us understand how visitors use the website. This helps us improve site performance and content.
- Functional Cookies: These cookies remember your preferences, such as language settings or location.
- Targeting Cookies: These cookies are used to deliver personalized advertisements based on your interests.
Managing Cookies
You can manage your cookie preferences through your web browser settings. Most browsers allow you to block or delete cookies, but doing so may affect the functionality of our website.
Third-Party Cookies
We may use third-party services, such as analytics or advertising partners, who may place cookies on your device. These cookies are governed by the third parties' privacy policies.
Changes to the Cookie Policy
We may update this Cookies Policy from time to time. You can always check the date at the top of this page to see when it was last updated.
Contacting the Regulator
If you believe we have not handled your personal data correctly, or if you are dissatisfied with how we’ve responded to your request, you have the right to file a complaint with the Information Commissioner’s Office (ICO) in the UK. You can reach them at:
Website: www.ico.org.uk/concerns
Phone: 0303 123 1113
If you are based outside of the UK, please contact the relevant data protection authority in your country of residence.
Final Notes
We hope this policy provides clarity on how we handle your data, and we remain committed to ensuring your privacy is protected. If you have any questions, don't hesitate to contact us.
Find a clinic