1. Who we are
Metovia is a private medical practice operated by Dr Anzal Qurbain MBBS BSc(Hons) MBA FFPM (GMC registration number 4369286). For the purposes of UK data protection law, Dr Anzal Qurbain is the data controller.
Contact: hello@metovia.co.uk | metovia.co.uk
2. What data we collect
We collect the following categories of personal data:
- Identity data: name, date of birth, sex
- Contact data: email address, phone number, postal address
- Health data: medical history, symptoms, medications, test results, consultation notes, prescriptions
- Financial data: payment records (payment card details are processed by our payment provider and not stored by us)
- Technical data: IP address, browser type, pages visited (for website analytics)
- Communications: enquiry messages and correspondence
3. Legal basis for processing
We process your personal data on the following legal bases under UK GDPR:
- Contract: to provide the medical services you have requested
- Legal obligation: to comply with our obligations under the GMC, CQC, and other regulatory bodies
- Vital interests: where necessary to protect your life or health in an emergency
- Legitimate interests: to operate and improve our service, and for fraud prevention
- Consent: for marketing communications (you may withdraw consent at any time)
For special category health data, we rely on Article 9(2)(h) UK GDPR (processing necessary for the provision of health care or treatment).
4. How we use your data
- To provide medical consultations, diagnoses and treatment
- To issue prescriptions and referral letters
- To maintain your medical record
- To contact you about appointments and follow-up care
- To comply with GMC, CQC and other regulatory requirements
- To process payments
- To respond to your enquiries
5. Sharing your data
We do not sell your personal data. We may share data with:
- Your NHS GP: with your consent, we will write to your GP to keep them informed of your care (this is GMC best practice)
- Other specialists: if we refer you for specialist care or investigations
- Laboratory services: to process blood tests and investigations
- Pharmacy: to dispense prescriptions
- Regulatory bodies: where we are legally required to disclose (e.g. GMC, CQC, MHRA)
- IT and hosting providers: who process data on our behalf under strict data processing agreements
6. Data retention
We retain medical records in accordance with NHS and medico-legal guidance — typically a minimum of 8 years from the date of last treatment for adults, or until age 25 for records created when the patient was a child. Financial records are retained for 7 years. Enquiries not resulting in a consultation are deleted after 12 months.
7. Your rights
Under UK GDPR you have the right to:
- Access your personal data (subject access request)
- Correct inaccurate data
- Request erasure (where legally permissible — note medical records cannot always be deleted)
- Object to processing
- Data portability
- Withdraw consent for marketing at any time
To exercise any of these rights, contact us at hello@metovia.co.uk. We will respond within one calendar month.
8. Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113.
9. Cookies
Our website uses essential cookies for functionality only. We do not use advertising or tracking cookies. We use basic server-side analytics (access logs) to understand website usage. No third-party analytics scripts are loaded without your consent.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified on our website. The date at the top of this page shows when it was last updated.