GDPR Policy

Last updated: June 2026

RegenerateMSKClinic is committed to the UK GDPR and the Data Protection Act 2018. This page summarises your data-subject rights and how to exercise them.

Your rights

  • Right to access — obtain a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure — request deletion ("right to be forgotten").
  • Right to data portability — receive your data in a machine-readable format.
  • Right to restrict or object — limit or object to certain processing.

Exercising your rights

Signed-in users can download their data and request erasure directly from their profile. The data export is provided as a machine-readable JSON file. Erasure anonymises your personal data; records required for legal or financial reasons are retained in anonymised form.

Security measures

  • SSL/TLS encryption for data in transit and encryption of sensitive data at rest.
  • Role-based access control with audit logs.
  • Passwords hashed with a modern algorithm (argon2); rate limiting and OWASP protections.

Data processing & location

Data is hosted within the UK/EU region. Where third-party processors are used, they are bound by appropriate data-processing agreements. See our Privacy Policy for details.