Our policy complies with UK law accordingly implemented, including that required by the UK General Data Protection Regulation (UK GDPR).
This Privacy policy covers personal information we collect, hold and process from visitors, users, customers and patients through our Website, located at https://www.mya.co.uk, by phone and in person at one of our clinics.
When we refer to “MYA” in this document we are referring to MYA Group Ltd and all subsidiaries who may share your information to enable MYA to provide the requested services to you. All subsidiary companies will be what’s known as the ‘Data Controllers’ of the personal information you provide to us. This privacy policy explains what personal data MYA collects from you, through our interactions with you.
Topics:
MYA’s legal basis for processing your data.
What information do we collect about you?
How will we use the information about you?
Who may we share you information with and why?
Your rights as a data subject.
MYA Medical Records
Changes to our privacy policy
How to contact us
MYA’s legal Basis for Processing your data
MYA will obtain your consent as the legal basis for us to collect your personal information to send you marketing communications relating to our business which we think may be of interest to you.
MYA’s legal basis for the processing of your personal and sensitive information is to allow us to fulfil or take steps to fulfil any contractual obligation to you. In addition to this, MYA can lawfully process special category data such as your health records, provided by you, in order to provide you with the appropriate healthcare.
What information do we collect about you?
We collect information about you when you enter your details into one of our website forms, when you speak with one of our team over the phone, via a video consultation when using the MYA patient portal and in clinic when you are being consulted. We may collect basic details such as full name, email address, phone number, age range and gender along with information relevant to your health, previous medical history and some lifestyle information.
MYA may also collect credit card details, however this information is not stored or processed through MYA’s IT Systems.
If you choose to withhold any Personal Information requested by us, it may not be possible for you to gain access to certain parts of our website, for us to respond to your enquiry or for you to continue your journey with MYA.
Website usage information is collected using cookies. Read more on our Cookie Policy.
Information collected from you is stored in a customer/medical record where it is held and processed electronically on secure servers which are subject to the appropriate technical security measures mandated by the UK General Data Protection Regulations.
More information
Our site uses 3 forms that visitors can use:
Contact Form – to request more information, book a consultation over the phone or sign up to our newsletter
Online Booking Form – to book a consultation online
Forum Form – to sign up to our online Forum to access a secure area
For the Contact Form and Online Booking Form, we collect the following information:
Full Name
Email Address
Mobile Number
Age range
Gender
Postcode
During a call with one of our advisors or on our online booking form, we may collect the following extra information:
Address
BMI (Body Mass Index)
DOB
Preferred Name
When using the MYA Patient Portal, we may collect the following information:
During a consultation at one of our clinics, we may collect the following extra information:
How will we use the information about you?
MYA Cosmetic Surgery need to hold and process the personal and health information you have provided us. This is to identify you, contact you during your journey, help us understand your expected outcomes, tailor your journey to offer you the best possible path to your desired results and meet contractual obligations.
Also, if you consent, we may use your contact details for marketing purposes to send you relevant information that you may find interesting.
More Information
We use your contact information in two ways:
For the purposes of staying in touch and communicating with you during your journey with MYA, including appointment information. (Phone, Email, SMS)
For marketing purposes to send you information about our company if you agree. (Email, SMS)
For marketing purposes to perform ad measurement services on behalf of MYA
We use information collected about you for marketing purposes in the following ways:
We would like to send you information about products and services of ours and other companies in our group, which may be of interest to you. If you have consented to receive marketing, you may opt out at a later date.
You have the right at any time to stop us from contacting you for marketing purposes. If you no longer wish to be contacted for marketing purposes, please click the ‘Update your communication preferences’ link on the bottom of our emails or visit https://privacy.mya.co.uk to manage your settings.
For the purpose of improving our conversion measurements, hashed first-party conversion data (like email address) is sent to Google in a privacy-safe way. Google acts as a data processor and report on aggregated and anonymised conversions. You can read about Google’s enhanced conversions and how Google use data.
For the purpose of improving our services, we request feedback via Third Party review sites like Reputation. Reputation act as a data processor and assist MYA to collect feedback from our customers on our behalf. You can read Reputation’s Privacy Notice here.
We use information collected from our website in the following ways:
Cookies
Cookies are text files placed on your computer to collect standard internet log information and visitor behavior information. This information is used to track visitor use of the website and to compile statistical reports on website activity.
When you visit the MYA website for the first time, you are able to decide (accept or reject) whether you will allow cookies to collect your personal data.
For further information, visit allaboutcookies.org or read MYA’s cookie policy: www.mya.co.uk/cookie-policy
You can set your browser not to accept cookies and the above website tells you how to remove cookies from your browser. However, in a few cases, some of our website features may not function as a result.
We use your information collected from the website to personalize your repeat visits to our website.
Lookalike Audiences
For advertising purposes, MYA occasionally use information about our customers to generate a "lookalike audience" of prospective customers through the Meta advertising platforms. This allows us to target advertisements on their platforms to potential customers who appear to have shared interests or similar demographics to our existing customers, based on the platforms' own data. We typically do this by uploading a list of email addresses. Facebook's policy is to irreversibly hash (encrypt) such lists prior to uploading, match the hashed data against their own customers, generate the lookalike audience, then delete the uploaded list and use it for no other purpose. We do not have access to the identity of anybody in the lookalike audience, unless they choose to click on the ads. Based on this, we believe that generating lookalike audiences poses little or no threat to the privacy of our customers.
Who may we share your information with and why?
During your journey with MYA, we may need to share your information, including sensitive data, with medical professionals, government agencies and third parties in order to deliver services you have requested.
More Information
Your Surgeon, Medical Practitioner or a member of the MYA medical Team for the purposes of the discussions around your procedure or any follow up treatment or any issue or complaint raised by you.
Your GP and or other relevant medical practitioners as it is important that they are aware of your intended procedure.
MYA may need to disclose or have a legal obligation to disclose information about you, including sensitive information, to government authorities, such as the General Medical Council (GMC), the Care Quality Commission (CQC) or the Police investigating criminal activity.
Your rights as a Data Subject
You have the right to request a copy of the information that we hold about you. You have the right for your details to be forgotten (right to erasure) for the sole purpose of processing for marketing communications. If you would like a copy, amend or erase some or all of your personal information, please email us, write to us or call 03330141014 and you be directed to the appropriate responsible person. To manage your settings, please click the ‘Update your communication preferences’ link on the bottom of our emails or visit https://privacy.mya.co.uk.
please click the ‘Update your communication preferences’ link on the bottom of our emails or visit https://privacy.mya.co.uk.
More Information
Unless subject to an exemption [under the UK GDPR], you have the following rights with respect to your personal data:
The right to request a copy of your personal data which the MYA Clinics Ltd holds about you.
The right to request that MYA Clinics Ltd corrects any personal data if it is found to be inaccurate or out of date.
The right to request your personal data is erased where it is no longer necessary for MYA Clinics Ltd to retain such data as per MYA Clinics legal basis for processing your data. If your personal data is being held as a medical record, MYA can still legally hold your data as per MYA’s retention periods.
The right to withdraw your consent to the processing at any time for which your consent has been given.
The right to request that the data controller provide the data subject with his/her personal data and where possible, to transmit that data directly to another data controller, (known as the right to data portability).
The right, where there is a dispute in relation to the accuracy or processing of your personal data, to request a restriction is placed on further processing.
The right to object to the processing of personal data.
The right to lodge a complaint with the Information Commissioners Office.
MYA Medical Records
What is a medical Record?
Once you have seen a surgeon or nurse, the information we hold about you as a customer record becomes a medical record because it will contain information entered by a medical professional.
Why are we processing medical and health information about you?
MYA is committed to providing the best possible care and outcomes for our patients and as such we need to keep records about your health and other personal information for medical purposes. Your personal and sensitive information is collected by MYA staff both electronically and on paper where it is stored within the UK and EU and is subject to the appropriate technical security measures mandated by the UK General Data Protection Regulations.
What Information are we collecting and storing?
MYA will record both personal data and sensitive personal data, such as information about your health and ethnic origin.
More Information
The records we keep about you may contain:
Basic details about you such as name, address, date of birth, next of kin, etc.
Contact we have had with you such as appointments.
Notes on your consultations during your journey with MYA. These may include audio and video recordings for staff training and quality purposes.
Detailed notes and information about your health and procedure including:
Information about allergies
Information about your medical history, including long-term conditions, such as diabetes or asthma.
Medical test results such as blood tests, allergy tests and other screenings.
Any clinically relevant lifestyle information, such as smoking, alcohol or weight.
Hospital records.
Details of your medicines.
Pre and Post-Operative photos for clinical assessments to be made of results achieved after surgery.
Data Retention Periods
In accordance with the Records Management Code of Practice for Health and Social Care 2016, Mya has implemented the following retention periods, dependent on the type of record and data being stored:
Changes to our privacy policy
We keep our privacy policy under regular review and we will place any updates on this webpage. This privacy policy was last updated on 10 May 2024.
How to contact us
Please contact us if you have any questions about our privacy policy or information we hold about you:
By email to info@mya.co.uk
Or write to us at: MYA Clinics Ltd, 1 Cardale Park, Harrogate, HG3 1RY.
MYA have appointed a Senior Information Risk Officer (SIRO) who is responsible for the management of all information and data under the control of MYA along with any associated risks or incidents. MYA’s SIRO can be contacted by emailing siro@mya.co.uk.
MYA has also appointed a Caldicott Guardian who is responsible for the management of patient information and patient confidentiality. MYA’s Caldicott Guardian can be contacted by emailing caldicott@mya.co.uk