Privacy Policy for Victor the Physio

This privacy notice tells you what to expect us to do with your personal information.

  • Contact details

  • What information we collect, use, and why

  • Lawful bases and data protection rights

  • Where we get personal information from

  • How long we keep information

  • Who we share information with

  • How to complain

Contact details

  • Telephone: 07969824160

  • Email: admin@victorthephysio.uk

What information we collect, use, and why

We collect or use the following information to provide patient care, services, pharmaceutical products and other goods:

  • Name, address and contact details

  • Gender

  • Date of birth

  • Next of Kin details including any support networks

  • Health information (including medical conditions, allergies, medical requirements and medical history)

  • Information about care needs (including disabilities, home conditions, medication and dietary requirements and general care provisions)

  • Test results (including psychological evaluations, scans, bloods, x-rays, tissue tests and genetic tests)

  • Payment details (including card or bank information for transfers and direct debits)

  • Insurance policy details

  • Credit reference information

  • Usage data

We also collect the following special category information to provide patient care, services, pharmaceutical products and other goods. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information for patient app or portal functionality:

  • Names and contact details

  • Addresses

  • Medical history

  • Payment details

  • Account information, including registration details

We also collect the following special category information for patient app or portal functionality. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information to comply with legal requirements:

  • Name

  • Contact information

  • Identification documents

  • Health and safety information

  • Any other personal information required to comply with legal obligations

  • Insurance details

We also collect the following special category information to comply with legal requirements. This information is subject to additional protection due to its sensitive nature:

  • Health information

We collect or use the following personal information for information updates, marketing or market research purposes:

  • Names and contact details

  • Addresses

  • Marketing preferences

  • Website and app user journey information

  • IP addresses

  • Personal information used for the purpose of research

  • Records of consent, where appropriate

We also collect the following special category information for information updates, marketing or market research purposes. This information is subject to additional protection due to its sensitive nature:

  • Health information

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyse Our Service.

You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.

Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close your web browser. Learn more about cookies: All About Cookies.

We use both session and persistent Cookies for the purposes set out below:

  • Necessary / Essential Cookies

    • Type: Session Cookies

    • Administered by: Us

    • Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.

  • Cookies Policy / Notice Acceptance Cookies

    • Type: Persistent Cookies

    • Administered by: Us

    • Purpose: These Cookies identify if users have accepted the use of cookies on the Website.

  • Functionality Cookies

    • Type: Persistent Cookies

    • Administered by: Us

    • Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.

  • Tracking and Performance Cookies

    • Type: Persistent Cookies

    • Administered by: Third-Parties

    • Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify you as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device you use to access the Website. We may also use these Cookies to test new advertisements, pages, features or new functionality of the Website to see how our users react to them.

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

  • Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.

  • Your right to rectification - You have the right to ask us to correct or delete personal information you think is inaccurate or incomplete. Read more about the right to rectification.

  • Your right to erasure - You have the right to ask us to delete your personal information. Read more about the right to erasure.

  • Your right to restriction of processing - You have the right to ask us to limit how we can use your personal information. Read more about the right to restriction of processing.

  • Your right to object to processing - You have the right to object to the processing of your personal data. Read more about the right to object to processing.

  • Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you. Read more about the right to data portability.

  • Your right to withdraw consent – When we use consent as our lawful basis you have the right to withdraw your consent at any time. Read more about the right to withdraw consent.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide patient care, services, pharmaceutical products and other goods are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legitimate interests - we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for patient app or portal functionality are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information to comply with legal requirements are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for information updates, marketing or market research purposes are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.

  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Where we get personal information from

  • Directly from you

  • Family members or carers

  • Insurance companies

How long we keep information

I will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Notice. I will retain and use Your Personal Data to the extent necessary to comply with my legal obligations (for example, if i am required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

In terms of my legal obligations as a health care service, your health records fall into ‘special category data’ and as such, I am required by law to retain your health records for 8 years after the conclusion of treatment or death.

I will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of my Service, or if I am legally obligated to retain this data for longer time periods.

Who we share information with

Data processors

Cliniko

This data processor does the following activities for us: Cliniko is practice management software that is used to book appointments, write and store client notes and produce invoices.

Physitrack

This data processor does the following activities for us: Physitrack is a software used to produce and send exercise programs to clients

Cetra Health

This data processor does the following activities for us: Cetra Health is a software used to send information sheets to clients about their prognosis/diagnosis

Healthcode

This data processor does the following activities for us: Healthcode is a web-based portal used to produce and send clients invoices to their respective health insurance provider.

Others we share personal information with

  • Other health providers (eg GPs and consultants)

  • Insurance companies, brokers and other intermediaries

  • Emergency services

Analytics

This website is hosted by Squarespace. Squarespace collects personal information when you visit this website, including:

  • Information about your browser, network and device

  • Web pages you visited prior to coming to this website

  • Web pages you view while on this website

  • Your IP address

Squarespace needs the data to run this website, and to protect and improve its platform and services. You can read more about how Squarespace uses your data (site usage information of end users) for its own purposes in their Privacy Policy.

This specific website collects personal information to power our site analytics, including:

  • Information about your browser, network, and device

  • Web pages you visited prior to coming to this website

  • Your IP address

This information may also include details about your use of this website, including:

  • Clicks

  • Internal links

  • Pages visited

  • Scrolling

  • Searches

  • Timestamps

We provide this information to Squarespace, our website analytics provider, to learn about site traffic and activity.

We may use third-party Service providers to monitor and analyse the use of our Service.

Google Analytics Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network. You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add- on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Cookies

This website uses cookies and similar technologies, which are small files or pieces of text that download to a device when a visitor accesses a website or app. For information about viewing the cookies dropped on your device, visit The cookies Squarespace uses.

Duty of confidentiality

We are subject to a common law duty of confidentiality. However, there are circumstances where we will share relevant health and care information. These are where:

  • you’ve provided us with your consent (we have taken it as implied to provide you with care, or you have given it explicitly for other uses);

  • we have a legal requirement (including court orders) to collect, share or use the data;

  • on a case-by-case basis, the public interest to collect, share and use the data overrides the public interest served by protecting the duty of confidentiality (for example sharing information with the police to support the detection or prevention of serious crime);

  • If in England or Wales – the requirements of The Health Service (Control of Patient Information) Regulations 2002 are satisfied; or

  • If in Scotland – we have the authority to share provided by the Chief Medical Officer for Scotland, the Chief Executive of NHS Scotland, the Public Benefit and Privacy Panel for Health and Social Care or other similar governance and scrutiny process.

Changes to this Privacy Notice

We may update our Privacy Notice from time to time. We will notify You of any changes by posting the new Privacy Notice on this page.

You are advised to review this Privacy Notice periodically for any changes. Changes to this Privacy Notice are effective when they are posted on this page.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address: Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF