Privacy Policy

Kriniko Medical Aesthetics Ltd
Website: https://kriniko.co.uk/
Last Updated: 20 June 2026

1. Introduction

Kriniko Medical Aesthetics Ltd (“we”, “our”, “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information when you visit our website, contact us, book consultations or treatments, purchase services, or otherwise interact with us.

We process personal information in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • Applicable healthcare and professional record-keeping requirements

By using our website or services, you acknowledge that you have read and understood this Privacy Policy.


2. Data Controller

Kriniko Medical Aesthetics Ltd is the Data Controller responsible for your personal information.

Contact Details

Kriniko Medical Aesthetics Ltd
1010 Cambourne Business Park
Great Cambourne
Cambourne
Cambridge
CB23 6DP

Email: clinic@kriniko.co.uk

WhatsApp/Text: 07775 809133

Landline: 01223 459251

Website: https://kriniko.co.uk/


3. Information We Collect

We may collect and process the following categories of personal information:

Identity Information

  • Full name
  • Date of birth
  • Gender
  • Photographic identification where required

Contact Information

  • Postal address
  • Email address
  • Telephone number
  • WhatsApp contact details

Medical and Health Information

For consultations and treatments we may collect:

  • Medical history
  • Health conditions
  • Medications
  • Allergies
  • Treatment history
  • Lifestyle information relevant to treatment suitability
  • Clinical notes
  • Consultation records
  • Treatment records

This information is classified as Special Category Data under UK GDPR.

Clinical Photography

We may take photographs before, during, and after treatment for:

  • Medical assessment
  • Treatment planning
  • Clinical records
  • Monitoring treatment outcomes

Marketing use of photographs will only occur with your separate written consent.

Financial Information

  • Payment details
  • Transaction history
  • Billing information

We do not store complete payment card details.

Website Usage Information

When you visit our website we may collect:

  • IP address
  • Browser type
  • Device information
  • Pages visited
  • Time spent on pages
  • Referral source
  • Cookie information

4. How We Collect Information

We collect information:

  • Directly from you
  • Through online enquiry forms
  • Through consultation forms
  • Through medical questionnaires
  • Through treatment consent forms
  • Through telephone conversations
  • Through WhatsApp communications
  • Through email correspondence
  • Through website analytics
  • Through cookies and similar technologies

5. Lawful Basis for Processing

Under UK GDPR, we rely on the following lawful bases:

Contract

Processing necessary to:

  • Arrange consultations
  • Provide treatments
  • Manage bookings
  • Process payments

Legal Obligation

Processing necessary to:

  • Maintain healthcare records
  • Meet regulatory requirements
  • Comply with taxation and accounting laws

Legitimate Interests

Processing necessary to:

  • Improve our services
  • Prevent fraud
  • Protect our business
  • Manage customer relationships

Consent

We rely on consent for:

  • Marketing communications
  • Certain cookies
  • Use of clinical photographs for marketing
  • Optional surveys and feedback

Healthcare and Special Category Data

Medical information is processed under Article 9 UK GDPR where necessary for:

  • Healthcare provision
  • Medical assessment
  • Treatment planning
  • Patient safety
  • Clinical record keeping

6. How We Use Your Information

We may use your information to:

  • Respond to enquiries
  • Book appointments
  • Deliver consultations and treatments
  • Assess suitability for treatments
  • Maintain treatment records
  • Monitor treatment outcomes
  • Process payments
  • Manage complaints
  • Improve our services
  • Comply with legal obligations
  • Communicate important treatment information
  • Send marketing communications where consent has been provided

7. Marketing Communications

We may send information regarding:

  • New treatments
  • Special offers
  • Clinic news
  • Educational content

You will only receive marketing communications where:

  • You have provided consent; or
  • We are legally permitted to contact you.

You may unsubscribe at any time by:


8. Clinical Photographs

Clinical photographs may be taken as part of your treatment record.

These images may be used for:

  • Treatment planning
  • Monitoring results
  • Medical records
  • Insurance purposes

Images used for:

  • Website content
  • Social media
  • Marketing materials
  • Educational presentations

will only be used with your explicit written consent.

You may withdraw this consent at any time, although materials already published may not always be removable.


9. Sharing Your Information

We do not sell personal information.

We may share information with:

Professional Service Providers

  • IT providers
  • Website hosting providers
  • Booking software providers
  • Payment processors
  • Accountants
  • Legal advisers

Healthcare Professionals

Where necessary for your care:

  • Prescribing practitioners
  • Medical professionals
  • Emergency healthcare providers

Regulatory Authorities

Where required by law, including:

  • Courts
  • HMRC
  • Law enforcement agencies
  • Regulatory bodies

All third parties are required to protect your information and process it lawfully.


10. International Transfers

Some service providers may process information outside the United Kingdom.

Where this occurs, we ensure appropriate safeguards are in place including:

  • UK adequacy regulations
  • International Data Transfer Agreements (IDTAs)
  • Standard Contractual Clauses

11. Data Security

We implement appropriate technical and organisational measures to protect personal information, including:

  • Secure systems
  • Password protection
  • Restricted staff access
  • Encrypted communications where appropriate
  • Secure storage of records
  • Staff confidentiality obligations

While we take reasonable steps to protect information, no internet transmission can be guaranteed completely secure.


12. Data Retention

We retain information only as long as necessary.

Typical retention periods include:

Medical Records

Up to 8 years after your last treatment or longer where professional obligations require.

Financial Records

Minimum 6 years for tax and accounting purposes.

Marketing Records

Until consent is withdrawn or records become inactive.

Retention periods may vary depending on legal, regulatory, insurance, or clinical requirements.


13. Your Rights

Under UK GDPR you have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request erasure of information where applicable
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent
  • Lodge a complaint

Requests should be submitted to:

clinic@kriniko.co.uk

We may require proof of identity before responding.


14. Cookies

Our website may use cookies to:

  • Ensure website functionality
  • Improve user experience
  • Analyse website traffic
  • Support security

You can control cookies through your browser settings.

A separate Cookie Policy may provide further details.


15. Third-Party Websites

Our website may contain links to external websites.

We are not responsible for the privacy practices or content of those websites and encourage users to review their privacy policies.


16. Children’s Privacy

Our services are intended for individuals aged 18 years and over.

We do not knowingly collect information from children without appropriate parental or legal authority.

If we become aware that information has been collected unlawfully, we will take steps to delete it.


17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Any updates will be published on this page together with the revised “Last Updated” date.

We encourage users to review this policy periodically.


18. Complaints

If you have concerns regarding how we handle your personal information, please contact us first:

Email: clinic@kriniko.co.uk

Telephone: 01223 459251

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Website: https://www.ico.org.uk

Telephone: 0303 123 1113


Contact Us

Kriniko Medical Aesthetics Ltd

1010 Cambourne Business Park
Great Cambourne
Cambourne
Cambridge
CB23 6DP

Email: clinic@kriniko.co.uk

WhatsApp/Text: 07775 809133

Landline: 01223 459251

Website: https://kriniko.co.uk/