Privacy and data protection

Your information, handled with care.

This notice explains how NeuroPath uses and protects personal information when you visit our website, contact us, receive an information pack, complete consent or questionnaires, or use an assessment pathway.

Effective from 7 October 2026. Version privacy-v1.0-2026-10-07.

Restricted access

Access to assessment information is limited to people with a legitimate role in the pathway.

Secure links

Consent and questionnaire links are personal, time-limited and do not give general portal access.

No automated diagnosis

Questionnaire responses are clinician-reviewed inputs, not an automated diagnosis or treatment decision.

1

Who is responsible for your information

NeuroPath Services Ltd, company number 17068367, is the controller for personal information collected through this website and in connection with our assessment pathways. Our registered office is 45 Albemarle Street, 3rd Floor, Mayfair, London, England, W1S 4JL. For privacy questions or to exercise your rights, contact us at info@neuropathservices.com.

2

Information we collect

Depending on how you contact or use NeuroPath, this may include your name, contact details, preferred contact method, enquiry details, appointment and communication records, identity or consent information, and information relevant to an assessment. Assessment, questionnaire, report and safeguarding information may include health information. We ask that you do not send detailed medical records or urgent safety information through a general website enquiry form or WhatsApp.

3

Why we use your information

We use information to respond to enquiries, provide requested information packs and consent forms, arrange and administer assessment pathways, communicate with you or an appropriate parent, carer or informant, maintain clinical and service records, protect safety, manage complaints and meet legal, regulatory and professional obligations. We do not sell personal information or use it for third-party advertising.

4

Our lawful bases and health information

The lawful basis depends on the activity. It may include taking steps at your request before entering an agreement, performance of a contract, our legitimate interests in running a safe and effective service, compliance with a legal obligation, protection of vital interests in limited circumstances, and consent where this is appropriate. Where we process health or other special-category information, we use an applicable UK GDPR condition, such as the provision or management of health or social care, public interest in health, or explicit consent where required. Consent is not treated as the only basis for all processing.

5

Who we may share information with

Access is limited to authorised NeuroPath staff and clinicians with a genuine role in the relevant pathway. We use carefully selected providers for secure hosting, file storage, email, communications and business operations under appropriate contractual controls. We may share information with other healthcare professionals, referrers, schools, insurers, regulators, legal advisers or public authorities only where you ask us to, where it is necessary for the service, or where the law, safeguarding duties or a valid legal request requires it. We do not give parent, guardian, teacher or informant questionnaire links general access to a patient portal.

6

How long we keep information

We keep information only for as long as necessary for the purpose it was collected, including clinical, legal, professional, accounting, complaint and safeguarding requirements. Clinical records are retained in line with NeuroPath’s retention schedule and applicable professional requirements. Enquiry information that does not progress to a service is reviewed and securely deleted or anonymised when it is no longer needed. Retention periods may be extended where a complaint, legal claim, investigation or legal obligation applies.

7

Security and confidential handling

NeuroPath applies access controls, time-limited invitation links, audit records and data-minimisation measures appropriate to the information being handled. No system is completely risk-free, but we work to protect information against unauthorised access, loss, alteration or disclosure. Please use the secure links NeuroPath sends for consent and questionnaires rather than sending sensitive information through ordinary email or WhatsApp.

8

Your rights

Subject to the UK GDPR and applicable exemptions, you may ask for access to your information, correction of inaccurate information, erasure, restriction, objection, portability where applicable, or to withdraw consent where processing depends on it. Withdrawal does not affect processing already carried out and may mean we cannot continue with an optional activity. To make a request, email info@neuropathservices.com. We may need to verify identity before responding.

9

Automated decisions and safety

NeuroPath does not use website forms, questionnaires or scores to make a solely automated diagnosis, treatment recommendation, eligibility decision or urgent-risk decision. Questionnaire results are clinician-reviewed assessment inputs. NeuroPath is not a crisis or emergency service. If you or someone else is in immediate danger, call 999 or attend A&E. For urgent mental health support when there is no immediate danger, contact NHS 111 and select the mental health option, your GP or a local urgent mental health service.

10

Cookies, external links and changes to this notice

The website may use essential technical services and privacy-respecting analytics to operate, secure and improve the website. External websites and social platforms have their own privacy notices and are not controlled by NeuroPath. We may update this notice when our services, systems or legal obligations change. The current version and effective date are shown below.

11

Complaints

Please contact NeuroPath first at info@neuropathservices.com so we can try to resolve a concern. You may also complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at ico.org.uk/make-a-complaint.