1. Who we are
Harding Physiotherapy Ltd (‘we’, ‘us’, ‘our’) is a private physiotherapy and sports therapy clinic. We are the data controller for the personal information we collect and use about you. This means we are responsible for deciding how and why your personal data is processed and for ensuring that it is handled lawfully, fairly and transparently.
Our clinicians are regulated healthcare professionals registered with the Health and Care Professions Council (HCPC), the Chartered Society of Physiotherapy (CSP), PhysioFirst, the Sports Therapy Association (STA) and the Acupuncture Association of Chartered Physiotherapists (AACP). As such, we are bound by professional and ethical obligations regarding the confidentiality of patient information, which sit alongside our legal obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
Our contact details
Harding Physiotherapy Ltd
2 West Newlands, Somersham, Huntingdon, Cambridgeshire, PE28 3EB
Tel: 01487 843 844
Email: info@hardingphysiotherapy.co.uk
Website: www.hardingphysiotherapy.co.uk
To exercise any of your data protection rights, or if you have any questions about this policy, please contact us using the details above.
2. Scope of this policy
This privacy policy applies to:
- Patients and prospective patients who attend our clinic for physiotherapy, sports therapy, acupuncture, sports massage, body composition testing or prehabilitation services.
- Individuals who contact us via telephone, email, website enquiry form or any other means.
- Visitors to our website hardingphysiotherapy.co.uk
- Insurance company representatives and referrers (GPs, consultants or other healthcare professionals) who share patient information with us.
- Room-hire clients and associated healthcare professionals who use our facilities.
This policy does not apply to third-party websites linked from our website. Those websites have their own privacy policies and data controllers.
3. What personal data we collect
Clinical and Health Data
Because we are a healthcare provider, much of the information we collect is special category data under Article 9 UK GDPR (health data). We collect:
- Your full name, date of birth and contact details (address, telephone, email).
- Details of your GP and any other treating clinicians.
- Your medical history, current medication and any relevant co-morbidities.
- Records of your assessment, examination findings, clinical diagnosis, and treatment notes.
- Your rehabilitation programme, home exercise plans and treatment outcomes.
- Body composition data where you undertake InBody scanning (including body fat mass, visceral fat levels, muscle mass and hydration).
- Information about your insurance provider, policy number and authorisation code where applicable.
- Payment and invoicing information (card or cash payment records, outstanding balances).
Website and administrative data
When you use our website or contact us, we may also collect:
- Your name, email address and message content when you submit an enquiry or contact form.
- Your IP address, browser type, pages visited and timestamps, collected via Google Analytics and our hosting provider.
- Cookie data as described in our separate Cookie Policy.
4. How and why we use your personal data
Purpose
UK GDPR Article 6 Basis
Article 9 Condition (health data)
Providing physiotherapy, sports therapy, acupuncture and related clinical services
Maintaining accurate clinical records and treatment notes
Communicating with the GP, consultant, other health professional or insurer who referred you, about your assessment, diagnosis and treatment
Sharing your clinical information with a third party who is not involved in your referral or care (for example, at your request)
Processing payment and managing invoices
Liaising with your private health insurer for billing and authorisation
Sending appointment reminders and clinic communications
Not applicable
Responding to website and telephone enquiries
Complying with our legal and regulatory obligations (HCPC, ICO, legal requests)
Improving our website and marketing our services (Google Analytics)
Not applicable
Managing room-hire arrangements with associated practitioners
Not applicable
5. Health data — additional safeguards
Important — Special Category Data
All clinical staff are bound by their professional body’s Code of Conduct, which imposes strict confidentiality obligations. Clinical records are stored securely and accessed only by those who need them for the purposes of your care or the administration of that care.
Communicating with the healthcare professionals and insurer involved in your referral and ongoing care — for example, reporting back to the GP, consultant or insurer who referred you on your assessment, diagnosis and treatment — is an integral part of providing your care. We carry out these communications under Article 9(2)(h) UK GDPR (provision of health care) and do not rely on your separate consent to do so, although we will keep you informed and you may ask us about them at any time.
We will not disclose your health data to any other third party without your explicit consent, unless any of these situations exist:
- We are required to do so by law (for example, by a court order or statutory authority).
- We have a safeguarding concern relating to a child or vulnerable adult, in which case we may share information with the appropriate statutory authority without your consent.
- We reasonably believe that disclosure is necessary to prevent serious harm to you or another person.
6. Our lawful bases
Performance of a contract
Legal obligation
Legitimate interests
Provision of health care
Consent
7. How long we keep your personal data
Type of Record
Retention Period and Basis
Adult patient clinical records
Children’s clinical records
Financial and invoicing records
Insurance correspondence and authorisations
8 years from the date of last treatment
Website enquiry/contact form data
12 months from the date of enquiry, unless a patient relationship is established
Website server logs (Spoton.net)
90 days (security monitoring)
Google Analytics data
As set by Google Analytics data retention settings (typically 26 months), anonymised
8. Who we share your data with
Clinical disclosures in connection with your referral and care
- Your GP or referring consultant, to update them on your assessment, diagnosis and treatment in line with good clinical practice and Department of Health guidelines.
- Other specialists or healthcare professionals, where a referral is made in your clinical interest.
- Your private health insurer (e.g. Bupa, AXA Health, Aviva), for the purpose of billing, authorisation and treatment reporting under the terms of your policy.
Data processors acting on our behalf
Processor
Role / Purpose
HMDG LIMITED (Company No. 10409692)
Website hosting — logs IP addresses for security and fault diagnosis; retained for 90 days
Cloudflare Inc.
Content delivery and DDoS protection — processes connection data to serve and protect the website
Google LLC (Google Analytics)
Practice management/booking software (if applicable)
Appointment booking, clinical records and payment processing — details available on request
Card payment processor
Secure processing of card transactions — we do not store card details ourselves
Other disclosures
- Law enforcement or regulatory bodies, where required by law or court order.
- Our professional indemnity insurers, in the event of a complaint or claim.
- A successor organisation, if the practice is acquired or transferred, you would be notified in advance of any such transfer.
Third-party website embeds
Pages on our website may load content from the following third parties, which may set their own cookies or collect connection data. We do not control how these parties use that data, and you should refer to their own privacy policies:
- Mapbox (mapping functionality)
- YouTube / Google (embedded video content)
9. International data transfers
Some of our third-party processors (including Google LLC and Cloudflare Inc.) may transfer and store data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, either by relying on the UK Government’s adequacy regulations (for transfers to countries deemed adequate), the UK International Data Transfer Agreement (UK IDTA) or equivalent transfer mechanisms.
Google’s data transfers are governed by its Data Processing Terms, which incorporate UK SCCs/IDTA. Cloudflare’s transfers are covered by its Data Processing Addendum. For further information, please contact us.
10. Your data protection rights
Your Right
What It Means
Right of access (Subject Access Request)
You have the right to request a copy of the personal data we hold about you, along with information about how it is used.
Right to rectification
You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
Right to erasure (‘right to be forgotten’)
Right to restriction of processing
You can ask us to pause processing your data in certain circumstances, for example, whilst accuracy is being contested.
Right to data portability
Where processing is based on consent or contract and is automated, you can ask us to provide your data in a structured, commonly used, machine-readable format.
Right to object
You can object to processing based on our legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your interests.
Rights related to automated decision-making
Right to withdraw consent
Where we process your data on the basis of consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing prior to withdrawal.
How to exercise your rights
To exercise any of your rights, please contact us:
- Email: info@hardingphysiotherapy.co.uk
- Post: Harding Physiotherapy Ltd, 2 West Newlands, Somersham, Huntingdon, PE283EB
- Tel: 01487 843 844
We will need to verify your identity before responding to any request. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
11. Complaints
If you are unhappy about how we have handled your personal data, please contact us in the first instance so that we can try to resolve the matter.
If you remain dissatisfied, you have the right to lodge a complaint with the UK’s supervisory authority:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113
Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You also have the right to seek a judicial remedy against a data controller or processor.
12. How we keep your data secure
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, including:
- Secure, password-protected clinical records systems with access restricted to authorised staff.
- Transport Layer Security (TLS/SSL) encryption for all data transmitted via our website.
- Our website is served via Cloudflare, which provides DDoS protection and encrypted connections.
- Physical security of paper records held at the clinic, including locked storage.
- Confidentiality obligations and data protection training for all staff who handle personal data.
- Regular review of systems and procedures to maintain appropriate security standards.
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach. Where the breach poses a high risk to you, we will also notify you directly without undue delay.
13. Cookies
Our website uses cookies. Cookies are small text files stored by your browser that allow us and third parties to recognise your browser as you navigate our site. We use cookies for the following purposes:
- Essential/functional cookies: necessary for the website to operate correctly.
- Analytics cookies (Google Analytics), to understand how visitors interact with our site, allowing us to improve content and user experience. These cookies do not identify you personally.
For full details of the cookies we use, their purposes, and how to manage or disable them, please see our Cookie Policy on our website.
You can manage cookie preferences through your browser settings. Disabling analytics cookies will not affect your ability to use the website or book appointments.
14. Changes to this Privacy Policy
We review this privacy policy at least annually and whenever there is a material change to the way we process personal data. The version date at the top of this document indicates when it was last updated.
Where changes are material or required by law, we will notify patients directly (by email or at their next appointment) and update the copy of this policy on our website. Historic versions are available on request.
15. Glossary of Key Terms
Term
Meaning
Data Controller
Data Processor
Personal Data
Special Category Data
UK GDPR
The UK General Data Protection Regulation — the retained EU GDPR as it forms part of UK law under the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications Regulations 2019.
DPA 2018
The Data Protection Act 2018 — the UK statute that supplements and implements UK GDPR.
ICO
The Information Commissioner’s Office — the UK’s independent data protection supervisory authority.
HCPC
The Health and Care Professions Council — the statutory regulator for physiotherapists and other health professionals in the UK.
Lawful Basis
The legal justification under Article 6 UK GDPR that permits the processing of personal data.
Subject Access Request (SAR)
A formal request by an individual to receive a copy of their personal data held by an organisation.
This privacy policy was drafted in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Harding Physiotherapy Ltd is registered in England and Wales. Registered address: 2 West Newlands, Somersham, Huntingdon, Cambridgeshire, PE28 3EB.
Ready to start your recovery?
Call the clinic or send an enquiry and the team will help you find the right appointment.