Privacy Notice
Last updated May 2026
This notice explains how Dr Andrew Margo (“the practice”, “I”) handles personal information received through this website. It is written in plain English and reflects the requirements of the UK GDPR and Data Protection Act 2018.
Who is the data controller
Dr Andrew Margo, Consultant Psychiatrist, GMC No. 1511932. For any data-related question, please contact my PA, Carol Beard, at carolatdrandrewmargo@gmail.com.
What data this site collects
This website does not collect any personal data on its own. There are no cookies, no analytics, no
tracking pixels and no contact form. The only way to contact the practice from this site is through a
mailto: link, which opens your own email application.
Data you send by email
When you choose to send an email enquiry, the content of your message and your email address are received in my PA’s professional inbox. This information is used solely to respond to your enquiry and, if you become a patient, to provide and document your clinical care in line with GMC and Caldicott guidance.
Lawful basis
For initial enquiries, the lawful basis is your consent and my legitimate interest in responding. For clinical care, the lawful bases are the provision of healthcare under Article 9(2)(h) UK GDPR, alongside contract.
How long data is kept
Enquiry emails that do not lead to clinical contact are deleted within twelve months. Clinical records are retained in line with NHS, Royal College of Psychiatrists and Medical Defence Union retention guidance.
Your rights
You have the right to access the information I hold about you, to ask for corrections, and in certain circumstances to request erasure or restriction. To exercise these rights, please email carolatdrandrewmargo@gmail.com. You also have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk).
Sharing
I do not share enquiry data with any third party. Where clinical care requires it, information may be shared with your GP, treating clinicians, or insurer with your consent. The hospital at which I consult — The Holly (Nuffield Health), Buckhurst Hill — operates its own separate privacy policy for any records it holds about your care.
Security
Email is transmitted over standard internet infrastructure. For sensitive clinical content I will, where appropriate, move communication to a secure channel.