New patient offer: use code NEW10 for 10% off your first booking.Book with NEW10
Privacy policy

GDPR-conscious handling of patient and website data.

Last updated

Who we are

PhysioOnClick is operated by Shivaliba Zala (trading as PhysioOnClick), the data controller for all personal data collected through this website and associated services. We are registered with the Information Commissioner's Office (ICO) as a data controller, registration reference ZC258927. Contact: hello@physioonclick.co.uk.

This policy explains how we collect, use, store and protect your personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What data we collect

We collect the following categories of personal data:

  • Contact details: name, email address, phone number
  • Appointment data: preferred dates, times, and service type
  • Clinical information: condition notes, session records, progress data, and exercise assignments entered through the patient portal
  • Home address (home visits only): the address line and postcode, collected only if you book a home visit. We use it to attend your appointment and to check that it is within the area we cover. We do not ask for it for video appointments
  • Dependant details: where you manage care for a child or another person, the details you add for them
  • Enquiry & chat content: messages you send through the contact form and the on-site chat assistant
  • Payment: payment is taken online when you book, through Stripe. We receive confirmation of payment, the amount and your billing name and email, but we never see or store your full card details
  • Movement check (optional): if you use the camera-based movement check in the patient portal, your video is processed on your own device only and is never recorded, uploaded or stored. We save only the resulting movement scores to your record
  • Usage data: pages visited and session activity, collected anonymously via analytics only where you have consented

Special category (health) data

Clinical and condition information is “special category” data under Article 9 of the UK GDPR and is given additional protection. We process it under Article 9(2)(h) — the provision of health care and treatment by a registered health professional bound by a duty of professional confidentiality (HCPC-registered physiotherapy). We only collect the health information needed to assess and treat you safely.

Lawful basis for processing

  • Contract performance (Art 6(1)(b)): processing your name, email, and appointment details to deliver the service you have booked
  • Legal obligation (Art 6(1)(c)): retaining clinical records for the period required by HCPC standards
  • Legitimate interests (Art 6(1)(f)): maintaining secure systems, communicating about your care, and improving the service
  • Consent (Art 6(1)(a)): for optional analytics cookies and any non-essential communications; you may withdraw consent at any time
  • Health care (Art 9(2)(h)): the additional condition for processing your clinical data, as above

Third-party processors

Your data is processed by the following third parties on our behalf, under written data-processing terms:

  • Google Firebase: Authentication, Firestore database and Storage, used to store account, appointment, and clinical data securely
  • Cal.com: used for appointment scheduling; booking data is shared with Cal.com to manage your calendar appointment. For a home visit this includes the visit address you give us
  • Google Calendar / Google Meet: used to create appointment events and video consultation links; attendee details (name, email) are shared with Google to generate the meeting link
  • Google Gemini: powers the on-site chat assistant; the content of your chat messages is processed to generate replies
  • Resend: sends transactional emails such as sign-in links and enquiry notifications. For a home visit, our payment receipt email includes the visit address
  • Google Analytics: anonymous usage statistics, loaded only after you accept analytics cookies
  • Stripe: processes your online payment and holds your card details securely; we never see your full card number. For a home visit, the visit address is also recorded against your payment so the booking can be completed once you have paid
  • Trustpilot: after a completed session we may share your name, email and a booking reference with Trustpilot so it can invite you to leave an independent review. Leaving a review is entirely optional
  • Cloudflare: hosts and protects this website; it processes technical data such as your IP address to deliver pages securely and block abuse

International data transfers

Some of our processors (including Google, Cal.com, Stripe, Trustpilot and Cloudflare) may store or process data on servers outside the UK. Where data is transferred outside the UK, it is protected by appropriate safeguards — the UK International Data Transfer Agreement or Addendum, UK adequacy regulations, or Standard Contractual Clauses — so your data receives an equivalent level of protection.

Automated decision-making

We do not make decisions about your care by solely automated means. The on-site chat assistant provides general information and helps you navigate the service; it does not diagnose, and it does not replace assessment by your physiotherapist. All clinical decisions are made by a registered professional.

Children's data

Where physiotherapy is provided to a child, their data is entered and managed by a parent or guardian with parental responsibility, who provides consent on the child's behalf. We hold children's clinical records to the same standard and retention period as any other patient.

Data retention

  • Adult clinical records: retained for 8 years from the date of last contact, in line with HCPC record-keeping standards
  • Children's clinical records: retained until the patient's 25th birthday (or 26th if the last entry was made at age 17)
  • Appointment and contact enquiries: retained for 12 months after the last interaction
  • Home visit address: held in our database in your booking record and payment record, and kept for 12 months after the last interaction, as for appointment enquiries above. Where the address is recorded in your clinical notes, it is kept with your clinical record (8 years for adults). Stripe and our booking calendar provider keep their own copies under their own retention policies

How we keep your data secure

Access to clinical records is restricted and authenticated. Data is transmitted over encrypted (HTTPS) connections and held with reputable providers that maintain their own security controls. If a personal data breach occurs that is likely to result in a risk to your rights, we will report it to the ICO within 72 hours and notify you where required.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectification of inaccurate data
  • Erasure of your data where there is no legal obligation to retain it
  • Restriction of processing in certain circumstances
  • Data portability: receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, where processing is based on consent (this does not affect processing already carried out)

To exercise any of these rights, email hello@physioonclick.co.uk. We will respond within one month.

Cookies

We use essential cookies to run the site and keep you signed in — these are required for the service to work and do not need consent. We also use optional analytics cookies (Google Analytics) to understand how the site is used; these are only set after you choose “Accept all” on the cookie banner, and are disabled by default. We do not use advertising or third-party marketing cookies. You can change your choice at any time by clearing this site's data in your browser, which will show the banner again.