IMY Diagnostics Centre Limited
Privacy Policy
This page provides the web version of the current IMY Diagnostics Centre Limited Privacy Policy covering personal data, data protection responsibilities and the use of cookies on imydiagnostics.com.
Definitions
For the purposes of this Privacy Policy, the following terms shall apply:
- “Information” – any data, records, or messages regardless of the form in which they are presented.
- “Personal Data” – any information relating to an identified or identifiable natural person (“data subject”). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
- “Processing of Personal Data” – any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, or destruction.
- “Data Controller” – the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Privacy Policy, IMY DIAGNOSTICS CENTRE LIMITED acts as the Data Controller.
- “Data Processor” – a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
- “Disclosure of Personal Data” – the act of making personal data available to a specific person or a defined group of persons in accordance with applicable law.
- “Dissemination of Personal Data” – the act of making personal data available to an indefinite group of persons or the public.
- “Information System of Personal Data” – any system, platform, or database used to store and process personal data, together with the associated information technologies and technical means.
General Provisions
Protecting the privacy and security of personal data is one of the core priorities of IMY Diagnostics. We are committed to ensuring that all personal data collected and processed by our organisation is handled responsibly, securely, and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
IMY Diagnostics has implemented a set of internal policies, technical measures, and organisational procedures designed to safeguard personal data against unauthorised access, loss, alteration, disclosure, or destruction. These policies are binding on all employees and contractors who have access to personal data.
This Privacy Policy sets out the principles, purposes, and conditions under which IMY Diagnostics processes personal data of its patients, employees, contractors, and other individuals. It also explains how we protect the rights and freedoms of data subjects, including the right to privacy, confidentiality of personal and family life, and protection against misuse of personal information.
All staff members of IMY Diagnostics who have access to personal data are personally responsible for ensuring compliance with applicable data protection laws and internal policies.
Failure to comply may result in disciplinary action and, where applicable, legal consequences.
1. Concept and Scope of Personal Data
2.1 Under this Privacy Policy, IMY Diagnostics defines personal data as any information relating to an identified or identifiable natural person (“data subject”). This includes information that can directly or indirectly identify a person, such as name, contact details, identification number, health information, or any other factor specific to the individual.
2.2 The processing of personal data at IMY Diagnostics is carried out in full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws and guidance issued by the Information Commissioner’s Office (ICO).
2.3 Depending on the category of data subjects, IMY Diagnostics may process the following types of personal data:
- Patients – identification data (name, date of birth, contact details), medical and diagnostic information (test results, medical history, referral details), billing and payment information.
- Employees and job applicants – personal details necessary for employment, including HR records, payroll and tax information, qualifications, training records, and occupational health information.
- Business partners, suppliers, and contractors – personal details of individuals acting on behalf of organisations, including name, position, contact details, and information necessary to manage business and contractual relationships.
2.4 Where required, IMY Diagnostics may also process special categories of personal data (e.g., health-related data, genetic or biometric data) strictly in accordance with UK GDPR, on the basis of explicit consent or other lawful grounds provided by law.
2. Purposes of Processing Personal Data
3.1 IMY Diagnostics processes personal data strictly in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and guidance from the Information Commissioner’s Office (ICO).
3.2 Personal data is processed for the following purposes:
- Provision of healthcare and diagnostic services – including the collection, testing, analysis, reporting, and delivery of medical test results, consultations, and related healthcare services.
- Contractual obligations – entering into, managing, and performing contracts with patients, employees, business partners, and suppliers, as necessary for the provision of services and business operations.
- Employment and HR purposes – maintaining personnel records, managing payroll and pensions, meeting obligations under UK employment, tax, and social security laws, ensuring workplace health and safety, and supporting training and professional development of staff.
- Regulatory and legal compliance – fulfilling obligations under applicable healthcare regulations, CQC standards, HMRC tax requirements, and other statutory duties.
- Communication – contacting patients and clients regarding appointments, results, follow-up care, service updates, and other operational matters.
- Legitimate business interests – ensuring the effective management of IMY Diagnostics, maintaining security of systems and premises, improving services, and protecting against fraud or misuse of services.
3.3 Where IMY Diagnostics processes special categories of personal data, such as health information, this is done on the basis of explicit consent, performance of healthcare obligations, or as otherwise permitted under UK GDPR.
3. Data Retention Periods
4.1 IMY Diagnostics retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, in line with the principles of the UK GDPR and the Data Protection Act 2018.
4.2 The retention period may vary depending on the type of data and the context of its processing. In particular:
- Patient data – retained for the duration of the patient’s relationship with IMY Diagnostics and for a minimum of 7 years after the last interaction, in accordance with NHS and CQC best practice guidelines. For children’s records, retention is until the patient reaches the age of 25, or 26 if the young person was 17 at the conclusion of treatment.
- Employee and HR records – retained during the term of employment and for at least 6 years after employment ends, in line with statutory requirements. Payroll and pension records may be retained longer where required by HMRC or pension law.
- Business partner and supplier data – retained for the duration of the contract and for up to 6 years thereafter, in line with the statutory limitation period under English law.
4.3 Once the applicable retention period expires, personal data will either be securely deleted, anonymised, or archived in compliance with legal requirements.
4.4 IMY Diagnostics regularly reviews its data retention policies to ensure compliance with applicable laws, regulations, and guidance from the Information Commissioner’s Office (ICO).
4. Rights and Responsibilities
5.1 Responsibilities of IMY Diagnostics (Data Controller)
IMY Diagnostics, as the Data Controller, is responsible for ensuring that all personal data is processed in accordance with UK GDPR, the Data Protection Act 2018, and applicable healthcare regulations. In particular, IMY Diagnostics shall:
- Process personal data lawfully, fairly, and transparently.
- Collect personal data only for specified, explicit, and legitimate purposes.
- Limit the processing of personal data to what is adequate, relevant, and necessary.
- Ensure that personal data is accurate and kept up to date.
- Retain personal data no longer than necessary for the purposes of processing.
- Implement appropriate technical and organisational measures to safeguard personal data.
- Disclose personal data to third parties only where permitted by law (e.g., HMRC, CQC, law enforcement authorities) or where necessary for the provision of services.
5.2 Rights of Data Subjects
Under UK GDPR, patients, employees, and other data subjects whose personal data is processed by IMY Diagnostics have the following rights:
- Right of access – to obtain confirmation whether their personal data is being processed and to receive a copy of such data.
- Right to rectification – to request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”) – to request deletion of personal data in certain circumstances (e.g., where the data is no longer necessary for the purposes for which it was collected, or consent is withdrawn).
- Right to restriction of processing – to request a temporary suspension of processing where accuracy is contested, or processing is unlawful.
- Right to data portability – to request transfer of their personal data to another provider, where technically feasible.
- Right to object – to object to the processing of personal data in certain situations, including processing based on legitimate interests.
- Right to lodge a complaint – to raise concerns with the Information Commissioner’s Office (ICO) if they believe their rights under data protection law have been infringed.
- Right to judicial remedy – to seek legal protection and compensation through the courts where rights have been violated.
5. Principles and Conditions of Personal Data Processing
6.1 IMY Diagnostics processes personal data in strict compliance with the principles set out under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The key principles are as follows:
- Lawfulness, fairness and transparency – personal data is processed lawfully, fairly, and in a transparent manner in relation to the data subject.
- Purpose limitation – personal data is collected for specified, explicit, and legitimate purposes and is not further processed in a way that is incompatible with those purposes.
- Data minimisation – personal data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
- Accuracy – personal data is accurate and, where necessary, kept up to date. Inaccurate data is corrected or erased without delay.
- Storage limitation – personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed.
- Integrity and confidentiality – personal data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage, using appropriate technical and organisational measures.
- Accountability – IMY Diagnostics is responsible for, and must be able to demonstrate, compliance with all of the above principles.
6.2 Conditions for processing personal data are determined in accordance with UK GDPR and the Data Protection Act 2018. Processing may take place on the basis of consent, contractual necessity, legal obligations, protection of vital interests, performance of tasks in the public interest, or legitimate interests pursued by IMY Diagnostics, provided such interests are not overridden by the rights and freedoms of data subjects.
6. Security of Personal Data
7.1 IMY Diagnostics implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are designed to ensure a level of security appropriate to the risks presented by the processing and the nature of the personal data.
7.2 Security measures may include, but are not limited to:
- Access controls and authentication procedures to prevent unauthorised access.
- Encryption and secure storage of digital records.
- Physical safeguards for premises and paper-based records.
- Regular staff training on data protection and information security.
- Regular review, testing, and updating of IT and cybersecurity systems.
7.3 IMY Diagnostics has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with data protection legislation and coordinating actions to ensure the security of personal data. Patients and staff may contact the DPO regarding any data protection matters.
7. Final Provisions
8.1 This Privacy Policy is an internal regulatory document of IMY Diagnostics and also serves as a public statement of our commitment to data protection.
8.2 The Policy will be updated whenever new legislation, regulatory requirements, or best practice standards are introduced, and in any case reviewed no less than once every three years.
8.3 Compliance with this Policy is mandatory for all employees and contractors of IMY Diagnostics.
8.4 Staff members of IMY Diagnostics who fail to comply with data protection rules and internal policies may be subject to disciplinary action and, where applicable, legal liability under UK law.
9. Cookie Policy
This Cookie Policy explains how IMY DIAGNOSTICS CENTRE LIMITED ("we", "us", or "our") uses cookies and similar technologies on our website https://imydiagnostics.com.
9.1. What are cookies?
Cookies are small text files placed on your device when you visit a website. They help us provide secure access to your account, improve our services, and ensure that important functions (such as booking tests and accessing results) work properly.
9.2. Types of cookies we use
- Strictly necessary cookies – These are essential for the functioning of our website and patient portal (e.g., login security, appointment booking, access to test results). These do not require your consent.
- Analytical / performance cookies – Help us understand how patients and visitors use our website (e.g., Google Analytics). These cookies are set only with your consent.
- Functionality cookies – Remember your preferences (such as language or location of the nearest laboratory). These are optional and require consent.
- Targeting / advertising cookies – May be used to provide you with information about our services, special offers, or health campaigns. These are set only with your consent.
9.3. Third-party cookies
Some cookies may be placed by trusted providers (e.g., Google Analytics, Facebook Pixel). These providers may process data outside the UK/EEA in compliance with UK GDPR.
9.4. Cookie consent
When you first visit our website, you will see a cookie banner that allows you to accept, reject, or customise your cookie preferences. You may withdraw or change your consent at any time by adjusting your browser settings or using our cookie management tool.
9.5. How long cookies are stored
Cookies may be stored for different periods:
- Session cookies – deleted when you close your browser.
- Persistent cookies – remain on your device for a defined period (e.g., up to 2 years) unless deleted manually.
9.6. Managing cookies
You can manage or delete cookies in your browser settings. Please note that disabling certain cookies may affect essential features, such as online booking or viewing laboratory test results.
9.7. More information
For more details on how we process your personal data, please see our Privacy Policy.
If you have any questions about our use of cookies, please contact us at info@imydiagnostics.com.
10. Google Search Console and Google API User Data
When an authorised IMY Diagnostics administrator connects Google Search Console to our internal IMY Analytics service, the service requests the Google Search Console read-only permission (webmasters.readonly). This permission does not allow IMY Analytics to change website settings or content in Google Search Console.
Google data we access. For the Search Console property selected by the authorised administrator, IMY Analytics may access the property/site list and search performance data including dates, pages, search queries, clicks, impressions, click-through rate (CTR), and average search position.
How we use Google data. We use this data only to provide internal SEO measurement, search performance reporting, dashboards, and analysis for IMY Diagnostics. Google Search Console data is not used for targeted advertising, credit decisions, sale to data brokers, or unrelated marketing purposes.
Storage and security. The Search Console integration is hosted on infrastructure controlled by IMY Diagnostics. OAuth credentials are stored securely and encrypted at rest. Imported Search Console performance data is stored within the IMY Analytics environment and access is restricted to authorised personnel.
Sharing and transfers. We do not sell, rent, or disclose Google user data to third parties for advertising or other unrelated purposes. Access is limited to personnel and service infrastructure required to operate and secure the IMY Analytics feature.
Artificial intelligence and machine learning. Google Search Console OAuth data is not used to train, develop, or improve general-purpose or non-personalised artificial intelligence or machine-learning models.
Retention, disconnection, and revocation. OAuth access may be disconnected from IMY Analytics, which removes the stored Google OAuth connection credentials. Access may also be revoked at any time through the Google Account permissions settings. Imported analytics data is retained only for as long as necessary for the internal analytics purposes described in this Policy and applicable legal or operational requirements, after which it is deleted or anonymised where appropriate.
Our use of information received from Google APIs is limited to providing and improving the user-facing functionality described above and is subject to the applicable Google API Services User Data Policy.
This HTML page reproduces the current Privacy Policy published by IMY Diagnostics Centre Limited in a responsive web format and includes the disclosures applicable to the IMY Analytics Google Search Console integration.