top of page

SG Physiotherapy & PilatesClient Privacy & Data Protection Notice Last updated: September 2026

 

SG Physiotherapy & Pilates is committed to protecting your privacy and handling your personal information securely and responsibly.This notice explains what information I collect, why I collect it, how I use it, where it is stored and your rights in relation to your information.I process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and applicable professional requirements.

1. Who is responsible for your information? The data controller is:SG Physiotherapy & Pilates

12 Desert Road

Mayobridge

Northern Ireland

Email: sgphysiopilates@gmail.com

As a sole-practitioner physiotherapy business, I am responsible for deciding how and why your personal information is processed.

2. Information I collect

Depending on the service you use, I may collect:

Contact and administrative information

Name

Date of birth

Address

Telephone number

Email address

Emergency contact information where appropriate

Appointment and booking information

Payment and transaction information

Clinical and health information

Where required to provide physiotherapy or rehabilitation, I may collect:

Medical history

Current symptoms

Previous injuries

Diagnoses

Medication

Surgical history

Pregnancy and postpartum information

Pelvic health information

Relevant menstrual or reproductive health information

Exercise and activity history

Assessment findings

Treatment provided

Clinical reasoning and treatment decisions

Rehabilitation plans

Progress and outcome measures

Health information is special category personal data under UK GDPR and receives additional protection.

Coaching and rehabilitation informationFor online coaching and rehabilitation, I may collect:

Exercise history

Training experience

Goals

Exercise preferences

Training availability

Exercise performance

Programme adherence

Exercise feedback

Symptoms and responses to exercise

Progress information

Photographs where voluntarily provided

Other information necessary to safely provide your programme

I aim to collect only information that is necessary for the service being provided.

3. How I collect informationI

nformation may be collected when you:

Contact me

Make a booking

Complete a consultation or health screening form

Attend an appointment or Pilates class

Complete a physiotherapy assessment

Participate in an online rehabilitation or coaching programme

Complete an online check-in

Communicate with me by email, telephone or messaging

Use my website

Provide information voluntarily during your treatment or programme

4. Why I use your informationI use your information to:

Provide physiotherapy assessment and treatment

Provide pelvic health physiotherapy

Provide sports injury management

Provide Pilates services

Provide pregnancy and postpartum rehabilitation

Provide online rehabilitation and coaching

Assess whether treatment or exercise is appropriate

Develop and adapt exercise programmes

Monitor your progress

Communicate with you about appointments and programmes

Manage bookings and cancellations

Process payments

Maintain appropriate clinical records

Meet professional and legal obligations

Protect your health and safety

Deal with complaints or concerns

Manage and protect my business

5. Lawful basis for using your informationFor ordinary personal information, I may rely on:

Contract – where processing is necessary to provide a service you have requested or purchased.

Legitimate interests – where necessary to operate and administer my business, provided your rights do not override those interests.

Legal obligation – where I am required to process information by law.

Consent – where consent is the appropriate lawful basis, such as certain optional marketing activities.

For health information, which is special category data, I rely on an applicable Article 9 condition alongside the relevant Article 6 lawful basis.For physiotherapy and healthcare-related services, processing may be necessary for the provision and management of health care by a health professional subject to a professional obligation of secrecy.Where I rely on consent, you can withdraw that consent at any time. Withdrawal of consent does not affect processing that took place before withdrawal.6. Clinical recordsYour clinical information is maintained as part of your physiotherapy record.Clinical records may include your assessment, relevant medical history, clinical findings, treatment, advice, rehabilitation and communications relating to your care.I maintain records in accordance with applicable legal, professional and regulatory requirements.Clinical records are stored securely and are not automatically deleted simply because you stop attending treatment.

7. ClinikoI use Cliniko as my practice management and clinical record system.

Cliniko may be used for:

Appointment booking

Client administration

Clinical records

Treatment notes

Forms and questionnaires

Appointment communications

Relevant practice administration

Cliniko acts as a data processor for information processed on my behalf. Cliniko provides data protection documentation and security measures intended to support healthcare businesses using the platform.

8. EverfitI use Everfit to deliver online coaching and rehabilitation programmes.

Everfit may contain:

Exercise programmes

Exercise demonstrations

Exercise tracking

Programme progress

Exercise feedback

Coaching communications

Check-ins

Relevant information required to safely deliver your programme

I will aim to keep the amount of personal and health information stored in Everfit to the minimum necessary.Where appropriate, detailed clinical information will remain in my clinical record in Cliniko rather than being duplicated in Everfit. Everfit states that it predominantly acts as a processor for health and fitness professionals using its platform. (Everfit)

9. Other service providersI may use third-party providers to operate my business, including providers for:

Website hosting

Appointment scheduling

Clinical records

Online coaching

Payments

Email and communications

Website analytics

Business administration

Where another organisation processes information on my behalf, I take reasonable steps to ensure appropriate data protection and security arrangements are in place.

10. Sharing information

I will not sell your personal information.I may share relevant information where necessary and lawful with:

Other healthcare professionals involved in your care

Service providers processing information on my behalf

Professional advisers

Insurers where necessary

Legal or regulatory authorities where legally required

Where information is shared for your direct care, I will normally seek your consent where appropriate unless there is another lawful basis to share it.Only information that is relevant and necessary will be shared.11. MarketingI may contact you about my services, classes, programmes or offers where I have an appropriate lawful basis.You can opt out of marketing at any time.Your clinical or health information will not be used for marketing without an appropriate lawful basis and, where required, your specific consent.12. Photographs and videosI may occasionally take photographs or videos during Pilates sessions, rehabilitation sessions or business activities.Where you can be identified and the material is intended for marketing or social media, I will obtain appropriate permission before using it.Agreeing to photography or marketing use is not a condition of receiving treatment or participating in a programme.

13. Data securityI take reasonable technical and organisational measures to protect your information against:

Unauthorised access

Loss

Misuse

Unauthorised disclosure

Accidental destruction

Unauthorised alteration

Systems containing sensitive information will be protected using appropriate passwords and security controls.Where available, additional security measures such as two-factor authentication will be used.

14. How long I keep your informationI retain information only for as long as necessary and in accordance with applicable legal, professional, insurance and regulatory requirements.Clinical records are retained according to the applicable retention requirements for physiotherapy records.Other information, including booking, financial and marketing information, is retained according to its purpose and applicable legal requirements.Information will be securely deleted or destroyed when it is no longer required.

15. Your rightsDepending on the circumstances, you may have the right to:

Request access to your personal information

Request correction of inaccurate information

Request deletion in certain circumstances

Request restriction of processing

Object to certain processing

Request data portability

Withdraw consent where consent is the lawful basis

Receive information about how your data is being used

Some rights are subject to legal exemptions, particularly in relation to professional records.To exercise your rights, contact: sgphysiopilates@gmail.com

 

16. Data breachesIf I become aware of a personal data breach, I will assess it promptly and take appropriate action in accordance with UK GDPR requirements.This may include containing the breach, assessing the risk to affected individuals, documenting the incident and notifying the ICO and/or affected individuals where legally required.

17. ComplaintsIf you have concerns about how your personal information has been handled, please contact me first.You can also complain to the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator.

18. Changes to this noticeThis privacy notice may be updated from time to time to reflect changes in my services, systems, legal requirements or how personal information is processed.The current version will be available on my website.Last updated: September 2026

 

 

SG Physiotherapy & Pilates

Internal Data Protection Policies

Owner: SG Physiotherapy & Pilates
Review date: September 2027
Last updated: September 2026

​

A. Data Retention Policy

Purpose

This policy explains how SG Physiotherapy & Pilates retains and securely disposes of personal and health information.

Clinical records

Clinical records will be retained for the period required by applicable Northern Ireland health-record guidance, professional requirements, insurance requirements and limitation periods.

As a working policy, adult physiotherapy records will be retained for at least eight years from the date of last treatment, subject to confirmation against the current Northern Ireland retention guidance.

Children’s records will be retained in accordance with the applicable requirements for children’s health records.

The retention period will be reviewed if relevant guidance changes.

CSP guidance states that private practitioners should consider the retention guidance applicable to their UK country and practice context. (The Chartered Society of Physiotherapy)

Coaching records

Information stored in Everfit will be limited to what is necessary to provide the coaching or rehabilitation service.

When a coaching programme ends, information will be reviewed and deleted or anonymised when it is no longer required, subject to any clinical, legal, insurance or professional requirement to retain it.

Where information forms part of the clinical record, the relevant information will be retained in accordance with the clinical record retention period.

Booking information

Booking and appointment information will be retained only for as long as necessary for administration, clinical, legal, insurance and accounting purposes.

Financial information

Financial records will be retained for the period required by applicable tax and accounting requirements.

Marketing information

Marketing information will be deleted or suppressed when it is no longer required or when an individual has withdrawn from marketing communications.

Secure disposal

When information is no longer required, it will be:

  • Securely deleted from electronic systems where appropriate

  • Securely destroyed in physical form

  • Removed from active systems

  • Anonymised where appropriate

B. Special Category Data Policy

SG Physiotherapy & Pilates processes health information because it is necessary to provide physiotherapy, rehabilitation, Pilates and coaching services safely and appropriately.

Health information includes information about injuries, symptoms, diagnoses, medical history, pregnancy, postpartum status, pelvic health and exercise responses.

Data protection principles

I will:

Lawfulness, fairness and transparency
Process information using a documented lawful basis and explain processing through the client privacy notice.

Purpose limitation
Use information only for specified and legitimate purposes.

Data minimisation
Collect only information necessary for treatment, rehabilitation, coaching, administration or legal/professional requirements.

Accuracy
Take reasonable steps to ensure information is accurate and up to date.

Storage limitation
Retain information only for as long as necessary.

Security
Use appropriate technical and organisational measures to protect information.

Accountability
Maintain appropriate records demonstrating compliance.

Systems

Clinical information is primarily maintained in Cliniko.

Everfit is used for delivery of online exercise, coaching and rehabilitation programmes.

Information will not be unnecessarily duplicated between systems.

Access

Access to personal information is restricted to the people and systems that require it for legitimate business, clinical or administrative purposes.

Review

This policy will be reviewed at least annually and whenever there is a significant change to:

  • Services

  • Software

  • Data processing

  • Legal requirements

  • Business structure

C. Data Breach Procedure

A data breach includes loss, theft, accidental disclosure, unauthorised access, hacking or accidental destruction of personal information.

Step 1 — Contain

Take immediate steps to prevent further access or disclosure.

Examples include:

  • Change passwords

  • Revoke access

  • Contact the relevant software provider

  • Recover a misdirected email

  • Secure a lost device

  • Disconnect compromised equipment

Step 2 — Record

Document:

  • What happened

  • When it happened

  • What information was involved

  • Who may have been affected

  • How many people may be affected

  • Immediate action taken

Step 3 — Assess risk

Consider:

  • Whether health information was involved

  • Whether the information could cause harm

  • Whether individuals could be identified

  • Whether the information was encrypted

  • Whether the information has been recovered

  • Whether the breach could lead to identity theft, distress, discrimination or other harm

Step 4 — ICO notification

Where legally required, notify the ICO without undue delay and, where applicable, within 72 hours of becoming aware of a reportable personal data breach.

Step 5 — Notify affected individuals

Where the breach is likely to result in a high risk to affected individuals, provide appropriate information and advice to those individuals.

Step 6 — Review

After the incident:

  • Identify why the breach happened

  • Implement corrective action

  • Update procedures if necessary

  • Record the outcome

D. Subject Access Request Procedure

Individuals may request access to their personal information.

Requests should be made to:

sgphysiopilates@gmail.com

On receiving a request:

  1. Record the date received.

  2. Verify the person’s identity where reasonably necessary.

  3. Identify the information requested.

  4. Search relevant systems, including Cliniko and Everfit where applicable.

  5. Review information for third-party confidentiality and applicable exemptions.

  6. Provide the information securely.

  7. Record how the request was handled.

Requests will normally be responded to within one month in accordance with UK GDPR requirements, subject to applicable extensions or exemptions.

E. Data Protection by Design

When introducing a new service, software platform or method of collecting information, SG Physiotherapy & Pilates will consider:

  • What information is genuinely necessary?

  • Does the service involve health information?

  • Where will the information be stored?

  • Who can access it?

  • Is the provider acting as a processor or controller?

  • Is there a suitable data processing agreement?

  • Are international transfers involved?

  • What security measures are available?

  • How long will the information be retained?

  • Does the processing create a high risk requiring a DPIA?

Before introducing a new platform, the privacy and security documentation of the provider should be reviewed.

F. Data Protection Impact Assessment Trigger

A DPIA will be considered before introducing processing that may create a high risk to individuals.

Examples may include:

  • Large-scale processing of health information

  • New technologies involving sensitive information

  • Extensive monitoring or profiling

  • Significant changes to how client health information is processed

Where appropriate, a DPIA will document the purpose, necessity, proportionality, risks and safeguards.

Policy owner: SG Physiotherapy & Pilates
Next review: September 2027

bottom of page