Last updated: 27 July 2026
1. Who we are
TTMJ Limited (“TTMJ”, “we”, “us”) is the data controller for the personal data described in this policy.
- Company: TTMJ Limited, registered in England & Wales, company number 12763805
- Registered address: 13 Hanover Square, London W1S 1HN, United Kingdom
- Email: info@ttmj.co.uk
- Telephone: +44 7471 488639
TTMJ is a business-to-business consultancy. Our clients are healthcare clinics; we are not a healthcare provider and we do not deliver medical treatment.
2. The personal data we collect
- Enquiry and contact data — name, email address, telephone number, company or clinic name, country and the content of your message, submitted through our contact form or by email, phone or WhatsApp.
- Event data — the name and contact details of attendees who register for an event we organise, plus attendance records.
- Business contact data — the names and work contact details of clinic staff and suppliers we work with.
- Technical data — data your browser sends when you visit this site, such as IP address, browser type and pages requested, recorded in standard server logs by our hosting provider.
3. Health information
TTMJ does not routinely collect or store patient medical records, clinical images or treatment histories. Where a prospective patient wishes to share medical information (for example x-rays or photographs) in order to obtain a treatment plan, that information is provided directly to the treating clinic, which acts as the controller for it.
If health information is nevertheless sent to us — for example within the free-text field of an enquiry form — we treat it as special category data under Article 9 of the UK GDPR, pass it to the relevant clinic only with the individual’s explicit consent, and delete our copy once it is no longer needed.
4. Why we use your data, and our lawful basis
- Responding to enquiries and providing our services — necessary for the performance of a contract, or for our legitimate interests in responding to business enquiries (UK GDPR Article 6(1)(b) and 6(1)(f)).
- Organising events and managing attendance — performance of a contract with our clinic client, and our legitimate interests in running those events (Article 6(1)(b), 6(1)(f)).
- Connecting prospective patients with a clinic — consent, and where health data is involved, explicit consent (Article 6(1)(a), Article 9(2)(a)).
- Marketing communications — consent, or our legitimate interests in business-to-business marketing where permitted by PECR. You can opt out at any time.
- Legal, accounting and security obligations — compliance with a legal obligation, and our legitimate interests in protecting our systems (Article 6(1)(c), 6(1)(f)).
5. Who we share data with
- Partner clinics — where you have asked to be connected with a clinic, or where you attend an event on a clinic’s behalf. Many of these clinics are located outside the United Kingdom.
- Service providers — our website host, email provider and the form-delivery service used to send contact form submissions to our inbox. They process data on our instructions only.
- Professional advisers and authorities — where we are required to share data by law, or to establish or defend legal claims.
We do not sell personal data.
6. International transfers
Because our partner clinics and some of our suppliers operate outside the UK, your data may be transferred to countries that do not have UK adequacy status. Where that happens we rely on an appropriate safeguard under Articles 44–49 of the UK GDPR — normally the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — or, for a referral you have requested, on your explicit consent. You can ask us for details of the safeguard used for a particular transfer.
7. How long we keep data
- Enquiries that do not proceed — up to 24 months from the last contact.
- Client and event records — for the duration of the relationship and for six years afterwards, to meet UK accounting and limitation requirements.
- Any health information received in error or in passing — deleted as soon as it has been passed to the clinic, and in any event within 30 days.
- Server logs — retained by our hosting provider for a short period as part of their standard operation.
8. How we protect data
This site is served over HTTPS. Access to our systems is limited to staff who need it, administrative areas are password protected, and data is stored on reputable hosted services. No transmission over the internet can be guaranteed to be completely secure, so we encourage you not to send sensitive medical detail through the website contact form.
9. Your rights
Under UK data protection law you have the right to:
- be informed about how we use your data;
- request a copy of the data we hold about you;
- have inaccurate data corrected;
- ask us to erase your data, or to restrict how we use it;
- object to processing based on legitimate interests, and to direct marketing at any time;
- request that data you provided be transferred to another organisation (data portability);
- withdraw consent at any time, where consent is our lawful basis.
To exercise any of these rights, email info@ttmj.co.uk. We will respond within one month.
10. Complaints
If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office: ico.org.uk/make-a-complaint, helpline 0303 123 1113.
11. Cookies
Details of the cookies and third-party services used on this site are set out in our Cookie Policy.
12. Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it was last revised.