1. Introduction
This Privacy Policy explains how Dr Jacob Ali Ranjbar, trading as "Dr Ranjbar" ("we," "us," "our"), collects, uses, stores, and protects your personal data when you use our website at drranjbar.com (the "Website"), book or receive treatments, or otherwise interact with us.
We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data Controller
The data controller responsible for your personal data is:
- Name: Dr Jacob Ali Ranjbar (trading as Dr Ranjbar)
- Address: [ADDRESS TO BE CONFIRMED]
- Email: privacy@drranjbar.com
- Phone: [PHONE TO BE CONFIRMED]
- ICO Registration Number: [ICO REGISTRATION PENDING]
3. Personal Data We Collect
We collect and process the following categories of personal data:
Identity and Contact Data
- Full name, date of birth, email address, phone number, postal address
- Lawful basis: Performance of a contract (to provide treatments you have booked) and legitimate interests (to communicate with you about your care)
Account Data
- Account credentials and authentication data managed through our authentication provider (Clerk)
- Lawful basis: Performance of a contract (to provide you with a user account as part of our service)
Medical and Health Data (Special Category Data)
- Medical history, current medications, allergies, skin conditions, treatment notes, consultation records, consent forms
- Lawful basis: Explicit consent (Article 9(2)(a) UK GDPR). You provide this consent when completing our medical consultation and consent forms. You may withdraw consent at any time before treatment begins, though withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Treatment Records and Images
- Before-and-after photographs, treatment plans, session records, clinical notes
- Lawful basis: Explicit consent (for photographs) and legitimate interests (for clinical records necessary to provide safe, consistent treatment)
Financial and Transaction Data
- Payment card details are processed directly by Stripe and are not stored on our systems. We retain records of transaction amounts, dates, and booking references.
- Lawful basis: Performance of a contract (to process payments for services) and legal obligation (HMRC record-keeping requirements)
Appointment Data
- Booking dates, times, treatment types, cancellation records
- Lawful basis: Performance of a contract
Communications Data
- Messages exchanged through our website chatbot, emails, and other correspondence
- Lawful basis: Legitimate interests (to respond to your enquiries and improve our services). The chatbot provides general information only and does not provide medical advice.
4. How We Use Your Data
We use your personal data for the following purposes:
- To provide, manage, and administer aesthetic treatments you have booked
- To process payments and issue invoices or receipts
- To maintain accurate clinical records for your safety and continuity of care
- To communicate with you about appointments, treatment plans, and aftercare
- To comply with our legal and regulatory obligations
- To respond to your enquiries and provide customer support
- To improve our services and Website
- To enforce our Terms and Conditions and protect our legal rights
5. Third-Party Data Processors
We use the following third-party service providers who process your data on our behalf. Each operates under a data processing agreement with us:
| Provider | Purpose | Data Processed | Location |
|---|
| Clerk (Clerk, Inc.) | User authentication and account management | Name, email, account credentials, session data | United States |
| Stripe (Stripe, Inc.) | Payment processing | Payment card details (not stored by us), transaction records | United States |
| Brevo (Brevo SAS) | Transactional emails (appointment confirmations, reminders) | Name, email address | France (EU), with sub-processors in the US and India |
| MinIO (self-hosted) | Secure file storage (treatment photos, consent forms) | Treatment images, signed consent documents | United Kingdom (hosted on our own infrastructure) |
We do not sell your personal data to any third party.
6. International Data Transfers
Some of our third-party processors are based in the United States. Where your data is transferred outside the United Kingdom, we ensure adequate protection through one or more of the following mechanisms:
- UK-US Data Bridge: Both Stripe and Clerk are certified under the EU-US Data Privacy Framework and its UK Extension (the UK-US Data Bridge), which has been recognised by the UK Government as providing adequate protection for personal data transfers since 12 October 2023.
- UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses: Where the Data Privacy Framework does not apply, we rely on the UK IDTA or the UK Addendum to the EU SCCs, as approved by the ICO.
- Data Processing Agreements: All processors are contractually bound to process data only on our instructions and to implement appropriate technical and organisational security measures.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected:
| Data Category | Retention Period | Reason |
|---|
| Medical and treatment records | 8 years from last treatment | UK clinical records guidance; limitation period for personal injury claims |
| Financial and transaction records | 6 years from the transaction | HMRC requirements |
| Account data | Duration of your account plus 2 years | To allow reactivation and resolve any outstanding matters |
| Before-and-after photographs | 8 years from last treatment, or until consent is withdrawn (whichever is sooner) | Clinical records guidance; consent-dependent |
| Chatbot conversations | 12 months | Service improvement |
| Consent form records | 8 years from last treatment | Evidential purposes aligned with clinical records retention |
After the applicable retention period, data is securely deleted or anonymised.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you (Subject Access Request). We will respond within 30 days.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You can request deletion of your data in certain circumstances. Please note that we may be unable to delete medical records during the retention period where retention is necessary for legal or regulatory compliance.
- Right to restrict processing: You can ask us to limit how we use your data in certain circumstances.
- Right to data portability: You can request your data in a structured, commonly used, machine-readable format.
- Right to object: You can object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent (e.g., medical data, photographs), you may withdraw consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at: privacy@drranjbar.com
We will respond to all valid requests within one calendar month. In complex cases, we may extend this by a further two months, and we will notify you if this is the case.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication through Clerk with session management and password hashing
- Payment data handled exclusively by Stripe (PCI DSS Level 1 certified); we never store card details
- Treatment photographs and consent forms stored on self-hosted, encrypted infrastructure within the United Kingdom
- Access to personal data restricted to authorised personnel only
- Regular review of security measures
10. Cookies
Our Website uses cookies for essential functions including authentication and payment processing. For full details of the cookies we use and how to manage them, please see our Cookie Policy.
11. Children
Our services are available only to individuals aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a person under 18, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when it was last updated. Where changes are significant, we will notify you by email or by prominent notice on our Website.
13. Contact Us
For any questions about this Privacy Policy or how we handle your personal data:
- Email: privacy@drranjbar.com
- Post: [ADDRESS TO BE CONFIRMED]
- Phone: [PHONE TO BE CONFIRMED]