Skip to main content

Legal

Privacy notice

What personal information Sevanta Health Ltd collects, why, who sees it, where it goes — including to India — how long we keep it, and your rights over it. Written in plain English because that is what the law requires and what you deserve.

01Who we are and how to reach us

Sevanta Health Ltd is a company registered in England and Wales, company number 17407709, registered in Cambridge, England. Our registered office address appears on the Companies House register and on all our written correspondence. We are the data controller for the personal information described in this notice.

We are registering with the Information Commissioner’s Office (ICO) before we accept a first enquiry; our registration number will appear here and in the footer of every page once issued. Questions about this notice, and any request to exercise your rights, can be sent by email or by post to the registered office, marked for the attention of the data protection lead. We reply within one month.

02What this notice covers, and some definitions

This notice applies to this website and to the coordination services Sevanta provides. “Personal data” means any information that identifies you or could identify you. “Special category data” means information about your health, which the law protects more strictly. “Processing” means anything we do with your data, from collecting it to deleting it. “Controller” means the organisation that decides why and how data is processed; “processor” means an organisation that handles data only on a controller’s instructions.

It does not apply to the hospitals that treat you, to our partner organisation in India, or to any other website we link to. Each of those has its own notice, and we point you to it where it matters.

03What we collect, and when

At first contact: your name, email address, telephone number, the treatment you are interested in, and anything you choose to tell us. We deliberately ask for no medical information at this stage, and we ask you not to send any. If a family member contacts us on your behalf we record their name and contact details as well as yours.

Only after you have read this notice and given separate, explicit consent: your medical history, imaging, clinic letters, medication list and other health information, which is special category data; your passport details for visa and admission purposes; and details of a companion, with their agreement.

Automatically: the enquiry form records the exact wording of the consent you gave and the time you gave it, because the law requires us to be able to show that. Our web server records only what is needed to serve pages and defend against attack, and we never write your IP address, name or any medical detail into logs, error reports or analytics.

04Why we use it, and our lawful basis

To reply to your enquiry and hold the first conversation: our legitimate interest in responding to someone who has asked us to, and, once you sign a coordination agreement, performance of that contract (Article 6(1)(b) and (f) UK GDPR).

To share your health information with the hospitals you have chosen to be considered by, so that a surgeon can assess your case and give you a quotation: your explicit consent (Article 9(2)(a)), given separately, unticked by default, and withdrawable at any time.

To send your discharge record to your GP when you return, and to brief your UK physiotherapist: your explicit consent, given separately.

To keep records of what we have done and told you: our legal obligations under consumer, tax and company law (Article 6(1)(c)), and our legitimate interest in being able to answer a complaint or a claim.

We do not use your data for marketing, profiling or automated decision-making, and we never sell it.

05Who sees it

The Sevanta coordinator handling your case. The surgeon and clinical team at each hospital you have chosen to be considered by — not every hospital on our register. Our partner organisation in India, which receives your travel, admission and contact details but not your clinical records unless you ask us to share them. Your UK physiotherapist and, with your consent, your GP. Our IT, email and secure file-transfer providers, under written contracts that bind them to our instructions and to the UK or EEA. Nobody else, and nobody for marketing.

We may also disclose personal data where the law requires it — to a court, a regulator or the police on a lawful request — and we will tell you when we have, unless the law prevents us.

06Transfers to India

India does not have a UK adequacy decision, so sending your information there is a “restricted transfer” under UK GDPR. Before any record leaves the UK we put in place an International Data Transfer Agreement (or the UK Addendum) with each hospital and with our partner organisation, complete a transfer risk assessment, and obtain your explicit, informed consent. You may see the agreement on request. Each hospital that receives your records becomes a controller in its own right under Indian law for the clinical record it creates. The data-protection page explains this in more detail.

07Where it is stored, and how it is protected

Our systems store personal data in the United Kingdom or the European Economic Area, encrypted at rest and in transit. Static parts of this website are served from a global content delivery network, which holds no personal data. Health information is held only in systems that meet our security standard, never in ordinary email, and never on a personal device. Access is limited to the people who need it for your case, and every access to a health record is logged.

08Cookies and analytics

This website sets no analytics or marketing cookies unless you choose to allow them, and nothing that is not strictly necessary is loaded before you do. If you accept analytics, we use a privacy-focused, EU-hosted service that counts page views without identifying you. The booking calendar and any embedded video are provided by third parties whose scripts may set cookies; they load only after you consent. Our cookie policy lists every cookie by name and purpose.

09How long we keep it

An enquiry that does not become a client relationship: twelve months from the last contact, then deleted. A client file: for the duration of the coordination agreement and the twelve-month follow-up, and then for the period required to defend a claim, which our retention schedule will state precisely once agreed with our advisers and insurers. Consent records: for as long as the data they relate to. We will publish the full retention schedule on this page before the first enquiry is accepted.

10Your rights

You can ask for a copy of everything we hold about you; ask us to correct it; ask us to delete it, which we will do unless a legal obligation requires us to keep it; restrict how we use it while a dispute is resolved; withdraw consent at any time, which stops further sharing though it cannot recall what a hospital already holds under its own obligations; object to processing based on legitimate interests; and ask for your data in a portable form. None of these costs anything, and we reply within one month.

You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right, and our complaints procedure sets out how.

11Children

Our services are for adults. We do not knowingly collect personal data from anyone under eighteen, and we will not coordinate treatment for a child. If you believe a child has given us information, contact us and we will delete it.

13Changes to this notice

When this notice changes, the previous version remains available on request. If a change affects how we use data you have already given us, we tell you directly before it takes effect rather than relying on you to notice.