Privacy Policy

What this policy covers

This policy explains how Child Psychiatry Consultancy Ltd collects, uses, stores, and protects your personal and health information. We are committed to handling all data lawfully, securely, and transparently in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What information we collect

We collect personal information about patients and families including: name, date of birth, address, and contact details; GP details and medical history; information shared during assessments and consultations; school reports and teacher questionnaires; assessment tool data; and prescribing and medication records.

Why we collect it and our lawful basis

We collect and use your information to provide medical assessment, diagnosis, and treatment. Our lawful basis for processing health data is Article 9(2)(h) of the UK GDPR — the management of health or social care systems. We may also process data to comply with legal obligations such as safeguarding, or where you have given explicit consent.

The systems we use

Your information is held and processed using the following systems, all of which operate under Data Processing Agreements and are compliant with UK GDPR:

•       Carebit — electronic clinical records, appointments, and correspondence

•       Clynxx (via Carebit) — electronic prescriptions for non-controlled medications

•       Healistic — secure encrypted prescriptions for controlled medications

•       Zoho Forms — new patient registration and questionnaires

•       Softr — patient portal for prescription refill requests and assessment questionnaires

•       Proton Workspace Business (ProtonMail) — all clinical and administrative email

•       Zoom Business — secure video consultations

•       ESET Endpoint Security Enterprise — device and data protection

•       ProtonDrive — administrative documents only (no clinical records)

•       MHS / Conners 4 — ADHD rating scales

•       QB Check (QbTech) — QB Test ADHD assessment

How we keep your information safe

All clinical records are stored in Carebit, which is encrypted and GDPR-compliant. All email correspondence is sent via Proton Workspace Business, which is end-to-end encrypted. All devices are encrypted and protected by ESET Endpoint Security Enterprise. Two-factor authentication is enabled on all systems. Video consultations are conducted via Zoom Business with waiting rooms and unique encrypted session links. No patient data is stored on USB drives, personal cloud accounts, or unencrypted devices.

Who we share your information with

Your information is treated as strictly confidential. We will only share it with your consent; when necessary for your child's direct clinical care (such as with your GP or school); when required by law such as for safeguarding purposes; or when required by a regulatory body such as the CQC or GMC. We will always tell you when information has been shared unless doing so would put someone at risk.

How long we keep your information

•       Children and young people's health records: until the child's 25th birthday, or 8 years after last contact — whichever is longer

•       Safeguarding records: 25 years from the date of last contact

•       Adult patient records: 8 years after last contact

•       Prescribing records: minimum 8 years

•       Administrative and financial records: minimum 6 years

Your rights

Under UK GDPR you have the right to: access your personal data; have inaccurate data corrected; request erasure (subject to legal retention requirements); restrict how we process your data; and complain to the Information Commissioner's Office (ICO) at ico.org.uk if you believe your rights have not been respected.

To exercise any of these rights, please contact our Data Protection Lead: Dr Athina Zakynthinaki at info@childpsychiatry.uk

Data breaches

If a data breach occurs that is likely to affect your rights or freedoms, we will notify you without undue delay and report to the ICO within 72 hours. All breaches are recorded and reviewed to prevent recurrence.

Contact us

•       Email: info@childpsychiatry.uk

•       ICO: ico.org.uk | 0303 123 1113