Privacy notice
Privacy Notice
Last updated: August 2026
This privacy notice explains how Dr Matthew Knight collects, uses, stores and shares personal information in connection with his private medical practice.
1. Who is responsible for your information?
Dr Rahul Mogal is the data controller for the personal and clinical information processed in connection with his private medical practice.
Dr Mogal provides private clinical services trading as Purabs Ltd.
Purabs Ltd provides the corporate and financial structure through which practice income is received and practice expenses are paid. It may process limited patient-identification, invoicing, payment and accounting information for those purposes.
Where Purabs Ltd processes clinical or administrative information on Dr Mogals behalf, it must do so only for authorised practice purposes and subject to appropriate confidentiality and data-protection controls.
MedicalSec Services Ltd provides contracted secretarial and practice-administration services, including:
-
arranging appointments;
-
communicating with patients;
-
preparing and sending correspondence;
-
dealing with insurers and hospitals;
-
invoicing;
-
obtaining reports and investigation results; and
-
other administrative work connected with your care.
MedicalSec Services Ltd processes information under contractual confidentiality and data-protection obligations.
2. Contact details
For clinical, administrative or privacy enquiries, contact:
The Chest Clinic
c/o MedicalSec Services Ltd
2 Henge Close
Adderbury
Banbury
OX17 3GA
Telephone: 0203 146 1771
Email: PA@chest-clinic.co.uk
ICO registration number: ZA231810
3. Hospitals and clinics
Dr Mogal practises at hospitals and clinics under practising privileges and is not employed by them.
The hospital or clinic at which you are seen is normally a separate data controller and the CQC-registered provider of the hospital service.
Relevant information may be shared with the hospital or clinic, including:
-
referral information;
-
investigation requests and results;
-
consultation records;
-
clinic letters;
-
treatment plans; and
-
information required for clinical governance, billing or regulatory purposes.
This allows the hospital or clinic to provide, document and govern your care.
You should also read the privacy notice issued by the hospital or clinic at which you are treated.
4. Information we collect
We may collect and use:
-
your name, date of birth, address and contact details;
-
NHS, hospital, insurer, policy and authorisation numbers;
-
referral information;
-
symptoms and medical history;
-
diagnoses, medicines and allergies;
-
examination findings;
-
clinical opinions and treatment plans;
-
investigation requests, results, medical images and reports;
-
consultation notes, transcripts and correspondence;
-
appointment information;
-
invoicing, payment and debt-recovery information;
-
communications with you and healthcare professionals involved in your care; and
-
relevant information about relatives, carers or other people where necessary for your care.
Information concerning your health is treated as special-category personal data under UK data-protection law.
5. Where information comes from
Information may be provided by:
-
you;
-
a relative, carer or representative;
-
your GP or referring clinician;
-
hospitals and clinics;
-
laboratories, imaging providers and diagnostic services;
-
other healthcare professionals;
-
your insurer, sponsor or funding organisation; and
-
public authorities or other lawful sources where relevant.
Where information is obtained from someone other than you, privacy information will be provided within the period required by law unless an applicable exemption applies.
6. Why we use your information
We use personal information to:
-
respond to enquiries;
-
arrange appointments;
-
provide, coordinate and document healthcare;
-
maintain an accurate and complete medical record;
-
prepare clinic letters and reports;
-
request and review investigations;
-
communicate with you;
-
communicate with your GP, referrer and other professionals;
-
obtain insurer authorisation;
-
administer insurance claims;
-
issue invoices and collect payments;
-
invite patients to provide service feedback;
-
respond to complaints, concerns and requests;
-
protect patients, staff and information systems;
-
undertake clinical governance and quality improvement;
-
meet professional, legal, regulatory, accounting and insurance obligations; and
-
establish, exercise or defend legal claims.
-
7. Our lawful bases
Article 6(1)(b): contract
Processing may be necessary to take steps at your request or to perform the contract to provide private healthcare.
Article 6(1)(c): legal obligation
Processing may be necessary to comply with legal, regulatory, taxation, accounting or professional obligations.
Article 6(1)(f): legitimate interests
Processing may be necessary for legitimate interests, including:
-
operating a safe and effective private medical practice;
-
arranging and administering care;
-
maintaining information security;
-
obtaining patient feedback;
-
managing accounts;
-
recovering properly due fees;
-
responding to complaints; and
-
protecting legal and professional rights.
Where we rely on legitimate interests, we consider whether the processing is necessary, proportionate and compatible with your rights.
Article 9(2)(h): healthcare
Processing may be necessary for medical diagnosis and the provision or management of healthcare by a health professional subject to confidentiality.
Article 9(2)(f): legal claims
Processing may be necessary to establish, exercise or defend legal claims.
We do not generally rely upon UK GDPR consent to create or retain your clinical record.
8. Carebit
We use Carebit as the practice-management and clinical-record system.
Carebit may hold or process:
-
patient details;
-
referrals;
-
appointments;
-
clinical notes;
-
investigation reports;
-
correspondence;
-
insurer information;
-
invoices;
-
payment records; and
-
communications relating to your care.
Carebit acts as a contracted data processor.
The approved clinical record and final correspondence are retained in Carebit and, where required by practising-privileges arrangements, within the relevant hospital’s clinical record.
9. Heidi: digital dictation and ambient scribing
Dr Mogal uses Heidi as a clinical documentation tool.
Heidi may be used:
-
after a consultation as a digital dictation tool; or
-
during a consultation as an AI-enabled ambient scribe.
An ambient scribe listens to a consultation and produces a draft transcript, note or letter.
Where Heidi is used during a consultation:
-
you are informed in advance;
-
Dr Mogal will tell you at the start of the session;
-
you may object or ask for Heidi to be stopped at any time;
-
your decision will not adversely affect your care;
-
an alternative method of documentation will be used if you object;
-
Heidi produces only a draft transcript, note or letter;
-
Dr Mogal reviews and corrects every output before it is used;
-
Dr Mogal remains responsible for the final record and correspondence; and
-
Heidi does not make autonomous decisions about diagnosis, prescribing or treatment.
In the practice configuration:
-
voice or audio storage is not enabled;
-
transcripts and drafts held within Heidi are retained for no more than 90 days;
-
those transcripts and drafts are then deleted; and
-
the approved clinical record is retained in Carebit and/or the relevant hospital record.
10. Secretarial and administrative access
Authorised MedicalSec Services Ltd personnel may access information where necessary to:
-
arrange appointments;
-
prepare clinics;
-
receive referrals;
-
obtain investigation results;
-
upload previous letters and reports;
-
prepare correspondence for clinician review;
-
communicate with patients, hospitals and insurers;
-
send clinician-approved correspondence;
-
issue invoices; and
-
administer payments.
Administrative personnel must not independently make clinical decisions or approve substantive clinical content.
Access is limited to what is reasonably required for the person’s role.
11. Patient reviews through Doctify
We use Doctify to invite patients to provide feedback about their experience of our service.
After an appointment, we may provide Doctify with your mobile telephone number or email address so that Doctify can send you a link inviting you to leave a review.
Leaving a review is entirely optional. You do not have to respond to the invitation, and deciding not to leave a review will not affect your present or future care.
Reviews submitted through Doctify are normally published anonymously. You should avoid including information in a review that could identify you or disclose personal or medical information that you do not wish to make public.
We use your contact details for this purpose on the basis of our legitimate interests in:
-
obtaining patient feedback;
-
monitoring service quality; and
-
improving patient experience.
You may object to receiving a Doctify invitation at any time.
We do not create a separate permanent practice copy of your contact details solely for the purpose of sending the invitation. Your ordinary contact details remain part of your practice record where they are needed for appointments and care.
Doctify processes the contact information supplied to it in accordance with its own privacy obligations and retention arrangements.
We do not use a Doctify invitation to send unrelated marketing.
You can ask us not to provide your contact details to Doctify by contacting:
PA@chest-clinic.co.uk
0203 146 1771
12. Who we may share information with
Where necessary and proportionate, information may be shared with:
-
the hospital or clinic at which you are treated;
-
your GP or referring clinician;
-
other clinicians involved in your care;
-
laboratories and imaging providers;
-
respiratory physiologists and diagnostic providers;
-
pharmacies;
-
your insurer, sponsor or funding organisation;
-
MedicalSec Services Ltd;
-
Carebit;
-
Heidi;
-
Doctify;
-
other approved IT and communications providers;
-
accountants and auditors;
-
legal and professional advisers;
-
medical indemnity insurers;
-
P&J Consumer Debt Services (Medical);
-
the General Medical Council;
-
the Care Quality Commission;
-
the Information Commissioner’s Office;
-
the Private Healthcare Information Network;
-
courts or tribunals;
-
law-enforcement authorities; and
-
safeguarding or public authorities.
We disclose only information reasonably necessary for the relevant purpose.
Information may also be disclosed where:
-
you have asked us to disclose it;
-
disclosure is necessary for your direct care;
-
disclosure is required by law;
-
disclosure is ordered by a court;
-
disclosure is necessary to protect a person from serious harm; or
-
disclosure is otherwise justified under professional confidentiality guidance.
13. Debt recovery
Where an invoice remains unpaid, relevant information may be provided to P&J Consumer Debt Services (Medical) for debt-recovery purposes.
Information shared may include:
-
your name;
-
contact details;
-
invoice information;
-
the amount due;
-
payment history; and
-
communications relevant to the outstanding account.
We will not normally provide detailed clinical information unless it is necessary and lawful to establish or defend the debt.
Debt recovery is based on our legitimate interests in recovering properly due fees and, where relevant, performing the healthcare contract.
14. International processing
Some approved suppliers or their authorised subprocessors may process or support information from outside the United Kingdom.
Where information is transferred to a country not covered by UK adequacy regulations, an appropriate transfer mechanism is required. This may include:
-
the UK International Data Transfer Agreement;
-
the UK Addendum to the EU Standard Contractual Clauses; or
-
another transfer mechanism permitted under UK law.
We may also undertake a transfer-risk assessment and require contractual, organisational and technical safeguards.
Heidi states that European customer data is held within the EU or EEA. Supplier contracts, hosting arrangements and subprocessors are reviewed as part of practice governance.
15. How we protect information
Measures used to protect information include:
-
named user accounts;
-
multi-factor authentication where supported;
-
role-based access;
-
access limited to those who need the information;
-
confidentiality agreements;
-
staff information-governance training;
-
phishing and cyber-security awareness training;
-
secure devices;
-
encryption;
-
system backups;
-
supplier due diligence;
-
contractual data-processing terms;
-
incident-response arrangements;
-
removal of access when roles change; and
-
clinician review of AI-generated clinical documentation.
No system can be guaranteed to be entirely risk-free, but reasonable and proportionate safeguards are maintained.
16. How long we retain information
For adult patients, the core private clinical record is normally retained for 11 years after the last episode of treatment.
This reflects:
-
a reasonable period during which a treatment plan may remain active; and
-
a further period for clinical, professional, indemnity and legal purposes.
For a patient treated while under 18, records are retained until at least the patient’s 28th birthday.
Records may be kept for longer where:
-
the 11-year period after the last treatment ends later;
-
care remains ongoing;
-
there is a complaint;
-
there is an investigation or claim;
-
there is a safeguarding concern;
-
a court order applies; or
-
a legal, regulatory or insurance hold requires continued retention.
Accounting, taxation and payment records may be retained for different statutory periods.
Heidi transcripts and drafts are retained for no more than 90 days.
Voice or audio storage is not enabled in Heidi.
Doctify and other external processors retain information in accordance with their contractual and legal obligations. We require processors not to retain information for longer than necessary for the service they provide.
17. Your rights
Depending on the circumstances, you may have the right to:
-
request access to your personal information;
-
ask us to correct inaccurate information;
-
ask us to complete incomplete information;
-
request restriction of processing;
-
object to processing based on legitimate interests;
-
request erasure where there is no overriding reason to retain the information;
-
receive certain information in a portable format;
-
withdraw consent where consent is the lawful basis; and
-
complain about how information has been handled.
These rights are not absolute.
In particular, it may be necessary to retain an accurate clinical record for:
-
patient safety;
-
continuing care;
-
professional accountability;
-
regulatory obligations;
-
insurance and indemnity purposes; or
-
legal claims.
We do not make solely automated decisions that produce legal or similarly significant effects concerning your care.
18. Access to your records
You are normally entitled to receive a copy of your personal information without charge.
A reasonable fee may be charged only where permitted by law, such as where a request is manifestly unfounded or excessive, particularly if it is repetitive, or where additional copies are requested.
To request access, contact:
We may need to verify your identity before releasing information.
Clinical records may need to be reviewed before disclosure to:
-
protect confidential information about another person;
-
protect information provided in confidence by another person;
-
prevent unlawful disclosure; or
-
apply another lawful exemption.
19. Correction of clinical records
If you believe that information is inaccurate, please contact us.
Clinical records will not normally be silently deleted or overwritten.
Where appropriate, a dated correction or supplementary entry will be added so that:
-
the original record remains auditable;
-
the correction is clear;
-
the person making the correction is identifiable; and
-
the integrity of the medical record is preserved.
A difference of clinical opinion does not necessarily mean that a record is factually inaccurate, but your concern may be added to the record where appropriate.
20. Erasure requests
You may ask for information to be erased, but this right does not automatically apply to clinical records.
An erasure request may be refused where information remains necessary for:
-
safe healthcare;
-
continuing treatment;
-
professional accountability;
-
legal or regulatory compliance;
-
insurance or indemnity purposes;
-
safeguarding;
-
public-interest obligations; or
-
establishing, exercising or defending a legal claim.
Where erasure is not appropriate, restriction or annotation may sometimes be considered.
21. Cookies and website technology
What is a cookie?
A cookie is a small data file placed in the browser of your computer, telephone or tablet when you visit a website.
Cookies may be used to:
-
make a website function;
-
maintain security;
-
remember choices;
-
support accessibility;
-
understand how the website is used; or
-
provide features supplied by another service.
Our website is hosted through Wix.
Essential cookies
Essential cookies may be placed automatically because they are required for the website to work securely and properly.
They may be used for:
-
website security;
-
fraud prevention;
-
network management;
-
accessibility;
-
page navigation;
-
remembering privacy choices; and
-
maintaining the operation of the Wix platform.
Essential cookies do not normally require consent because the website cannot function properly without them.
Optional cookies
Depending on the website’s current configuration, optional cookies may be used for:
-
website analytics;
-
understanding which pages are visited;
-
measuring website performance;
-
identifying the type of device or browser used;
-
understanding how visitors reached the website;
-
remembering non-essential preferences; or
-
supporting third-party website features.
Where consent is legally required, optional cookies should not be placed unless you have accepted them through the cookie banner or cookie settings.
Analytics information
Where analytics are enabled and permitted, information may include:
-
pages visited;
-
date and time of visits;
-
approximate location derived from an internet address;
-
device and browser type;
-
time spent on a page;
-
referral source; and
-
movement through the website.
We do not use website analytics to access your medical record or make decisions about your care.
Advertising
We do not knowingly use website cookies for targeted advertising.
We do not sell website visitor information to advertisers.
If advertising or marketing technology is added to the website in future, this notice and the website’s cookie controls will be updated before that technology is used.
Third-party services
Third-party services embedded in or linked from the website may use their own cookies or similar technology.
Examples may include:
-
maps;
-
video players;
-
booking tools;
-
review platforms;
-
accessibility tools; or
-
analytics services.
Those third parties are responsible for explaining their own use of cookies and personal information.
Managing cookies
You can manage optional cookies using the cookie banner or Cookie Settings function on the website.
You may also delete or block cookies through your browser settings.
Blocking essential cookies may prevent parts of the website from working correctly.
22. Communications and ordinary email
We may use email, telephone, SMS or secure electronic systems to communicate with you.
Ordinary email and text messages are not completely secure.
We therefore ask patients not to send unnecessary sensitive medical information by ordinary email or SMS.
Where appropriate, more secure methods may be used for:
-
clinical records;
-
imaging;
-
large attachments;
-
identity documents; or
-
particularly sensitive information.
By providing an email address or mobile number, you acknowledge that these may be used for reasonable communications connected with your care, appointments, billing and administration.
This does not authorise unrelated direct marketing.
23. Children and representatives
Where a patient is a child, information may be shared with a person who has parental responsibility where this is lawful and appropriate.
The child’s:
-
age;
-
maturity;
-
capacity;
-
confidentiality rights; and
-
best interests
will be considered.
Where another person acts on your behalf, we may require evidence of:
-
your authority;
-
parental responsibility;
-
a lasting power of attorney;
-
deputyship;
-
executorship; or
-
another lawful basis for representation.
24. Complaints
Please contact the practice first if you have concerns about how your information has been used:
The Chest Clinic
c/o MedicalSec Services Ltd
2 Henge Close
Adderbury
Banbury
OX17 3GA
Telephone: 0203 146 1771
Email: PA@chest-clinic.co.uk
You may also complain to the Information Commissioner’s Office:
Telephone: 0303 123 1113
Website: www.ico.org.uk
You retain the right to seek a judicial remedy where applicable.
25. Changes to this notice
This notice will be reviewed periodically and whenever there is a material change to:
-
the services provided;
-
the controller or processor arrangements;
-
the hospitals or clinics used;
-
Carebit;
-
Heidi;
-
Doctify;
-
website cookies or integrations;
-
data locations or subprocessors;
-
retention periods;
-
applicable law; or
-
professional or regulatory guidance.
The most current version will be published on this website.
