1. Who We Are

Clinic Plastic Surgery is operated by Mr Andrej Salibi and Miss Maria Chasapi, consultant plastic surgeons practising in Birmingham and London, United Kingdom. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you interact with our Website (www.clinicplasticsurgery.com) or contact us to enquire about our services.

For the purposes of UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is Clinic Plastic Surgery.

Contact for data protection matters:

  • Email: contact@clinicplasticsurgery.com
  • Telephone: (+44) 01217169654

2. The Information We Collect

2.1 Information You Provide to Us

When you complete a consultation booking form or contact us via the Website, we may collect:

  • Your full name
  • Email address
  • Telephone number
  • The subject or nature of your enquiry
  • Any additional information you include in your message

If you proceed to a consultation, further information will be collected directly by the clinical team or our partner facilities, governed by their own data practices and the applicable healthcare confidentiality frameworks.

2.2 Information Collected Automatically

When you visit our Website, we may automatically collect certain technical information, including:

  • Your IP address and browser type
  • Pages visited and time spent on the Website
  • Referring website or search terms used to find us
  • Device type and operating system

This information is collected via cookies and similar technologies. Please see Section 8 (Cookies) for more detail.

3. Special Category Data

Health information is sensitive personal data under UK GDPR and is handled with the highest level of care.

Information relating to your health, medical history, or intended medical procedures constitutes special category data under UK GDPR (Article 9). Where you share such information in your enquiry or consultation, we process it on the basis of:

  • Your explicit consent (Article 9(2)(a))
  • The provision of healthcare services (Article 9(2)(h)), including preventative medicine, medical diagnosis, the provision of health or social care or treatment

We will never use health information for any purpose other than managing your care and enquiries, and will process it in accordance with Article 9 of UK GDPR and Schedule 1 of the Data Protection Act 2018.

4. How We Use Your Information

We use the personal information we collect for the following purposes:

  • To respond to consultation enquiries and arrange appointments
  • To communicate with you regarding your enquiry or confirmed consultation
  • To provide pre- and post-operative information and follow-up care where relevant
  • To comply with our legal and professional regulatory obligations
  • To improve the Website and our services based on aggregate usage data
  • To manage the security and integrity of our digital communications

5. Legal Basis for Processing

We rely on the following lawful bases under UK GDPR to process your personal data:

  • Consent (Article 6(1)(a)): where you have actively provided your information and agreed to our contacting you
  • Legitimate Interests (Article 6(1)(f)): to operate and improve the Website and manage enquiries in a way you would reasonably expect
  • Legal Obligation (Article 6(1)(c)): to comply with applicable laws, regulatory requirements, or professional standards
  • Vital Interests or Healthcare (Articles 6(1)(d), 9(2)(h)): in connection with the provision of clinical care

6. Sharing Your Information

We do not sell, rent, or trade your personal data. We may share your information in the following limited circumstances:

Partner Clinical Facilities

When a consultation is confirmed, necessary details will be shared with the relevant partner facility (Cadogan Clinic in London or Kat & Co. Clinic in Birmingham) for the purpose of administering your appointment. These facilities operate under their own data protection frameworks and healthcare confidentiality obligations.

Service Providers

We may use third-party service providers to help operate the Website (such as web hosting, form processing, and email delivery services). These providers act as data processors and are contractually required to process your data only on our instructions and in compliance with UK GDPR.

Legal and Regulatory Requirements

We may disclose your information where required by law, court order, or regulatory authority, including to the General Medical Council (GMC), Care Quality Commission (CQC), or any other body with lawful authority to require disclosure.

7. International Transfers

We aim to keep your data within the United Kingdom and European Economic Area (EEA) wherever possible. Where any third-party service provider processes data outside the UK or EEA, we ensure that appropriate safeguards are in place, such as UK adequacy decisions or standard contractual clauses, in compliance with UK GDPR Chapter V.

8. Cookies

Our Website uses cookies – small text files placed on your device – to support the functioning of the Website and to help us understand how visitors use it. The types of cookies we may use include:

  • Essential cookies: required for the Website to function correctly, including form functionality
  • Analytics cookies: used to collect anonymous data about how visitors interact with the Website (e.g. via Google Analytics)
  • Preference cookies: used to remember your settings or preferences

You can control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Website. By continuing to use the Website without changing your cookie settings, you consent to our use of cookies as described above.

We may update our cookie practices in line with changes to relevant technology or regulation. Please revisit this policy periodically for updates.

9. Data Retention

We retain your personal information only for as long as is necessary for the purposes described in this Policy, or as required by law or professional regulation.

  • Website enquiry and contact data: retained for up to 2 years from the date of last contact, unless you request earlier deletion
  • Clinical and health-related data: retained in accordance with NHS and healthcare regulatory guidelines, typically a minimum of 8 years for adult patients from the date of last treatment (or until age 25 for patients who were minors at the time of treatment)
  • Analytics and technical data: typically retained for up to 26 months in aggregated or anonymised form

10. Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include secure email communications, access controls, and encrypted data transmission via HTTPS.

However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours, and you will be notified directly where required.

11. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access: to request a copy of the personal data we hold about you
  • Right to rectification: to request correction of inaccurate or incomplete data
  • Right to erasure: to request deletion of your data in certain circumstances
  • Right to restrict processing: to request that we limit how we use your data
  • Right to data portability: to receive your data in a structured, machine-readable format
  • Right to object: to object to processing based on legitimate interests or for direct marketing
  • Rights relating to automated decision-making: we do not use your data for automated decision-making or profiling

To exercise any of these rights, please contact us at contact@clinicplasticsurgery.com. We will respond to your request within one calendar month. We may need to verify your identity before processing your request.

If you are not satisfied with how we handle your data or respond to your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: www.ico.org.uk
  • Helpline: 0303 123 1113

12. Children's Privacy

Our Website is not directed at children under 18. We do not knowingly collect personal data from individuals under 18 without appropriate parental or guardian consent. If you believe we have inadvertently collected data from a minor without consent, please contact us immediately and we will take steps to delete that information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. We will indicate the date of the most recent revision at the top of this page. Your continued use of the Website following any update constitutes your acceptance of the revised Policy.

For material changes that significantly affect how we use your data, we will make reasonable efforts to notify you directly where we hold valid contact details.

14. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

  • Email: contact@clinicplasticsurgery.com
  • Telephone: (+44) 01217169654
  • Birmingham: Kat & Co. Clinic, 20 Calthorpe Rd, Edgbaston, Birmingham, B15 1RP
  • London: Cadogan Clinic, 120 Sloane Street, Chelsea, London, SW1X 9BW
Logo of The British Association of Aesthetic Plastic Surgeons with acronym BAAPS and medical symbol.Royal College of Surgeons of Edinburgh emblem featuring a crowned eagle on a checkerboard base.Queen Mary University of London logo with a stylized crown above the text.Logo of the International Society of Aesthetic Plastic Surgery (ISAPS).Word 'INCISION' in large uppercase gray letters on a white background.