Privacy Policy

Last updated: March 2026  |  Version 2.0

This policy explains how Diverse Diagnostics collects, uses, stores and shares your personal information when you use our website or services. Please read it carefully. If you have any questions, contact us using the details at the end of this document.

1. Who We Are

Diverse Diagnostics Limited is a private healthcare provider offering neurodevelopmental and mental health assessments and related services. We are the data controller for the personal information you provide to us.

We are registered with the Information Commissioner's Office (ICO). Our ICO registration number is  ZB952063

Our registered address is: 2 Roman Road, Suite 7 Tribune Court, Bearsden, G61 2SW

Contact for data protection enquiries:

2. The Information We Collect

Information you provide to us

When you enquire about, book, or attend an assessment with us, we collect:

  • Your name, email address, phone number and date of birth
  • Details about the assessment you are seeking and any background information you provide
  • GP details, where relevant to your care
  • Payment information (processed securely through our payment provider; we do not store card details)
  • Any communications you send to us
Special category (sensitive) data

Because we provide mental health and neurodevelopmental assessments, the information we process about you is classified as special category health data under UK GDPR Article 9. We treat this with the highest level of care and apply appropriate safeguards at all times.

This includes information about your mental and physical health, assessment outcomes, and any clinical correspondence.

Information collected automatically

When you visit our website, we and our third-party service providers collect certain information automatically, including through cookies. This may include your IP address, browser type, pages visited, and how you reached our site. Please see our Cookie Policy for full details.

3. Our Lawful Basis for Processing Your Data

Under UK GDPR, we must have a lawful basis for processing your personal data. We rely on the following:

  • Contract: to fulfil our agreement with you to provide an assessment or other service
  • Legitimate interests: for operational purposes such as managing appointments, improving our services, and communicating with you about your care
  • Legal obligation: where we are required to process or retain data by law
  • Explicit consent: where we ask for your consent before processing, for example for marketing communications or for sharing specific information

For special category health data, we rely on:

  • Article 9(2)(h): processing necessary for the provision of health or social care treatment
  • Article 9(2)(a): your explicit consent, where applicable

4. How We Use Your Information

We use your information to:

  • Schedule and conduct your assessment
  • Communicate with you about your appointment, care, or enquiry
  • Share relevant information with your GP, where required for your care or where you have consented
  • Record calls for quality and training purposes, where you are informed of this at the start of the call
  • Process payments for our services
  • Maintain clinical records as required by law and professional standards
  • Send you appointment reminders and follow-up communications
  • Send marketing communications about our services, where you have given consent (you can opt out at any time)
  • Analyse and improve our website and services
  • Comply with our legal, regulatory and professional obligations

5. How We Share Your Information

We do not sell your personal data. We may share it in the following circumstances:

Healthcare professionals

We will share relevant clinical information with your GP and, where appropriate, other healthcare professionals involved in your care. We will inform you when we do this, except where doing so could place you or others at risk of harm. In circumstances where there is believed to be an immediate risk to your safety or the safety of others, we may share information with relevant parties, including your GP, social services, or emergency services, without notifying you in advance. We will always document our reasoning when we disclose information in this way.

Technology and service providers

We use trusted third-party providers to operate our business. These providers act as data processors or independent controllers, as applicable, and are required to handle your data securely and in accordance with applicable data protection law. Current providers include:

  • HubSpot: our customer relationship management (CRM) platform, used to manage contact records, appointment communications and marketing
  • Cliniko: our clinical appointment booking and patient record system
    MHS: external platform used to administer ADHD assessment questionnaires. Patients complete questionnaires via secure links; completed responses are uploaded into Cliniko
  • Sinch (WhatsApp Business API): used to send appointment reminders and nurture communications via WhatsApp, where you have consented to this channel
  • Stripe: payment processing. Where you choose Klarna as your payment method at checkout, your payment data is handled by Klarna as a sub-processor of Stripe
  • CallRail: call tracking and analytics
  • Google Analytics and Microsoft Clarity: website analytics
  • CookieYes: consent management platform used to record and manage visitor cookie preferences on our website
  • APIANT: integration platform used to transfer data between HubSpot, Cliniko and Stripe
  • Notion: used for internal documentation and operational tracking, including patient names and appointment dates
  • iPECS: telephone system used to manage inbound and outbound calls with patients and contacts. Calls may be recorded for quality and training purposes.
Legal requirements

We may disclose your information without your consent in limited circumstances where we are required to do so by law, court order, or where there is a compelling public interest (for example, to protect a child or young person from harm). We will always document our reasoning when we do so.

Data transfers outside the UK/EEA

Some of the third-party providers we use to operate our services are based outside the UK or European Economic Area, or may process your data on servers located outside these areas. Where this is the case, we ensure that appropriate safeguards are in place to protect your data, including reliance on the UK adequacy regulations, standard contractual clauses approved by the ICO, or other lawful transfer mechanisms. We only use providers whose data transfer arrangements we are satisfied meet the required standard.

6. Mobile Communications

Where you have consented to receiving communications via WhatsApp, we may send you appointment reminders and information about our services through the WhatsApp Business platform, integrated with HubSpot via Sinch.

All messages sent via this channel are pre-approved templates. We will not send sensitive clinical information through WhatsApp.

You can opt out of WhatsApp communications at any time by replying STOP to any message, or by contacting us directly. Opting out will not affect your ability to access our services.

WhatsApp message records may be stored within your contact record in HubSpot where you reply to a message. These records are subject to the same access controls and retention periods as other contact data.

Where you have provided your mobile number, we may send you appointment reminders and service communications via SMS through Cliniko, our clinical management system. We will not send sensitive clinical information via SMS. You can opt out of SMS communications at any time by contacting us directly. Opting out will not affect your ability to access our services.

7. How Long We Keep Your Data

We do not keep your data for longer than is necessary. Our retention periods are based on legal and professional requirements:

  • Mental health records (adults): 20 years from the date of last contact, or 3 years from death if sooner
  • Mental health records (children and young people): until the individual reaches the age of 25, or 8 years from death if sooner
  • General enquiries:  24 months from the date of the enquiry, after which contact records are securely deleted unless you have subsequently become a patient
  • Employee data: 6 years from the last date of employment
  • WhatsApp message records: in line with the relevant contact retention period above

When data is no longer required, digital records are securely deleted and physical records are shredded.

8. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right to be informed: to know how we use your data (this policy fulfils that obligation)
  • Right of access: to request a copy of the personal data we hold about you
  • Right to rectification: to ask us to correct inaccurate or incomplete data
  • Right to erasure: to ask us to delete your data in certain circumstances
  • Right to restrict processing: to ask us to limit how we use your data
  • Right to data portability: to receive your data in a structured, machine-readable format
  • Right to object: to object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making: we do not make automated decisions about you that have legal or similarly significant effects

To exercise any of these rights, please contact us using the details in Section 1. We will respond within one calendar month. We may need to verify your identity before processing your request.

If you are not satisfied with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.

9. How We Keep Your Data Secure

We take the security of your personal data seriously and have implemented technical and organisational measures to protect it, including:

  • Access controls limiting who can view patient data
  • Multi-factor authentication on key systems
  • Encryption of data in transit and at rest
  • Regular staff training on data protection and confidentiality
  • Secure destruction of physical records
  • Password management controls to protect access to systems containing personal data.

If you suspect any misuse, loss or unauthorised access to your data, please contact us immediately.

10. Cookies

Our website uses cookies to help it function, to understand how it is used, and to support marketing activity. For full details of the cookies we use, including how to manage your preferences, please see our Cookie Policy, available on our website.

We use a consent management platform (CookieYes) to record your cookie preferences. You can update your preferences at any time using the Consent Preferences link on our website.

11. Children and Young People

Where we provide assessments or services to children and young people, we will seek consent from a parent or person with parental responsibility before collecting and processing their data.

We apply additional safeguards to data relating to children and young people, including extended retention periods and stricter access controls.

12. Changes to This Policy

We review this policy at least annually and will update it when our practices change or when required by law. When we make significant changes, we will notify you by email where we hold your contact details, or by a prominent notice on our website.

The date at the top of this document shows when it was last updated.

13. Contact Us

If you have any questions about this policy or about how we handle your personal data, please contact us:

You can also contact the ICO directly if you have concerns about how we handle your data:

  • Website: www.ico.org.uk
  • Telephone: 0303 123 1113

Diverse Diagnostics Limited  |  Privacy Policy  |  Version 2.0  |  April 2026