Skip to main content

Our Privacy Statement

Andrich Urology Privacy Notice

At Andrich Urology, we are fully committed to upholding and protecting your privacy at all times. We take our responsibilities under data protection legislation extremely seriously. This privacy notice serves as a comprehensive overview of how we collect and utilize your personal information, the robust security measures we have in place to safeguard it, and your legal rights pertaining to your data.

Who are we?

Andrich Urology is a privately owned company that provides comprehensive urological healthcare services. Our services encompass outpatient consultations, treatments, surgical procedures, and diagnostic imaging. We also offer practice management services, including appointment scheduling, medical records management, collection of clinical outcomes, secretarial services, and billing. Dr. Andrich is responsible for determining the information she requires from you and may maintain her own set of medical records related to the treatment she provides. As a Data Controller, Dr. Andrich must adhere to data protection laws and applicable guidelines when handling your personal information. In line with this Privacy Notice, you can expect Dr. Andrich and her administrative team to handle your information appropriately. Further details on how your personal information is used are provided below.

Registered office

Our registered office is 10 Western Road, Romford, Essex RM1 3JT

What types of data do we collect and use? 

Andrich Urology requires certain types of personal and sensitive data about you in order to provide you with the necessary care and treatment.

The personal data we collect encompasses the following information:

  • Your full name, title, date of birth, and gender.
  • Your address and contact details, including email address and telephone numbers.
  • Emergency contact details and/or next of kin.
  • Your National Health Number.
  • Details about other clinicians involved in your care or referral, such as your GP or physiotherapist.
  • Financial information, including credit card or other bank details if you are responsible for paying all or part of the bills related to your care.
  • Your medical insurance details or information about other organizations responsible for funding your care.

We also collect and retain data categorized as a special category of personal data, which includes:

  • Details of your current and previous physical and mental health, including any treatments you have received elsewhere and from other clinicians.
  • Medical records, including past treatments, investigation results, tests, and scan reports.
  • Imaging materials, such as X-rays, ultrasound and MRI scans, as well as their corresponding reports, photographs, and videos.
  • Information regarding your religion, nationality, race, and/or ethnicity.
  • Details about your sexual orientation.
  • Genetic or biometric data relating to you.

Please note that the collection of this information is vital for us to provide you with appropriate and effective care and treatment.


Where does this information come from?

The information included in your medical record may originate from various sources, including yourself, your GP, your referring clinician, your consultant, and other healthcare professionals involved in your care. Additionally, additional information may be shared by your insurer or other parties responsible for funding your treatment.

Furthermore, we gather information directly from you when you visit our website and patient portals.

What legal basis does Andrich Urology have for storing and using my personal data?

According to the General Data Protection Regulations (GDPR), specifically Article 6(1) and Article 9(2), we possess the right to process your data for the following purposes:

  • Supporting the provision of high-quality treatment and clinical care that aligns with your specific needs.
  • Facilitating communication with you regarding your clinical care, as well as addressing any queries, concerns, or complaints you may have.
  • Engaging in communication with other healthcare professionals and referring clinicians involved in your care.
  • Conducting clinical audits and statistical analyses to monitor and enhance the standard of care provided, thereby improving clinical performance.
  • Ensuring proper payment for the treatment you receive.
  • Fulfilling our legal obligations as required.

How will Andrich Urology use my personal data?

The personal data will be used for the following purposes:

  • To ensure you are receiving appropriate clinical care for your needs
  • Arranging appointments, investigations, scans, procedures and surgeries
  • To respond to your queries, complaints and concerns 
  • Quality assurance through the evaluation of your treatment and outcomes
  • Processing of invoices and payment of fees in connection with your account with us and/or your consultant
  • Disclosure of details of your treatment with us to your referring physician or clinician or to another clinician for further treatment when required. If you would prefer us not to share this information please notify us
  • We will never market our services or pass on your information to a third party without your consent except in the circumstances in a section below.

Do I have to provide my personal information?

While you are not obligated to disclose any information to us, it’s important to note that limiting the information you provide may result in us being unable to offer you a comprehensive range of services. Consequently, it could potentially affect the level of service we can provide to you.

In cases where collecting and processing your data is necessary under data protection law, we will seek your explicit consent. You have the right to withdraw your consent at any time by reaching out to the Data Protection Officer at Andrich Urology.

Will Andrich Urology share my personal data with others?

Under certain circumstances, your data held by Andrich Urology may be shared with relevant parties. However, we will only share the necessary information in the following situations:

  1. Sharing information with those involved in your healthcare, which may include:
  • Consultants, anaesthetists, radiologists, and other healthcare professionals involved in your treatment, such as physiotherapists.
  • External companies providing services to Andrich Urology as part of your care pathway, such as blood tests, radiological imaging, archiving, and reporting.
  • Other healthcare providers involved in your care, such as pharmacy services.
  • Your GP and/or other referring clinicians.
  • Other staff members, such as administrators, receptionists, and medical secretaries.
  • Local Safeguarding Team if there are concerns regarding your vulnerability or well-being, consisting of specialists from the local authority, NHS organizations, and the police.
  • Individuals you have requested us to communicate with or designated as emergency contacts.

  1. Sharing information with those involved in the administration of your care, such as:
  • Your private medical insurer or any organization responsible for funding your care.
  • Debt collection agencies in case of non-payment, limited to contact details and copy invoices without sharing your medical records.

  1. Sharing information with third parties not directly involved in your care, including:

  • External organizations necessary for the operation, security, and integrity of business functions. Only relevant information is shared, and these third parties can include software providers, document scanning and storage facilities, legal and professional advisors, and auditors.
  • Pseudonymized, anonymized, and aggregated data may be shared as part of quality assurance processes.
  • Regulatory bodies or when legally obligated, such as sharing information with regulatory bodies, court orders, and law enforcement agencies for crime detection and prevention.
  • Limited information may be shared with the Private Healthcare Information Network (PHIN) for quality and cost publication, in compliance with data processing laws.

  1. Sharing personal data for research and marketing:
  • Personal data will not be used for marketing purposes without your consent, and we will not sell your personal data to third parties.
  • Andrich Urology is dedicated to advancing research and education in urological conditions and treatments. With your explicit consent, we may use your personal data for clinical research and education in accordance with research ethics requirements and data protection laws.

  1. Sharing data with your consent:
  • With your consent, we may disclose your personal information to other parties, such as companies handling claims on your behalf and national registries monitoring treatment outcomes.

Rest assured, we prioritize the protection and privacy of your personal data in all instances.

How long will my data be retained by Andrich Urology?

We will retain your personal data only for the duration necessary to fulfil the purposes stated in this privacy notice and to comply with applicable legal and regulatory obligations. The retention periods align with the guidelines provided by the Information Governance Alliance Records Management Code of Practice for Health and Social Care 2016.

Is my data secure?

Andrich Urology relies on Carebit, its official IT service provider, to uphold the security of your data. Carebit has implemented various technical controls on behalf of Andrich Urology to safeguard the confidentiality, integrity, and availability of the processed data.

To ensure data availability and enable business continuity, daily backups are performed. This precautionary measure guarantees that data remains readily accessible in the event of natural disasters or technical issues, while also ensuring exceptional customer service.

Encryption controls have been put in place for data in transit, such as email transmissions. This encryption ensures that the data remains secure and can only be accessed by the intended recipient(s).

All machines within the system adhere to a standardized process and predefined requirements. This ensures that each machine is built securely, configured with appropriate user levels, and utilizes approved tools throughout its lifecycle. Additionally, password protection is enforced on all machines, restricting access solely to authorized personnel.

What rights do I have as a data subject?

As the data subject, you have certain rights regarding your personal data while we possess or process it. These rights include:

  • Right of access: You can request a copy of the information we hold about you, which will be provided free of charge within one month of receiving your request.
  • Right of rectification: You have the right to request the correction of any inaccurate or incomplete data we hold about you, and we will respond within one month of receiving your request.
  • Right to be forgotten: In certain circumstances, you can ask us to erase the data we hold about you from our records.
  • Right to restriction of processing: Under specific conditions, you have the right to restrict the processing of your information that we hold.
  • Right of portability: You can request to have the data we hold about you transferred to another organization.
  • Right to object: You have the right to object to certain types of processing, such as direct marketing.
  • Right to object to automated processing, including profiling: You have the right not to be subject to legal effects resulting from automated processing or profiling.
  • Right to judicial review: If we refuse your request under the right of access, we will provide you with a reason for our decision. If a third party is involved, we will forward your request to them.

If you have any queries or wish to exercise your rights, you can contact the Andrich Urology Data Protection Officer using the address provided below. When making a data request, you will need to provide identification such as a passport, driving licence, utility bill from the last three months, or another form of photo ID.

If you are unsatisfied with our response to your request or believe we have not fulfilled our legal obligations, you can lodge a complaint with the Information Commissioner’s Office (ICO). We encourage you to first inform the Data Protection Officer about the issue to give us an opportunity to address it before contacting the ICO. Making a complaint will not affect any other legal rights or remedies you may have. You can find more information on the ICO website or contact them using the provided contact details.

How do I complain?

If you wish to make a complaint about the processing of your personal data by Andrich Urology, please contact the Data Protection Officer at Andrich Urology. You also have the right to lodge a complaint directly with the Information Commissioner’s Office. The contact details for both entities are provided below:

Information Commissioner’s Office:

  • Wycliffe House
  • Water Lane
  • Wilmslow
  • Cheshire
  • SK9 5AF
  • Email:
  • Telephone: 0303 123 1113 (local rate) or 01625 545 745 (national rate)

Data Protection Officer:

Additional information relating to our Website

When you visit our website or utilize our other digital services, such as our patient portal, we may collect and utilize certain personal data. This information is collected in addition to the data mentioned earlier. The following information is collected through the website:

  • Visits to our website
  • Information provided in enquiry and feedback forms
  • Survey information
  • Enquiries or calls made via the website about our services

We use this information in the following ways:

  • Analysing the website to ensure an optimal user experience, such as making web pages easy to read and presenting information effectively
  • Notifying you about changes to products and services
  • Providing you with information about our products and services, if you have given consent to be contacted, for instance, by subscribing to receive information about our events.

How secure is my data?

At Andrich Urology, any personal information you provide is stored on secure servers and is encrypted. We have implemented measures to ensure the security of your data within our systems. However, it is important to note that the transmission of information over the internet cannot be guaranteed to be completely secure. While we take precautions to protect your data during transmission, such as through forms or email, there are inherent risks involved, and the security of your data during transmission is done at your own risk.

How do you use cookies?

Cookies are small data files that can identify you when you visit a website. They serve various purposes, such as remembering your settings and enhancing the speed and security of the website.

At Andrich Urology, we use cookies on our website to enhance the visitor’s experience. This includes ensuring that our website is responsive, fast, and displays relevant information. By using cookies, we can also improve our website and tailor our marketing efforts.

It’s important to note that we do not use cookies to collect any personally identifiable information about you, nor do we share personally identifiable data with third parties. You have the option to disable cookies in your browser settings. However, if your browser settings are set to accept cookies, we interpret this as your agreement to their usage.

Do you share my data?

When you submit an online enquiry form, the information you provide is exclusively shared with Andrich Urology. We do not disclose your information to any third parties unless you have explicitly granted us permission to do so. When you send an email or complete a referral form, Andrich Urology will not share your email address with individuals or organizations outside of the clinic, except for those directly involved in providing the services related to your inquiry. If you choose to subscribe to our mailing lists and give consent to receive communication from us, we will only send you information in the specific format you have requested. 

Are all downloads checked for viruses?

While we make every reasonable effort to ensure that files downloaded or accessed are free of defects and viruses, Andrich Urology does not provide any warranty or guarantee regarding the files. If you have any comments, queries, or feedback about this privacy notice, please send an email to