Privacy Policy
Last updated: 28 May 2026
Professor Firas Al-Niaimi (“we”, “our”, or “us”) is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website: https://www.drfirasalniaimi.co.uk/.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable privacy laws.
1. Who We Are
Website owner and data controller:
Professor Firas Al-Niaimi
Website: https://www.drfirasalniaimi.co.uk/
If you have any questions regarding this Privacy Policy or your personal data, please contact us through the contact details provided on the website.
2. Information We Collect
We may collect and process the following types of personal data:
Information You Provide Directly
This may include:
- Name
- Email address
- Telephone number
- Information submitted through contact forms
- Appointment or treatment enquiries
- Messages or correspondence you send to us
Automatically Collected Information
When you visit the website, we may automatically collect:
- IP address
- Browser type and version
- Device information
- Operating system
- Pages visited
- Date and time of access
- Referral source
- Website usage data
This information may be collected through cookies, analytics tools, and server logs.
3. How We Use Your Information
We may use your information to:
- Respond to enquiries
- Provide requested information or services
- Manage appointments or consultations
- Improve website functionality and performance
- Monitor website usage and security
- Prevent fraud, spam, or abuse
- Comply with legal and regulatory obligations
- Send communications where consent has been provided
We will only use your personal data where we have a lawful basis to do so.
4. Lawful Bases for Processing
Under UK GDPR, we rely on the following lawful bases:
- Consent — where you have given consent for specific processing activities
- Legitimate interests — to operate, improve, and secure our website and services
- Contractual necessity — where processing is necessary to respond to enquiries or provide services
- Legal obligations — where we are required to retain or disclose information under applicable law
5. Cookies and Tracking Technologies
We use cookies and similar technologies to improve user experience, analyse website traffic, and support website functionality.
These may include:
- Essential cookies
- Analytics cookies
- Functional cookies
- Security and anti-spam cookies
For more information, please see our Cookie Policy.
6. Google Analytics and Google Services
We use services provided by Google, which may include:
- Google Analytics
- Google Tag Manager
- Google Site Kit
- Google reCAPTCHA
These services may collect information about your use of the website, including IP address, device information, and browsing activity.
Google may process this information on servers located outside the United Kingdom.
Google reCAPTCHA is used to protect forms from spam and abuse.
You can learn more about how Google uses data at:
https://policies.google.com/privacy
7. WooCommerce and Ecommerce Functionality
Where applicable, WooCommerce may process personal data required to support purchases, bookings, or transactional functionality.
This may include:
- Billing information
- Order information
- Transaction records
- Cart/session information
Payment information is processed securely through third-party payment providers and is not stored directly on our servers unless explicitly stated.
8. Data Sharing
We do not sell your personal data.
We may share information with trusted third-party service providers where necessary to operate the website and services, including:
- Website hosting providers
- Analytics providers
- Security and spam prevention services
- Email delivery providers
- Technical support providers
These providers are required to handle personal data securely and only for authorised purposes.
We may also disclose information where required by law or to protect legal rights.
9. International Transfers
Some third-party providers may process personal data outside the UK.
Where international transfers occur, we take reasonable steps to ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, security, and regulatory requirements.
Retention periods may vary depending on the nature of the information and legal obligations.
11. Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or disclosure.
Security measures may include:
- SSL encryption
- Website security monitoring
- Access controls
- Security plugins and logging systems
However, no method of transmission over the internet can be guaranteed to be completely secure.
12. Your Rights
Under UK data protection law, you may have rights including:
- The right to access your personal data
- The right to request correction of inaccurate data
- The right to request deletion of your data
- The right to restrict processing
- The right to object to processing
- The right to data portability
- The right to withdraw consent
To exercise your rights, please contact us using the details on our website.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
13. Third-Party Links
Our website may contain links to external websites. We are not responsible for the privacy practices or content of third-party websites.
We encourage users to review the privacy policies of any external websites they visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, technology, or our services.
Any updates will be posted on this page with a revised “Last updated” date.
15. Contact
For privacy-related enquiries, please contact us through the contact details available on: