1. Who we are
Harding Physiotherapy Ltd (‘we’, ‘us’, ‘our’) is a private physiotherapy and sports therapy clinic. We are the data controller for the personal information we collect and use about you. This means we are responsible for deciding how and why your personal data is processed and for ensuring that it is handled lawfully, fairly and transparently.
Our clinicians are regulated healthcare professionals registered with the Health and Care Professions Council (HCPC), the Chartered Society of Physiotherapy (CSP), PhysioFirst, the Sports Therapy Association (STA) and the Acupuncture Association of Chartered Physiotherapists (AACP). As such, we are bound by professional and ethical obligations regarding the confidentiality of patient information, which sit alongside our legal obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
Our contact details
Harding Physiotherapy Ltd
2 West Newlands, Somersham, Huntingdon, Cambridgeshire, PE28 3EB
Tel: 01487 843 844
Email: info@hardingphysiotherapy.co.uk
Website: www.hardingphysiotherapy.co.uk
To exercise any of your data protection rights, or if you have any questions about this policy, please contact us using the details above.
2. Scope of this policy
This privacy policy applies to:
- Patients and prospective patients who attend our clinic for physiotherapy, sports therapy, acupuncture, sports massage, body composition testing or prehabilitation services.
- Individuals who contact us via telephone, email, website enquiry form or any other means.
- Visitors to our website www.hardingphysiotherapy.co.uk
- Insurance company representatives and referrers (GPs, consultants or other healthcare professionals) who share patient information with us.
- Room-hire clients and associated healthcare professionals who use our facilities.
This policy does not apply to third-party websites linked from our website. Those websites have their own privacy policies and data controllers.
3. What personal data we collect
Clinical and Health Data
Because we are a healthcare provider, much of the information we collect is special category data under Article 9 UK GDPR (health data). We collect:
- Your full name, date of birth and contact details (address, telephone, email).
- Details of your GP and any other treating clinicians.
- Your medical history, current medication and any relevant co-morbidities.
- Records of your assessment, examination findings, clinical diagnosis, and treatment
notes. - Your rehabilitation programme, home exercise plans and treatment outcomes.
- Body composition data where you undertake InBody scanning (including body fat mass,
visceral fat levels, muscle mass and hydration). - Information about your insurance provider, policy number and authorisation code where
applicable. - Payment and invoicing information (card or cash payment records, outstanding
balances).
Website and administrative data
When you use our website or contact us, we may also collect:
- Your name, email address and message content when you submit an enquiry or contact
form. - Your IP address, browser type, pages visited and timestamps, collected via Google
Analytics and our hosting provider. - Cookie data as described in our separate Cookie Policy
4. How and why we use your personal data
We set out below the purposes for which we use your personal data, the lawful basis under Article 6 UK GDPR, and, where health data is involved, the Article 9 condition we rely on.
Purpose
UK GDPR Article 6 Basis
Article 9 Condition (health data)
Providing physiotherapy, sports therapy, acupuncture and related clinical services
Article 6(1)(b) – performance of a contract
Article 9(2)(h) – medical
diagnosis and the provision
of health care
Maintaining accurate clinical records and treatment note
Article 6(1)(b) – performance of a contract Article 6(1)(c) – legal obligation (HCPC standards)
Article 9(2)(h) – health care provision
Communicating with your GP or other treating clinicians with your consent
Article 6(1)(a) – consent
Article 9(2)(a) – explicit consent
Processing payment and managing invoices
Article 6(1)(b) – performance of a contract
Not applicable
Liaising with your private health insurer for billing and authorisation
Article 6(1)(b) – performance of a contract
Article 9(2)(h) – health care provision
Sending appointment reminders and clinic communications
Article 6(1)(f) – legitimate interests (efficient clinic administration)
Not applicable
Responding to website and telephone enquiries
Article 6(1)(f) – legitimate interests
Not applicable
Complying with our legal and regulatory obligations (HCPC, ICO, legal requests
Article 6(1)(c) – legal obligation
Article 9(2)(h) / Article 9(2)(b) as appropriate
Improving our website and marketing our services (Google Analytics)
Article 6(1)(f) – legitimate interests
Not applicable
Managing room-hire arrangements with associated practitioners
Article 6(1)(b) – performance of a contract
Not applicable
5. Health data — additional safeguards
Important — Special Category Data
Health and clinical data are ‘special category’ data under UK GDPR. It attracts a higher level of legal protection. We process it only where strictly necessary for your care, and always under an appropriate Article 9 condition. We have in place additional organisational and technical safeguards, including access controls, secure record-keeping and confidentiality obligations binding all staff and contractors.
All clinical staff are bound by their professional body’s Code of Conduct, which imposes strict confidentiality obligations. Clinical records are stored securely and accessed only by those who need them for the purposes of your care or the administration of that care.
We will not disclose your health data to any third party without your explicit consent, unless any of these situations exist:
- We are required to do so by law (for example, by a court order or statutory authority).
- We have a safeguarding concern relating to a child or vulnerable adult, in which case
we may share information with the appropriate statutory authority without your consent. - We reasonably believe that disclosure is necessary to prevent serious harm to you or
another person
6. Our lawful bases
Performance of a contract
When you book an appointment with us, you enter a contractual relationship. We need to process your data, including your clinical history and treatment records, to perform that contract and deliver safe, effective care.
Legal obligation
We are subject to regulatory requirements imposed by the HCPC, and to statutory obligations under the DPA 2018 and other legislation. We process data to the extent
necessary to comply with these obligations, including maintaining records for the periods required by professional guidelines.
Legitimate interests
Where we rely on legitimate interests, we have assessed that our interests (or those of our patients) are not overridden by your privacy rights. Examples include sending appointment reminders by text or email, analysing website traffic to improve our services, and retaining hosting-provider logs for security purposes. You have the right to object to processing based on legitimate interests, please see Section 10 below.
Consent
We ask for your explicit consent before sharing your clinical information with your GP or other healthcare professionals. You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of any processing already carried out. To withdraw consent, please contact us using the details in Section 1.
7. How long we keep your personal data
We retain personal data only for as long as necessary for the purposes for which it wascollected, taking into account applicable legal, regulatory and professional requirements.
Type of Record
Retention Period and Basis
Adult patient clinical records
8 years from the date of last treatment (HCPC / professional body guidance)
Children’s clinical records
Until the patient’s 25th birthday, or 8 years from the last treatment if longer
Financial and invoicing records
6 years from the end of the relevant financial year (Companies Act / HMRC)
Insurance correspondence and authorisations
8 years from the date of last treatment
Website enquiry/contact form data
12 months from the date of enquiry, unless a patient relationship is established
Website server logs (Spoton.net)
90 days (security monitoring)
Google Analytics data
As set by Google Analytics data retention settings (typically 26 months), anonymised
After the relevant retention period, data is securely deleted or anonymised. Anonymised data (from which you cannot be identified) may be retained for statistical or service improvement purposes.
8. Who we share your data with
Clinical disclosures (with your knowledge or consent)
- Your GP or referring consultant, to update them on your assessment, diagnosis and
treatment in line with good clinical practice and Department of Health guidelines. - Other specialists or healthcare professionals, where a referral is made in your clinical
interest. - Your private health insurer (e.g. Bupa, AXA Health, Aviva), for the purpose of billing,
authorisation and treatment reporting under the terms of your policy.
Data processors acting on our behalf
We use a small number of third-party service providers who process data on our behalf as data
processors. They are contractually required to process data only on our instructions, to
maintain appropriate security, and not to use your data for their own purposes.
Processor
Role / Purpose
Spoton.net Ltd (Company No. 06139437)
Website hosting — logs IP addresses for security and fault diagnosis; retained for 90 days
Cloudflare Inc.
Content delivery and DDoS protection — processes connection data to serve and protect the website
Google LLC (Google Analytics)
Website analytics — tracks visitor interaction to produce statistical reports; data is anonymised / pseudonymised. You can opt out via our Cookie Policy.
Practice management/booking software (if applicable)
Appointment booking, clinical records and payment processing — details available on request
Card payment processor
Secure processing of card transactions — we do not store card details ourselves
Other disclosures
- Law enforcement or regulatory bodies, where required by law or court order.
- Our professional indemnity insurers, in the event of a complaint or claim.
- A successor organisation, if the practice is acquired or transferred, you would be notified
in advance of any such transfer.
Third-party website embeds
Pages on our website may load content from the following third parties, which may set their own cookies or collect connection data. We do not control how these parties use that data, and you should refer to their own privacy policies:
- Mapbox (mapping functionality)
- YouTube / Google (embedded video content)
9. International data transfers
Some of our third-party processors (including Google LLC and Cloudflare Inc.) may transfer and store data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, either by relying on the UK Government’s adequacy regulations (for transfers to countries deemed adequate), the UK International Data Transfer Agreement (UK IDTA) or equivalent transfer mechanisms.
Google’s data transfers are governed by its Data Processing Terms, which incorporate UK SCCs/IDTA. Cloudflare’s transfers are covered by its Data Processing Addendum. For further information, please contact us.
10. Your data protection rights
Under UK GDPR, you have the following rights. We will respond to any request within one calendar month (this may be extended by up to two further months for complex requests, in which case we will inform you).
Your Right
What It Means
Right of access (Subject Access Request)
You have the right to request a copy of the personal data we hold about you, along with information about how it is used.
Right to rectification
You have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
Right to erasure (‘right to be forgotten’)
In certain circumstances, you can ask us to delete your personal data. Note that this right is limited where we are
required to retain data for legal, regulatory or professional reasons (e.g. clinical record retention).
Right to restriction of processing
You can ask us to pause processing your data in certain circumstances, for example, whilst accuracy is being contested.
Right to data portability
Where processing is based on consent or contract and is automated, you can ask us to provide your data in a structured, commonly used, machine-readable format.
Right to object
You can object to processing based on our legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your interests.
Rights related to automated decision-making
We do not use automated decision-making or profiling in relation to clinical care. If this changes, we will update this
policy and inform you.
Right to withdraw consent
Where we process your data on the basis of consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing prior to withdrawal.
How to exercise your rights
To exercise any of your rights, please contact us:
- Email: info@hardingphysiotherapy.co.uk
- Post: Harding Physiotherapy Ltd, 2 West Newlands, Somersham, Huntingdon, PE283EB
- Tel: 01487 843 844
We will need to verify your identity before responding to any request. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
11. Complaints
If you are unhappy about how we have handled your personal data, please contact us in the first instance so that we can try to resolve the matter.
If you remain dissatisfied, you have the right to lodge a complaint with the UK’s supervisory authority:
Information Commissioner's Office (ICO)
Website: www.ico.org.uk
Helpline: 0303 123 1113
Post: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You also have the right to seek a judicial remedy against a data controller or processor.
12. How we keep your data secure
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, including:
- Secure, password-protected clinical records systems with access restricted to authorised staff.
- Transport Layer Security (TLS/SSL) encryption for all data transmitted via our website.
- Our website is served via Cloudflare, which provides DDoS protection and encrypted connections.
- Physical security of paper records held at the clinic, including locked storage.
- Confidentiality obligations and data protection training for all staff who handle personal data.
- Regular review of systems and procedures to maintain appropriate security standards.
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach. Where the breach poses a high risk to you, we will also notify you directly without undue delay.
13. Cookies
Our website uses cookies. Cookies are small text files stored by your browser that allow us and third parties to recognise your browser as you navigate our site. We use cookies for the following purposes:
- Essential/functional cookies: necessary for the website to operate correctly.
- Analytics cookies (Google Analytics), to understand how visitors interact with our site, allowing us to improve content and user experience. These cookies do not identify you
personally.
For full details of the cookies we use, their purposes, and how to manage or disable them, please see our Cookie Policy on our website.
You can manage cookie preferences through your browser settings. Disabling analytics cookieswill not affect your ability to use the website or book appointments.
14. Changes to this Privacy Policy
We review this privacy policy at least annually and whenever there is a material change to the way we process personal data. The version date at the top of this document indicates when it was last updated.
Where changes are material or required by law, we will notify patients directly (by email or at their next appointment) and update the copy of this policy on our website. Historic versions are available on request.
15. Glossary of Key Terms
Term
Meaning
Data Controller
The organisation that determines the purposes and means of processing personal data — in this case, Harding
Physiotherapy Ltd.
Data Processor
A third party that processes personal data on the controller’s behalf, under written instructions.
Personal Data
Any information relating to an identified or identifiable living individual.
Special Category Data
Personal data revealing health, racial or ethnic origin, religious beliefs, sexual orientation or similar sensitive attributes. Health data receives the highest level of legal protection under UK GDPR.
UK GDPR
The UK General Data Protection Regulation — the retained EU GDPR as it forms part of UK law under the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications Regulations 2019.
DPA 2018
The Data Protection Act 2018 — the UK statute that supplements and implements UK GDPR.
ICO
The Information Commissioner’s Office — the UK’s independent data protection supervisory authority.
HCPC
The Health and Care Professions Council — the statutory regulator for physiotherapists and other health professionals in the UK.
Lawful Basis
The legal justification under Article 6 UK GDPR that permits the processing of personal data.
Subject Access Request (SAR)
A formal request by an individual to receive a copy of their personal data held by an organisation.
This privacy policy was drafted in accordance with the UK General Data Protection Regulation (UK
GDPR) and the Data Protection Act 2018.
Harding Physiotherapy Ltd is registered in England and Wales. Registered address: 2 West Newlands,
Somersham, Huntingdon, Cambridgeshire, PE28 3EB.
Ready to start your recovery?
Call the clinic or send an enquiry and the team will help you find the right appointment.