Privacy Policy
Last updated: 1st August 2025
Joe Sharp Physiotherapy Limited (“we”, “us”, “our”) collects, processes, and stores personal information in line with the UK GDPR and Data Protection Act 2018. This notice explains how we handle your data on https://sharpphysiotherapy.co.uk.
1. Definitions
-
Personal Data: Any information identifying you (e.g. name, address, IP address).
-
Special Categories of Personal Data: Sensitive details such as health history or medical conditions.
-
Processing: Any operation on personal data, including collection, use, or deletion.
-
Data Controller: The entity deciding how your data is processed — that’s us.
-
Data Processor: A third party acting on our behalf (e.g. our booking provider).
-
Data Subject: You — the individual whose data is being processed.
2. Who We Are
-
Joe Sharp Physiotherapy Limited
-
Email: reception@sharpphysio.co.uk
- Address: 14 The Courtyard, Bawtry, Doncaster DN10 6JG
- Company Number: 09064302
-
We are the Data Controller of your personal data.
3. What Data We Collect
We collect and process:
-
Identity & Contact Data – Name, date of birth, email, phone, address
-
Health Data – Medical history, treatment notes, condition details
-
Booking Data – Appointment history, cancellations, referral source
-
Technical Data – IP address, browser type, device info
-
Usage Data – Site visits, session times, cookie data
-
Marketing Preferences – Consent for updates or downloads
We do not knowingly collect data from individuals under 18 without parental consent.
4. How We Collect Your Data
-
Through booking forms or downloadable guides
-
Via phone, email, or in-person sessions
-
Using cookies and website tracking tools
-
From email opt-ins (e.g. updates, resources)
5. Legal Basis for Processing
Legal Basis | Purpose |
---|---|
Contract | Booking and delivering physiotherapy services |
Consent | Email updates, downloads, or health questionnaires |
Legal Obligation | Maintaining medical records (UK healthcare rules) |
Legitimate Interest | Website improvements, fraud prevention |
You may withdraw consent at any time by contacting us.
6. How We Use Your Data
We process your data to:
-
Manage physiotherapy appointments and treatments
-
Respond to enquiries and follow-ups
-
Provide downloadable content you’ve requested
-
Send email updates if consented
-
Improve our services and website experience
-
Fulfil legal and healthcare obligations
We do not use automated decision-making or profiling.
7. Sharing Your Data
We only share data when necessary:
-
With booking and practice management software providers
-
With email and analytics platforms
-
With medical professionals, only with your consent
-
For legal reasons, e.g. court orders or healthcare regulations
All third-party processors operate under GDPR-compliant contracts.
8. International Transfers
Some services (e.g. analytics, email tools) may store data outside the UK.
Where applicable, we ensure transfers are safeguarded using UK-approved mechanisms.
9. Data Security & Breach Procedures
We take data protection seriously and implement:
-
SSL encryption on our website
-
Limited access to systems and records
-
Encrypted storage for health records
-
Staff confidentiality agreements
-
Internal breach procedures and ICO notification, if required
10. Change of Purpose
If we intend to use your data for a new purpose, we will update this policy and notify you beforehand.
11. Your Rights
Under UK GDPR, you can:
-
Access your data
-
Request updates or corrections
-
Request deletion (where allowed)
-
Withdraw consent or restrict processing
-
Request a copy of your data
-
Object to data use based on legitimate interest
We respond within one month. Complex requests may take longer. Excessive requests may be subject to reasonable admin fees.
12. Data Retention
We retain personal data only as long as necessary for:
-
Clinical, legal, or business needs
Once no longer required, it is securely deleted or anonymised.
13. Cookies
We use cookies to enhance your experience and monitor website usage.
For full details, see our Cookie Policy.
14. Updates to This Policy
This policy may be updated periodically. The “Last updated” date will always reflect the latest revision.
15. Contact Us
You may also contact the Information Commissioner’s Office (ICO) at www.ico.org.uk