GDPR Compliance

Last updated: [insert date]

PhysioPro is built to help UK physiotherapy clinics meet their UK GDPR obligations when handling patient data. This page summarises the measures we take as a data processor, and what clinics remain responsible for as data controllers.

Our role: processor, not controller

For patient health data, your clinic is the data controller — you decide what data to collect and why. PhysioPro is your data processor, acting only on your instructions under a data processing agreement (DPA), available on request.

Technical & organisational measures

[Add any measures not yet listed here once confirmed — e.g. penetration testing cadence, backup encryption, staff access reviews, incident response plan.]

Data subject rights

The platform is designed to support clinics in fulfilling patient rights requests: access, rectification, erasure (subject to healthcare record-keeping law), and data portability. Patients should raise requests with their clinic directly; PhysioPro provides the tools clinics need to action them.

Special category data

Health data is "special category" data under UK GDPR Article 9, requiring an additional lawful basis beyond the standard six — typically Article 9(2)(h), provision of health or social care, for a clinical platform like this. Clinics should ensure this basis is documented in their own privacy notices to patients.

Sub-processors

Data breach process

[Describe your actual breach notification process here — UK GDPR requires notifying the ICO within 72 hours of becoming aware of a qualifying breach, and affected data subjects without undue delay where there's high risk to their rights.]

Data Processing Agreement

Clinics on a paid plan can request a signed DPA covering the specifics of our processing activities. Contact hello@fit4physio.co.uk to request one.