Privacy Policy

Practice: JTG Medical Ltd
Policy owner: Director / Practice Lead
Version: 2.0
Effective date: 3rd September 2026

1. Purpose

JTG Medical Ltd is committed to protecting personal information and maintaining the confidentiality of patients, prospective patients, professional contacts and business information.

This policy explains how the practice manages personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable professional confidentiality requirements.

It is proportionate to the practice's structure and reflects that the practice does not operate its own standalone electronic clinical record or payment system.

2. Who we are

JTG Medical Ltd is the private practice of Miss Jana Torres Grau, Consultant Paediatric Surgeon. The practice is the data controller for the information described in this policy.

  • Practice: JTG Medical Ltd
  • Registered in England and Wales: company number 15054002
  • Registered office: 2 St Marys Road, Tonbridge, Kent, England, TN9 2LB
  • Correspondence address: Evelina London Children's Hospital, St Thomas' Hospital, Westminster Bridge Road, London SE1 7EH
  • Email: team@janatorresgrau.com
  • ICO registration number: ZC217684

Miss Jana Torres Grau is the person responsible for data protection within the practice, and can be contacted using the details above.

3. Scope

This policy applies to personal information processed by JTG Medical Ltd, including:

  • enquiries received through the practice website or initial enquiry email;
  • correspondence with patients and prospective patients;
  • administrative and financial information;
  • invoices and accounting records;
  • the practice's Google Business Profile and associated activity;
  • information processed through third-party providers on behalf of the practice.

4. Clinical records

JTG Medical Ltd does not maintain a separate standalone electronic clinical record system.

Clinical information relating to patients receiving treatment through the hospital is recorded and maintained within the hospital's clinical information systems. Hospital appointments and payments relating to treatment are managed in the same way.

Access to these systems is provided to authorised members of the hospital medical team, according to the hospital's own access-control and information-governance procedures. Those records are subject to the hospital's own retention arrangements.

Where clinical information is received independently by the practice, it is handled confidentially and transferred to the appropriate clinical record or hospital system where required. The practice does not create duplicate clinical records unnecessarily.

If you wish to see or correct your clinical records, the request will usually need to be directed to the relevant hospital organisation. We are happy to help you identify the right team.

5. Initial enquiries

Initial enquiries may be received through the practice website or the practice's initial enquiry email service.

At this stage we ask only for the information reasonably necessary to respond to your enquiry. This is normally a name, contact details and a short description of the reason for getting in touch.

The website contact form and initial enquiry email are ordinary email services, and are not designed for detailed medical histories or highly sensitive clinical information. Where clinical information is required, we will direct you towards an appropriate secure communication route or hospital system.

6. Email

The practice uses its hosted email service for initial administrative enquiries. NHSmail is used for appropriate medical correspondence where required.

Sensitive clinical information is communicated using NHSmail or another appropriately secure method rather than the ordinary website or initial enquiry email. Email addresses are checked carefully before confidential information is sent.

7. Data protection principles

JTG Medical Ltd complies with the principles of UK GDPR by ensuring that personal information is:

  • processed lawfully, fairly and transparently;
  • collected for specified and legitimate purposes;
  • adequate, relevant and limited to what is necessary;
  • accurate and kept up to date where necessary;
  • retained only for as long as necessary;
  • protected against unauthorised or unlawful processing, loss, destruction or damage.

8. Lawful processing

The practice identifies an appropriate lawful basis before processing personal information. Depending on the circumstances, this may include:

  • taking steps at your request before entering into a contract;
  • performance of a contract;
  • compliance with a legal obligation, such as tax and accounting requirements;
  • legitimate interests, for example responding to an enquiry or dealing with a complaint;
  • consent, for example for non-essential cookies;
  • the provision or management of healthcare, where applicable.

Where special category health information is processed, an appropriate condition under Article 9 of the UK GDPR is also identified. This is normally the provision of health care by a health professional bound by a duty of confidentiality, or the establishment or defence of legal claims.

Where processing relies on your consent, you may withdraw that consent at any time.

9. Children and young people

This is a paediatric practice, and most patients are children.

In most cases a parent or legal guardian will contact the practice and provide information on the child's behalf. Where a young person is able to make their own decisions about their care, that will be respected, in line with normal clinical practice and the hospital's arrangements.

Information relating to children is handled with the same care and confidentiality as all other patient information.

10. Data sharing

Personal information may be shared with:

  • the relevant hospital and authorised hospital medical team;
  • healthcare professionals involved in a patient's care;
  • professional advisers where necessary;
  • insurers or legal advisers where appropriate;
  • IT, website or other service providers where necessary;
  • public authorities where legally required.

Information is only shared where there is an appropriate lawful basis and where the disclosure is proportionate. The practice does not sell personal information.

11. Data processors

Where third-party organisations process personal information on behalf of JTG Medical Ltd, appropriate contractual arrangements are considered. Relevant suppliers include website hosting, email and other technical service providers.

The practice takes reasonable steps to ensure that suppliers provide appropriate security for personal information.

Some suppliers may store or process information outside the United Kingdom. Where this happens, the practice relies on an approved safeguard, such as an adequacy decision or the UK International Data Transfer Addendum, so that the information continues to receive an equivalent level of protection.

12. Website information and cookies

Information submitted through the website is retained only for as long as necessary for the purpose for which it was collected.

Cookies are small files placed on your device. Some are necessary for the website to function. Others, such as analytics cookies, are only used where you have given permission through the cookie banner, and that permission can be changed at any time.

Further detail is set out in our cookie policy.

Website technical logs and analytics information may be retained according to the relevant provider's settings and the practice's legitimate requirements.

13. Google Business Profile

Information associated with the practice's Google Business Profile, including reviews and business communications, may be retained as part of normal marketing and business administration.

Patient-identifiable information is not published in reviews, responses or other public content.

14. Retention

The practice seeks to retain information for no longer than necessary, while complying with legal, regulatory, professional and accounting requirements.

Information received through the website or initial enquiry email is retained only for as long as necessary to respond to the enquiry, arrange appropriate onward contact or referral, maintain an appropriate administrative record, and meet any applicable legal requirement. Where an enquiry does not result in treatment, unnecessary personal or clinical information is not retained indefinitely.

Relevant business and patient correspondence may need to be retained where it forms part of the administrative record. Routine or duplicate correspondence that is no longer required is deleted securely.

Invoices and financial records are retained for the period required by applicable tax, accounting and company-law requirements.

Clinical records held within hospital systems are retained under the hospital's own records-management arrangements.

Information is not destroyed where there is a legitimate reason to retain it, including an ongoing complaint, legal proceedings, an insurance matter, an investigation or a regulatory requirement.

15. Secure disposal

When information is no longer required, it is securely deleted or destroyed. Confidential paper information is shredded or disposed of through an appropriate confidential-waste service. Electronic information is deleted using appropriate methods, taking account of backups and the capabilities of the relevant system.

16. Data security

The practice implements appropriate technical and organisational measures to protect information. These include:

  • password protection;
  • secure email arrangements;
  • appropriate device security;
  • restricted access;
  • secure website hosting;
  • secure disposal of confidential information;
  • minimisation of information held outside hospital systems;
  • appropriate management of third-party suppliers.

No method of internet transmission or electronic storage is completely secure, but the practice takes reasonable and proportionate steps to protect the information it holds.

17. Data breaches

Any suspected loss, unauthorised disclosure, unauthorised access or other personal data breach is reported promptly to the Director / Practice Lead and assessed.

Where a breach is likely to result in a risk to individuals' rights and freedoms, notification is made to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of the practice becoming aware of it. Where a breach is likely to result in a high risk to an individual, that individual is informed where required by law.

Where an incident relates to hospital-controlled systems, it is reported through the hospital's own information-governance or incident-reporting process.

18. Automated decision-making

The practice does not use automated decision-making or profiling.

19. Your rights

Individuals have rights under UK GDPR, subject to applicable exemptions. These may include rights to:

  • access personal information held about you;
  • request correction of inaccurate or incomplete information;
  • request erasure in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing in certain circumstances;
  • data portability where applicable;
  • withdraw consent where processing relies on consent.

Requests are considered and handled in accordance with applicable legal requirements, and we will normally respond within one month. Where information is held within a hospital's clinical system, requests relating to those records may need to be directed to the relevant hospital organisation.

To make a request, please contact us using the details in section 21.

20. Concerns and complaints

If you have a concern about how the practice has handled your information, please contact us first so that we can look into it.

You also have the right to raise the matter with the Information Commissioner's Office, the UK regulator for data protection.

  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
  • Helpline: 0303 123 1113
  • ico.org.uk/make-a-complaint

21. Contact

For any question about this policy, or to exercise any of your rights, please contact:

  • Email: team@janatorresgrau.com
  • Post: JTG Medical Ltd, Evelina London Children's Hospital, St Thomas' Hospital, Westminster Bridge Road, London SE1 7EH
  • Contact form: Contact page

22. Review

This policy is reviewed at least annually, or following a significant change to the practice's systems, services or data-processing activities.