Last updated: March 2026 | Version 2.0
This policy explains how Diverse Diagnostics collects, uses, stores and shares your personal information when you use our website or services. Please read it carefully. If you have any questions, contact us using the details at the end of this document.
Diverse Diagnostics Limited is a private healthcare provider offering neurodevelopmental and mental health assessments and related services. We are the data controller for the personal information you provide to us.
We are registered with the Information Commissioner's Office (ICO). Our ICO registration number is ZB952063
Our registered address is: 2 Roman Road, Suite 7 Tribune Court, Bearsden, G61 2SW
Contact for data protection enquiries:
When you enquire about, book, or attend an assessment with us, we collect:
Because we provide mental health and neurodevelopmental assessments, the information we process about you is classified as special category health data under UK GDPR Article 9. We treat this with the highest level of care and apply appropriate safeguards at all times.
This includes information about your mental and physical health, assessment outcomes, and any clinical correspondence.
When you visit our website, we and our third-party service providers collect certain information automatically, including through cookies. This may include your IP address, browser type, pages visited, and how you reached our site. Please see our Cookie Policy for full details.
Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following:
For special category health data, we rely on:
We use your information to:
We do not sell your personal data. We may share it in the following circumstances:
We will share relevant clinical information with your GP and, where appropriate, other healthcare professionals involved in your care. We will inform you when we do this, except where doing so could place you or others at risk of harm. In circumstances where there is believed to be an immediate risk to your safety or the safety of others, we may share information with relevant parties, including your GP, social services, or emergency services, without notifying you in advance. We will always document our reasoning when we disclose information in this way.
We use trusted third-party providers to operate our business. These providers act as data processors or independent controllers, as applicable, and are required to handle your data securely and in accordance with applicable data protection law. Current providers include:
We may disclose your information without your consent in limited circumstances where we are required to do so by law, court order, or where there is a compelling public interest (for example, to protect a child or young person from harm). We will always document our reasoning when we do so.
Some of the third-party providers we use to operate our services are based outside the UK or European Economic Area, or may process your data on servers located outside these areas. Where this is the case, we ensure that appropriate safeguards are in place to protect your data, including reliance on the UK adequacy regulations, standard contractual clauses approved by the ICO, or other lawful transfer mechanisms. We only use providers whose data transfer arrangements we are satisfied meet the required standard.
Where you have consented to receiving communications via WhatsApp, we may send you appointment reminders and information about our services through the WhatsApp Business platform, integrated with HubSpot via Sinch.
All messages sent via this channel are pre-approved templates. We will not send sensitive clinical information through WhatsApp.
You can opt out of WhatsApp communications at any time by replying STOP to any message, or by contacting us directly. Opting out will not affect your ability to access our services.
WhatsApp message records may be stored within your contact record in HubSpot where you reply to a message. These records are subject to the same access controls and retention periods as other contact data.
Where you have provided your mobile number, we may send you appointment reminders and service communications via SMS through Cliniko, our clinical management system. We will not send sensitive clinical information via SMS. You can opt out of SMS communications at any time by contacting us directly. Opting out will not affect your ability to access our services.
We do not keep your data for longer than is necessary. Our retention periods are based on legal and professional requirements:
When data is no longer required, digital records are securely deleted and physical records are shredded.
Under UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us using the details in Section 1. We will respond within one calendar month. We may need to verify your identity before processing your request.
If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.
We take the security of your personal data seriously and have implemented technical and organisational measures to protect it, including:
If you suspect any misuse, loss or unauthorised access to your data, please contact us immediately.
Our website uses cookies to help it function, to understand how it is used, and to support marketing activity. For full details of the cookies we use, including how to manage your preferences, please see our Cookie Policy, available on our website.
We use a consent management platform (CookieYes) to record your cookie preferences. You can update your preferences at any time using the Consent Preferences link on our website.
Where we provide assessments or services to children and young people, we will seek consent from a parent or person with parental responsibility before collecting and processing their data.
We apply additional safeguards to data relating to children and young people, including extended retention periods and stricter access controls.
We review this policy at least annually and will update it when our practices change or when required by law. When we make significant changes, we will notify you by email where we hold your contact details, or by a prominent notice on our website.
The date at the top of this document shows when it was last updated.
If you have any questions about this policy or about how we handle your personal data, please contact us:
You can also contact the ICO directly if you have concerns about how we handle your data:
Diverse Diagnostics Limited | Privacy Policy | Version 2.0 | April 2026
Suite 7 Tribune Court,
2 Roman Road,
Bearsden,
Glasgow G61 2SW