GDPR Compliance
Last updated: [insert date]
PhysioPro is built to help UK physiotherapy clinics meet their UK GDPR obligations when handling patient data. This page summarises the measures we take as a data processor, and what clinics remain responsible for as data controllers.
Our role: processor, not controller
For patient health data, your clinic is the data controller — you decide what data to collect and why. PhysioPro is your data processor, acting only on your instructions under a data processing agreement (DPA), available on request.
Technical & organisational measures
- Encryption of data in transit (HTTPS/TLS) and at rest
- Hashed, salted password storage (bcrypt) — passwords are never stored in plain text
- Role-based access control (admin / practitioner / receptionist), so staff only see what their role requires
- Separate authentication systems for staff and patients
- Multi-tenant data isolation — each clinic's data is logically separated and inaccessible to other clinics
- Clinical notes lock after signing, supporting audit-ready record integrity
- UK-based hosting infrastructure
[Add any measures not yet listed here once confirmed — e.g. penetration testing cadence, backup encryption, staff access reviews, incident response plan.]
Data subject rights
The platform is designed to support clinics in fulfilling patient rights requests: access, rectification, erasure (subject to healthcare record-keeping law), and data portability. Patients should raise requests with their clinic directly; PhysioPro provides the tools clinics need to action them.
Special category data
Health data is "special category" data under UK GDPR Article 9, requiring an additional lawful basis beyond the standard six — typically Article 9(2)(h), provision of health or social care, for a clinical platform like this. Clinics should ensure this basis is documented in their own privacy notices to patients.
Sub-processors
- Stripe — payment processing
- [Email/SMTP provider] — transactional email delivery
- [Hosting provider] — infrastructure
Data breach process
[Describe your actual breach notification process here — UK GDPR requires notifying the ICO within 72 hours of becoming aware of a qualifying breach, and affected data subjects without undue delay where there's high risk to their rights.]
Data Processing Agreement
Clinics on a paid plan can request a signed DPA covering the specifics of our processing activities. Contact hello@fit4physio.co.uk to request one.