Privacy Policy
Effective date: 1 May 2026
This Privacy Policy explains how Dr. Carol Williams (“we”, “us”, “our”) collects, uses, stores and protects personal information when you visit or use www.drcarolwilliams.co.uk and any related pages or services (the “Website”).
We are committed to handling personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (“PECR”).
1. Who we are
We are the data controller for the personal information collected through this Website.
Contact details:
Dr. Carol Williams
2. Information we collect
We may collect and process the following types of information:
-
Identity and contact information you provide to us, such as your name, email address, phone number, or message content if you contact us through a form, by email, or by any other method.
-
Technical information such as IP address, browser type, device information, operating system, time zone, and pages viewed.
-
Usage information about how you use the Website, such as pages visited, time spent on pages, clicks, and referring website addresses.
-
Cookie and similar technology data collected through cookies, pixels, tags, and similar tools.
-
Communication records if you correspond with us.
-
Any other information you choose to provide voluntarily.
We do not intentionally collect special category data unless you choose to send it to us. If you do provide such data, we will only process it where we have a lawful basis to do so.
3. How we collect information
We collect information:
-
directly from you when you contact us, subscribe, submit a form, or otherwise interact with the Website;
-
automatically through cookies, server logs, and similar technologies when you browse the Website; and
-
from third parties where relevant, such as service providers supporting website functionality, analytics, advertising, or security.
4. How we use your information
We use personal data for the following purposes:
-
to operate, maintain and improve the Website;
-
to respond to enquiries and provide support;
-
to manage communications you send to us;
-
to monitor website performance, security and stability;
-
to analyse how the Website is used;
-
to display and measure advertising;
-
to comply with legal, regulatory, tax, accounting or other obligations; and
-
to establish, exercise or defend legal claims.
5. Lawful bases for processing
We rely on one or more of the following lawful bases under UK GDPR:
-
Consent — where you have given clear consent, for example for certain cookies or marketing emails.
-
Contract — where processing is necessary to respond to a request or provide a service you ask for.
-
Legal obligation — where we must process data to comply with the law.
-
Legitimate interests — where processing is necessary for our legitimate business interests and those interests are not overridden by your rights.
Where we rely on consent, you may withdraw that consent at any time.
6. Cookies and advertising
The Website uses cookies and similar technologies. These may be used for essential website functions, preferences, analytics, and advertising.
We may use Google AdSense to display advertisements on the Website. Google and its partners may use cookies or similar technologies, and may also use information such as your IP address, browser information, and browsing activity to serve and measure ads. Google’s advertising products also use records of ads served and related technical information for ad delivery and security purposes. (Google Help)
Where required by law, we will ask for your consent before setting non-essential cookies. UK ICO guidance says cookie consent must be a clear positive action, and visitors must be given easy ways to enable or disable non-essential cookies. (ICO)
You can control cookies through your browser settings and, where applicable, through any cookie banner or preferences tool displayed on the Website. You can also manage Google ad preferences through Google’s ad settings. (Google Policies)
7. Analytics and third-party services
We may use third-party services such as website analytics, hosting, embedded media, or security tools. These providers may process technical information in connection with their services.
Where third parties place or access cookies, pixels or other identifiers, they may collect information from your device or browser. We will identify such services in this Policy or in our cookie notice where applicable. (ICO)
8. Sharing your information
We may share personal data with:
-
service providers and processors who help us run the Website;
-
professional advisers, insurers, regulators, or law enforcement where required;
-
hosting, analytics, email, advertising, or security providers; and
-
other parties where you have asked us to do so or where we are legally permitted to do so.
We require our service providers to handle personal data securely and only in accordance with our instructions where they act as processors.
9. International transfers
Some of our service providers, including Google and other technology providers, may process data outside the UK. Where this happens, we will take steps intended to ensure appropriate safeguards are in place for the transfer of personal data, as required by applicable law.
10. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, reporting, or record-keeping requirements.
The retention period depends on the nature of the data and the reason we collected it. For example:
-
enquiry emails may be kept for as long as needed to handle the communication and any follow-up;
-
cookie and analytics data may be kept for the period stated in the relevant cookie notice or service settings; and
-
records needed for legal, tax or accounting purposes may be kept longer.
11. Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or misuse. However, no online system is completely secure, and we cannot guarantee absolute security.
12. Your rights
Under UK data protection law, you may have the right to:
-
request access to the personal data we hold about you;
-
request correction of inaccurate or incomplete data;
-
request erasure of your data in certain circumstances;
-
request restriction of processing in certain circumstances;
-
object to processing based on legitimate interests;
-
object to direct marketing at any time; and
-
request portability of data in certain circumstances.
Where we rely on consent, you have the right to withdraw that consent at any time.
13. Marketing communications
We will only send you marketing communications where permitted by law. You can opt out of marketing at any time by following the unsubscribe instructions in the message or contacting us directly.
14. Children
This Website is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it where appropriate.
15. Links to other websites
The Website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to read their privacy policies.
16. Complaints
If you have concerns about how we use your personal data, please contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office (ICO). The ICO is the UK regulator responsible for data protection matters, and ICO guidance says privacy notices should explain people’s rights and how to complain. (ICO)
17. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be posted on this page with the updated effective date.
18. Contact us
If you have any questions about this Privacy Policy or how we handle your information, please contact:
Dr. Carol Williams
Email: drcarolwilliams@gmail.com
