Privacy policy
This explains what we do with your information, both on this website and when you become a patient. It is written to the UK GDPR and the Data Protection Act 2018. Last reviewed 13 August 2026.
Who we are
Harmony Medical Aesthetics Ltd, also trading as Harmony by Dr Ayah, is the data controller for the information described here.
We operate two clinics: 5 Harrison Road, Halifax, HX1 2AF, and 10 Harley Street, London, W1G 9PF.
We are registered with the Information Commissioner’s Office, reference ZB283587.
Dr Komal Ayah Siddiqi is responsible for data protection. For anything about your information, email info@harmonymedical.uk or write to the Halifax address.
What this website collects
This site collects very little, deliberately.
- Your email address, only if you enter it on the price list page. That goes to Kit, our email provider, so we can send you the price list and occasional clinic emails.
- A cookie recording your cookie choices, set by our consent banner.
- Standard server logs kept by our host, Krystal, including IP address, browser type and pages requested, used for security and troubleshooting.
- Login protection records, if someone attempts to log into the site administration.
We do not run Google Analytics, Google Tag Manager, a Facebook pixel, or any other advertising or tracking script on this website.
Booking happens on Square, at a different web address, so nothing about your booking is stored on this website.
What we collect when you become a patient
This is separate from the website, and it is the part that matters most.
- Contact details: name, date of birth, address, email and phone number.
- Medical history, medications, allergies and relevant lifestyle information.
- Clinical photographs and imaging, including skin scans and ultrasound images.
- Notes on your assessment, treatment given, doses, batch numbers and aftercare.
- Consent forms.
- Payment records. We do not hold your full card details; those stay with the payment provider.
Clinical photographs and imaging are part of your medical record. We do not use them for marketing or on social media unless you have given separate, specific written consent, and you can withdraw that consent at any time.
Why we are allowed to hold it
Under UK GDPR we rely on the following.
- For your medical records: Article 9(2)(h), the provision of health care and treatment, together with Article 6(1)(b), performing our contract with you.
- For appointment reminders and clinical follow-up: our legitimate interests in delivering safe care.
- For marketing emails: your consent, which you can withdraw at any time.
- For accounting and tax records: our legal obligations.
Where your records are held
Clinical records, including photographs and imaging, are held in encrypted cloud storage provided by Dropbox, on a business account configured for healthcare data.
Access is limited to the clinicians and staff who need it to deliver your care.
Booking and payment information is held by Square. Our email is hosted by Google Workspace. This website is hosted by Krystal.
Where any provider stores data outside the UK, that transfer is covered by the safeguards required under UK data protection law.
Who we share it with
We do not sell your information, and we do not pass it to anyone for their own marketing.
- Square, for appointment booking and card payments.
- Dropbox, for secure storage of clinical records.
- Kit, for marketing emails, and only if you gave us your email for that purpose.
- Google Workspace, which hosts our email.
- Krystal, which hosts this website.
- Our accountant and insurers, where required.
- Other clinicians, but only with your agreement, for example if we refer you.
We may share information without your agreement only where the law requires it, or where there is a serious risk to someone’s safety.
How long we keep it
Clinical records for adults: eight years after your last treatment.
Clinical records for anyone treated under the age of 18: ten years.
Marketing emails: until you unsubscribe. We then keep a record that you unsubscribed, so we do not contact you again.
Website server logs: a short period set by our host, for security purposes.
Accounting records: as long as HMRC requires.
Your rights
You can ask us to do any of the following, free of charge, and we will respond within one month.
- See a copy of what we hold about you.
- Correct anything that is wrong or incomplete.
- Delete information, where we are not legally required to keep it. Clinical records are usually one of the exceptions.
- Restrict or object to how we use it.
- Receive it in a portable format.
- Withdraw consent, including for marketing or for the use of your photographs.
Email info@harmonymedical.uk to make any of these requests.
Cookies
A cookie is a small file stored by your browser. Our banner lets you accept or decline anything that is not essential.
- Essential cookies keep the site working and remember your cookie choice. These cannot be turned off.
- Nothing else is set unless you use the price list form, which is provided by Kit.
You can delete or block cookies in your browser settings. Blocking essential ones may stop parts of the site working.
Security
This website runs over an encrypted connection. Its administration is protected by login limits and regular backups.
Clinical records are held in encrypted storage with access limited to the people who need it.
If we suffered a breach affecting your rights, we would tell you and report it to the Information Commissioner’s Office within 72 hours.
Complaints
If you are unhappy with how we have handled your information, tell us first at info@harmonymedical.uk and we will look into it.
You also have the right to complain directly to the Information Commissioner’s Office at ico.org.uk, or by phone on 0303 123 1113.
Changes
We review this policy at least once a year, and whenever we change how we handle information. The date at the top shows when it was last reviewed.