Privacy Policy
Privacy Policy — HytheHopes Limited
Last updated: 8th August 2026
1. About this notice
Hythehopes Limited (“we“, “us“, “our“) is committed to protecting your personal data and respecting your privacy. This notice explains what personal data we collect about you, why we collect it, how we use it, who we share it with, how long we keep it, and your rights.
This notice applies to our websites at www.hythehopes.com and www.hythehopes.co.uk (together, “our site“), and to individuals who contact us, complete our online billing assessment, pay an invoice through our site, or are otherwise in touch with us.
If you are a patient whose bill is being managed by HytheHopes on behalf of your consultant, clinic, hospital, or other customer of ours, section 10 below is particularly relevant to you.
We are a data controller for the personal data described in this notice, except in relation to patient billing data managed on behalf of our customers, where we act as a data processor for the customer (see section 10).
2. Who we are
Hythehopes Limited is registered in England and Wales (company number 3242863), with registered office at 43 Bridge Road, Grays, Essex, RM17 6BU. Our VAT registration number is 681 4092 33.
We are registered with the Information Commissioner’s Office under number Z2150591.
3. How to contact us about privacy
For any question about this notice or how we handle personal data, please contact our Data Protection Officer:
Data Protection Officer
Hythehopes Limited, 43 Bridge Road, Grays, Essex, RM17 6BU
Email: dataprotection@hythehopes.co.uk
4. The personal data we collect
We may collect the following categories of personal data:
When you use our site or contact us
- Name, email address, telephone number, and any information you include in messages, forms, or enquiries.
- Details of your correspondence with us.
- Information about your visits to our site, including IP address, device information, browser type, pages viewed, and referring URL. See our Cookie Policy for more.
When you complete our online billing assessment
- Your responses to the assessment questions.
- Your email address, if you provide it to receive a copy of your results.
When you pay an invoice through our site
- Your name, contact details, invoice reference, and details of the payment. Card details are handled directly by our payment processor, Worldpay, and are not stored on our systems (see section 7).
If you are a customer of ours — including a consultant, clinic, hospital, or other medical professional
- Contact details, correspondence, contract details, billing records, and information relating to the services we provide to you.
If you are a patient of one of our customers
- Information supplied to us by the customer for the purpose of raising invoices and collecting fees (see section 10).
5. Special category data
Some of the information we handle in the course of medical billing — including patient names and the medical specialty concerned — may reveal information about health, which is special category personal data under Article 9 of the UK GDPR.
Where we process such data, we do so under Article 9(2)(h) of the UK GDPR — processing necessary for the provision of health or social care or treatment — together with the associated condition in Schedule 1 of the Data Protection Act 2018 which requires the processing to be carried out under a duty of confidentiality equivalent to that owed by a health professional.
We have in place an appropriate policy document under Schedule 1 of the Data Protection Act 2018, which is available on request.
6. Why we process your data and our lawful basis
We only process personal data where we have a lawful basis to do so. The lawful bases we rely on under Article 6 of the UK GDPR are:
Performance of a contract (Article 6(1)(b)) — where we process your data to provide a service you have asked for (for example, processing a payment on the Pay Your Invoice page) or to perform a contract with a customer.
Legitimate interests (Article 6(1)(f)) — where we process your data because it is necessary for our legitimate business interests and those interests are not overridden by your rights and interests. We rely on this basis for:
- Responding to enquiries from prospective customers;
- Managing our relationship with existing customers and their staff;
- Following up on billing assessments where you have provided your email address;
- Recovering unpaid invoices on behalf of our customers;
- Fraud prevention, credit risk reduction, and business administration;
- Improving our website and services.
Consent (Article 6(1)(a)) — where you have opted in to non-essential cookies (see our Cookie Policy). You can withdraw consent at any time by contacting us using the details in section 3, or by changing your cookie preferences on our site.
Legal obligation (Article 6(1)(c)) — where processing is necessary to comply with a legal duty, such as record-keeping obligations to HMRC or responding to lawful requests from regulators.
For special category data (see section 5), Article 9(2)(h) applies in addition.
7. Who we share your data with
We share personal data with the following categories of recipient:
Our customers, in the ordinary course of providing our services to them, where you are their patient.
Service providers who process data on our behalf. These currently include:
- Google (Google Analytics) — for website analytics. We do not attempt to identify individual visitors from analytics data.
- Worldpay — for payment processing on the Pay Your Invoice page.
- Healthcode — for the exchange of billing information with insurers and related purposes in the medical billing process.
- Our website hosting provider.
Each of these providers acts as our data processor under a written data processing agreement in accordance with Article 28 UK GDPR.
Our professional advisers — including our accountants, solicitors, insurers, and auditors — where necessary and under duties of confidentiality.
Regulators and law enforcement, where we are legally required to disclose information.
A prospective buyer or seller in the event of a sale, acquisition, or restructuring of our business. Where personal data is disclosed for this purpose, we will ensure it is either anonymised, aggregated, or subject to appropriate contractual safeguards (including non-disclosure agreements and controller-to-controller data protection terms). We will not disclose special category data as part of any preliminary due diligence except where anonymised or subject to enhanced safeguards.
We do not sell your personal data, and we do not rent or trade email lists.
8. International transfers
Personal data we collect is primarily processed in the United Kingdom. Some of our service providers, including Google (which provides Google Analytics), process data outside the UK.
Where personal data is transferred outside the UK to our service providers, we ensure appropriate safeguards are in place, using where possible:
- an adequacy decision by the UK government (including the UK–US Data Bridge, where applicable);
- the UK International Data Transfer Agreement; or
- the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
Transfers at your request. Separately, where you ask us to send correspondence, invoices, payment information, or other information to you or a person you nominate at an address, email account, or destination outside the United Kingdom, we will do so on the basis of your explicit request and consent, or where necessary for the performance of our contract with you or with the customer on whose behalf we act. In these circumstances the transfer is made under Article 49 of the UK GDPR. Please be aware that data protection laws in the destination country may not offer the same level of protection as UK law.
You can request further information about our transfer safeguards by contacting us using the details in section 3.
9. How long we keep your data
We keep personal data only for as long as necessary for the purposes for which it was collected. Our retention approach is:
- Where we act as a data processor (in particular, patient billing data handled on behalf of a customer): six years from the date we received the data, unless a different retention period is agreed with the customer or required by law.
- Where we act as a data controller (in particular, customer records, correspondence, billing assessment responses, and accounting records): six years from the end of the financial year in which the data was created or last used, unless a different retention period is required by law.
Financial and accounting records are retained for at least six years to comply with HMRC requirements.
Where a shorter period is appropriate, we will reduce retention accordingly.
10. If you are a patient
If your consultant, clinic, hospital, or other medical professional uses HytheHopes to manage their billing and collection, we will process your personal data on their behalf. This may include your name, contact details, appointment and invoice information, and the medical specialty concerned. It may include health-related information (see section 5).
In this context, we act as a data processor for our customer, who is the data controller. This means our customer is primarily responsible for informing you about how your data is used and for handling requests to exercise your data protection rights. You should contact them in the first instance.
We handle your data strictly in accordance with the written instructions of our customer, under a data processing agreement that meets the requirements of Article 28 UK GDPR. We do not use your data for our own marketing, do not sell it, and do not share it with anyone other than as necessary for the purpose of billing and collection.
A dedicated patient privacy notice with more detail is in preparation and will be published on this website. In the meantime, if you have any question about your data, please contact us using the details in section 3, or contact your consultant, clinic, or hospital.
11. Your rights
Under UK data protection law, you have the following rights in relation to your personal data:
- To be informed about how your data is used (which is what this notice is for);
- Access — to a copy of the personal data we hold about you;
- Rectification — to have inaccurate data corrected;
- Erasure — to have your data deleted in certain circumstances;
- Restriction — to limit how your data is processed;
- Portability — to receive your data in a portable format, in certain circumstances;
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time;
- Rights in relation to automated decision-making and profiling.
We do not use automated decision-making or profiling that has legal or similarly significant effects on you.
To exercise any of these rights, please contact us using the details in section 3. We will respond within one month of receiving your request. There is no charge for exercising these rights, except in exceptional circumstances allowed by law.
To verify your identity before responding, we may ask for information to confirm who you are.
12. Cookies
We use cookies and similar technologies on our site. Full details, including how to manage your cookie preferences, are set out in our Cookie Policy.
13. Security
We take the security of personal data seriously. We use technical and organisational measures to protect data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include:
- Access controls and role-based permissions on systems holding personal data;
- Encryption of data in transit;
- Secure backup arrangements;
- Staff training on data protection and confidentiality;
- Written contracts with all data processors requiring appropriate security measures.
No system is perfectly secure, and we cannot guarantee absolute security. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of the breach, and, where the risk is high, we will also notify affected individuals.
14. Complaints
If you have a concern about how we handle your personal data, please contact us first using the details in section 3, and we will do our best to resolve it. We aim to acknowledge complaints within five working days and provide a substantive response within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
15. Changes to this notice
We may update this notice from time to time to reflect changes in our practices or in the law. When we make changes, we will update the “Last updated” date at the top of this page. Where the changes are material, we will notify affected individuals by email or through a prominent notice on our site.
16. Links to other websites
Our site may contain links to other websites operated by third parties. We are not responsible for the privacy practices of those websites. Please review their privacy notices before providing them with personal data.
