Privacy Policy
Last updated: 26 July 2026 · Applies to PhysioPro and the fit4physio.com website
PhysioPro ("we", "us", "our") provides practice management software for UK physiotherapy clinics. This policy explains what personal data we collect, why, and how it is handled — both for clinic staff who use our platform, and for patients whose data clinics store within it.
1. Who we are
PhysioPro, West Yorkshire, United Kingdom (full registered address to be added once the company is formally incorporated), is the data controller for account and billing information relating to clinics that subscribe to PhysioPro. For patient health data entered by a clinic (appointments, clinical notes, medical history), the subscribing clinic is the data controller, and PhysioPro acts as their data processor under a data processing agreement.
2. What data we collect
| Category | Examples | Collected from |
|---|---|---|
| Account data | Name, email, password (hashed), role, clinic name | Staff at signup |
| Patient data | Name, DOB, contact details, NHS number, insurance details, GP details | Clinic staff, or patient via the portal |
| Clinical data | SOAP notes, body chart markers, appointment history, ROM measurements | Practitioners |
| Billing data | Invoices, payment status (card details handled by Stripe, not stored by us) | Clinic staff, Stripe |
| Technical data | IP address, browser type, login timestamps | Automatically, on use |
3. Why we process this data (lawful basis)
- Contract: to provide the practice management service you've signed up for
- Legal obligation: to meet healthcare record-keeping and HCPC-related requirements
- Legitimate interests: to maintain security, prevent fraud, and improve the platform
- Consent: for patient portal registration and optional communications, where applicable
Health data specifically is processed under UK GDPR Article 9(2)(h) — provision of health/social care — on the instructions of the clinic acting as controller.
4. Who we share data with
- Stripe — payment processing (card data never touches our servers)
- IONOS — SMTP email delivery, for sending invoices and notifications
- IONOS — UK-based server hosting and infrastructure
We do not sell personal data, and do not share patient health data with any third party for marketing purposes.
5. Data retention
Account and clinical data is retained for as long as a clinic maintains an active subscription, and for a further period after account closure to meet healthcare record-keeping obligations. Following standard UK NHS records management guidance: 8 years for adult patient records after the end of treatment; records for children are typically retained until their 25th birthday (or 26th if they were 17 at the conclusion of treatment); mental health records are typically retained for 20 years after the last treatment, or 8 years after death. Clinics should confirm which category applies to their patient records and can request earlier deletion where legally permitted.
6. Your rights
Under UK GDPR you have the right to: access your data, correct inaccuracies, request erasure (subject to healthcare record-keeping law), restrict or object to processing, and data portability. Patients should contact their clinic directly for most requests, since the clinic controls their records; account holders can contact us directly at hello@fit4physio.co.uk.
7. Security
We use encryption in transit and at rest, hashed passwords, role-based access controls, and audit logging on clinical records. [Add specifics once finalised — e.g. TLS version, backup encryption, access review cadence.]
8. International transfers
Our infrastructure is hosted in the UK. Where any sub-processor (e.g. Stripe) transfers data outside the UK/EEA, this is done under an approved transfer mechanism such as Standard Contractual Clauses.
9. Contact & complaints
Questions or concerns: hello@fit4physio.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.