Privacy notice
Effective 1 October 2026.
Who is responsible
SHINIMINI LTD trading as FixedAbroad is the controller for our patient coordination records. Company number 15190504, registered in England and Wales. Registered office: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF. For privacy enquiries, withdrawal or requests, email leah.th@fixedabroad.com or call +44 7455 700029.
What we collect and why
When you enquire, we use your contact details, treatment interests, budget and preferred dates to answer your request, qualify your enquiry and arrange coordination. Where necessary for requested pre-contractual steps or our contract, the basis is Article 6(1)(b) UK GDPR. Providing necessary contact details enables us to answer and arrange the service; you can enquire without buying.
For invoices and statutory accounting records we use Article 6(1)(c), legal obligation. For proportionate security, fraud prevention and handling ordinary administrative disputes we use Article 6(1)(f), legitimate interests. You may object to processing based on legitimate interests. Health information has an additional condition as explained below.
Clinical images and histories
Photos used for assessment, X-rays, CBCT scans and medical histories are health data. Before requesting them, we ask for a separate, recorded, specific opt-in naming SHINIMINI, the assessment purpose, the proposed receiving clinic and Turkey. For necessary coordination we use Article 6(1)(b) with Article 9(2)(a), explicit consent for health data.
Consent to treatment is handled by the clinician. Visiting this website or sending a photograph does not complete our health-data consent process. You can decline or withdraw health-data consent by contacting us. Withdrawal stops future consent-based processing and sharing and may prevent assessment or ongoing coordination. It does not change the lawfulness of earlier processing.
Please do not send clinical images, scans or medical histories through our public enquiry forms, WhatsApp or an automated call. We provide an agreed secure clinical route only once the recipient, consent, security and transfer safeguards are in place. We share only the information the clinician needs. A new clinic recipient requires an appropriate fresh consent.
Who receives information
Authorised staff use information for coordination. Our website hosting and email services, WhatsApp service supplied through Meta, callback provider Retell, and workflow systems handle the information necessary for the enquiry channels you use. Automated callbacks can process voice and call records. Please keep these channels to appointment and administrative enquiries; ask a person to arrange a secure route for clinical information.
The receiving clinic is identified to you before clinical sharing. It normally acts as a separate controller for its own assessment and treatment and provides its own privacy information. We confirm roles and permitted uses with each clinic. We do not authorise clinical images or health details for group chats, advertising audiences or general-purpose AI tools.
International transfers
Turkey has no UK adequacy decision. Clinical sharing with a separate clinic there, including remote access to UK-held files, requires a documented transfer route. For routine referrals we require a UK International Data Transfer Agreement or, where appropriate, EU standard contractual clauses with the UK Addendum, plus a transfer assessment and any additional protections it identifies. We identify the actual receiving clinic and safeguards before sharing. You may request information or a redacted copy of the applicable safeguards.
Health-data consent is separate from the transfer mechanism. An explicit-consent exception for a particular transfer would require separate information about that transfer and its risks and a documented assessment of whether the exception applies. It is not our default route for recurring clinic referrals.
Enquiry-channel suppliers may process information outside the UK under their own arrangements. Clinical use of those channels is restricted pending a review of their contracts, locations, security and retention. Contact us for the current supplier and transfer details relevant to your enquiry.
Security and retention
Our approved clinical workflow requires restricted staff access, MFA, encrypted storage and transfer, and records of consent and sharing. It remains closed to clinical uploads or referrals until those controls and the clinic-specific arrangements are confirmed. We use a booking reference where practical and remove unnecessary metadata while preserving clinically necessary information.
For our own records, the retention policy is: unsuccessful enquiries, up to 12 months after the last substantive contact; clinical files for a case that does not proceed, 30 days after closure; clinical files for a completed case, 90 days after the agreed administrative follow-up ends. Withdrawal brings forward deletion of consent-based clinical files once the request is actioned, unless a separate lawful retention basis applies.
We retain necessary financial records for six years after the relevant financial year. Minimal agreement, consent and service-delivery evidence may be retained for six years after closure where justified for legal claims. This excludes a blanket right to keep clinical images. Retaining health data for an actual or anticipated claim requires a separate basis, including Article 9(2)(f) where applicable, and periodic review. We explain any relevant legal hold. The clinic sets and explains its own lawful clinical-record retention.
Marketing, publication and cookies
Optional marketing and publication of before-and-after photographs require separate permissions where consent is relied on. Refusing them does not affect coordination. We do not use assessment consent as publication permission. You can withdraw optional permissions or unsubscribe at any time.
Our cookie choice controls optional analytics and advertising cookies. These use consent under Article 6(1)(a), alongside applicable electronic-communications rules. See the cookie policy. Website use alone is not cookie or health-data consent.
Your rights and complaints
You can ask for access, correction, deletion, restriction and, where applicable, portability. You can object to legitimate-interest processing and withdraw consent. Rights depend on the circumstances and lawful retention duties. We normally respond within one month, with any permitted extension explained.
We do not use solely automated decisions with legal or similarly significant effects to decide clinical suitability. A treating clinician makes that decision. To raise a concern, contact leah.th@fixedabroad.com. You may also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint/ or call 0303 123 1113.