Privacy Policy

Privacy Policy

1. Introduction and Contact Details

Providence Physio (“we,” “us,” or “our”) is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website or receive clinical services from us.

 

Data Controller

  • Data Controller Name: Providence Physio
  • Website Address: https://providencephysio.co.uk/
  • Registered Address: 1 East Street, Hythe, Kent, CT21 5ND
  • Data Protection Contact: Srinivasulu Reddy
  • Email Address: info@providencephysio.co.uk

2. Information We Collect About You

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

CategoryPurposeRequired for Function?
A. Strictly Necessary CookiesThese cookies are essential for you to browse the website and use its features, such as accessing secure areas or remembering your cookie consent preference. Without these, the website cannot function correctly.Yes
B. Analytical/Performance CookiesThese cookies collect information about how visitors use our website (e.g., which pages are visited most often, or if they receive error messages). We use this data to improve the way our website works. (e.g., Google Analytics).No (Require Consent)
C. Functionality CookiesThese cookies allow the website to remember choices you make (such as your language or region) and provide enhanced, more personal features. They may also be used to provide services you have asked for, such as using our online booking widget.No (Require Consent)
D. Targeting/Marketing CookiesThese cookies are used to deliver advertisements more relevant to you and your interests. They are also used to limit the number of times you see an advertisement and help measure the effectiveness of the advertising campaigns.No (Require Consent)

3. How We Collect Your Data
We use different methods to collect data from and about you, including:

  • Direct Interactions: You provide us with your Identity, Contact, Financial, and Clinical Data when you:
    • Book an appointment online, by phone, or in person.
    • Complete patient registration and consent forms.
    • Communicate with us via email, phone, or messaging.
  • Automated Technologies or Interactions: As you interact with our website, we automatically collect Technical and Usage Data using cookies and similar technologies (see our separate Cookie Policy).
  • Third Parties: We may receive Personal Data about you from third parties, such as:
    • Referral letters from your GP, Consultant, or another healthcare professional.
    • Private medical insurers confirming your coverage.
    • Online booking platforms or payment providers.

 

4. How and Why We Use Your Data (Legal Basis)
Under GDPR, we must have a lawful basis to process your personal data.

A. General Personal Data (Identity, Contact, Financial, etc.)

Purpose of ProcessingLawful Basis for Processing
To manage your registration and provide clinical services.Performance of a contract with you.
To process payments for services rendered.Performance of a contract with you; Necessary for our legitimate interests (to recover debts due to us).
To send you essential appointment reminders or changes.Necessary for our legitimate interests (running our business, service provision).
To comply with our legal and regulatory obligations.Necessary to comply with a legal obligation (e.g., tax, professional regulations).

B. Special Category Data (Health/Clinical Data)
Clinical notes, treatment plans, and medical history are considered Special Category Data and require a stricter legal basis.

We process your health data because it is necessary for the provision of healthcare, specifically the diagnosis, treatment, or management of a health condition by a healthcare professional (physiotherapist). This is permitted under GDPR Article 9(2)(h).

5. Data Sharing and Disclosure
We may share your personal data with the following parties:

  • Healthcare Professionals: Your GP, Consultant, or other healthcare providers (e.g., massage therapists, dietitians) where required for the continuity of your care and treatment. This is typically done with your explicit consent.
  • Regulators and Legal Authorities: We may disclose your information to the HCPC, HMRC, or other legal or regulatory authorities if legally required to do so.
  • Third-Party Service Providers: These include IT and system administration services, website hosting, payment processors, and our secure electronic clinical record system providers. We only share the minimum data necessary and require third parties to respect the security of your data and treat it in accordance with the law.
  • Private Medical Insurers: If you are claiming through insurance, we will share the necessary clinical and financial details with your insurer to process payment.

We do not sell, rent, or trade your personal data to any external third parties for marketing purposes.

6. Data Security and Retention
6.1 Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way. This includes password protection, data encryption, and secure clinical record systems. Access to your personal data is limited to employees, agents, and other third parties who have a business need to know.

6.2 Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements.

As a healthcare provider in the UK, we must adhere to professional guidelines. We typically retain adult patient clinical records for a minimum of 8 years after the last occasion on which treatment was provided, or until the patient’s 25th birthday if the patient was a child.

7. Your Legal Rights Under GDPR
Under the GDPR, you have the right to:

  1. Request access to your personal data (commonly known as a “data subject access request”).
  2. Request rectification of the personal data that we hold about you if it is inaccurate or incomplete.
  3. Request erasure of your personal data (the “right to be forgotten”). Note: This right is heavily restricted concerning clinical records which we are legally required to retain.
  4. Object to processing of your personal data where we are relying on a legitimate interest.
  5. Request restriction of processing of your personal data.
  6. Request the transfer of your personal data to you or a third party (data portability).
  7. Withdraw consent at any time where we are relying on consent to process your personal data.

If you wish to exercise any of these rights, please contact our Data Protection Contact using the details provided in Section 1.

8. Making a Complaint
If you are not satisfied with our response to any privacy concerns, or if you believe we are processing your personal data unlawfully, you have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.

ICO Contact Details: Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Website: https://www.ico.org.uk/

9. Changes to This Privacy Policy
We may update this policy periodically. We will notify you of significant changes by posting the new policy on our website and updating the “Last Updated” date at the top of this page.