Privacy & Cookie Policy for Phoenix Mental Health Services LLP
Policy Reference Number 8.1 – June 2026
1. Introduction
Phoenix Mental Health Services (Phoenix MHS) is committed to safeguarding your personal information and ensuring your privacy. This Privacy & Cookie Policy explains how we collect, use, and protect your personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and our common law duty of confidentiality. By using our website, you consent to the practices described in this policy.
2. Who We Are
Phoenix Mental Health Services LLP
Website: https://phoenix-mhs.com
Email: enquiries@phoenix-mhs.com
Phone: 0370 162 0673
3. Information We Collect
Depending on your relationship with us, we may collect the following types of information:
- Personal details (e.g., name, address, contact information)
- Health and care information (e.g., diagnoses, prescriptions, referrals)
- GP and referrer details
- Emergency contact or carer information
- Consent preferences and communication history
- Through our website enquiry forms
- Through feedback forms and surveys
- Through partner pharmacies where required for prescribing
- Through insurance providers where applicable
4. How We Collect Your Data
We collect personal data in the following ways:
- When you are referred to us by the NHS, your GP, or another healthcare provider
- When you contact us directly (via email, phone, or online form)
- Through electronic systems (e.g., Carebit and ThinkDivergent)
- When you complete digital forms or attend consultations
5. How We Use Your Data
We use the data we collect for the following purposes:
- To provide safe and effective mental health assessments and treatments
- To communicate with you regarding your care
- To send reports to your GP, referrer, or insurance provider for funding purposes
- To fulfill NHS contractual obligations
- To process prescriptions and medication requests
- To obtain feedback about our services
- To comply with legal, regulatory and safeguarding obligations
- To investigate complaints and incidents
- To maintain medical records in compliance with legal requirements
6. Lawful Basis for Processing Your Data
Under the UK GDPR, we process your personal data based on the following lawful grounds:
- Article 6(1)(e) – Processing necessary for the performance of a task carried out in the public interest (healthcare)
- Article 9(2)(h) – Processing necessary for the provision of health or social care under the common law duty of confidentiality, with implied consent for care delivery and explicit consent for sharing non-direct care information (e.g., with carers)
- International Transfers: We primarily store and process data within the UK. Where any supplier uses cloud infrastructure that may involve processing outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including adequacy regulations or approved contractual clauses where required.
7. Data Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy and in accordance with our legal and regulatory obligations. For health-related data, we retain records in compliance with the NHS Records Management Code of Practice. If your data is no longer required, it will be securely deleted.
8. Sharing Your Information
We may share your personal data in the following situations:
- With your GP, referrer, or other healthcare providers who are directly involved in your care
- With approved IT service providers to support the management of your care
- With other professionals or clinicians who are involved in providing your treatment, such as pharmacists, prescribers, or psychologists
- Partner pharmacies for prescription processing and dispensing
- Professional advisers, insurers and regulatory bodies where required
- IT support providers who may access systems under strict confidentiality arrangements
- MEDSU for patient feedback collection and complaint management support where applicable
- With other services where you have given explicit consent
- Debt recovery (rare occurrence): In very rare cases, where payments for services rendered have not been made. This is generally only necessary in situations where insurance companies have failed to pay their portion of fees following treatment, despite our efforts to resolve the issue. Such actions are taken only when absolutely necessary.
We do not share your data for marketing or commercial purposes. All third-party providers are subject to appropriate contractual, confidentiality and data protection obligations.
9. National Data Opt-Out
Phoenix Mental Health Services does not currently share data for planning or research purposes. Should this change, we will comply with the National Data Opt-Out policies, which give you the option to opt-out of having your data used for these purposes. For more information, please visit NHS Data Opt-Out. We do have a policy available, which you can request via email to enquiries@phoenix-mhs.com.
10. How We Protect Your Data
We take your data security seriously. All data is stored securely using cloud-based platforms (such as Carebit and AWS), and encryption is applied to protect it. We use role-based access controls, encryption of data in transit and at rest where appropriate, multi-factor authentication where available, audit logging, secure cloud hosting and regular staff training in data protection and cyber security.
We do not use paper records. Any physical or digital data that is no longer required will be securely deleted in line with the NHS Records Management Code of Practice.
11. Your Rights
Under the UK GDPR, you have several rights in relation to your personal data:
- The right to access the personal data we hold about you
- The right to request the correction of any inaccurate or incomplete data
- The right to request data portability (in certain circumstances)
- The right to withdraw consent where consent is the legal basis for processing
- The right to request restriction of processing in certain circumstances
- The right to object to processing in certain circumstances.
- The right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we are not complying with data protection laws. You can contact the ICO at www.ico.org.uk.
To exercise any of these rights, please contact us at the details provided below.
Subject Access Requests will normally be responded to within one month unless an extension is permitted under data protection legislation.
12. Cookies
We use cookies to enhance your experience on our website. Cookies help us understand how you use our site, which in turn allows us to improve its functionality. You can manage or disable cookies through your browser settings, but please note that some features of the website may not function properly without cookies.
For detailed information about the cookies we use and how you can control them, please request a copy of our cookie policy.
13. Contact Us
If you have any questions or concerns regarding how we process your data, or if you wish to exercise any of your rights outlined in this policy, please contact us at:
Data Protection Officer: Jasmin Samuel
Email: enquiries@phoenix-mhs.com
Phone: 0370 162 0673
