Privacy Policy

How Physio Central collects, uses and protects your personal data across our clinics and website. Transparent, GDPR-compliant, and written in plain English.
Last updated: 23 September 2026  ·  Version 2.1UK GDPR • HCPC COMPLIANT

1. Who we are & scope

Physio Central (“we”, “us”) is the data controller for personal data collected via our website physiocentral.co.uk, booking system, phone, email and in-clinic forms across our all London clinics: Wembley, Ealing, Baker Street and 3 partner sites.

Controller: Physio Central Ltd, London, UK. Data Protection contact: info@physiocentral.co.uk — 0330 912 7579. We are registered with the ICO.

This policy applies to patients, website visitors, enquirers and job applicants. Clinical information is also governed by HCPC standards and NHS record-keeping guidance.

2. What we collect

  • Contact & booking: name, phone, email, preferred clinic/time, marketing preferences.
  • Clinical: history, assessment findings, diagnosis, treatment plan, exercise programme, progress notes, outcome scores — stored in our encrypted clinical system.
  • Payment: amount, method, transaction ID. We never store full card numbers — payments via Stripe / Apple Pay / Google Pay, PCI-DSS compliant.
  • Communications: emails, calls, SMS reminders, feedback and complaints.
  • Website & analytics: anonymised page views, device/browser, approximate location, referrer — via essential cookies and (with consent) analytics cookies. No cross-site tracking.
  • Applicants: CV, right-to-work, references, HCPC registration where relevant.

Children: For under-18s we collect parent/guardian contact and process health data only where necessary for care with appropriate consent.

3. How we use it

  • Provide physiotherapy: assess, treat, plan, review across any clinic/therapist you choose — one shared record.
  • Manage bookings: confirmations, reminders, rescheduling, waitlists, cancellations.
  • Clinical governance: audit, supervision, safety, continuity of care, referrals (GP/imaging) with your consent.
  • Contact you about appointments and — only if you opt in — occasional service updates. No spam.
  • Improve our website and services (aggregated analytics).
  • Legal: comply with HCPC, HMRC, insurance and court orders where required.

We do not sell your data. We do not use automated decision-making that produces legal effects.

4. Legal basis (UK GDPR)

6
Art.6: Contract (booking/care), Legitimate interests (service improvement, security), Legal obligation (records, tax), Consent (marketing/analytics) — withdrawn anytime.
9
Art.9 (health data): Healthcare provision (Art.9(2)(h)) plus explicit consent for sharing between Physio Central therapists involved in your care. You may restrict sharing, but it may affect continuity.

5. Your shared record — how it works

Your clinical record is held on an encrypted, GDPR-compliant clinical system (UK/EU data residency) with role-based access. Only Physio Central physiotherapists directly involved in your care can access it. Access is logged and audited.

Benefits: visit any of our clinics, any therapist — history, plan and exercises follow you. No repeat forms. Progress is tracked.

You can request a copy (SAR) at any time — see §8. We provide it within 1 month in a portable PDF.

EncryptedAES-256 at rest & TLS in transit
Role-basedNeed-to-know access only
AuditedAccess logs & reviews

6. Sharing & processors

We share only where necessary:

  • Clinical system & booking platform (processors) under Art.28 contracts — UK/EU hosting.
  • Payment provider (Stripe) — card data never touches our servers.
  • Email/SMS reminder service for appointment comms.
  • Referrals: GP, consultant or imaging only with your explicit consent and referral letter.
  • Legal: where required by law, HCPC or court order.

We do not sell data. International transfers (if any) use UK adequacy or SCCs.

7. Retention

Clinical records
Per HCPC/NHS guidance
8 years after last contact
Minors
Until age 25 (or 26 if 17 at last contact)
Longer
Enquiries (non-patients)12 months
Analytics14–26 months (aggregated)

After retention, data is securely deleted or anonymised. Invoices kept 6 years for HMRC.

8. Your rights

You have rights under UK GDPR (subject to clinical/legal retention):

Access (SAR)Copy of your data — free, within 1 month
RectificationCorrect inaccurate facts
ErasureWhere retention rules allow
Restriction & objectionLimit or object to processing
PortabilityReceive data in portable form
Withdraw consentFor marketing/analytics or sharing

To exercise: email info@physiocentral.co.uk with subject “Data request”. We verify ID first. You also have the right to complain to the ICO (Wycliffe House, SK9 5AF) but please contact us first.

9. Cookies & analytics

We use only what we need:

✓

Essential cookies: booking, load balancing, security — always on, no consent needed.

◯

Analytics (opt-in): anonymised page views to improve the site (GA4 / similar). Disabled until you consent via banner. Withdraw in browser or via banner.

You can block non-essential cookies in your browser. Our site remains fully usable.

10. Security & contact

  • Encryption at rest (AES-256) and in transit (TLS 1.2+), strong passwords + MFA for staff, access reviews, device encryption.
  • Staff are trained, HCPC-registered and bound by confidentiality.
  • We report qualifying personal data breaches to the ICO within 72h and to affected individuals where required.
Questions about privacy?Data Protection — info@physiocentral.co.uk · 0330 912 7579
Contact DPO →

We may update this policy with notice on this page. Last updated date above is the effective version. For material changes we will notify by email/SMS where appropriate.

Need a copy of your record or want to update consent?

One email. We handle the rest — access, correction, sharing preferences, marketing opt-out. Response within 1 month.