Privacy Policy

Last updated: 26 July 2026 · Applies to PhysioPro and the fit4physio.com website

PhysioPro ("we", "us", "our") provides practice management software for UK physiotherapy clinics. This policy explains what personal data we collect, why, and how it is handled — both for clinic staff who use our platform, and for patients whose data clinics store within it.

1. Who we are

PhysioPro, West Yorkshire, United Kingdom (full registered address to be added once the company is formally incorporated), is the data controller for account and billing information relating to clinics that subscribe to PhysioPro. For patient health data entered by a clinic (appointments, clinical notes, medical history), the subscribing clinic is the data controller, and PhysioPro acts as their data processor under a data processing agreement.

2. What data we collect

CategoryExamplesCollected from
Account dataName, email, password (hashed), role, clinic nameStaff at signup
Patient dataName, DOB, contact details, NHS number, insurance details, GP detailsClinic staff, or patient via the portal
Clinical dataSOAP notes, body chart markers, appointment history, ROM measurementsPractitioners
Billing dataInvoices, payment status (card details handled by Stripe, not stored by us)Clinic staff, Stripe
Technical dataIP address, browser type, login timestampsAutomatically, on use

3. Why we process this data (lawful basis)

Health data specifically is processed under UK GDPR Article 9(2)(h) — provision of health/social care — on the instructions of the clinic acting as controller.

4. Who we share data with

We do not sell personal data, and do not share patient health data with any third party for marketing purposes.

5. Data retention

Account and clinical data is retained for as long as a clinic maintains an active subscription, and for a further period after account closure to meet healthcare record-keeping obligations. Following standard UK NHS records management guidance: 8 years for adult patient records after the end of treatment; records for children are typically retained until their 25th birthday (or 26th if they were 17 at the conclusion of treatment); mental health records are typically retained for 20 years after the last treatment, or 8 years after death. Clinics should confirm which category applies to their patient records and can request earlier deletion where legally permitted.

6. Your rights

Under UK GDPR you have the right to: access your data, correct inaccuracies, request erasure (subject to healthcare record-keeping law), restrict or object to processing, and data portability. Patients should contact their clinic directly for most requests, since the clinic controls their records; account holders can contact us directly at hello@fit4physio.co.uk.

7. Security

We use encryption in transit and at rest, hashed passwords, role-based access controls, and audit logging on clinical records. [Add specifics once finalised — e.g. TLS version, backup encryption, access review cadence.]

8. International transfers

Our infrastructure is hosted in the UK. Where any sub-processor (e.g. Stripe) transfers data outside the UK/EEA, this is done under an approved transfer mechanism such as Standard Contractual Clauses.

9. Contact & complaints

Questions or concerns: hello@fit4physio.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.