top of page

Privacy Policy

Dr Kyprianou's Clinic: MigrAnna. Last updated: July 2026

​

1. Who We Are

MigrAnna ("we", "us", "our") is a private headache and migraine clinic providing diagnostic and treatment services. We are the data controller for the personal and health information we collect from you.

  • Registered address: Unit 10 Silver End Business Park, Brettell Lane, Brierley Hill, West Midlands, England, DY5 3LG

  • Contact email: book.dr.kyprianou@gmail.com

  • Data Protection Officer (if applicable): Thomas Ambler book.dr.kyprianou@gmail.com

If you have any questions about this policy or how we handle your data, please contact us using the details above.

​

2. Information We Collect

We collect only the information necessary to provide safe, effective care:

  • Identity and contact details: name, date of birth, address, phone number, email address.

  • Health information: headache/migraine history, symptoms, triggers, medication history, diagnostic test results, imaging reports, treatment plans, clinical notes, and correspondence with other healthcare providers (e.g. GP, neurologist).

  • Appointment and administrative data: booking details, attendance records, invoices and payment information.

  • Communications: emails, messages, or call notes relating to your care.

  • Technical data (if you use our website or online booking system): Browser type, and cookie data, used only to operate and secure the site.

We do not collect more information than we need, and we do not use your data for marketing.

​

3. How We Use Your Information

We use your information to:

  • Assess, diagnose, and treat your headache or migraine condition.

  • Communicate with you about appointments, results, and ongoing care.

  • Coordinate care with other healthcare professionals involved in your treatment, only with your knowledge and, where required, your consent.

  • Maintain accurate clinical records as required by professional and legal obligations.

  • Process payments and manage billing.

  • Meet our legal, regulatory, and insurance obligations.

  • Improve our services (using anonymised or aggregated data only, wherever possible).

​

4. Our Legal Basis for Processing

Under UK GDPR and the Data Protection Act 2018, we rely on:

  • Consent — for elective treatments, sharing information with third parties, and any marketing communications.

  • Contract — to provide the clinical services you have booked.

  • Legal obligation — for record-keeping, safeguarding, and regulatory reporting.

  • Vital interests — in rare emergency situations where sharing information is necessary to protect your life or someone else's.

Health data is "special category data" under data protection law. We only process it where we have your explicit consent, or where processing is necessary for the provision of health care by, or under the responsibility of, a health professional.

​

5. Consent and Sharing Your Information

We do not share your personal or health information with any third party without your consent, except in the limited circumstances described below.

We may share information:

  • With other healthcare professionals directly involved in your care (e.g. your GP), only where you have agreed to this or it is necessary for continuity of your treatment and you have been informed.

  • With third-party providers who support our clinic operations (e.g. secure IT hosting, billing services), under strict data processing agreements that require them to protect your data and use it only as we instruct.

  • Where required by law, court order, or to protect against an imminent risk to life or safety.

  • In an anonymised or aggregated form that cannot identify you, for research or service improvement.

You can withdraw consent to non-essential sharing at any time by contacting us. This will not affect the lawfulness of any processing carried out before you withdrew it.

We never sell your personal data.

​

6. How We Protect Your Information

We take the security of your data seriously and apply the following safeguards:

  • Two-factor authentication (2FA) is required for all staff access to systems holding patient records and clinical data.

  • Encryption of data both in transit and at rest.

  • Role-based access controls, so staff can only view the information necessary for their role.

  • Audit logging of access to clinical records.

  • Regular security reviews and staff training on data protection and confidentiality.

  • Secure, access-controlled premises for any physical records.

  • Data processing agreements with any third-party suppliers who handle data on our behalf, requiring equivalent security standards.

While we take every reasonable step to protect your information, no system can be guaranteed 100% secure. We will notify you and, where required, the Information Commissioner's Office (ICO), promptly in the event of a data breach affecting your personal data.

​

7. How Long We Keep Your Information

We retain clinical records in line with professional and regulatory guidance (typically a minimum of 8 years for adult patients, longer for children, or as otherwise required by law or our regulating body). Administrative and billing records are retained only as long as necessary for tax, legal, and accounting purposes, after which they are securely deleted or anonymised.

​

8. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.

  • Rectify inaccurate or incomplete data.

  • Erasure of your data, where legally possible (note: clinical record-keeping obligations may limit this).

  • Restrict or object to certain processing.

  • Data portability, where technically feasible.

  • Withdraw consent at any time, without affecting past lawful processing.

  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.

To exercise any of these rights, contact us at book.dr.kyprianou@gmail.com. We will respond within one month, as required by law.

​

9. Cookies (Website)

If you interact with our website or online booking portal, we may use essential cookies to keep the site secure and functioning. We do not use tracking or advertising cookies.

​

10. Children's Information

Where we treat patients under 18, we collect only the information necessary for their care and obtain consent from a parent or legal guardian where required, in line with relevant guidance on children's capacity to consent.

​

11. Changes to This Policy

We may update this policy from time to time to reflect changes in law or our practices. The latest version will always be available at www.drkatykyprianou.com/privacypolicy, with the date of last update shown at the top.

​

12. Contact Us

If you have questions, concerns, or wish to exercise your data protection rights, please contact: MigrAnna, Unit 10 Silver End Business Park, Brettell Lane, Brierley Hill, West Midlands, England, DY5 3LG, book.dr.kyprianou@gmail.com

You can also contact the ICO, the UK's independent regulator for data protection, at ico.org.uk or on 0303 123 1113.

bottom of page