Privacy Policy

The Alexander Clinic

Privacy Policy

This policy explains what information we hold about you, why we hold it, how long we keep it, and who — if anyone — ever sees it. It covers our cosmetic services and wellness programmes. It is written to be read, not skimmed past.

Last updated 28/07/2026 Version 1.0 Applies to thealexanderclinic.co.uk and all clinic services
01

Who we are

The Alexander Clinic is the data controller for the information described in this policy. That means we decide what is collected and why, and we are accountable for it under the UK General Data Protection Regulation and the Data Protection Act 2018.

Registered address: Bartle House, Oxford Court, Manchester M2 3WQ
Data protection enquiries: contact@thealexanderclinic.co.uk

The clinic is led by Dr Sajid Raza, registered with the General Medical Council (GMC number 7525293). All handling of your information is governed both by data protection law and by the professional duty of confidentiality that binds every registered doctor.

02

The short version

The full detail is below. If you read nothing else, read this.

Our commitments to you

  • We never sell, rent, licence or trade your information. There is no commercial arrangement under which anyone pays us for access to it.
  • Your genetic data is never shared with insurers, employers, advertisers, data brokers, or researchers — by us or, under their published policy, by our laboratory partner.
  • Your DNA report is never stored on our systems, ever — not during your programme, not after it. We view it live through CircleDNA's secure Partner Portal; we never hold, download, or print a copy.
  • You can withdraw your consent at any time, without giving a reason, and without affecting any other care you receive from us.
  • We collect the minimum we need to deliver your programme safely — and nothing beyond it.
03

What we collect

When you contact us

  • Your name, email address, telephone number
  • The content of your enquiry or message
  • Appointment dates and times

When you become a client

  • Date of birth and address
  • Relevant health background, medication and allergy information — taken so that we can deliver treatment safely
  • Consultation notes and consent records
  • A record of treatments provided and dates
  • Clinical photography, where you have separately consented to it
  • Payment records (we do not hold your full card number — that is handled by our payment provider)

If you join the DNA Insights programme

  • A saliva sample, collected by cheek swab
  • The genetic report generated from that sample
  • Lifestyle information you choose to share so that we can interpret the report usefully

A note on special category data

Health information and genetic information are what the law calls special category data. They carry the highest level of protection under UK GDPR. We only process them where you have given us explicit, written, freely given consent (Article 9(2)(a)), or where processing is necessary for the provision of care by a professional bound by a duty of confidentiality (Article 9(2)(h)). We will always tell you which applies before we begin.

04

Your DNA: what actually happens

Genetic information is the most personal information there is. It doesn't change, it can't be reissued like a password, and it says something about your relatives as well as you. We think you are entitled to know precisely where your sample goes and who touches it. Here is the whole chain.

STEP 01

You consent, in writing, before anything begins

Nothing is collected until you have read the consent form, had the chance to ask questions, and signed it. Consent is specific to this programme — it is not bundled into any other agreement.

STEP 02

Your sample is collected and labelled with a code

A simple cheek swab. The kit is identified by a reference number, not by your name.

STEP 03

The sample goes to the laboratory — CircleDNA

The analysis is performed by CircleDNA, a service operated by Prenetics Limited. This is the only organisation outside the clinic that ever handles your sample. A laboratory is unavoidable: there is no way to analyse DNA without one.

STEP 04

Your report is generated — and stays — on CircleDNA's servers

Your report is never downloaded, exported, printed, or copied onto any clinic system. There is no clinic file, no clinic folder, no clinic backup that contains your genetic data. The only place your report physically exists is on CircleDNA's servers.

STEP 05

You view your own report directly, any time, via the CircleDNA App

This is your own account, held directly with CircleDNA, independent of the clinic. You control it, and you can view your full report whenever you like.

STEP 06

We view it — we don't hold it — through the CircleDNA Partner Portal

As a registered CircleDNA Partner, the clinic can view your report through CircleDNA's secure Partner Portal to guide your consultations, including future ones. Viewing is not storing: nothing is saved, printed, or exported onto a clinic system in the process. See section 07 for how long that viewing access lasts and how you can end it.

Where your genetic data physically lives

Your genetic data is stored on CircleDNA's servers only. The Alexander Clinic does not store any client genetic data. We do not hold a copy, a backup, an export, or a printed report anywhere in our systems or on our premises. When a member of our team needs to refer to your results in a consultation, they view your report live through CircleDNA's Partner Portal — the same way you might view a document through a secure web link rather than being sent the file itself. Nothing is downloaded, and nothing is printed.

Why we chose CircleDNA

We looked at the market and selected a partner on three criteria: the quality of the science, the strength of the security, and the clarity of the privacy commitments. CircleDNA met all three.

  • Next-generation sequencing rather than microarray genotyping. Most consumer tests read a few hundred thousand pre-selected genetic markers. CircleDNA sequences across more than three million data points, which means it can detect variants that a targeted array is not looking for. CircleDNA states an analytical accuracy rate of 99.9%.
  • ISO 27001 certified information security. This is the recognised international standard for managing information security, and it is independently audited rather than self-declared.
  • De-identification by design. CircleDNA separates your registration details from your genetic data, assigns the genetic data a random identifier, and segments it across separate database systems so that re-identification is not straightforward even internally.
  • Encryption at rest and in transit, with access restricted to authorised personnel on a least-privilege basis.
  • A published commitment not to sell, lease or rent personal information to third parties for research purposes, and to keep genetic data within their own organisation.
  • You hold the account. Your data and sharing preferences sit under your control and can be changed by you at any time.

Those last four points are CircleDNA's own published commitments rather than ours. We think that matters — a promise you can read for yourself and hold a company to is worth more than a promise relayed second-hand. Their full policy is at circledna.com/pages/privacy, and we encourage you to read it before you consent.

What "not shared with third parties" means — precisely

We want to be exact here rather than reassuring-but-vague, because vague promises are the ones that turn out to have exceptions.

Never

Insurers, for underwriting or any other purpose

Never

Employers or prospective employers

Never

Advertisers, marketers or data brokers

Never

Research databases or academic studies

Never

Supplement, cosmetic or wellness brands

Never

Sold, rented or licensed to anyone, in any form

Never

Printed, exported, or kept as a physical copy anywhere in the clinic

The single organisation that handles your genetic sample is the laboratory that analyses it. That is CircleDNA, and it is disclosed to you before you consent. To run their own operations, CircleDNA uses service providers of its own — cloud hosting, IT security, shipping — each of which must be under a written data processing agreement. This is normal and unavoidable for any laboratory service; it is set out in full in their policy, and we would rather you heard it from us first than discovered it in the small print later.

Where in the world your data goes

CircleDNA is operated by Prenetics Limited, which is headquartered in Hong Kong and operates internationally. Your sample and the resulting data may therefore be processed outside the United Kingdom.

Where data leaves the UK, UK GDPR requires that it remains protected to an equivalent standard. Those transfers are made under the safeguards permitted by Chapter V of the UK GDPR. You can ask us for details of the safeguards in place at any time and we will provide them.

Withdrawing consent

You can withdraw your consent to the DNA programme at any point, in writing, without giving a reason. If you withdraw before analysis, we will instruct that your sample be destroyed. If you withdraw afterwards, we will immediately end our Partner Portal viewing access to your report — because we never hold a separate copy, there is nothing further for us to delete on our own systems. You can separately manage or delete your report through your own CircleDNA App account at any time. Withdrawing consent will never affect any other treatment you receive from us, and will never affect how you are treated by our team.

05

Why we're allowed to hold it

Every piece of information we hold needs a lawful basis. Here is ours, in plain terms.

WhatWhy we hold itLawful basis
Enquiry details To answer your question and arrange a consultation Legitimate interests — responding to someone who contacted us
Consultation and treatment records To deliver your programme safely and keep an accurate record of your care Contract; and Article 9(2)(h) — provision of care by a regulated professional
Health background To identify anything that would make a treatment unsuitable for you Explicit consent, Article 9(2)(a)
Genetic data and DNA report
(viewed via CircleDNA Partner Portal — never stored by us)
To provide personalised lifestyle guidance, in consultation and at follow-ups Explicit consent, Article 9(2)(a) — and nothing else
Payment and invoicing records Because we are required to keep them Legal obligation — HMRC requirements
Marketing emails To send you things you asked to receive Consent — withdrawable in one click, in every email
06

Who else sees your information

A short and deliberately closed list:

  • CircleDNA (Prenetics Limited) — the laboratory that analyses your sample and hosts your report, for DNA programme clients only. The clinic views your results through their Partner Portal rather than receiving a copy — see section 04.
  • Our practice management and booking systemCalendly, under a written data processing agreement.
  • Our payment providerStripe / Monzo, who handle card details so that we never hold them.
  • Our accountant — for invoicing and financial records only. They see no health or genetic information.
  • Our medical defence organisation and insurers — only in the event of a complaint or claim, and only what is necessary to respond to it.
  • Regulators, or a court — where we are legally required to disclose, or where there is a serious risk to someone's safety. This is a legal duty, not a choice, and it applies to every healthcare provider in the country.

Nobody else. Not now, and not as we grow.

07

How long we keep things

This is where most privacy policies get vague. We would rather be specific, including where the answer is less convenient than "we delete everything immediately".

InformationKept forThen
Your DNA report and any genetic data Not stored by us at all. We hold Partner Portal viewing access for the duration of our clinical relationship with you, so results remain available for future consultations The report itself always remains solely on CircleDNA's servers under their policy. You can end our viewing access at any time by telling us, or by managing permissions in your own CircleDNA App
Enquiries that don't become bookings 12 months Deleted
Consultation and treatment records 8 years from your last appointment Securely destroyed
Consent forms 8 years from your last appointment Securely destroyed
Clinical photography 8 years, or until you withdraw consent Securely deleted
Financial records 6 years Destroyed — HMRC requirement
Marketing contact details Until you unsubscribe Removed immediately on request

Two different things: viewing access, and the clinical record

These are separate, and worth telling apart. Your genetic report is never held on our systems — only viewed, live, through CircleDNA's Partner Portal. We keep that viewing access open for as long as you remain a client, so that if you return for a future consultation we can refer back to your results without asking you to re-test. This is a question of access, not storage: nothing about it involves us holding a copy of your data. You can end this access at any time, and it ends automatically if our clinical relationship does.

Separately, every registered doctor in the UK has a professional obligation to keep a clear, accurate clinical record of the care they provide, for 8 years from your last appointment. That record is what allows us to treat you safely if you return, and it is what protects you if you ever need to raise a concern or make a claim. A clinic with no records is not a private clinic; it is an undefendable one, and you would be the person left without recourse.

What that clinical record contains is deliberately minimal: that a DNA-informed programme was provided, when, your signed consent, and the lifestyle recommendations we made. It never contains your genetic data itself — that stays with CircleDNA, as described above. The retention period follows the standard set out in the NHS England Records Management Code of Practice, which the General Medical Council expects doctors to follow whether or not they work in the NHS.

08

How we keep it safe

  • Records are held in encrypted systems, accessed only by named clinic personnel
  • Access is limited to those who need it to do their job — not everyone sees everything
  • Multi-factor authentication on every system holding client information
  • Any paper records are held in locked storage on clinic premises
  • Everyone working at the clinic is bound by a written confidentiality agreement
  • All third-party providers operate under written data processing agreements

No system is perfect, and we won't claim otherwise. If a breach ever occurred that was likely to result in a risk to your rights, we would report it to the Information Commissioner's Office within 72 hours and tell you directly without undue delay.

09

Your rights

These are yours by law. Exercising them is free, and we will respond within one month.

  • Access — ask for a copy of everything we hold about you
  • Rectification — have anything inaccurate corrected
  • Erasure — ask us to delete your information, subject to the record-keeping obligations in section 07, which we will explain to you if they apply
  • Restriction — ask us to pause processing while a concern is resolved
  • Portability — receive your information in a transferable format
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent — at any time, for anything based on consent, without needing to justify it
  • Automated decisions — we do not make automated decisions or profile you in any way that produces legal or similarly significant effects

To exercise any of these, email contact@thealexanderclinic.co.uk.

10

If you're unhappy

Please tell us first — write to contact@thealexanderclinic.co.uk and we will investigate and respond within 30 days.

You also have the right to complain directly to the Information Commissioner's Office at any time, and you do not need to come to us first. The ICO can be reached at ico.org.uk/make-a-complaint or on 0303 123 1113.

11

Cookies, children, and changes

Cookies

Our website uses cookies. Non-essential cookies are only set once you have accepted them, and you can change your preferences at any time.

Under-18s

We do not provide DNA Insights or aesthetic treatments to anyone under 18, and we do not knowingly collect information from under-18s. If you believe we hold information about a child, contact us and we will delete it.

Changes to this policy

If we change this policy we will update the date at the top of the page. Where a change materially affects how we handle your information, we will contact current clients directly rather than relying on you to notice.

The Alexander Clinic's services, including DNA Insights, are cosmetic and aesthetic in scope and are provided for lifestyle and wellbeing purposes. They are not a diagnostic service and are not a substitute for medical care. Genetic insights describe tendencies, not certainties, and no result should be read as a diagnosis or a prediction. This service is cosmetic and aesthetic in scope — for any medical concern please consult your GP or a registered medical practitioner.

Privacy Policy

Last updated: [Insert date]

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and interact with our services, including through advertising platforms such as Meta (Facebook and Instagram). Please read this policy carefully.

1. Who We Are

We are a doctor-led health, wellness, and longevity clinic based in the UK ("we", "us", "our"). We are the data controller responsible for your personal data under UK data protection laws.

If you have any questions about this policy or how we handle your data, please contact us at:

Email: [Insert contact email]

2. Information We Collect

We may collect and process the following types of information:

a) Personal Information You Provide

  • Name

  • Email address

  • Phone number

  • Information submitted through contact forms, booking forms, or consultation requests

b) Automatically Collected Information

When you visit our website, we may automatically collect:

  • IP address

  • Browser type and version

  • Device information

  • Pages visited and time spent on pages

  • Referral source

This information is collected using cookies, pixels, and similar technologies.

3. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Improve website functionality and performance

  • Understand how users interact with our website

  • Measure the effectiveness of our marketing campaigns

You can control or disable cookies through your browser settings. Please note that disabling cookies may affect website functionality.

4. Meta (Facebook & Instagram) Advertising

We use Meta advertising services, including the Meta Pixel, to:

  • Deliver relevant advertisements to users on Facebook and Instagram

  • Measure and analyse the performance of our advertising campaigns

  • Build custom audiences and lookalike audiences for marketing purposes

Meta may collect or receive information from our website and use that information in accordance with its own Data Policy.

This may include:

  • Your interaction with our website

  • IP address

  • Device and browser information

You can manage how Meta uses your data for advertising by adjusting your ad preferences within your Facebook or Instagram account.

For more information, please review Meta’s Privacy Policy.

5. How We Use Your Information

We use your information to:

  • Respond to enquiries and consultation requests

  • Provide and improve our services

  • Communicate with you about appointments or services

  • Run and optimise advertising and marketing campaigns

  • Comply with legal and regulatory obligations

6. Legal Basis for Processing (UK GDPR)

We process your personal data under the following lawful bases:

  • Consent – where you have given clear permission

  • Legitimate interests – for marketing, analytics, and business operations

  • Contractual necessity – to provide services you request

  • Legal obligation – to comply with applicable laws

7. Sharing Your Information

We do not sell your personal data.

We may share your data with trusted third parties, including:

  • Website hosting providers

  • Analytics providers

  • Advertising platforms such as Meta

  • Booking and CRM systems

All third parties are required to handle your data securely and lawfully.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, or disclosure.

10. Your Data Protection Rights

Under UK data protection law, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request deletion of your data

  • Object to or restrict processing

  • Withdraw consent at any time

  • Lodge a complaint with the Information Commissioner’s Office (ICO)

11. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

13. Contact Us

If you have any questions about this Privacy Policy or how we use your data, please contact via email.


Let’s Work Together