Elevate Metabolic Health – Privacy Policy
At Elevate Metabolic Health, we take your privacy seriously. This policy sets out how we handle your personal information when you visit our website, make an enquiry, or receive our clinical or coaching services. It explains what we collect, why we collect it, and the steps we take to keep your information secure.
By using our website or accessing our services, you are acknowledging and accepting the terms of this policy.
1. Purpose of this Policy
This document describes how Elevate Metabolic Health (“we”, “our”, “us”) processes your personal data when you communicate with us, book an appointment, participate in a consultation, or use our online services.
We operate in accordance with relevant UK legislation, including:
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Care Quality Commission (CQC) guidance (where applicable)
2. Who is Responsible for Your Data
Elevate Metabolic Health acts as the Data Controller for all personal information we receive.
If you have any queries about how your information is managed, please contact:
Data Protection Lead: Dr Caroline Butler
Email: hello@drcarolinebutler.com
Phone: 07356 223362
Postal Address: Elevate Metabolic Health, c/o Unit 4, Stirling Court Yard, Stirling Way, Borehamwood, England, WD6 2FX
3. Information We Collect
We gather information directly from you and, where appropriate, from trusted healthcare sources. The information we hold may include:
a) Personal Details
Name
Gender at birth
Date of birth
Postal address
Email address
Telephone number
Emergency contact details
NHS number (when applicable)
Registered GP details
b) Health and Medical Data
Medical and lifestyle history
Current concerns, symptoms, or conditions
Medication lists
Treatment plans or clinical recommendations
Laboratory and diagnostic results
Information relevant to metabolic health assessments and coaching
c) Digital and Technical Information
IP address
Device and browser details
Website interaction or usage patterns
d) Payment Information
Details required to process payments for clinical services, laboratory testing, and coaching
(We do not store full card numbers on our systems.)
4. How Your Information Is Used
We use your data to provide safe, personalised, and effective care. Typical uses include:
Clinical assessment and treatment
Organising appointments, reminders, and follow-up care
Maintaining medical records as required under UK healthcare regulations
Correspondence, such as notifying you of results or responding to enquiries
Coaching and lifestyle support, including programme materials and updates
Payment processing for services
Referrals to laboratories, pharmacies, or other healthcare professionals when needed
We only process information where a lawful basis exists and will never use your data in ways that are incompatible with the purpose for which it was obtained.
5. Legal Grounds for Processing
Under UK GDPR, your information is processed under one or more of the following bases:
Consent – when you have chosen to allow us to share or use information in a particular way
Contract – to deliver healthcare or coaching services you have requested
Legal obligation – when required to meet regulatory or statutory duties
Vital interests – where information is needed to prevent serious harm
Public interest in the area of health – for specific regulated healthcare functions
6. When We Share Your Data
We may share relevant information with:
Laboratories and other clinicians involved in your care
Pharmacies dispensing medication (if required)
Regulatory bodies such as the CQC or GMC, if legally obliged
Secure IT providers who support our clinical and administrative systems
Payment service providers for processing transactions
Sharing without explicit consent
In exceptional circumstances—such as safeguarding, legal requirements, or serious risk to life—we may share information without your prior agreement.
We do not share your personal information for advertising purposes.
7. Protecting Your Information
We have robust processes in place to keep your data safe, including:
Secure, encrypted systems for storing and transferring data
Restricting access to staff who require it for clinical or administrative purposes
Regular system checks and audits to ensure compliance
A defined procedure for handling and reporting any data breaches
8. How Long We Keep Your Information
Information is retained only for as long as necessary and in line with UK healthcare record-keeping rules.
Clinical records are normally stored for a minimum of eight years from your last interaction with the service, or longer where legislation requires it.
9. Your Rights
Under UK data protection law, you have the following rights:
To see the information we hold about you (Subject Access Request)
To request corrections to inaccurate or incomplete data
To ask for deletion, where legally possible
To limit how your data is used
To request data portability, allowing transfer to another provider
To object to processing in specific circumstances
To withdraw consent at any time for uses based on your permission
To exercise any of these rights, please contact our Data Protection Lead.
10. Cookies and Website Tracking
Our website uses cookies to support functionality, monitor performance, and improve user experience.
Full details are available in our separate Cookie Policy.
11. Updates to This Privacy Policy
From time to time, we may make changes to this policy to reflect updates in legislation or adjustments to our services. Any updated version will be published on this page.
12. How to Contact Us
If you have questions, concerns, or complaints about how your data is used, please contact:
Data Protection Lead: Dr Caroline Butler
Email: hello@drcarolinebutler.com
Phone: 07356 223362
Postal Address: Elevate Metabolic Health, c/o Unit 4, Stirling Court Yard, Stirling Way, Borehamwood, England, WD6 2FX