Privacy and data
This privacy notice aims to give you information on how we collect and process your personal data through your use of this website, including any data you may provide through this website when you: sign up to any newsletter/purchase a product or service.
This website is not intended for children and we do not knowingly collect data from children.
You should read this privacy notice together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This privacy notice supplements the other notices and is not intended to override them.
Prideaux Consultancy Ltd is owned and administered by Samuel Prideaux and Simon Prideaux is an employee.
Simon Prideaux is the data controller registered with the Information Commissioners Office.
Osteopaths and IBCLCs are required and wish to respect people’s right to privacy and confidentiality so protecting your privacy is fundamental. Simon Prideaux is required by professional bodies to maintain professional standards in all areas of his practice which includes record keeping and safe storage of documents and images.
This notice explains what information may be collected from you, why it’s collected, under what circumstance this information may be shared, how long it is stored and how you can access it.
Our email addresses are simon@heavens-gate.org.uk and karen@heavens-gate.org.uk
Our postal address is: 73 Bishopstone Aylesbury Bucks HP17 8SH
Our website address is https://heavens-gate.org.uk/
If you are not happy with any aspect of how your data is collected, you have the right to complain to the Information Commissioner’s Office (www.ico.org.uk)
Please contact us first however if you do have a complaint so that we can try to rectify things for you.
Sensitive Data
The Data (Use and Access) 2025 Act reinforces that children merit specific protection and requires this to be considered in regulatory oversight and relevant processing contexts.
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. It does not replace the UK GDPR, the Data Protection Act 2018 or the Privacy and Electronic Communications Regulations 2003, but it amends them to simplify aspects of compliance, support innovation and responsible data sharing, and maintain data protection standards.
During our communications by any means electronic or otherwise we will collect and record personal information about you and your baby. This information will include relevant medical information. Your contact information may be used at a later date for follow up. Whilst steps are taken to ensure your information remains as secure as possible please note that electronic communications may not be secure so keep this in mind when using these methods. If you send documents by email which contain sensitive data you may wish to password protect these.
Keeping clear and accurate records helps us to contact you and to provide safe and effective care for you and your baby. These records will contain your personal/medical information and that of your child.
They may include summaries of our consultations and copies of emails and any other messages you’ve sent to me during our conversations. They are stored on electronic devices which are password protected and have security software installed or securely in the ‘cloud’. We use Microsoft office 365 for this purpose.
Your explicit consent for processing sensitive data (medical information) is needed and GDPR says the consent we obtain must be freely given by you, specific, informed, and unambiguous. GDPR requires that consent be:
Freely given
Not coerced or tied to unrelated benefits.Specific
Clearly tied to the purpose (e.g. storage of medical records).Informed
You know what they’re agreeing to.Unambiguous
Expressed through an active choice, not pre-checked boxes or implied agreement
We may use your personal information in a number of ways or as otherwise described at the time of collection:
Service delivery and operations. We may use your personal information to:
Create your medical records and manage our relationship with you
Run and manage our business, including resolving billing and financial disputes
Evaluate your eligibility for marketing offers, products and services
Provide a product or service that you have requested by any means
Connect you with other medical specialists
Communicate with you, such as sending you electronic notifications concerning your account, invoices and payment history with us
Understand your needs and interests, and personalize your experience with the Services and our communications.
Provide you with support and resolve disputes
Authenticate your identity
Manage event registrations and attendance, including sending related communications to you
Register visitors to our offices for security reasons and manage non-disclosure agreements that visitors may be required to sign
Please sign up to the enrolment list here http://eepurl.com/dvASn5 .
We may without notice use any information provided, anonymised, for auditing or research purposes, case studies or for teaching purposes.
We may request a signed consent in agreement of this.
How we use your personal data
I will only use your personal data when legally permitted. The most common uses of your personal data are:
To help and advise you
Appointment booking
Our legitimate interests
Compliance with legal or regulatory obligations
Exercise our rights in the course of judicial, administrative, or arbitration proceedings
Purposes for processing your personal data
Set out below is a description of the ways I intend to use your personal data and the legal grounds on which I will process such data. I have also explained what our legitimate interests are where relevant.
I may process your personal data for more than one lawful ground, depending on the specific purpose for which I am using your data.
For the purpose of helping and advising you when assessing and proposing a treatment plan, along with follow-up care and to process payment we may need to use the following
Contact details
Financial details
Medical details.
Payment for services Privacy Policy | SumUp
For you to make an online booking
Artificial Intelligence (AI) and Automated processing
we may process your personal information using automated and manual (human) methods.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Contact forms
This site may have a contact form for you to contact us. The information is used to answer any query and continue our communications.
I retain email data shared over email for 12 months from our last contact in case you come back to me subsequently.
We retain medical records until your child is 28 years of age (10 years, post 18) and then they will be deleted. Your information will not be used for marketing purposes. The Data held about you may include name, age, address, email, your child’s name and date of birth, medical history, consultation notes, and may include a baby’s weight chart, care plan and a report to your GP. Information may be shared with your health professionals usually with your consent
I will not share any information with anyone except in the following circumstances
With your consent I may contact your midwife, GP, HV or other healthcare professionals involved in your care and share relevant information to enhance the care of you and your baby.
Should I have a concern about the safety of your child then I have a legal and professional obligation to share relevant information with the relevant agencies and in this case your consent is not required.
Anonymised data may be used and shared for the purpose of internal and external audits/research.
In the event of a complaint or claim relevant information will be shared with my indemnity provider and legal team.
Photographs may be used to form part of our consultation record, for educational and publicity purposes but only with your consent.
Transaction and financial data may be shared with my accountant, bank, card payment machine provider and with HMRC in certain circumstances.
Data Security
I have put in place what I believe are appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Access to your personal data will be restricted but may be shared with administrative staff
In the event of a data breach, I will notify you and any applicable regulator of the breach where we’re legally required to do so.
Data Retention
We only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data the relevant legislation, the amount, nature, and sensitivity of the data and the potential risk of harm from unauthorised use or disclosure of your personal data is considered. Also the purposes for which it’s processed and whether those purposes could be achieved through other means
By law basic information including Contact, Identity, Financial and Transaction Data must be kept for six years after they cease being customers for tax purposes.
Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:
Request access to your personal data.
Request correction of your personal data.
Request erasure of your personal data.
Object to processing of your personal data.
Request restriction of processing your personal data.
Request transfer of your personal data.
Right to withdraw consent.
You can see more about these rights at Your data matters | ICO
If you wish to exercise any of the rights set out above, please contact us
No fee required – with some exceptions
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, I may charge a reasonable admin fee if your request is clearly unfounded, repetitive or excessive. Alternatively, I may refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
· Subject access requests: Controllers only need to carry out reasonable and proportionate searches when responding to subject access requests, and the Act clarifies response procedures, including circumstances where the response period may be paused while further information is awaited.
Time limit to respond
We aim to respond to all legitimate requests within one month. Occasionally it may take longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
· Complaints: Organisations must provide a process for individuals to complain directly to the controller about data protection concerns before or alongside escalation to the Information Commissioner’s Office.