Privacy notice
Last updated 16 September 2026
Who is responsible
HBOT Medics is the hyperbaric service within RosMedics (Pontcanna Hospital), an independent hospital registered with Healthcare Inspectorate Wales under HIW/02039RM, at The Mews, 38 Cathedral Road, Cardiff CF11 9LL.
HBOT Medics shares its booking, payment and clinical record systems with IronOx Clinic at the same hospital, and one administration team handles data-protection requests for both. Contact them at info@ironoxclinic.com.
Information we collect
- Identity and contact details, date of birth, address and booking preferences.
- Health information supplied in the course declaration, screening, communications and clinical record.
- Appointment, attendance, consent and treatment information.
- Payment status and transaction references. Stripe processes card details; we do not store full card data.
- Messages you send us, including enquiries from clinics about renting or buying a chamber.
- Essential security and technical information needed to operate and protect the service.
- Privacy-safe funnel events containing an anonymous UUID, brand, package and event time—never a name, email or clinical answer.
Why we use it
We use information to arrange and deliver the service, screen for safety, communicate about appointments and declarations, maintain health records, process payments and refunds, respond to concerns, prevent misuse and meet legal or regulatory duties.
Depending on the activity, the lawful basis may be contract, legal obligation or legitimate interests. Health information is processed for health or social care under Article 9(2)(h) UK GDPR and associated UK law. Consent is used where the law specifically requires it; withdrawing optional consent does not erase records we must retain.
Who receives it
Access is limited to authorised clinical and administrative staff and the service providers needed to run the booking and care pathway: Supabase for hosted records, Stripe for payment, Cloudflare for website delivery and security, Resend for email and Twilio for text messages. Information may also be shared with clinicians, emergency services, regulators or authorities where care, safeguarding or law requires it. We do not sell patient data.
How long we keep it
- Health and treatment records: 8 years from your last contact with us, in line with NHS records management guidance.
- Booking and contact details: 2 years from your last appointment.
- Payment records: 6 years, for tax and accounting.
Some records must be kept longer where the law, a complaint or a regulator requires it.
We apply access controls, audit trails, encryption in transit, environment separation and least-privilege administration. No internet system is risk-free, and suspected incidents are assessed under the hospital’s information-governance process.
Cookies and browser storage
This website does not use advertising or analytics cookies. The booking page uses Cloudflare Turnstile to check that a real person is booking. Your browser’s session storage keeps your chosen appointment times and the anonymous booking-funnel identifier until you close the tab. Stripe’s checkout page sets its own cookies to process payment securely.
Your rights and concerns
You may ask for access, correction, restriction, objection, portability or erasure where the relevant right applies. Clinical and legal retention duties can limit erasure. Contact the administration address above; we will respond within one month. You may also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
