Last updated: 16/08/26
We appreciate the trust you place in us when you share your personal information. Protecting that information is important to us. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and how we keep it secure. It also explains your rights over your personal data and how to exercise them.
Please read this carefully. By providing your personal data to us, or by using our website, you accept the practices described in this policy.
Oniorthopaedics Limited is the data controller for the personal data described in this policy. We are committed to protecting your privacy and to meeting our obligations under the UK GDPR and the Data Protection Act 2018.
If you have any questions about this policy or how we use your information, please contact us using the details above.
This policy does not cover other websites we link to. We encourage you to read the privacy policies of any other sites you visit.
This website collects only the information you choose to send us when you make an enquiry, together with limited technical information about your visit:
We do not hold your medical records on this website. Any clinical records relating to your care are held by the hospital that treats you. See "How your enquiry is handled" below.
When you submit an enquiry through this website, it is sent to the booking team at The Horder Centre so they can arrange your consultation. A copy of your initial enquiry is also held by our website platform provider, Webflow, which stores and processes it on our behalf under a data processing agreement. We retain these enquiries for 6 months and then delete them.
Once your consultation is arranged, all further communication and your ongoing care are handled directly by the treating hospital, away from this website. Your care and any medical records created as part of it are managed by the hospital where you are treated under its own privacy notice, for example The Horder Centre's privacy notice. This website is not used to deliver or record your clinical care.
We rely on the following lawful bases under the UK GDPR:
We share your enquiry only with:
We do not sell your information or share it for marketing. We will only disclose it otherwise where the law requires it, or where someone's safety is at risk. Once your care is underway, any onward sharing of clinical information (for example with your GP or insurer) is handled by the treating hospital under its own privacy notice, not by this website.
Our website uses cookies, which are small text files placed on your device that help the site function and help us understand how it is used. When you first visit, we ask whether you accept non-essential cookies. You can withdraw or change your choice at any time through your browser settings or our cookie preferences.
For full details of the cookies we use, please see our Cookie Policy.
We use the contact details you provide only to respond to your enquiry and to pass it to the hospital's booking team so your consultation can be arranged. You can subscribe to recieve updates from Mr Oni and insights into orthopaedics and relevant hip and knee conditions. Any appointment reminders or ongoing correspondence come from the treating hospital, not from this website.
We keep website enquiries no longer than necessary. Enquiries stored via our website platform are retained for 6 months and then deleted. Any records relating to your clinical care are held separately by the treating hospital, in line with its own retention policy and the statutory requirements for medical records.
We take all reasonable measures to keep your information secure. Our website and enquiry data are hosted by Webflow. As Webflow is based in the United States, your enquiry data may be transferred outside the UK; where this happens we rely on appropriate safeguards (such as the UK extension to the EU-US Data Privacy Framework and/or standard contractual clauses) to protect it.
Under data protection law you have the right to:
To exercise any of these rights, please contact us using the details in the "Who we are" section. We verify the identity of anyone making a request and may refuse where we cannot do so.
If you have concerns about how we have handled your personal data, please contact us first using the details above. If you remain dissatisfied, you can contact the Information Commissioner's Office (ICO):
We may update this policy from time to time. The date at the top shows when it was last revised.