Last updated: May 2026

1. Who we are

This website is operated by Fiona Roy, trading as Pectus Care with Fiona.

Data controller:
Fiona Roy
Contact email:
[TO BE CONFIRMED]
ICO Registration Number:
[TO BE CONFIRMED — registration pending]

2. What information we collect

When you complete our screening form or otherwise contact us, we may collect:

  • Your name, and the name of the patient if you are completing the form on behalf of a child or another person
  • Date of birth
  • Contact details, including email address, phone number, and postal address
  • Information about a medical diagnosis and relevant medical history
  • Details of whether a GP or doctor has been consulted about the condition
Please note: Information about health and medical conditions constitutes special category data under UK GDPR and is afforded a higher level of protection.

3. Why we collect it and our legal basis

We collect and use your personal information to:

  • Assess whether this service is appropriate and clinically safe for you
  • Provide clinical consultations and ongoing specialist orthotics support
  • Communicate with you about your care and treatment

The legal basis for processing your personal data is the performance of, or preparation for, a contract for services with you. The legal basis for processing special category health data is Article 9(2)(h) of UK GDPR — processing that is necessary for the purposes of the provision of health care or treatment by a health professional.

4. How we store your information

Your information is stored securely and is accessible only to Fiona Roy as the data controller and treating clinician.

Your personal information is not shared with third parties except where required by law, or where this is strictly necessary to provide your treatment — for example, passing relevant order details to Klobe for vacuum bell device fulfilment.

5. How long we keep your information

We retain your records for the period required by our professional body and indemnity insurer, calculated from the date of your last contact with this service. After this period has elapsed, your records will be securely and permanently deleted.

Exact retention period to be confirmed in line with professional guidance.

6. Your rights

Under UK GDPR you have the following rights in relation to your personal data:

  • Access — the right to request a copy of the personal data we hold about you
  • Rectification — the right to request correction of any inaccurate data
  • Erasure — the right to request deletion of your data, subject to our legal and professional obligations
  • Restriction — the right to request that we restrict our processing in certain circumstances
  • Objection — the right to object to processing in certain circumstances
  • Complaint — the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk

To exercise any of these rights, please contact us at: [TO BE CONFIRMED]

7. Changes to this policy

We may update this privacy policy from time to time, for example to reflect changes in the law or our working practices. We will always post the updated version on this page with a revised "last updated" date. We encourage you to check this page periodically. This policy was last updated May 2026.