Privacy Policy
Last updated 5 October 2026. See also our Cookie Policy, Website Terms of Use and Terms and Conditions of Service.
1. Who we are and what this policy covers
London Sports and Rheumatology Imaging (LSRI) is the trading name of LSRI LTD, a company registered in England and Wales (company number 15796158, registered office 2 Wheeleys Road, Birmingham B15 2LD). We provide private musculoskeletal imaging (MRI, ultrasound, X-ray and other imaging), ultrasound-guided injections, consultations, second opinions, medicolegal reports and CPD training from our clinics at 19 Harley Street, London W1G 9QJ and 62 Station Road, North Harrow HA2 7SJ, and through partner imaging centres across the UK.
LSRI LTD and its practitioners are the data controller for the personal data described in this policy, and our practice is registered with the Information Commissioner’s Office (ICO).
Data protection enquiries: email info@lsri.uk with “Data protection” in the subject line, call 0203 633 5040, or write to LSRI LTD, 19 Harley Street, London W1G 9QJ.
This policy applies to everyone whose personal data we handle: patients and prospective patients; people who contact us or book on their behalf (parents, carers, relatives, staff and other authorised persons); referrers (GPs, consultants, physiotherapists, osteopaths, sports clubs, employers and other professionals); solicitors, insurers and claimants in medicolegal work; delegates on our CPD courses; visitors to lsri.uk; suppliers and job applicants. It explains what we collect, why, who we share it with, how long we keep it and your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and the common-law duty of confidentiality.
It does not apply to the privacy practices of other organisations, including our partner imaging centres, referrers, insurers, software providers and websites we link to. Each has its own privacy notice, which we encourage you to read.
This policy was last updated on 5 October 2026. We may change it at any time; the version on lsri.uk is the one that applies.
2. The personal data we collect
We collect only what we need to provide safe care, run the clinic and meet our legal duties. Most of it comes from you; some comes from your referrer, your insurer, our partner centres or your previous clinicians.
| Who | What we collect | Where it comes from |
|---|---|---|
| Patients and prospective patients | Name, date of birth, sex, address, phone numbers, email, WhatsApp number, NHS number (if given), next of kin or emergency contact, GP details, insurer and policy/authorisation numbers, payment details (card payments are processed by our payment provider; we do not store full card numbers), appointment history, booking notes, correspondence | You, the person booking for you, your referrer, your insurer |
| Health data (special category) | Symptoms, medical and surgical history, medication and allergies, pregnancy status, implants and MRI safety screening answers, previous scans and reports, referral letters, our scan images (DICOM) and reports, ultrasound stills and video, consent forms, injection records, consultation notes, letters to your GP, outcomes and follow-up, images or messages you send us (for example a photo of a swelling) | You, your referrer, previous providers, partner imaging centres, our clinicians |
| Identity and safeguarding | Photo ID where needed (for example medicolegal work), details of a parent or guardian for patients under 18, chaperone records, safeguarding notes where a concern arises | You, your parent or guardian, our staff |
| Referrers and professional contacts | Name, role, practice or organisation, professional registration number, work contact details, the patients you refer, correspondence and clinical queries | You, public registers (GMC, HCPC), your organisation |
| Medicolegal clients | Instructing solicitor or agency details, claimant details, case reference, letters of instruction, medical records disclosed to us, examination findings, our reports, invoices, court directions | Instructing parties, claimants, courts |
| CPD training delegates | Name, role, employer, registration number, contact details, attendance, certificates issued, feedback, payment | You, your employer |
| Website visitors | IP address, device and browser type, pages viewed and time on site, referring site, approximate location, form submissions (contact and referral forms), click events on call, WhatsApp and booking buttons | Your browser, our analytics and form tools (see our Cookie Policy) |
| Callers, texters and messagers | Phone number, voicemail, call notes, SMS and WhatsApp message content and attachments, email content and attachments | You |
| Reviewers | Your name as shown on Google and the review text (we display public Google reviews on our site through a reviews widget) | Google, the review platform you used |
| Suppliers and job applicants | Contact and contract details, bank details for payment, CVs, references, right-to-work documents, DBS checks where the role requires them | You, your employer, referees, the DBS |
Call and message recording: calls to and from 0203 633 5040, and messages exchanged with us, may be recorded or stored for training, quality and record-keeping. Recordings and messages are kept for the periods in section 6.5 and in line with our telephony and messaging providers’ policies.
If you give us information about someone else (for example when booking for a child, relative, friend or employee, or for anyone who has authorised you to act for them), you confirm you have their authority to do so and that you have told them about this policy.
You are not obliged to give us your information. If you do not, we may be unable to book, scan, treat or report on you safely, or at all.
3. How we use your data and our lawful bases
UK GDPR requires a lawful basis under Article 6 for all personal data and, because health data is “special category” data, an additional condition under Article 9. Our clinical processing is carried out by or under the responsibility of health professionals who owe a duty of confidentiality (UK GDPR Article 9(2)(h) and Data Protection Act 2018, Schedule 1, paragraph 2). We do not generally rely on consent as our data-protection lawful basis for clinical records, because we could not then withdraw care records on request; your consent to a scan or injection is a separate, clinical consent.
| Purpose | Article 6 basis | Article 9 condition (health data) |
|---|---|---|
| Booking, scanning, reporting, treating and following you up; writing to your referrer and GP | Contract (6(1)(b)); legitimate interests (6(1)(f)) where you are not the contracting party | Health or social care (9(2)(h)) |
| Clinical safety: MRI safety screening, pregnancy checks, allergy and medication checks, chaperones | Legal obligation (6(1)(c)) and contract | Health or social care (9(2)(h)); vital interests (9(2)(c)) in an emergency |
| Arranging scans at partner imaging centres and receiving their images and reports | Contract; legitimate interests | Health or social care (9(2)(h)) |
| Second opinions and sharing with other specialists you are referred to | Contract; legitimate interests | Health or social care (9(2)(h)) |
| Billing, insurer pre-authorisation and claims, instalment plans, debt recovery | Contract; legitimate interests; legal obligation (tax and accounting) | Health or social care (9(2)(h)) for the minimum clinical detail insurers require; legal claims (9(2)(f)) for recovery |
| Medicolegal reports and expert work | Contract; legitimate interests; legal obligation (court directions) | Legal claims and judicial acts (9(2)(f)); explicit consent (9(2)(a)) where the instruction requires it |
| Complaints, incidents, clinical audit, quality improvement and revalidation | Legitimate interests; legal obligation | Health or social care (9(2)(h)); legal claims (9(2)(f)) |
| Safeguarding and statutory reporting (for example to the CQC, GMC, public health bodies, police or courts) | Legal obligation; public task where applicable | Substantial public interest (9(2)(g)) with the relevant Schedule 1 condition; health or social care |
| Service messages (confirmations, reminders, results ready, invoices) by phone, SMS, email or WhatsApp | Contract; legitimate interests | Health or social care (9(2)(h)) |
| Marketing emails or messages about our services | Consent (PECR); legitimate interests only for existing customers under the “soft opt-in” | Not applicable (we do not use health data for marketing) |
| Running and securing lsri.uk, analytics, fraud and abuse prevention | Legitimate interests; consent for non-essential cookies (PECR) | Not applicable |
| CPD training administration and certificates | Contract | Not applicable |
| Recruitment and HR | Contract; legal obligation; legitimate interests | Employment law (9(2)(b)) where relevant |
| Defending or bringing legal claims, insurance notifications | Legitimate interests | Legal claims (9(2)(f)) |
Legitimate interests we rely on include: running a safe and efficient clinic; communicating with you in the way you have asked; protecting our staff, patients, systems and premises; recovering fees we are owed; improving our services; and promoting our services to people who have used them. Where we rely on legitimate interests we have balanced them against your rights and you can object (section 6).
Anonymised and pseudonymised data: we may use images and case details with identifying details removed for teaching, CPD courses, audit, research, educational blog articles and insights, and publications. Where an image could still identify you (for example a recognisable feature), we will ask your explicit consent first.
Automated decision-making: we do not make decisions about you solely by automated means. Some software we use (for example scanner or reporting tools) may include AI-assisted features; a clinician always reviews and is responsible for your report.
4. Who we share your data with
We share personal data only where it is necessary for your care, to run our service, or where the law requires or permits it. We never sell personal data or share it for someone else’s marketing.
4.1 For your care (independent controllers). These organisations decide for themselves how they use the data we send them and have their own privacy notices:
- Partner imaging centres and providers where your scan or X-ray is carried out, or whose equipment we use. These include Vista Health (InHealth Limited), InHealth Group, Modality LLP and other partner centres in our network of 70+ UK locations. We send the clinical details they need to perform your scan safely (identity, contact details, referral, MRI safety answers, relevant history) and they send us the images and any report. Scans at partner centres are performed under that centre’s own procedures and terms.
- Your referrer (GP, consultant, physiotherapist, osteopath, sports club doctor or other clinician) and, with your agreement, your NHS GP: we send reports, letters and, where relevant, images, unless you ask us in writing not to.
- Other healthcare professionals, specialists and experts we involve in your care or whose opinion we seek: orthopaedic and spinal surgeons, rheumatologists, pain specialists, physiotherapists (including our own physiotherapy team), sub-specialist radiologists for second reads, laboratories and pathology services, and the clinicians at the clinic you are referred on to.
- Hospitals and NHS services in an emergency, or where you are admitted or referred.
4.2 To pay for your care.
- Private medical insurers (for example Bupa, AXA Health, Aviva, Vitality, WPA, Cigna and others) and their intermediaries, to obtain pre-authorisation, submit invoices and answer queries. We give the minimum clinical detail they require. Your policy with your insurer governs what they may do with it.
- Our payment, card-terminal and finance providers (UK-regulated payment, card and banking providers), debt-collection agencies and our accountants and auditors.
- Embassies, employers, sponsors or solicitors who have agreed to pay for your care, limited to billing information.
4.3 Our service providers (processors). These companies process data on our instructions under written contracts (data-processing agreements) that require them to keep it confidential and secure. They include:
| Service | Provider(s) | What they hold |
|---|---|---|
| Practice management, bookings, clinical notes, online booking | Carepatron (Carepatron Inc., USA; UK/EU data-processing addendum) or similar practice-management software | Patient records, appointments, correspondence |
| Cloud file storage and sharing of images and reports | Cloud platforms such as pCloud (pCloud AG, Switzerland) and other cloud services (for example Google Workspace, Microsoft 365, Dropbox or WeTransfer) | Scan images, reports, letters, shared folders |
| Radiology image archive and viewer (PACS) and reporting software | DICOM viewing and reporting software such as Weasis, Horos, OsiriX, 3D Biotronics or similar, and our PACS provider | DICOM images, reports |
| Email, calendar and office software | Google Workspace or Microsoft 365 | Emails and attachments |
| Messaging | WhatsApp Business (WhatsApp Ireland Ltd / Meta Platforms) and our SMS provider | Message content and attachments, phone numbers |
| Telephony and call handling | Our telephone and VoIP provider (for example Tamar Telecommunications UK or similar) and any answering service | Call records, voicemail |
| Website hosting and security | Hostinger International Ltd (web hosting), LiteSpeed caching, Jetpack/Automattic (site security and stats), Akismet (spam filtering) | Website logs, form submissions, security logs |
| Website forms and referrals | Contact Form 7 (on our server), Jotform Inc. (referral form) | Form submissions including referral details |
| Analytics | Google Analytics 4 (Google LLC / Google Ireland Ltd) | Pseudonymous usage data (see Cookie Policy) |
| Reviews widget | TrustIndex.io and Google | Public Google review content displayed on our site |
| Invoicing and accounting | Accounting software (for example Xero or QuickBooks) and our accountants | Invoices, payment records |
| IT support, backup, secure destruction | IT providers | Whatever systems they support |
We may change providers from time to time; the current list is available on request.
4.4 Where the law requires or permits. We may disclose personal data without your consent where we are required or permitted to by law, including to: courts and tribunals (under a court order, witness summons or civil procedure rules); the Care Quality Commission, General Medical Council, Health and Care Professions Council and other regulators; HM Revenue & Customs; the police and law-enforcement agencies for the prevention or detection of crime; public-health bodies (for example notifiable disease reporting); the NHS Counter Fraud Authority; safeguarding authorities where a child or adult at risk may be harmed; our professional-indemnity insurers, medical defence organisations and legal advisers in connection with a complaint, claim or incident; and anyone else where disclosure is necessary to protect someone’s life.
4.5 Medicolegal and expert work. Where we are instructed to examine you or report on you for legal proceedings, our report and relevant records will be sent to the instructing party (solicitor, insurer, medical agency or court) and may be disclosed to the other parties and the court under the rules of the proceedings. The instructing party will normally obtain your consent first; we cannot withhold a report from the court once it is ordered.
4.6 Business changes. If LSRI LTD merges with, is sold to or transfers its clinics or patient lists to another provider, patient records may be transferred to the successor so that your care and your right of access continue. You will be told where the law requires it.
4.7 Public reviews and testimonials. We display Google reviews that you have chosen to make public. We will only use your name, story or images in marketing with your separate written consent, which you may withdraw at any time.
5. How we communicate with you, and the risks of each channel
We will contact you by the channels you give us: telephone, SMS text message, email, WhatsApp, post, and secure cloud links for files and images. You can tell us at any time which channels you prefer or want us to stop using, by emailing info@lsri.uk. We will always use a channel if we need to reach you urgently about a clinical safety matter.
By contacting us or replying through a channel, you agree to our using that channel for your care, including sending appointment details, invoices, results and reports, and receiving images or messages from you. No electronic channel is completely secure. In particular:
| Channel | What you should know |
|---|---|
| Ordinary email is not encrypted end to end. Messages pass through your provider’s and our provider’s servers and can be misdirected if an address is mistyped. We may password-protect reports on request. Check that emails claiming to be from us come from an @lsri.uk address and never send card details by email. | |
| SMS text messages | Text messages are not encrypted and may be seen by anyone with access to your phone. We keep clinical detail out of texts and use them mainly for reminders and links. |
| WhatsApp messages are end-to-end encrypted in transit, but WhatsApp (Meta) processes your phone number and message metadata, may store backups on your device or cloud account, and its servers are outside the UK. By messaging our WhatsApp number you accept this. Please do not send us anything you would not want held on your own phone backup. We use a business account; our staff may see messages on shared clinic devices. | |
| Telephone and voicemail | We will confirm your identity before discussing clinical information. We will only leave a voicemail if you have agreed we may, and we keep it brief. |
| Cloud file sharing (pCloud and similar) | We share large files (scan images, DICOM folders, reports) through time-limited, password-protected links. Links should not be forwarded. Once a file is downloaded to your device or to your referrer’s systems, its security is outside our control. |
| Online booking (Carepatron) | Information you enter is held by our practice-management provider under contract with us. |
| Video consultations | Our free 5-minute video consultations use Carepatron, WhatsApp video or a similar service. Please take the call somewhere private. We do not record video consultations unless we tell you and you agree. |
| Post | Reports and invoices may be posted to the address you give us. Tell us promptly if you move. |
Communicating with referrers and other professionals. We send reports, letters and images to your referrer, GP and other professionals involved in your care using secure email, NHS-approved or encrypted channels where available, PACS image-sharing, or cloud links. Where a referrer or partner centre asks us to use a particular platform (for example their own portal), their terms govern that platform.
Mistaken or intercepted messages. If you receive a message from us that is not meant for you, please tell us at once and delete it. We will investigate any misdirected message as a potential data breach. If your own device, email or WhatsApp account is compromised, we cannot protect the copies held there.
Marketing. We only send marketing messages (for example newsletters, offers or news about new services) if you have opted in, or, where the law allows, if you are an existing patient and have not opted out. Every marketing message includes a way to unsubscribe. We will never use your clinical details to target marketing, and we do not send marketing by WhatsApp or SMS without your specific consent.
6. Transfers, security, third parties, retention and your rights
6.1 International transfers. We are based in the UK and aim to keep your data in the UK or the European Economic Area. Some of our providers store or access data elsewhere: Carepatron (United States), WhatsApp/Meta (United States), Google and Jotform (United States), and support staff of other providers. Where data leaves the UK we rely on the UK’s adequacy regulations (including for the EEA, Switzerland and the UK–US Data Bridge), the ICO’s International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another safeguard permitted by Articles 44–49 UK GDPR. You can ask us for details of the safeguards used.
6.2 Security. We take reasonable technical and organisational measures appropriate to the sensitivity of health data, including: access controls and individual logins; multi-factor authentication on clinical and administrative systems; encryption in transit (TLS) and at rest where our providers support it; password-protected or time-limited file links; staff confidentiality agreements and data-protection training; website hardening, malware scanning and backups; and secure disposal of paper records. Our clinicians are bound by the GMC’s and their professional bodies’ confidentiality rules.
6.3 Third-party systems and breaches. We choose reputable providers and partners and put written contracts in place with our processors. However, each partner centre, referrer, insurer and software provider operates its own systems, which we do not control. To the fullest extent permitted by law, LSRI LTD is not responsible for any loss, unauthorised access, disclosure, alteration or misuse of your personal data that occurs within the systems, networks, devices or premises of a third party — including partner imaging centres, referrers and other professionals, insurers, cloud, messaging, email, telephony and software providers, your own email, phone or cloud accounts, or the internet generally — or that results from a cyber-attack, security vulnerability or failure on their side, or from your own choice of communication channel. Where such a third party is our processor, we will take the steps the law requires of us as controller (including investigating, notifying the ICO and you where required, and enforcing our contract with them). Nothing in this policy excludes any liability that cannot be excluded under UK GDPR, the Data Protection Act 2018 or other law.
6.4 Data breaches. If a personal-data breach is likely to result in a risk to you, we will report it to the ICO within 72 hours of becoming aware and, where the risk is high, tell you without undue delay, as Articles 33 and 34 UK GDPR require.
6.5 How long we keep your data. We follow the NHS Records Management Code of Practice retention schedule as a benchmark for a private provider.
| Record | Retention |
|---|---|
| Adult clinical records, scan images and reports | 8 years from the last contact, then reviewed and securely destroyed unless there is a clinical, legal or regulatory reason to keep them longer |
| Children’s records | Until the patient’s 25th birthday (26th if they were 17 at the last contact), or 8 years after death if sooner |
| Records of patients who have died | 8 years from death |
| Medicolegal reports and instructions | 7 years after the case closes, or longer if directed by the court or the instructing party (limitation periods under the Limitation Act 1980) |
| Consent forms, MRI safety questionnaires, injection records | Kept with the clinical record for the same period |
| Complaints, incidents and safeguarding records | 10 years from closure |
| Invoices, payment and insurer records | 7 years after the end of the financial year (HMRC and Companies Act requirements) |
| Emails, SMS and WhatsApp messages with patients | Clinically relevant content is copied into the clinical record; the original messages are deleted from messaging apps within 12 months |
| Website analytics data | Up to 14 months (Google Analytics default) |
| Contact-form and referral-form submissions | 12 months unless they become part of a clinical record |
| CPD delegate records and certificates | 6 years |
| Recruitment records (unsuccessful applicants) | 6 months after the vacancy closes |
| CCTV (host building) | Per the host building’s policy, typically 30 days |
6.6 Your rights. Under UK GDPR you have the right to: access your records (a subject access request; we respond within one calendar month, free in most cases); rectification of inaccurate data (we may add a note rather than delete clinical opinions); erasure in limited cases (we normally cannot delete clinical records during their retention period, because we must keep them under our professional and legal duties); restriction of processing; objection to processing based on legitimate interests and to any direct marketing; data portability of data you provided to us under contract; and the right to withdraw consent where consent is our basis (for example for marketing or use of identifiable images), without affecting earlier processing. To exercise a right, email info@lsri.uk or write to us at 19 Harley Street, London W1G 9QJ. We may ask for proof of identity. Copies of your scan images can be provided on disc or by secure link; a reasonable fee may apply for repeat copies.
6.7 Complaints. If you are unhappy with how we handle your data, please tell us first at info@lsri.uk so we can put it right. You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow SK9 5AF.
6.8 Children and people who lack capacity. For patients under 16 we normally take instructions from a parent or guardian, unless the young person is assessed as competent to decide for themselves (Gillick competence). For adults who lack capacity we act in their best interests under the Mental Capacity Act 2005 and may share information with their attorney, deputy or carers as appropriate.
6.9 Links and third-party sites. lsri.uk links to other websites (for example Google Maps, our booking provider, insurers and professional bodies). We are not responsible for their content or privacy practices.
6.10 Changes to this policy. We review this policy at least annually and whenever our services, suppliers or the law change. Material changes will be flagged on lsri.uk and, where appropriate, sent to patients by email.
CPD Approved Provider #790052
CPD Accredited Medical Training
We offer specialized CPD-accredited training in musculoskeletal and rheumatology imaging, delivered by Consultant MSK Radiologist Dr Prashant Sankaye. Our courses are fully accredited by The CPD Group.
- Counts towards your annual CPD requirement
- Delivered by a Specialist Consultant Radiologist
- Independently verified by The CPD Group
Accredited Excellence
LSRI Ltd meets strict standards for educational quality.
Verify our accreditation at thecpdregister.com