Privacy Policy
Data Collection
I maintain confidential records and information about my patients, beginning when a potential patient or parent contacts me through the website's contact form, professional secure email, or correspondence with the GP. During consultations, I take clinical notes covering relevant information for assessment and treatment, including physical health measurements, psychiatric and medical history, developmental history, educational history, and family background.
Following assessment, I prepare a psychiatric report, securely sent to the patients and their parents/guardians via email. With consent, the report may also be sent to the GP and/or educational professionals.
Communication
Contact with parents/guardians is initiated for the purpose of scheduling appointments and to gather and offer additional information relevant to the psychiatric consultation. Newsletters or group emails are not sent. I do not send unsolicited messages, marketing, or product information. I respond to enquiries from parents/guardians via secure email, telephone, or password-protected correspondence.
Data Security
I implement stringent measures to ensure complete confidentiality, including sending encrypted emails, password-protecting portable devices, employing up-to-date antivirus software, and securely storing notes. All data is accessible only by me. Information sharing, for instance with a patient's GP, occurs only with explicit consent from the patients and their parents/guardians.
Website & Cookies
This website is hosted by Netlify and serves as an online platform for patients to learn about services and make contact through the enquiry form. The site uses minimal cookies necessary for basic functionality.
Subject Access
Data obtained about patients is solely for providing optimal care and assuring service quality. Clinical records are retained in line with applicable health record retention guidance and medico-legal requirements. For children and young people, this usually means retaining records at least until the young person’s 25th birthday, or 26th birthday if they were 17 when treatment ended, unless a longer retention period is required. Patients may exercise their GDPR rights with a subject access request. Information is released upon written application with proof of identity, and responses are provided within one calendar month.
Consent
Upon initial contact, parents/guardians will be asked to complete a consent form. This allows patients to consent to the assessment and treatment process, specify preferred contact methods, and confirm their understanding of the privacy policy.
Disclosure of Personal Data
I maintain a private and confidential electronic record system, holding patient information in confidence. Patient names or information are not disclosed unless ethically or legally required, such as in cases of serious harm risk. Any proposed disclosure is discussed with the patient unless doing so would increase risk.
Ethics & Professional Development
I adhere to the code of ethics and good clinical practice outlined by the General Medical Council and Royal College of Psychiatrists. Ongoing education, regular supervision, peer group learning, annual appraisal, and revalidation are consistently pursued.
Feedback & Complaints
All feedback and complaints are welcomed and taken seriously. If you are unhappy with any aspect of the service, please contact me by email with details of your concern. I will acknowledge complaints within 5 working days and aim to provide a full response within 20 working days. Complaints are handled confidentially and will not affect your child’s care.
If your concern relates to data handling, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Data Controller & Lawful Basis
The data controller is Dr Shimrit Ziv, Consultant Child & Adolescent Psychiatrist. The lawful basis for processing personal data for clinical care is GDPR Article 6(1)(f) (legitimate interests) and Article 9(2)(h) (health or social care purposes) for special category health data. Data is processed for the purposes of providing psychiatric assessment, diagnosis, treatment and clinical correspondence.
Data processors and systems used may include the website host (Netlify), secure email, clinical notes systems, payment processing and, where relevant, Pharmacierge for prescription delivery. Information may be shared with GPs, schools and other professionals only with explicit consent, or where required by law or safeguarding obligations.
For young people, I consider the young person’s own right to confidentiality alongside parental access, in line with Gillick competence principles and GMC guidance on children and young people.
Data Breach
Procedures are in place to detect, report, and investigate any personal data breaches. I am registered with the ICO and have procedures in place to support compliance with data protection obligations.
Last updated: June 2026