The Alexander Clinic
Privacy Policy
This policy explains what information we hold about you, why we hold it, how long we keep it, and who — if anyone — ever sees it. It covers our cosmetic services and wellness programmes. It is written to be read, not skimmed past.
Who we are
The Alexander Clinic is the data controller for the information described in this policy. That means we decide what is collected and why, and we are accountable for it under the UK General Data Protection Regulation and the Data Protection Act 2018.
Registered address: Bartle House, Oxford Court, Manchester M2 3WQ
Data protection enquiries: contact@thealexanderclinic.co.uk
The clinic is led by Dr Sajid Raza, registered with the General Medical Council (GMC number 7525293). All handling of your information is governed both by data protection law and by the professional duty of confidentiality that binds every registered doctor.
The short version
The full detail is below. If you read nothing else, read this.
Our commitments to you
- We never sell, rent, licence or trade your information. There is no commercial arrangement under which anyone pays us for access to it.
- Your genetic data is never shared with insurers, employers, advertisers, data brokers, or researchers — by us or, under their published policy, by our laboratory partner.
- Your DNA report is never stored on our systems, ever — not during your programme, not after it. We view it live through CircleDNA's secure Partner Portal; we never hold, download, or print a copy.
- You can withdraw your consent at any time, without giving a reason, and without affecting any other care you receive from us.
- We collect the minimum we need to deliver your programme safely — and nothing beyond it.
What we collect
When you contact us
- Your name, email address, telephone number
- The content of your enquiry or message
- Appointment dates and times
When you become a client
- Date of birth and address
- Relevant health background, medication and allergy information — taken so that we can deliver treatment safely
- Consultation notes and consent records
- A record of treatments provided and dates
- Clinical photography, where you have separately consented to it
- Payment records (we do not hold your full card number — that is handled by our payment provider)
If you join the DNA Insights programme
- A saliva sample, collected by cheek swab
- The genetic report generated from that sample
- Lifestyle information you choose to share so that we can interpret the report usefully
A note on special category data
Health information and genetic information are what the law calls special category data. They carry the highest level of protection under UK GDPR. We only process them where you have given us explicit, written, freely given consent (Article 9(2)(a)), or where processing is necessary for the provision of care by a professional bound by a duty of confidentiality (Article 9(2)(h)). We will always tell you which applies before we begin.
Your DNA: what actually happens
Genetic information is the most personal information there is. It doesn't change, it can't be reissued like a password, and it says something about your relatives as well as you. We think you are entitled to know precisely where your sample goes and who touches it. Here is the whole chain.
You consent, in writing, before anything begins
Nothing is collected until you have read the consent form, had the chance to ask questions, and signed it. Consent is specific to this programme — it is not bundled into any other agreement.
Your sample is collected and labelled with a code
A simple cheek swab. The kit is identified by a reference number, not by your name.
The sample goes to the laboratory — CircleDNA
The analysis is performed by CircleDNA, a service operated by Prenetics Limited. This is the only organisation outside the clinic that ever handles your sample. A laboratory is unavoidable: there is no way to analyse DNA without one.
Your report is generated — and stays — on CircleDNA's servers
Your report is never downloaded, exported, printed, or copied onto any clinic system. There is no clinic file, no clinic folder, no clinic backup that contains your genetic data. The only place your report physically exists is on CircleDNA's servers.
You view your own report directly, any time, via the CircleDNA App
This is your own account, held directly with CircleDNA, independent of the clinic. You control it, and you can view your full report whenever you like.
We view it — we don't hold it — through the CircleDNA Partner Portal
As a registered CircleDNA Partner, the clinic can view your report through CircleDNA's secure Partner Portal to guide your consultations, including future ones. Viewing is not storing: nothing is saved, printed, or exported onto a clinic system in the process. See section 07 for how long that viewing access lasts and how you can end it.
Where your genetic data physically lives
Your genetic data is stored on CircleDNA's servers only. The Alexander Clinic does not store any client genetic data. We do not hold a copy, a backup, an export, or a printed report anywhere in our systems or on our premises. When a member of our team needs to refer to your results in a consultation, they view your report live through CircleDNA's Partner Portal — the same way you might view a document through a secure web link rather than being sent the file itself. Nothing is downloaded, and nothing is printed.
Why we chose CircleDNA
We looked at the market and selected a partner on three criteria: the quality of the science, the strength of the security, and the clarity of the privacy commitments. CircleDNA met all three.
- Next-generation sequencing rather than microarray genotyping. Most consumer tests read a few hundred thousand pre-selected genetic markers. CircleDNA sequences across more than three million data points, which means it can detect variants that a targeted array is not looking for. CircleDNA states an analytical accuracy rate of 99.9%.
- ISO 27001 certified information security. This is the recognised international standard for managing information security, and it is independently audited rather than self-declared.
- De-identification by design. CircleDNA separates your registration details from your genetic data, assigns the genetic data a random identifier, and segments it across separate database systems so that re-identification is not straightforward even internally.
- Encryption at rest and in transit, with access restricted to authorised personnel on a least-privilege basis.
- A published commitment not to sell, lease or rent personal information to third parties for research purposes, and to keep genetic data within their own organisation.
- You hold the account. Your data and sharing preferences sit under your control and can be changed by you at any time.
Those last four points are CircleDNA's own published commitments rather than ours. We think that matters — a promise you can read for yourself and hold a company to is worth more than a promise relayed second-hand. Their full policy is at circledna.com/pages/privacy, and we encourage you to read it before you consent.
What "not shared with third parties" means — precisely
We want to be exact here rather than reassuring-but-vague, because vague promises are the ones that turn out to have exceptions.
Never
Insurers, for underwriting or any other purpose
Never
Employers or prospective employers
Never
Advertisers, marketers or data brokers
Never
Research databases or academic studies
Never
Supplement, cosmetic or wellness brands
Never
Sold, rented or licensed to anyone, in any form
Never
Printed, exported, or kept as a physical copy anywhere in the clinic
The single organisation that handles your genetic sample is the laboratory that analyses it. That is CircleDNA, and it is disclosed to you before you consent. To run their own operations, CircleDNA uses service providers of its own — cloud hosting, IT security, shipping — each of which must be under a written data processing agreement. This is normal and unavoidable for any laboratory service; it is set out in full in their policy, and we would rather you heard it from us first than discovered it in the small print later.
Where in the world your data goes
CircleDNA is operated by Prenetics Limited, which is headquartered in Hong Kong and operates internationally. Your sample and the resulting data may therefore be processed outside the United Kingdom.
Where data leaves the UK, UK GDPR requires that it remains protected to an equivalent standard. Those transfers are made under the safeguards permitted by Chapter V of the UK GDPR. You can ask us for details of the safeguards in place at any time and we will provide them.
Withdrawing consent
You can withdraw your consent to the DNA programme at any point, in writing, without giving a reason. If you withdraw before analysis, we will instruct that your sample be destroyed. If you withdraw afterwards, we will immediately end our Partner Portal viewing access to your report — because we never hold a separate copy, there is nothing further for us to delete on our own systems. You can separately manage or delete your report through your own CircleDNA App account at any time. Withdrawing consent will never affect any other treatment you receive from us, and will never affect how you are treated by our team.
Why we're allowed to hold it
Every piece of information we hold needs a lawful basis. Here is ours, in plain terms.
| What | Why we hold it | Lawful basis |
|---|---|---|
| Enquiry details | To answer your question and arrange a consultation | Legitimate interests — responding to someone who contacted us |
| Consultation and treatment records | To deliver your programme safely and keep an accurate record of your care | Contract; and Article 9(2)(h) — provision of care by a regulated professional |
| Health background | To identify anything that would make a treatment unsuitable for you | Explicit consent, Article 9(2)(a) |
| Genetic data and DNA report (viewed via CircleDNA Partner Portal — never stored by us) |
To provide personalised lifestyle guidance, in consultation and at follow-ups | Explicit consent, Article 9(2)(a) — and nothing else |
| Payment and invoicing records | Because we are required to keep them | Legal obligation — HMRC requirements |
| Marketing emails | To send you things you asked to receive | Consent — withdrawable in one click, in every email |
Who else sees your information
A short and deliberately closed list:
- CircleDNA (Prenetics Limited) — the laboratory that analyses your sample and hosts your report, for DNA programme clients only. The clinic views your results through their Partner Portal rather than receiving a copy — see section 04.
- Our practice management and booking system — Calendly, under a written data processing agreement.
- Our payment provider — Stripe / Monzo, who handle card details so that we never hold them.
- Our accountant — for invoicing and financial records only. They see no health or genetic information.
- Our medical defence organisation and insurers — only in the event of a complaint or claim, and only what is necessary to respond to it.
- Regulators, or a court — where we are legally required to disclose, or where there is a serious risk to someone's safety. This is a legal duty, not a choice, and it applies to every healthcare provider in the country.
Nobody else. Not now, and not as we grow.
How long we keep things
This is where most privacy policies get vague. We would rather be specific, including where the answer is less convenient than "we delete everything immediately".
| Information | Kept for | Then |
|---|---|---|
| Your DNA report and any genetic data | Not stored by us at all. We hold Partner Portal viewing access for the duration of our clinical relationship with you, so results remain available for future consultations | The report itself always remains solely on CircleDNA's servers under their policy. You can end our viewing access at any time by telling us, or by managing permissions in your own CircleDNA App |
| Enquiries that don't become bookings | 12 months | Deleted |
| Consultation and treatment records | 8 years from your last appointment | Securely destroyed |
| Consent forms | 8 years from your last appointment | Securely destroyed |
| Clinical photography | 8 years, or until you withdraw consent | Securely deleted |
| Financial records | 6 years | Destroyed — HMRC requirement |
| Marketing contact details | Until you unsubscribe | Removed immediately on request |
Two different things: viewing access, and the clinical record
These are separate, and worth telling apart. Your genetic report is never held on our systems — only viewed, live, through CircleDNA's Partner Portal. We keep that viewing access open for as long as you remain a client, so that if you return for a future consultation we can refer back to your results without asking you to re-test. This is a question of access, not storage: nothing about it involves us holding a copy of your data. You can end this access at any time, and it ends automatically if our clinical relationship does.
Separately, every registered doctor in the UK has a professional obligation to keep a clear, accurate clinical record of the care they provide, for 8 years from your last appointment. That record is what allows us to treat you safely if you return, and it is what protects you if you ever need to raise a concern or make a claim. A clinic with no records is not a private clinic; it is an undefendable one, and you would be the person left without recourse.
What that clinical record contains is deliberately minimal: that a DNA-informed programme was provided, when, your signed consent, and the lifestyle recommendations we made. It never contains your genetic data itself — that stays with CircleDNA, as described above. The retention period follows the standard set out in the NHS England Records Management Code of Practice, which the General Medical Council expects doctors to follow whether or not they work in the NHS.
How we keep it safe
- Records are held in encrypted systems, accessed only by named clinic personnel
- Access is limited to those who need it to do their job — not everyone sees everything
- Multi-factor authentication on every system holding client information
- Any paper records are held in locked storage on clinic premises
- Everyone working at the clinic is bound by a written confidentiality agreement
- All third-party providers operate under written data processing agreements
No system is perfect, and we won't claim otherwise. If a breach ever occurred that was likely to result in a risk to your rights, we would report it to the Information Commissioner's Office within 72 hours and tell you directly without undue delay.
Your rights
These are yours by law. Exercising them is free, and we will respond within one month.
- Access — ask for a copy of everything we hold about you
- Rectification — have anything inaccurate corrected
- Erasure — ask us to delete your information, subject to the record-keeping obligations in section 07, which we will explain to you if they apply
- Restriction — ask us to pause processing while a concern is resolved
- Portability — receive your information in a transferable format
- Objection — object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent — at any time, for anything based on consent, without needing to justify it
- Automated decisions — we do not make automated decisions or profile you in any way that produces legal or similarly significant effects
To exercise any of these, email contact@thealexanderclinic.co.uk.
If you're unhappy
Please tell us first — write to contact@thealexanderclinic.co.uk and we will investigate and respond within 30 days.
You also have the right to complain directly to the Information Commissioner's Office at any time, and you do not need to come to us first. The ICO can be reached at ico.org.uk/make-a-complaint or on 0303 123 1113.
Cookies, children, and changes
Cookies
Our website uses cookies. Non-essential cookies are only set once you have accepted them, and you can change your preferences at any time.
Under-18s
We do not provide DNA Insights or aesthetic treatments to anyone under 18, and we do not knowingly collect information from under-18s. If you believe we hold information about a child, contact us and we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle your information, we will contact current clients directly rather than relying on you to notice.
The Alexander Clinic's services, including DNA Insights, are cosmetic and aesthetic in scope and are provided for lifestyle and wellbeing purposes. They are not a diagnostic service and are not a substitute for medical care. Genetic insights describe tendencies, not certainties, and no result should be read as a diagnosis or a prediction. This service is cosmetic and aesthetic in scope — for any medical concern please consult your GP or a registered medical practitioner.
Privacy Policy
Last updated: [Insert date]
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and interact with our services, including through advertising platforms such as Meta (Facebook and Instagram). Please read this policy carefully.
1. Who We Are
We are a doctor-led health, wellness, and longevity clinic based in the UK ("we", "us", "our"). We are the data controller responsible for your personal data under UK data protection laws.
If you have any questions about this policy or how we handle your data, please contact us at:
Email: [Insert contact email]
2. Information We Collect
We may collect and process the following types of information:
a) Personal Information You Provide
Name
Email address
Phone number
Information submitted through contact forms, booking forms, or consultation requests
b) Automatically Collected Information
When you visit our website, we may automatically collect:
IP address
Browser type and version
Device information
Pages visited and time spent on pages
Referral source
This information is collected using cookies, pixels, and similar technologies.
3. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
Improve website functionality and performance
Understand how users interact with our website
Measure the effectiveness of our marketing campaigns
You can control or disable cookies through your browser settings. Please note that disabling cookies may affect website functionality.
4. Meta (Facebook & Instagram) Advertising
We use Meta advertising services, including the Meta Pixel, to:
Deliver relevant advertisements to users on Facebook and Instagram
Measure and analyse the performance of our advertising campaigns
Build custom audiences and lookalike audiences for marketing purposes
Meta may collect or receive information from our website and use that information in accordance with its own Data Policy.
This may include:
Your interaction with our website
IP address
Device and browser information
You can manage how Meta uses your data for advertising by adjusting your ad preferences within your Facebook or Instagram account.
For more information, please review Meta’s Privacy Policy.
5. How We Use Your Information
We use your information to:
Respond to enquiries and consultation requests
Provide and improve our services
Communicate with you about appointments or services
Run and optimise advertising and marketing campaigns
Comply with legal and regulatory obligations
6. Legal Basis for Processing (UK GDPR)
We process your personal data under the following lawful bases:
Consent – where you have given clear permission
Legitimate interests – for marketing, analytics, and business operations
Contractual necessity – to provide services you request
Legal obligation – to comply with applicable laws
7. Sharing Your Information
We do not sell your personal data.
We may share your data with trusted third parties, including:
Website hosting providers
Analytics providers
Advertising platforms such as Meta
Booking and CRM systems
All third parties are required to handle your data securely and lawfully.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, or disclosure.
10. Your Data Protection Rights
Under UK data protection law, you have the right to:
Access your personal data
Request correction of inaccurate data
Request deletion of your data
Object to or restrict processing
Withdraw consent at any time
Lodge a complaint with the Information Commissioner’s Office (ICO)
11. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.
13. Contact Us
If you have any questions about this Privacy Policy or how we use your data, please contact via email.

