Data Protection Policy
Clear information about how Luton Hospital collects, uses, discloses, retains and protects personal data when patients, website visitors and service users interact with our hospital.
Lawful handling
We collect and use personal data only for lawful, clear and necessary hospital purposes.
Health data protection
Health and sensitive personal data is handled with additional confidentiality and access safeguards.
Patient rights
Patients and service users may request access, correction, restriction, objection and other applicable rights.
Secure communication
Privacy concerns and rights requests can be sent to the official hospital privacy contact.
1. Overview and scope
Luton Medical Hospital Limited is committed to protecting personal data and handling it lawfully, fairly, transparently and securely.
This Data Protection Policy applies when you use our website, submit an appointment request, contact us, receive or enquire about healthcare services, or otherwise interact with us.
This policy should be read together with any specific privacy notice, consent form or service notice given at the time your data is collected.
| Data controller | Luton Medical Hospital Limited |
|---|---|
| Postal address | P.O. Box 34444–00100, China Centre, Ngong Road, Nairobi, Kenya |
| Privacy contact | info@lutonhospital.co.ke |
| Telephone | +254 111 003 400; +254 726 510 000; +254 711 300 900 |
2. Personal data we may collect
The data we collect depends on how you interact with Luton Hospital and the service requested. We only ask for information that is relevant to the purpose.
- Identity and contact information
- Appointment and enquiry information
- Health and medical information
- Payment, insurance and cover information
- Communications and documents
- Website and device information
3. Why we process personal data
We process personal data for lawful and specified purposes connected with healthcare, administration, communication, safety, compliance and service improvement.
Collect
We receive information through care, forms, calls, email, WhatsApp or authorised sources.
Use
We use it for healthcare, appointments, billing, communication, compliance and safety.
Protect
We apply access control, confidentiality and security safeguards appropriate to the data.
Retain or delete
We keep data only as needed, then securely delete, destroy or anonymise where appropriate.
- Receiving, assessing and responding to enquiries and appointment requests.
- Identifying patients or service users and maintaining accurate records.
- Arranging, coordinating and providing healthcare or related services.
- Communicating about appointments, care, service availability, follow-up or administration.
- Verifying SHA, insurance, corporate-cover or payment information and administering billing or claims.
- Managing complaints, incidents, quality assurance, clinical governance, audit and service improvement.
- Preventing and investigating fraud, misuse, unlawful activity, cyber threats and threats to safety.
- Operating, securing, maintaining and troubleshooting our website, communications and information systems.
- Complying with legal, regulatory, professional, public-health, reporting and recordkeeping duties.
4. Legal grounds for processing
We rely on one or more lawful grounds depending on the specific data and purpose. Consent is not always the legal basis for healthcare processing.
- Consent, where consent is required and has been freely given for a specific purpose.
- Steps requested before entering into a contract or performance of a contract with you.
- Compliance with a legal obligation imposed on the hospital.
- Protection of vital interests, including urgent circumstances involving life or health.
- Performance of a task carried out in the public interest, where applicable.
- Legitimate interests, where those interests are not overridden by rights and freedoms.
- Additional grounds permitted for health or other sensitive personal data.
5. When we may disclose personal data
We may disclose the minimum personal data reasonably necessary to recipients who have a lawful need to receive it. We do not sell personal data.
- Healthcare professionals and authorised staff involved in care or administration.
- Laboratories, imaging centres, referral facilities or other healthcare providers involved in a requested service.
- SHA, insurers, employers or corporate-cover administrators for verification, authorisation, billing or claims.
- Professional advisers, auditors and insurers acting under appropriate duties.
- Authorised providers supporting hosting, communications, cybersecurity, records, maintenance or hospital systems.
- Regulators, courts, law-enforcement agencies, public-health bodies and other public authorities where required or permitted by law.
- Another person where the patient or service user has authorised disclosure.
6. Data security, confidentiality and breaches
We apply technical, organisational and physical safeguards appropriate to the nature of the data, the processing and the risks involved.
Access to personal data should be limited to persons who need it for an authorised purpose and who are subject to confidentiality or professional duties.
We maintain procedures for assessing and responding to suspected personal-data breaches. Where the legal threshold is met, the hospital will notify the relevant authority and affected persons as required by law.
7. Data retention
We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected and for any applicable legal, clinical, professional, accounting, reporting, insurance, claims or dispute-resolution requirement.
Retention periods may differ for appointment requests, communications, clinical records, prescriptions, billing and cover information, complaints, security logs and website data.
When retention is no longer justified, data will be securely deleted, destroyed or anonymised, subject to technical limits and lawful exceptions.
8. Your data-protection rights
Subject to applicable conditions, exemptions and verification requirements, you may have the following rights under applicable data-protection law.
- Be informed about how personal data is used.
- Request access to personal data held about you and receive a copy.
- Request correction of inaccurate or incomplete personal data.
- Request erasure where there is a lawful basis for deletion.
- Request restriction of processing in qualifying circumstances.
- Object to processing based on particular grounds, including direct marketing.
- Request data portability where legal requirements are met.
- Withdraw consent for future processing that depends on consent.
- Seek safeguards concerning qualifying automated decisions.
9. How to exercise your rights or raise a concern
Send a clear request to info@lutonhospital.co.ke or write to the Privacy and Data Protection Contact, Luton Medical Hospital Limited, P.O. Box 34444–00100, China Centre, Ngong Road, Nairobi, Kenya.
Please describe the right you wish to exercise and the data or interaction concerned. We may request information reasonably necessary to verify identity, authority and the scope of the request.
Public policy note
This public page provides general information about Luton Hospital’s data protection approach. It does not replace any specific privacy notice, patient consent form, clinical confidentiality duty, employment notice or legal obligation applicable to a particular service.
Download the full Data Protection Policy
The PDF version is stored in public/uploads/policies/data-protection-policy.pdf. Use the open button to confirm the file is reachable, and the download route to force download.