Data Protection Statement
Introduction
This Data Protection Statement explains how Gastric Band Support collects, uses, and protects personal data in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Given the nature of our services, we recognise the importance of handling personal and health-related data with a high level of care, confidentiality, and security.
Who We Are
Gastric Band Support provides gastric band aftercare, adjustments, and related support services within the UK.
For the purposes of data protection law, we act as a data controller in relation to the personal data we process.
Types of Personal Data We Process
Depending on how you interact with us, we may process the following categories of personal data:
Personal Information
Name
Email address
Telephone number
Location or clinic preference
Service and Enquiry Information
Information submitted via contact or booking forms
Appointment details
Communications with you
Health Information (Special Category Data)
Due to the nature of our services, we may process health-related information, which is classified as special category data under UK GDPR.
This may include:
Information relating to gastric band procedures
Treatment history or aftercare needs
Relevant medical or lifestyle information you choose to provide
Technical Data
IP address
Browser type and device information
Website usage data
How We Use Personal Data
We process personal data to:
Respond to enquiries and provide support
Arrange and manage appointments
Deliver healthcare-related services and aftercare
Maintain appropriate medical and service records
Improve our services and website functionality
Ensure the security and integrity of our systems
Comply with legal and regulatory obligations
Lawful Basis for Processing
We rely on the following lawful bases under UK GDPR:
For Personal Data:
Consent – where you submit enquiries or agree to cookies
Contractual necessity – to provide requested services
Legitimate interests – to manage and improve our services
For Special Category (Health) Data:
We process health data under Article 9 UK GDPR, including:
Explicit consent
Provision of health or social care (where applicable and permitted under law)
Data Sharing
We do not sell personal data.
We may share personal data where necessary with:
IT and website service providers
Booking or communication systems
Professional advisers (e.g. legal or accounting)
Any third parties processing data on our behalf are required to implement appropriate data protection safeguards.
International Data Transfers
We do not routinely transfer personal data outside the United Kingdom.
If this changes, we will ensure that appropriate safeguards are in place, such as adequacy regulations or approved contractual clauses.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, regulatory, and professional obligations.
Where health-related data is involved, retention may be subject to specific healthcare or professional record-keeping requirements.
Data Security
We implement appropriate technical and organisational measures to protect personal data, including:
Restricted access to personal information
Secure storage systems
Measures to prevent unauthorised access, loss, or disclosure
Your Rights
Under UK data protection law, you have the right to:
Access your personal data
Request correction of inaccurate or incomplete data
Request erasure of your data (where applicable)
Restrict or object to processing
Request data portability (where applicable)
Withdraw consent at any time (where processing is based on consent)
To exercise your rights, please contact us using the details below.
Contact Details
If you have any questions about this Data Protection Statement or how your data is handled, please contact:
Gastric Band Support
Email: [email protected]
Telephone: 07947 606 275
Complaints
If you are not satisfied with how your personal data is handled, you have the right to lodge a complaint with:
Information Commissioner’s Office (ICO)
https://ico.org.uk/
Updates to This Statement
We may update this Data Protection Statement from time to time. Updates will be published on this page.
Last updated: 20/03/2026