Privacy Policy
Privacy Policy
Effective date: 21 July 2026
Version: 1.0
1. Introduction
F3 Optimising Health is committed to protecting the privacy, confidentiality and security of the personal information entrusted to us.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when individuals:
-
visit or use the F3 Optimising Health website;
-
contact us by telephone, email, website form, social media or another method;
-
enquire about, book or receive an F3 service;
-
attend a consultation, assessment, Health MOT or follow-up appointment;
-
undergo health screening, diagnostic testing or other clinical services arranged through F3;
-
purchase or pay for a service;
-
subscribe to communications or marketing;
-
provide feedback, reviews or testimonials; or
-
otherwise interact with F3 Optimising Health.
This policy also explains the rights individuals have in relation to their personal information.
We process personal information in accordance with applicable UK data protection and privacy legislation, including:
-
the UK General Data Protection Regulation;
-
the Data Protection Act 2018;
-
the Privacy and Electronic Communications Regulations 2003;
-
the Data (Use and Access) Act 2025; and
-
other applicable healthcare, professional, regulatory and confidentiality requirements.
2. Who we are
The F3 Optimising Health website and service are operated by:
F3 Optimising Health
Company number: 17392731
Registered office:
27–29 Ashley Road
Montpelier
Bristol
BS6 5NJ
F3 Optimising Health is the data controller responsible for determining how and why personal information covered by this policy is processed.
3. How to contact us
Questions about this Privacy Policy or the use of personal information should be directed to:
Data Protection Lead
F3 Optimising Health
27–29 Ashley Road
Montpelier
Bristol
BS6 5NJ
Telephone: 07349971991
Email: info@f3health.co.uk
Please mark correspondence concerning data protection as “Private and Confidential – Data Protection”.
4. The personal information we collect
The information we collect will depend on how an individual interacts with us and which services they request or receive.
4.1 Identity and contact information
We may collect:
-
full name;
-
title;
-
date of birth;
-
age;
-
sex;
-
gender, where relevant to care;
-
home address;
-
email address;
-
telephone number;
-
emergency contact details;
-
next-of-kin details;
-
preferred method of communication;
-
communication or accessibility requirements;
-
identification information where necessary to confirm identity; and
-
NHS number or other patient identifier where relevant.
4.2 Health and clinical information
Where an individual enquires about or receives health-related services, we may collect and process information concerning their physical or mental health.
This may include:
-
current and previous medical conditions;
-
symptoms and presenting concerns;
-
diagnoses;
-
medication and supplement use;
-
allergies and adverse reactions;
-
previous investigations, treatments and procedures;
-
family medical history;
-
immunisation history;
-
reproductive and sexual health information, where relevant;
-
mental health and emotional wellbeing information;
-
disability and accessibility information;
-
alcohol use, smoking status and substance-use information;
-
dietary habits;
-
physical activity and fitness information;
-
sleep information;
-
stress and lifestyle information;
-
height, weight, body composition, blood pressure and other measurements;
-
blood-test results and other diagnostic or screening results;
-
clinical photographs, where necessary and agreed;
-
consultation notes;
-
clinical correspondence;
-
treatment, lifestyle and health-optimisation plans;
-
referrals, prescriptions and recommendations;
-
correspondence with an individual’s GP or another healthcare professional;
-
appointment history;
-
consent decisions;
-
safeguarding information; and
-
other information that is reasonably required to provide safe and appropriate care.
Health information is treated as special-category personal data and is subject to additional safeguards.
4.3 Booking, account and service information
We may collect:
-
appointment requests;
-
booking dates and times;
-
services requested or received;
-
membership or package information;
-
consultation history;
-
cancellation and attendance information;
-
account login details, where an online account is provided;
-
records of telephone calls, emails and other communications;
-
enquiries and requests;
-
consent forms;
-
signed agreements;
-
feedback;
-
complaints; and
-
information about an individual’s preferences and requirements.
4.4 Payment and financial information
We may collect:
-
billing address;
-
payment status;
-
invoices;
-
transaction details;
-
refunds;
-
information required for accounting and taxation;
-
information about the person or organisation responsible for payment.
Further information about payment processing is provided in section 12.
4.5 Website and technical information
When an individual visits our website, certain information may be collected automatically, including:
-
internet protocol address;
-
browser type and version;
-
device type;
-
operating system;
-
approximate location derived from the internet connection;
-
referral source;
-
pages visited;
-
date and time of access;
-
time spent on pages;
-
links selected;
-
forms started or submitted;
-
website navigation information;
-
cookie identifiers;
-
error reports; and
-
security and diagnostic information.
Further information is provided in section 13, our separate Cookie Policy and the website’s cookie-consent controls.
4.6 Marketing and communication information
Where applicable, we may collect:
-
marketing preferences;
-
newsletter subscriptions;
-
event registrations;
-
communication preferences;
-
responses to campaigns;
-
interactions with emails;
-
social-media interactions; and
-
records of consent or withdrawal of consent.
Further information about marketing communications and opt-out rights is provided in section 14.
4.7 Feedback, reviews, photographs and testimonials
Where an individual voluntarily provides feedback, a review, photograph, video, case study or testimonial, we may process:
-
their name;
-
their image or voice;
-
the content of their feedback;
-
information about their experience of our service; and
-
health information included in their account.
We will obtain specific consent before publishing identifiable patient testimonials, images, recordings or case studies.
5. How we obtain personal information
We may obtain information:
-
directly from the individual;
-
from a parent, guardian, carer or authorised representative;
-
from an individual’s GP or another healthcare professional;
-
from a referring organisation;
-
from a hospital, clinic, pharmacy, laboratory or diagnostic provider;
-
from a private medical insurer;
-
from payment and booking providers;
-
through our website, cookies and analytics tools;
-
from publicly available sources;
-
from regulators, public authorities or safeguarding bodies; and
-
from another person where this is necessary to protect the individual or another person.
Where information is provided by someone acting on another individual’s behalf, we may ask for evidence of their authority to act.
We will not automatically access or combine an individual’s Supported Independence care records with their F3 clinical records merely because both services are operated by the same individual. Information will only be shared between the services where there is a lawful basis, a genuine need and appropriate confidentiality safeguards.
6. Why we use personal information
We may use personal information to:
-
respond to enquiries;
-
assess whether our services are suitable;
-
create and manage bookings;
-
verify identity;
-
provide consultations, assessments and clinical services;
-
understand an individual’s health, goals and concerns;
-
support diagnosis, treatment, prevention and health optimisation;
-
prepare personalised recommendations or care plans;
-
arrange blood tests, investigations, referrals or prescriptions;
-
communicate with GPs, laboratories, pharmacies and other healthcare professionals;
-
maintain complete and accurate clinical records;
-
manage patient safety and clinical risk;
-
identify and respond to safeguarding concerns;
-
manage emergencies;
-
process payments, invoices and refunds;
-
administer memberships, packages or service agreements;
-
communicate appointment reminders and important service information;
-
respond to complaints, concerns and feedback;
-
investigate incidents;
-
establish, exercise or defend legal claims;
-
comply with legal, professional, insurance and regulatory requirements;
-
maintain clinical and corporate governance;
-
audit and improve the quality, safety and effectiveness of our services;
-
train and supervise staff and healthcare professionals using appropriately protected information;
-
maintain website security and functionality;
-
understand how the website is used;
-
improve the website and user experience;
-
prevent fraud, misuse and cybercrime;
-
send marketing communications where permitted;
-
manage consent and communication preferences; and
-
protect the rights, property, safety and interests of individuals, F3 and others.
7. Our lawful bases for processing
The lawful basis used will depend on the information concerned and the reason it is being processed.
7.1 Contract
We may process personal information where this is necessary:
-
to take steps at an individual’s request before entering into a contract;
-
to arrange an appointment or service;
-
to provide a service the individual has requested;
-
to administer a membership or package;
-
to process payment; or
-
to fulfil our obligations under a service agreement.
7.2 Legal obligation
We may process information where necessary to comply with a legal or regulatory obligation, including obligations relating to:
-
clinical records;
-
safeguarding;
-
health and safety;
-
medicines;
-
taxation and accounting;
-
complaints;
-
insurance;
-
regulatory inspections;
-
professional standards; and
-
the prevention, detection or investigation of unlawful activity.
7.3 Legitimate interests
We may process information where this is necessary for our legitimate interests or those of another person, provided those interests are not overridden by the individual’s rights and freedoms.
These interests may include:
-
operating and administering F3;
-
responding to enquiries;
-
managing our relationship with patients and customers;
-
ensuring the safety and quality of our services;
-
maintaining appropriate clinical governance;
-
keeping accurate records;
-
improving our services;
-
protecting our systems and website;
-
preventing fraud or misuse;
-
responding to complaints;
-
managing legal claims; and
-
communicating with existing customers about closely related services where permitted.
Where we rely on legitimate interests, we will consider whether the processing is necessary and proportionate and whether it may have an unjustified effect on the individual.
7.4 Consent
We may rely on consent for activities such as:
-
sending certain electronic marketing communications;
-
using non-essential cookies;
-
publishing testimonials;
-
using identifiable photographs or recordings;
-
sharing information in circumstances where consent is the appropriate basis; or
-
processing optional information that is not necessary to provide the service.
Consent may be withdrawn at any time. Withdrawal will not affect the lawfulness of processing undertaken before consent was withdrawn. Further information about direct marketing is provided in section 14.
7.5 Vital interests
In an emergency, we may process or disclose information where this is necessary to protect someone’s life or prevent serious harm.
8. Special-category information
Health information and certain other sensitive information are classified as special-category personal data.
In addition to an applicable lawful basis under Article 6 of the UK GDPR, we will rely on an appropriate condition under Article 9. Depending on the circumstances, this may include processing that is necessary for:
-
the provision or management of health or social care;
-
medical diagnosis;
-
preventive or occupational medicine;
-
assessing an individual’s capacity for work;
-
protecting vital interests where the individual is incapable of giving consent;
-
establishing, exercising or defending legal claims;
-
reasons of substantial public interest, where authorised by law;
-
public-health purposes, where applicable; or
-
processing for which the individual has given explicit consent.
Clinical information will be processed by, or under the responsibility of, healthcare professionals or other individuals who are subject to professional, contractual or legal duties of confidentiality.
9. Clinical confidentiality
Information disclosed during a consultation or contained in a clinical record will be treated confidentially.
We may share relevant information with another healthcare professional where this is necessary for direct care, patient safety or continuity of care. Wherever appropriate, we will discuss this with the individual.
There may be circumstances in which information must be disclosed without consent, including where:
-
disclosure is required by law or court order;
-
there is a serious and immediate risk to the individual or another person;
-
there is a safeguarding concern;
-
disclosure is necessary to prevent or detect a serious crime;
-
a regulator has a lawful right to obtain the information; or
-
disclosure is otherwise justified in the public interest.
Any disclosure will be limited to information that is relevant and necessary.
10. Sharing information with other organisations
We do not sell personal information.
We may share information, where necessary and lawful, with:
-
healthcare professionals involved in an individual’s care;
-
the individual’s GP or NHS care provider;
-
private hospitals and clinics;
-
diagnostic laboratories and screening providers;
-
pharmacies and prescribing services;
-
clinical-record and practice-management system providers;
-
appointment and communication providers;
-
website-hosting and website-management providers;
-
secure email, cloud-storage and information-technology providers;
-
payment processors and banks;
-
accountants, auditors and financial advisers;
-
legal advisers;
-
consultants and contractors providing services on our behalf;
-
regulators and professional bodies;
-
the Care Quality Commission, where applicable;
-
the Information Commissioner’s Office;
-
safeguarding authorities;
-
commissioners and public authorities;
-
police, courts and other law-enforcement bodies; and
-
another organisation involved in a merger, restructuring, acquisition or transfer of the F3 service, subject to appropriate confidentiality protections.
Service providers acting on our behalf are required to process information only in accordance with our instructions, maintain confidentiality and implement appropriate security measures.
We will only disclose information that is reasonably necessary for the relevant purpose.
11. Sharing information with an individual’s GP
Where appropriate for safe and joined-up care, we may share relevant information about a consultation, test result, prescription or treatment with an individual’s registered GP. We will normally explain what information will be shared and why. Sections 9 and 10 explain the applicable confidentiality safeguards, other recipients and circumstances in which information may be disclosed without consent.
12. Payments
Payments may be processed by third-party payment providers.
Payment providers may collect card details, billing information, fraud-prevention information and other information required to complete the transaction. Their use of information will be governed by their own privacy terms.
We will generally retain transaction records, invoices and payment status but will not normally retain complete card numbers or card-security codes.
13. Cookies and website analytics
Our website may use cookies and similar technologies.
Some cookies are necessary for the operation, security and accessibility of the website. Other cookies, including analytics or marketing cookies, will only be used where the user has provided the required consent.
Cookies may be used to:
-
enable website functions;
-
remember preferences;
-
maintain website security;
-
understand website usage;
-
measure performance;
-
diagnose faults;
-
improve content; and
-
measure the effectiveness of communications.
Users can manage non-essential cookie preferences through the website’s cookie controls. They may also be able to block or delete cookies through their browser settings, although this may affect some website functions.
A separate Cookie Policy should identify the cookies and similar technologies used by the website, their providers, purposes and duration.
14. Direct marketing
We may send information about F3 services, events, health information or related services where:
-
the individual has consented;
-
the communication is permitted under applicable electronic-marketing rules; or
-
another lawful basis applies.
Marketing preferences can be changed at any time by:
-
using the unsubscribe facility in an email;
-
contacting us by email;
-
contacting us by telephone; or
-
writing to our Data Protection Lead.
Individuals have an absolute right to object to the use of their personal information for direct marketing.
When an individual opts out, we may retain limited information on a suppression list to ensure that further marketing is not sent to them.
Clinical and administrative communications, such as appointment reminders, test-result notifications, safety information or changes to a booked service, are not marketing communications.
15. International transfers
Some service providers may store or process personal information outside the United Kingdom.
Where personal information is transferred internationally, we will ensure that an appropriate lawful transfer mechanism and safeguards are in place. These may include:
-
transfer to a country covered by UK adequacy regulations;
-
the UK International Data Transfer Agreement;
-
the UK Addendum to approved standard contractual clauses;
-
another approved transfer mechanism; and
-
appropriate technical, contractual and organisational safeguards.
Further information about the safeguards applying to a particular transfer may be requested from our Data Protection Lead.
16. How long we keep personal information
We retain personal information only for as long as it is reasonably required for the purpose for which it was collected and to meet applicable legal, regulatory, professional, insurance and contractual requirements.
Retention periods may vary according to the nature of the information and the circumstances.
In general:
-
enquiry records that do not result in a service may normally be retained for up to two years after the last meaningful contact;
-
adult clinical records will normally be retained for at least eight years after the conclusion of treatment or the individual’s last attendance, and may be retained longer where required by law, professional guidance, insurance requirements or the circumstances of the care;
-
records concerning children or young people, where applicable, may be retained for longer in accordance with health-record retention requirements;
-
financial, invoice and taxation records will normally be retained for at least six years after the relevant financial period;
-
complaint, incident, safeguarding and legal-claim records may be retained for the applicable limitation period and for longer where the circumstances require;
-
marketing information will be retained until consent is withdrawn, the individual objects or it is no longer required;
-
suppression-list information may be retained to ensure that marketing preferences continue to be respected;
-
cookie information will be retained for the period identified in the Cookie Policy; and
-
website security and technical logs will be retained only for as long as necessary for security, investigation and system-management purposes.
At the end of the relevant retention period, information will be securely deleted, destroyed or anonymised unless continued retention is lawful and necessary.
17. Security
We use appropriate technical and organisational measures designed to protect personal information against:
-
unauthorised access;
-
accidental or unlawful disclosure;
-
loss;
-
destruction;
-
alteration;
-
misuse; and
-
other unlawful processing.
These measures may include:
-
access controls;
-
password protection;
-
multi-factor authentication;
-
encryption;
-
secure clinical-record systems;
-
secure backups;
-
device and network security;
-
confidentiality agreements;
-
staff training;
-
role-based access;
-
audit trails;
-
incident-response procedures;
-
supplier checks; and
-
physical security measures.
Access to health and clinical information is restricted to people who require it for their role.
Although we take reasonable steps to protect information, transmission over the internet cannot be guaranteed to be completely secure. Individuals should avoid including unnecessary or highly sensitive clinical information in ordinary email or unencrypted website messages.
18. Personal-data breaches
We maintain procedures for identifying, investigating and responding to suspected personal-data breaches.
Where required, we will report a breach to the Information Commissioner’s Office and inform affected individuals in accordance with applicable law.
19. Automated decision-making and profiling
We do not currently make decisions about individuals based solely on automated processing where the decision would have a legal or similarly significant effect.
We may use limited automated processes for administrative purposes, such as:
-
issuing appointment reminders;
-
confirming bookings;
-
identifying incomplete forms;
-
processing payments;
-
managing communication preferences; and
-
detecting potential website-security threats.
These processes do not replace clinical judgement.
Should we introduce significant automated decision-making in the future, we will provide appropriate information about the process, the information used, the likely consequences and the individual’s applicable rights.
20. Anonymised information, audit and service improvement
We may use information that has been anonymised so that individuals cannot reasonably be identified for:
-
service evaluation;
-
clinical audit;
-
quality improvement;
-
statistical analysis;
-
reporting;
-
training;
-
planning; and
-
research or development.
Information that has been effectively anonymised is not personal data.
We will not use identifiable patient information for an unrelated research project without an appropriate lawful basis, ethical and governance arrangements where required, and clear information being provided to the individual.
21. Children’s information
F3 services are primarily intended for adults unless a service for a child or young person has been expressly agreed.
Where we process information about a child or young person, we will take account of:
-
their age and understanding;
-
parental responsibility;
-
consent and capacity;
-
the child’s best interests;
-
safeguarding requirements; and
-
applicable healthcare and data-protection obligations.
A child or young person may have rights over their information independently of their parent or guardian, depending on their age, capacity and circumstances.
22. Information concerning other people
Where an individual provides information about another person, such as a family member, emergency contact or carer, they should ensure that they are authorised to provide that information and, where appropriate, that the other person is made aware of this Privacy Policy.
23. Providing personal information
Some information is required before we can safely or lawfully provide a service.
Where required information is not provided, we may be unable to:
-
assess whether the service is appropriate;
-
provide safe clinical advice;
-
arrange testing or treatment;
-
issue a prescription;
-
process a payment;
-
complete a booking; or
-
comply with our legal and professional responsibilities.
We will explain where information is mandatory and the likely consequences of not providing it.
24. Individual data-protection rights
Depending on the circumstances and the lawful basis relied upon, individuals may have the following rights.
24.1 Right to be informed
Individuals have the right to receive clear information about how their personal information is collected and used.
24.2 Right of access
Individuals may request:
-
confirmation of whether we process their personal information;
-
a copy of their personal information; and
-
supporting information about how it is used.
This is commonly known as a subject access request.
24.3 Right to rectification
Individuals may ask us to correct inaccurate personal information or complete information that is incomplete.
Clinical records will not normally be altered by deleting an original professional entry. Where appropriate, an amendment or explanatory note may be added so that the record remains complete and accurate.
24.4 Right to erasure
Individuals may ask us to erase their personal information in certain circumstances.
This right is not absolute. We may be required to retain information for clinical safety, legal compliance, professional accountability, safeguarding, public-interest reasons or legal claims.
24.5 Right to restriction
Individuals may ask us to restrict how their personal information is used in certain circumstances.
24.6 Right to data portability
In certain circumstances, individuals may request that personal information they provided to us is supplied in a structured, commonly used and machine-readable format or transmitted to another controller.
24.7 Right to object
Individuals may object to processing based on legitimate interests or certain other grounds.
We will consider the objection and stop the processing unless we have compelling legitimate grounds to continue or the information is required for legal claims.
The right to object to direct marketing is absolute.
24.8 Rights concerning automated decisions
Individuals have rights relating to certain decisions made solely by automated means that produce legal or similarly significant effects. Further information about our current use of automated processes is provided in section 19.
24.9 Right to withdraw consent
Where processing is based on consent, consent may be withdrawn at any time.
Withdrawal will not affect processing that was lawful before consent was withdrawn. In some circumstances, we may continue to retain or process information where another lawful basis applies.
25. Exercising data-protection rights
Requests should be sent to our Data Protection Lead using the contact details in section 3.
Individuals do not normally have to pay a fee to exercise their rights. We may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, where permitted by law.
We may request information to confirm identity and protect personal information from unauthorised disclosure.
Where someone makes a request on another person’s behalf, we may require evidence of their authority.
We will respond within the applicable statutory timeframe. Where a request is complex or involves multiple requests, the response period may be extended where legally permitted. We will inform the individual where this applies.
26. Complaints
Concerns about the use of personal information should initially be raised with our Data Protection Lead so that we have an opportunity to investigate and respond.
Individuals also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Further information and an online complaints service are available through the Information Commissioner’s Office website.
Making a complaint to us does not affect an individual’s right to complain to the Information Commissioner’s Office.
27. Third-party websites
Our website may contain links to websites, platforms or services operated by third parties.
We are not responsible for the privacy, content or security practices of third-party websites. Individuals should review the privacy information provided by the relevant third party before submitting personal information.
28. Changes to this Privacy Policy
We may amend this Privacy Policy to reflect:
-
changes to our services;
-
changes to the way we process information;
-
changes to our suppliers or systems;
-
legal or regulatory developments; or
-
changes to professional guidance.
The current version will be published on the F3 website and will state the date on which it became effective.
Where a change is material, we may take additional steps to bring it to the attention of affected individuals.
29. Document control
Policy owner: F3 Optimising Health
Service: F3 Optimising Health
Data controller: F3 Optimising Health
Version: 1.0
Effective date: 21 July 2026
Review date: July 2027, or earlier if required