Emma Nicholas Neuro Physio
Privacy Policy
Effective date: 22 February 2026
1. Data Controller
Business name: Emma Nicholas Neuro Physio Physiotherapist: Emma Nicholas
Address: Cromwell Cottage, Church Lane, Ropley, SO24 0EA Email: emmanicholasneurophysio@gmail.com
2. Personal Data Collected
Personal data includes contact details, date of birth, medical history, neurological condition information, assessment findings, treatment notes, consent records, appointment details, invoices, and correspondence.
3. How Data Is Collected
Information is collected directly from clients via forms, consultations, communication, and treatment sessions.
4. Lawful Basis for Processing
Data is processed under consent, contractual necessity, legal obligation, vital interests, and legitimate interests. Health data is processed under Article 9(2)(h) UK GDPR for healthcare purposes.
5. Use of Personal Data
Data is used to provide safe and effective neurological physiotherapy, maintain clinical records, manage appointments and payments, and comply with legal and professional obligations.
6. Data Storage and Security
Records are stored securely in password-protected electronic systems or locked storage. Only the physiotherapist has access to identifiable data.
7. Data Sharing
Data is not shared without consent unless legally required, for safeguarding, or with other healthcare professionals involved in care with permission.
8. Data Retention
Adult records are retained for 8 years, children’s records until age 25, and financial records for 6 years, after which data is securely destroyed.
9. Your Rights
You have the right to access, rectify, erase (where permitted), restrict processing, withdraw consent, and request data portability.
10. Complaints
Concerns should be raised directly. Complaints may also be made to the Information Commissioner’s Office (ICO).
11. Policy Updates
This policy may be updated periodically. The most recent version will be available on request.