Legal & compliance

Privacy policy

How we collect, use, and protect personal information when you contact the practice, attend clinic, or use this website.

Last reviewed 13 June 2026

This privacy policy explains how Breastory Limited (“Breastory”, “we”, “us”) collects, uses, and protects personal information when you contact the practice, attend a clinic, or use this website.

Breastory is the trading name of Breastory Limited, a company registered in England and Wales — company number 12588047. Dr Fiona Tsang-Wright is the sole practising clinician and is registered with the General Medical Council (GMC) — GMC number 4549831.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the common-law duty of confidentiality that applies to health records.

Who is the data controller

Breastory Limited is the data controller for the information we hold about you.

For questions about this policy, or to exercise any of the rights set out below, please contact the practice PA in the first instance.

What information we collect

When you contact the practice

When you email, call, or message the PA, we record your name, contact details, the reason for your enquiry, and any clinical information you share so we can respond appropriately and arrange an appointment.

When you attend a clinic

When you are seen in clinic we record standard clinical information, including:

  • Name, date of birth, contact details, next-of-kin (if provided)
  • NHS number (where available) and GP details
  • Clinical history, examination findings, and any family history relevant to breast disease
  • Imaging, pathology, and other investigation results
  • Treatment plans, operation notes, correspondence, and follow-up arrangements
  • Details of your private medical insurer (where applicable) or self-pay arrangements

This information forms your medical record and is held by the hospital where you are seen (HCA Healthcare UK, Circle Health Group, or Buckinghamshire Healthcare NHS Trust), and by Breastory as the treating consultant’s practice.

When you use this website

This website does not require account registration. We may collect:

  • Information you provide via contact forms (name, email, message)
  • Standard server logs (IP address, browser type, pages visited), retained for security and performance monitoring
  • Analytics data (aggregated page-view information) if analytics are enabled

Cookies and tracking technologies, where used, are detailed in our cookie notice.

How we use your information

We use personal information to:

  • Respond to enquiries and arrange appointments
  • Provide clinical care and keep accurate medical records
  • Liaise with your GP, other specialists, and your private medical insurer with your consent
  • Comply with legal and regulatory obligations (including CQC and GMC requirements)
  • Manage payment, billing, and insurance claims
  • Improve the service, respond to complaints, and defend any legal claims

Under UK GDPR we rely on the following legal bases:

  • Contract — to arrange and provide the service you have asked for
  • Legitimate interests — to administer the practice, manage billing, and respond to enquiries
  • Legal obligation — to meet statutory, regulatory, and tax record-keeping requirements
  • Public interest / official authority — where data sharing is required by law (for example, cancer registry reporting)

For health data (a “special category” under UK GDPR) we additionally rely on:

  • Article 9(2)(h) — provision of health care and treatment
  • Article 9(2)(c) — vital interests, in an emergency
  • Explicit consent — for any processing outside the above, such as including your case in teaching or research

Who we share information with

We share information only where necessary and with appropriate safeguards. This may include:

  • The hospital where you are seen (HCA Healthcare UK, Circle Health Group, or the NHS trust) — which co-holds your medical record
  • Your GP — follow-up letters after each appointment
  • Other clinicians involved in your care — radiologists, pathologists, oncologists, plastic surgeons, breast-care nurses, anaesthetists
  • Multidisciplinary team (MDT) meetings — every cancer case is discussed in an MDT with radiology, pathology, oncology, and nursing before treatment is confirmed
  • Your private medical insurer — for pre-authorisation and invoicing, with your consent
  • Regulatory and statutory bodies — including the Cancer Registry, where required by law
  • IT suppliers — under contract and with appropriate data-protection terms

We do not sell your personal data. We do not share your personal data for marketing purposes.

AI tools used in your care

Two AI tools are used in routine clinical workflow at Breastory. Both are explained in plain language on the AI in your care page; this section sets out the data-protection specifics.

AI-assisted radiology (used by the imaging centre)

When you have imaging at any of the imaging centres the practice uses (HCA’s facilities at Harley Street and Chelsea, Circle Health Group at Great Missenden), the imaging centre operates AI-assisted reading software as a second-look layer alongside the consultant radiologist. Examples of the software vendors in use are Lunit INSIGHT MMG, Kheiron MIA, and iCAD ProFound AI.

Under UK GDPR, the imaging centre is the data controller for your image data — Breastory is not. The flow is:

  • Your image is captured and processed within the imaging centre’s data-handling perimeter.
  • The AI software runs on the imaging centre’s infrastructure (or cloud infrastructure operated under the imaging centre’s data-protection contract with the AI vendor).
  • The consultant radiologist reads the image and the AI’s flags, then writes the report.
  • Breastory receives the radiologist’s written report, not the AI’s output directly. The report is a clinician’s document.

Specific questions about your image data — where it’s stored, who can access it, retention periods — are best directed to the imaging centre’s data protection officer. Breastory’s role with respect to your imaging is to act on the radiologist’s report and store it as part of your clinical record.

Heidi consultation scribe (used by Dr Tsang-Wright)

Dr Tsang-Wright uses Heidi, a clinical-grade AI scribe, during consultations. Heidi processes the consultation audio to generate a structured clinic note that Dr Tsang-Wright reviews, edits, and signs off. Specifically:

  • Lawful basis under UK GDPR: processing of special-category health data for the purposes of the provision of healthcare under Article 9(2)(h), supported by your explicit consent under Article 9(2)(a) confirmed at the start of each consultation in which the tool is used.
  • What is processed: the audio of the consultation, the resulting transcript, and the structured clinic note generated from that transcript.
  • Where it is processed: on Heidi’s infrastructure, in cloud servers operated under Heidi’s data-handling policy. Heidi is a third-party data processor with whom Breastory has a written data-processing agreement compliant with UK GDPR Article 28.
  • Retention: the audio is retained for a defined period (currently 30 days at the time of writing) after which Heidi deletes it. The transcript and the structured clinical note become part of your clinical record at the practice and are retained per the standard retention periods set out in How long we keep information below.
  • Sub-processors: Heidi may use sub-processors (e.g., cloud hosting providers, speech-recognition components). These are listed in Heidi’s published data-protection documentation; we will provide the current list on request.
  • International transfers: if and where audio or transcript data is processed in jurisdictions outside the UK / EEA, the transfer is subject to UK GDPR-compliant transfer mechanisms (UK addendum to the EU Standard Contractual Clauses, or an adequacy decision). Heidi’s published policy lists the current data-processing locations.
  • Access: the structured clinical note is accessible to Dr Tsang-Wright, the practice PA for administrative purposes, and your GP if a copy of the consultation letter is sent to them at your request. Heidi’s own staff do not routinely access individual consultation audio or transcripts.

Your rights specifically with respect to AI tools

In addition to the rights set out under Your rights below, in relation to the AI tools described in this section you can specifically:

  • Decline use of Heidi at any consultation. Tell Dr Tsang-Wright at the start of the appointment; she will take notes by hand instead. There is no need to justify the decision and it does not affect your care.
  • Request earlier deletion of Heidi audio. The standard retention period is set by Heidi; if you would like a specific consultation’s audio deleted earlier, contact Sarah at [email protected] and the practice will request deletion on your behalf.
  • Request a copy of any AI-generated material relating to you. Subject to the Your rights section below, you can make a Subject Access Request for the transcript, the structured note, or any other material Heidi has produced from your consultations.
  • Decline AI-assisted radiology. Most UK private imaging centres apply AI-assisted reading to every scan as part of standard workflow, so opting out is harder than for tools the practice uses directly. Some centres can arrange a human-only second-reader pathway at additional cost; speak to Sarah for practical advice on the options at each clinic.

If a new AI tool is added to the practice’s clinical workflow, this policy will be updated and patients will be informed at their next appointment before the tool is used in their care.

How long we keep information

Medical records are retained in line with current NHS Records Management Code of Practice and independent-healthcare guidance. For adult breast-cancer records this is typically 30 years from the last entry; other clinical records are retained for at least 8 years from the last entry. Financial records are retained for 7 years for tax purposes. Non-clinical enquiry correspondence is retained for as long as needed to respond and then deleted.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you (a “subject access request”)
  • Rectification of inaccurate data
  • Erasure of data, subject to the legal retention periods above
  • Restriction of processing in certain circumstances
  • Object to processing based on legitimate interests
  • Data portability for data you have provided
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, please contact the PA at [email protected]. We will respond within one calendar month.

Security

We take the security of personal data seriously. Clinical records are held on the hospitals’ secure clinical systems. Practice email and records are held on platforms with encryption in transit and at rest, and access is restricted to the treating clinician and authorised practice staff. We review our security arrangements regularly.

Complaints

If you are concerned about how we have handled your personal data, please contact us first — we will always try to resolve concerns directly. You also have the right to complain to the Information Commissioner’s Office (ICO):

Changes to this policy

This policy may be updated from time to time. The date of the most recent update is shown below. Material changes will be highlighted on the website for a reasonable period.

Last updated: 13 June 2026