Privacy

How EPOCH METABOLIC handles your information

EPOCH METABOLIC LIMITED is a UK clinical practice in pre-launch with CQC registration in process. This policy describes the personal and clinical data the practice collects through this website and through clinical engagement, how it is used, who it is shared with, and the rights of the data subject under UK GDPR.

Who we are

EPOCH METABOLIC LIMITED is registered in England and Wales. Trading address and registered office available on written request to enquiries@epochmetabolic.com. The data controller is EPOCH METABOLIC LIMITED.

What information we collect

Through this website, we collect: contact form submissions including name, optional organisation and role, email address, the enquiry type and free-text message, plus your consent to be contacted. Where you engage clinically with EPOCH, we additionally collect: clinical history, biomarker findings, lifestyle assessment, consultation notes and the longitudinal data the EPOCH Index integrates. Where the engagement involves an institutional partner (your employer, your school, your sport club), the boundary of what is shared with the partner is set in writing in advance and is held throughout the engagement.

How we use information

Contact form submissions are used to respond to your enquiry and, with consent, to follow up on related communications. Clinical data is used to deliver the clinical work you have engaged with, to maintain the longitudinal clinical record any serious clinical practice requires, and to satisfy the regulatory and professional obligations under which Robin and Amanda practise. We do not use clinical or contact data for marketing to third parties, and we do not sell data.

Lawful basis for processing

Contact form data is processed on the lawful basis of legitimate interest and, where applicable, consent. Clinical data is processed on the lawful basis of explicit consent, the performance of the clinical contract between you and EPOCH, and the legal obligations of the regulated clinical practice. Where institutional engagement is involved, the lawful basis is set out in the engagement contract.

Who we share information with

Clinical data may be shared with the laboratory partners EPOCH commissions for biomarker analysis, with imaging partners where imaging is clinically warranted, and with specialists to whom Robin and Amanda may signpost where clinical findings indicate. Sharing is on the basis of clinical necessity and is conducted under the appropriate professional and regulatory framework. Where institutional engagement is involved, the boundary of sharing with the institutional partner is set in writing.

Data retention

Clinical records are retained under the professional and regulatory framework under which Robin and Amanda practise. Contact form submissions that do not lead to clinical engagement are retained for up to twenty-four months and then deleted, unless you request earlier deletion.

Your rights under UK GDPR

You have the right to access the personal and clinical data EPOCH holds about you, to request correction of inaccurate data, to request deletion (subject to the clinical record retention obligations above), to restrict processing, to data portability, and to withdraw consent at any time. To exercise any of these rights, write to enquiries@epochmetabolic.com. We will respond within thirty days.

Cookies

This website uses minimal functional cookies necessary for the site to operate. Where consented, we may use privacy-respecting analytics (calibrated to clinical practice expectations rather than the broader corporate web analytics environment) to understand how the site is being used. We do not use third-party advertising cookies and we do not run tracking pixels for advertising platforms.

Security

EPOCH applies appropriate technical and organisational measures to protect personal and clinical data, including encryption in transit and at rest, access controls, and the regulatory framework under which the clinical practice operates. No security framework is absolute; we will notify the Information Commissioner's Office and affected data subjects within seventy-two hours of any personal data breach in accordance with UK GDPR.

Complaints

If you are unhappy with how EPOCH has handled your data, please write first to enquiries@epochmetabolic.com so we can address the concern directly. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Changes to this policy

This policy may be updated as the practice moves through its pre-launch period and into full clinical operation. Material changes will be flagged at the top of this page. This version is dated May 2026 and reflects the pre-launch posture.

This policy is undergoing legal review by Bevan Brittan as part of the Phase 1 legal engagement. The current draft reflects the EPOCH pre-launch posture and the UK GDPR framework; the final policy will be in place before clinical operation commences.