Privacy Policy
Effective from 22 September 2026. This policy is regularly reviewed and updated.
This privacy policy sets out how I, Anna Doran (Anna Doran Health), use and protect any personal information that you provide to me. Should I ask you to provide certain information by which you can be identified when using my services, you can be assured that it will only be used in accordance with this privacy policy and the UK General Data Protection Regulation (UK GDPR).
About me
- Business name: Anna Doran Health
- HCPC Registration: DT034558
- Email: contact@annadorandiet.com
- ICO Registration: CSN1032456
- Postal address for data protection queries: available on request by emailing contact@annadorandiet.com
Why I collect your data
I collect your personal data so that I can provide my independent nutrition and dietetic services to you, and so that I can reply when you get in touch. Separately, if you have ticked the box to ask for it, I use your email address to send you my newsletter. The legal grounds for each of these are set out in the next section.
Lawful basis for processing
I process your personal data under Article 6(1)(b) UK GDPR (performance of a contract) when you book a paid service, and Article 6(1)(a) (consent) for the newsletter and contact form enquiries.
Health and dietary information is special category data under Article 9 UK GDPR. As an HCPC-registered dietitian, I process this data under Article 9(2)(h) (provision of health care by a health professional under a duty of confidentiality), read with Schedule 1 Part 1 paragraph 2 of the Data Protection Act 2018. Where I share information with your GP or another healthcare professional, I will obtain your separate explicit consent (Article 9(2)(a)) before doing so.
What information I collect
- Name, date of birth, age, sex, next of kin, GP name and address, marital status, living arrangements and occupation.
- Contact details: email and telephone numbers.
- Clinical and health-related information via forms, emails and verbally during a consultation. This includes dietary information, symptoms, medical history, and food diaries.
- Payment information processed securely by Stripe. I do not store your card details — these are handled entirely by Stripe in compliance with PCI DSS standards.
This information is required for
- Professional clinical record keeping of client information in accordance with the British Dietetic Association Guidance for Records and Record Keeping.
- Sharing information with relevant healthcare professionals such as your GP or medical team (your separate consent will always be obtained before this is done).
In exceptional circumstances, information about a client may be disclosed without consent if it is in the public interest to do so. This might be in circumstances where disclosing the information is necessary to prevent a serious crime or serious harm to other people.
What information is collected via this website
- This website uses Google Analytics to help me understand how the site is used — for example which pages are most read. It is entirely optional: no analytics cookie is set and no data is sent to Google unless you press 'Accept analytics' on the cookie notice, and you can change your mind at any time using the 'Cookie settings' link in the footer. IP addresses are anonymised, and I only ever see general trends, never individual visitors. There is no advertising pixel or session-recording tool on this site. My hosting provider also keeps standard server logs for security and reliability purposes.
- This website uses cookies to help provide a better user experience. Please see my Cookie Policy for full details. You may disable cookies in your browser if you prefer.
- You can subscribe to my newsletter from the signup form, the bloating quiz or the enquiry form. In every case it is a separate, optional tick box — I will never add you to the list because you contacted me or took the quiz. The signup form asks for your email address only. If you subscribe through the quiz or the enquiry form, the name you gave there is stored alongside it. Your details are held in MailerLite, used only to send you updates, and you can unsubscribe from any email at any time.
- When you submit the contact form, your name, email, phone number, selected service and message are saved securely on my own server. A short notification is sent to me via Telegram so that I can respond promptly. That notification contains only your first name, the service you selected and how you would prefer to be contacted. Telegram is operated outside the UK; see 'Sending data outside the UK' below.
- If you complete the bloating quiz, your answers produce a general result category (for example 'FODMAP-related'). Your name, email and that category are stored securely on my own server so that I can follow up with you, and are also added to MailerLite if — and only if — you tick the newsletter box. The quiz is a general educational tool, not a diagnosis or an assessment of your health. You can ask me to delete your quiz record at any time.
- If you complete the client consent form, your name, email and a record of which consents you gave are stored securely, together with the date and the version of the wording you agreed to. I keep this because data protection law requires me to be able to show that consent was properly given.
Third-party service providers
I use the following third-party services to operate my business. Each provider has their own privacy policy and data protection measures:
- Stripe — payment processing. Your card details are handled securely by Stripe and are never stored on my systems.
- MailerLite — email newsletter. Your email address is stored so that I can send you the nutrition updates you asked for, together with your name if you subscribed through the quiz or the enquiry form.
- Telegram — sends me an instant notification when you submit the contact form, the client consent form or the bloating quiz, so that I can respond to you promptly. Notifications contain only a first name and, depending on the form, the service you selected or your general quiz result category. I read each full submission in my own admin system. Telegram is operated outside the UK; see 'Sending data outside the UK' below.
- Contabo (server hosting) — the website and database are hosted on secure servers in Europe.
- Google Meet — used for online video consultations. Audio and video are transmitted in real time and are not recorded unless separately agreed with you in writing. Google Meet is provided as part of my Google Workspace subscription and operates under Google's Data Processing Addendum.
- Google Workspace — my professional email (contact@annadorandiet.com), client contact records (Google Sheets) and client documents (Google Drive) are hosted on Google Workspace under Google's Data Processing Addendum. My subscription does not include regional data storage, so some of this processing may take place outside the UK; see 'Sending data outside the UK' below.
- Cal.com — booking scheduler for free discovery calls. Cal.com stores your name, email and appointment time under its own GDPR-aligned Data Processing Agreement.
- WhatsApp Business — used for direct client communication (appointment logistics only, no clinical or health data). Messages are end-to-end encrypted. WhatsApp is operated by Meta Platforms Ireland under its own Data Processing Agreement.
- Google Analytics — optional website statistics, active only if you accept analytics cookies. It records anonymised information such as pages viewed, approximate region and device type. Google LLC processes some of this data in the United States under the UK extension to the EU–US Data Privacy Framework.
- Healthcode — the secure system used across UK private healthcare to submit invoices to insurers. If you claim on insurance, your billing and appointment details pass through Healthcode. It is a UK company and this data stays in the UK.
- Social media (Instagram, TikTok, YouTube and LinkedIn) — I post nutrition content on these platforms. If you message or comment there, that message is handled by the platform under its own privacy policy, and I cannot keep it as confidential as email. I do not discuss your health or any clinical details on social media: please use email or the contact form for anything personal.
If you use private medical insurance
If you claim through a private medical insurer, I share information with them so that your care can be invoiced. This normally includes your name, date of birth, policy and authorisation numbers, the dates and type of your appointments, and the clinical codes describing your treatment. I share it only with your own insurer, and only with your separate explicit consent under Article 9(2)(a) UK GDPR, which you give on my client consent form.
Your insurer decides for itself how it uses your information, so it acts as an independent data controller and its own privacy policy applies alongside mine. Your insurer may also send me information about you, such as your policy details and authorisation for treatment. You are never obliged to claim on insurance — you are always welcome to pay for your appointments directly.
Controlling your personal information
I will not distribute, sell or lease your personal information to third parties unless I have your explicit permission or am required by law to do so.
You may request details of personal information which I hold about you under the UK General Data Protection Regulation (UK GDPR). If you believe that any information I am holding on you is incorrect or incomplete, please contact me as soon as possible and I will promptly correct it.
All service providers used to store and process information related to carrying out dietetic services have robust security procedures in place and are GDPR compliant. BDA and HCPC record-keeping guidelines are strictly adhered to for one-to-one consultations.
Data retention
Records relating to the care of a client will be stored for eight years, in line with British Dietetic Association Guidance for Records and Record Keeping. Contact form enquiries and bloating quiz records are retained for 12 months. Payment records are retained for six years in accordance with HMRC requirements.
Your rights under UK GDPR
- The right to access the personal data we hold about you (Subject Access Request).
- The right to request correction of any inaccurate data.
- The right to request deletion of your data (right to be forgotten).
- The right to restrict or object to processing of your data.
- The right to data portability.
- The right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
If you are unhappy with how your data has been handled, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Sending data outside the UK
Most of your information stays in the UK or the European Economic Area. My website and its database are held on servers in Europe. Some of the services I use process data further afield, and I set each of them out honestly below.
Google — Google LLC processes anonymised website statistics in the United States. My Google Workspace subscription, which holds my email, client records and documents, does not include regional data storage, so some of that processing may also take place outside the UK. Google is certified under the UK Extension to the EU–US Data Privacy Framework, which the UK government recognises as providing adequate protection, and applies the UK International Data Transfer Addendum to other transfers. WhatsApp Business is provided by Meta Platforms Ireland, based in the European Economic Area; messages are end-to-end encrypted, and Meta relies on the Data Privacy Framework and standard contractual clauses for any onward processing in the United States.
Telegram — used only to alert me that a form has been submitted. Telegram FZ-LLC is based in the United Arab Emirates, which is not covered by a UK adequacy decision, and Telegram does not offer a data processing agreement or International Data Transfer Agreement for its notification service. For that reason I keep these notifications to the minimum that is useful: a first name, the service you chose and how you would like me to reply. Your surname, email address, phone number and message never leave my own server, and I read every enquiry in my admin system rather than in Telegram.
You are never obliged to use Telegram or WhatsApp, and you do not have to use the contact form at all. If you would prefer that none of your information leaves the UK, email me directly at contact@annadorandiet.com and I will handle your enquiry that way.
How I keep your information safe
I take the security of your information seriously. All data sent to and from this website is encrypted in transit. Client records are held in access-controlled accounts protected by strong, unique passwords and two-factor authentication, on devices that are encrypted and kept up to date. Access is limited to me alone. Payment card details never reach my systems at all. If a data breach were ever to occur that posed a risk to your rights, I would report it to the ICO within 72 hours and tell you directly where required.
Automated decision-making
I do not make any decisions about you by automated means, and I do not carry out profiling that produces legal or similarly significant effects. Website analytics are viewed only as aggregate trends and are never used to make decisions about an individual. The bloating quiz sorts your answers into a general category for educational purposes only — every clinical judgement about your care is made by me personally.
Questions and complaints
If you have any concern about how your information has been handled, please contact me first at contact@annadorandiet.com so that I can put it right. I aim to respond within five working days and to resolve matters within one month. If you are not satisfied with my response, you have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You may also raise concerns about my professional practice with the Health and Care Professions Council at hcpc-uk.org.
Changes to this policy
I review this policy regularly and will update it whenever my services or the tools I use change. The effective date at the top of this page always shows when it was last revised. Where a change materially affects how your information is used, I will tell existing clients directly.
Data controller
I (Anna Doran, HCPC registered dietitian) am the data controller at Anna Doran Health. Please contact me at contact@annadorandiet.com with any queries or requests related to your personal data and I will respond promptly.
